CVE tracker
363 subscribers
4.96K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-4354 - Tenda DAP-1520 Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-4354
Published : May 6, 2025, 1:15 p.m. | 1 hour, 34 minutes ago
Description : A vulnerability was found in Tenda DAP-1520 1.10B04_BETA02 and classified as critical. Affected by this issue is the function check_dws_cookie of the file /storage. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4355 - Tenda DAP-1520 Heap-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-4355
Published : May 6, 2025, 1:15 p.m. | 1 hour, 34 minutes ago
Description : A vulnerability was found in Tenda DAP-1520 1.10B04_BETA02. It has been classified as critical. This affects the function set_ws_action of the file /dws/api/. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4356 - Tenda DAP-1520 Stack-Based Buffer Overflow in Authentication Handler

CVE ID : CVE-2025-4356
Published : May 6, 2025, 2:15 p.m. | 34 minutes ago
Description : A vulnerability was found in Tenda DAP-1520 1.10B04_BETA02. It has been declared as critical. This vulnerability affects the function mod_graph_auth_uri_handler of the file /storage of the component Authentication Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4357 - Tenda RX3 Command Injection Vulnerability

CVE ID : CVE-2025-4357
Published : May 6, 2025, 2:15 p.m. | 34 minutes ago
Description : A vulnerability was found in Tenda RX3 16.03.13.11_multi. It has been rated as critical. This issue affects some unknown processing of the file /goform/telnet. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4358 - PHPGurukul Company Visitor Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4358
Published : May 6, 2025, 2:15 p.m. | 34 minutes ago
Description : A vulnerability classified as critical has been found in PHPGurukul Company Visitor Management System 2.0. Affected is an unknown function of the file /admin-profile.php. The manipulation of the argument adminname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4359 - iSourcecode Gym Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4359
Published : May 6, 2025, 2:15 p.m. | 34 minutes ago
Description : A vulnerability classified as critical was found in itsourcecode Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_member. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22479 - Dell Storage Center - Dell Storage Manager Path Traversal Vulnerability

CVE ID : CVE-2025-22479
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-23379 - Dell Storage Center - Dell Storage Manager Cross-site Scripting

CVE ID : CVE-2025-23379
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45487 - Linksys E5600 Command Injection Vulnerability

CVE ID : CVE-2025-45487
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45488 - Linksys E5600 Command Injection Vulnerability

CVE ID : CVE-2025-45488
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45489 - Linksys E5600 Command Injection Vulnerability

CVE ID : CVE-2025-45489
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45490 - Linksys E5600 Command Injection Vulnerability

CVE ID : CVE-2025-45490
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45491 - Linksys E5600 Command Injection Vulnerability

CVE ID : CVE-2025-45491
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45492 - Netgear EX8000 Command Injection Vulnerability

CVE ID : CVE-2025-45492
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the Iface parameter in the action_wireless function.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4363 - iSourcecode Gym Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4363
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : A vulnerability, which was classified as critical, has been found in itsourcecode Gym Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=end_membership. The manipulation of the argument rid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4368 - Tenda AC8 Buffer Overflow Vulnerability

CVE ID : CVE-2025-4368
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : A vulnerability, which was classified as critical, was found in Tenda AC8 16.03.34.06. Affected is the function formGetRouterStatus of the file /goform/MtuSetMacWan. The manipulation of the argument shareSpeed leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4384 - PcVue MQTT Certificate Validation Bypass

CVE ID : CVE-2025-4384
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet become valid. This allows malicious devices to present certificates that are not rejected properly. The use of a client certificate reduces the risk for random devices to take advantage of this flaw.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-33770 - "RealtyX SQL Injection"

CVE ID : CVE-2023-33770
Published : May 6, 2025, 5:15 p.m. | 1 hour, 34 minutes ago
Description : Real Estate Management System v1.0 was discovered to contain a SQL injection vulnerability via the message parameter at /contact.php.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22476 - Dell Storage Center Dell Storage Manager Command Injection

CVE ID : CVE-2025-22476
Published : May 6, 2025, 5:15 p.m. | 1 hour, 34 minutes ago
Description : Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-26262 - R-fx Networks Linux Malware Detect Arbitrary Code Execution and Privilege Escalation

CVE ID : CVE-2025-26262
Published : May 6, 2025, 5:15 p.m. | 1 hour, 34 minutes ago
Description : An issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate privileges and execute arbitrary code via supplying a file that contains a crafted filename.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30165 - vLLM ZeroMQ Remote Code Execution Vulnerability

CVE ID : CVE-2025-30165
Published : May 6, 2025, 5:16 p.m. | 1 hour, 33 minutes ago
Description : vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, vLLM uses ZeroMQ for some multi-node communication purposes. The secondary vLLM hosts open a `SUB` ZeroMQ socket and connect to an `XPUB` socket on the primary vLLM host. When data is received on this `SUB` socket, it is deserialized with `pickle`. This is unsafe, as it can be abused to execute code on a remote machine. Since the vulnerability exists in a client that connects to the primary vLLM host, this vulnerability serves as an escalation point. If the primary vLLM host is compromised, this vulnerability could be used to compromise the rest of the hosts in the vLLM deployment. Attackers could also use other means to exploit the vulnerability without requiring access to the primary vLLM host. One example would be the use of ARP cache poisoning to redirect traffic to a malicious endpoint used to deliver a payload with arbitrary code to execute on the target machine. Note that this issue only affects the V0 engine, which has been off by default since v0.8.0. Further, the issue only applies to a deployment using tensor parallelism across multiple hosts, which we do not expect to be a common deployment pattern. Since V0 is has been off by default since v0.8.0 and the fix is fairly invasive, the maintainers of vLLM have decided not to fix this issue. Instead, the maintainers recommend that users ensure their environment is on a secure network in case this pattern is in use. The V1 engine is not affected by this issue.
Severity: 8.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...