CVE tracker
363 subscribers
4.96K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-4350 - D-Link DIR-600L Wake-on-LAN Command Injection Vulnerability

CVE ID : CVE-2025-4350
Published : May 6, 2025, 12:15 p.m. | 2 hours, 34 minutes ago
Description : A vulnerability classified as critical was found in D-Link DIR-600L up to 2.07B01. This vulnerability affects the function wake_on_lan. The manipulation of the argument host leads to command injection. The attack can be initiated remotely. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4352 - Golden Link Secondary System SQL Injection Vulnerability

CVE ID : CVE-2025-4352
Published : May 6, 2025, 12:15 p.m. | 2 hours, 34 minutes ago
Description : A vulnerability, which was classified as critical, has been found in Golden Link Secondary System up to 20250424. This issue affects some unknown processing of the file /reprotframework/tcEntrFlowSelect.htm. The manipulation of the argument custTradeId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4353 - Golden Link Secondary System SQL Injection Vulnerability

CVE ID : CVE-2025-4353
Published : May 6, 2025, 12:15 p.m. | 2 hours, 34 minutes ago
Description : A vulnerability, which was classified as critical, was found in Golden Link Secondary System up to 20250424. Affected is an unknown function of the file /paraframework/queryTsDictionaryType.htm. The manipulation of the argument dictCn1 leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2018-1359 - Apache HTTP Server Authentication Bypass

CVE ID : CVE-2018-1359
Published : May 6, 2025, 1:15 p.m. | 1 hour, 34 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4354 - Tenda DAP-1520 Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-4354
Published : May 6, 2025, 1:15 p.m. | 1 hour, 34 minutes ago
Description : A vulnerability was found in Tenda DAP-1520 1.10B04_BETA02 and classified as critical. Affected by this issue is the function check_dws_cookie of the file /storage. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4355 - Tenda DAP-1520 Heap-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-4355
Published : May 6, 2025, 1:15 p.m. | 1 hour, 34 minutes ago
Description : A vulnerability was found in Tenda DAP-1520 1.10B04_BETA02. It has been classified as critical. This affects the function set_ws_action of the file /dws/api/. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4356 - Tenda DAP-1520 Stack-Based Buffer Overflow in Authentication Handler

CVE ID : CVE-2025-4356
Published : May 6, 2025, 2:15 p.m. | 34 minutes ago
Description : A vulnerability was found in Tenda DAP-1520 1.10B04_BETA02. It has been declared as critical. This vulnerability affects the function mod_graph_auth_uri_handler of the file /storage of the component Authentication Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4357 - Tenda RX3 Command Injection Vulnerability

CVE ID : CVE-2025-4357
Published : May 6, 2025, 2:15 p.m. | 34 minutes ago
Description : A vulnerability was found in Tenda RX3 16.03.13.11_multi. It has been rated as critical. This issue affects some unknown processing of the file /goform/telnet. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4358 - PHPGurukul Company Visitor Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4358
Published : May 6, 2025, 2:15 p.m. | 34 minutes ago
Description : A vulnerability classified as critical has been found in PHPGurukul Company Visitor Management System 2.0. Affected is an unknown function of the file /admin-profile.php. The manipulation of the argument adminname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4359 - iSourcecode Gym Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4359
Published : May 6, 2025, 2:15 p.m. | 34 minutes ago
Description : A vulnerability classified as critical was found in itsourcecode Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_member. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22479 - Dell Storage Center - Dell Storage Manager Path Traversal Vulnerability

CVE ID : CVE-2025-22479
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-23379 - Dell Storage Center - Dell Storage Manager Cross-site Scripting

CVE ID : CVE-2025-23379
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45487 - Linksys E5600 Command Injection Vulnerability

CVE ID : CVE-2025-45487
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45488 - Linksys E5600 Command Injection Vulnerability

CVE ID : CVE-2025-45488
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45489 - Linksys E5600 Command Injection Vulnerability

CVE ID : CVE-2025-45489
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45490 - Linksys E5600 Command Injection Vulnerability

CVE ID : CVE-2025-45490
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45491 - Linksys E5600 Command Injection Vulnerability

CVE ID : CVE-2025-45491
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45492 - Netgear EX8000 Command Injection Vulnerability

CVE ID : CVE-2025-45492
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the Iface parameter in the action_wireless function.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4363 - iSourcecode Gym Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4363
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : A vulnerability, which was classified as critical, has been found in itsourcecode Gym Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=end_membership. The manipulation of the argument rid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4368 - Tenda AC8 Buffer Overflow Vulnerability

CVE ID : CVE-2025-4368
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : A vulnerability, which was classified as critical, was found in Tenda AC8 16.03.34.06. Affected is the function formGetRouterStatus of the file /goform/MtuSetMacWan. The manipulation of the argument shareSpeed leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4384 - PcVue MQTT Certificate Validation Bypass

CVE ID : CVE-2025-4384
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet become valid. This allows malicious devices to present certificates that are not rejected properly. The use of a client certificate reduces the risk for random devices to take advantage of this flaw.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...