CVE tracker
280 subscribers
3.76K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-6484 - Code-projects Online Shopping Store SQL Injection

CVE ID : CVE-2025-6484
Published : June 22, 2025, 5:15 p.m. | 2 hours, 59 minutes ago
Description : A vulnerability was found in code-projects Online Shopping Store 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /action.php. The manipulation of the argument cat_id/brand_id/keyword/proId/pid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6485 - TOTOLINK A3002R OS Command Injection Vulnerability

CVE ID : CVE-2025-6485
Published : June 22, 2025, 5:15 p.m. | 2 hours, 59 minutes ago
Description : A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been classified as critical. This affects the function formWlSiteSurvey of the file /boafrm/formWlSiteSurvey. The manipulation of the argument wlanif leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6486 - TOTOLINK A3002R Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-6486
Published : June 22, 2025, 6:15 p.m. | 1 hour, 59 minutes ago
Description : A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been declared as critical. This vulnerability affects the function formWlanMultipleAP of the file /boafrm/formWlanMultipleAP. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6487 - TOTOLINK A3002R Stack-Based Buffer Overflow

CVE ID : CVE-2025-6487
Published : June 22, 2025, 6:15 p.m. | 1 hour, 59 minutes ago
Description : A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been rated as critical. This issue affects the function formRoute of the file /boafrm/formRoute. The manipulation of the argument subnet leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6489 - iSourcecode Agri-Trading Online Shopping System SQL Injection Vulnerability

CVE ID : CVE-2025-6489
Published : June 22, 2025, 7:15 p.m. | 59 minutes ago
Description : A vulnerability has been found in itsourcecode Agri-Trading Online Shopping System 1.0 and classified as critical. This vulnerability affects unknown code of the file /transactionsave.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6490 - Nokogiri Heap-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-6490
Published : June 22, 2025, 7:15 p.m. | 59 minutes ago
Description : A vulnerability was found in sparklemotion nokogiri up to 1.18.7 and classified as problematic. This issue affects the function hashmap_set_with_hash of the file gumbo-parser/src/hashmap.c. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6492 - MarkText Regular Expression Complexity Remote Vulnerability

CVE ID : CVE-2025-6492
Published : June 22, 2025, 8:15 p.m. | 3 hours, 59 minutes ago
Description : A vulnerability has been found in MarkText up to 0.17.1 and classified as problematic. Affected by this vulnerability is the function getRecommendTitleFromMarkdownString of the file marktext/src/main/utils/index.js. The manipulation leads to inefficient regular expression complexity. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6493 - CodeMirror Markdown Mode Regular Expression Complexity Remote Vulnerability

CVE ID : CVE-2025-6493
Published : June 22, 2025, 10:15 p.m. | 1 hour, 59 minutes ago
Description : A vulnerability was found in CodeMirror up to 5.17.0 and classified as problematic. Affected by this issue is some unknown functionality of the file mode/markdown/markdown.js of the component Markdown Mode. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Not all code samples mentioned in the GitHub issue can be found. The repository mentions, that "CodeMirror 6 exists, and is [...] much more actively maintained."
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6494 - Nokogiri Heap-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-6494
Published : June 22, 2025, 11:15 p.m. | 59 minutes ago
Description : A vulnerability was found in sparklemotion nokogiri up to 1.18.7. It has been classified as problematic. This affects the function hashmap_get_with_hash of the file gumbo-parser/src/hashmap.c. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6496 - Apache Tidy Null Pointer Dereference Vulnerability

CVE ID : CVE-2025-6496
Published : June 23, 2025, 12:15 a.m. | 3 hours, 59 minutes ago
Description : A vulnerability was found in HTACG tidy-html5 5.8.0. It has been declared as problematic. This vulnerability affects the function InsertNodeAsParent of the file src/parser.c. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52926 - Spytrap-ADB Stalkerware Detection UI Vulnerability

CVE ID : CVE-2025-52926
Published : June 23, 2025, 1:15 a.m. | 2 hours, 59 minutes ago
Description : In scan.rs in spytrap-adb before 0.3.5, matches for known stalkerware are not rendered in the interactive user interface.
Severity: 2.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6497 - "HTACG Tidy-html5 Assertion Vulnerability"

CVE ID : CVE-2025-6497
Published : June 23, 2025, 1:15 a.m. | 2 hours, 59 minutes ago
Description : A vulnerability was found in HTACG tidy-html5 5.8.0. It has been rated as problematic. This issue affects the function prvTidyParseNamespace of the file src/parser.c. The manipulation leads to reachable assertion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6498 - HTACG Tidy-HTML5 Memory Leak Vulnerability

CVE ID : CVE-2025-6498
Published : June 23, 2025, 2:15 a.m. | 1 hour, 59 minutes ago
Description : A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the function defaultAlloc of the file src/alloc.c. The manipulation leads to memory leak. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6499 - Apache vstakhov libucl Heap-Based Buffer Overflow

CVE ID : CVE-2025-6499
Published : June 23, 2025, 3:15 a.m. | 59 minutes ago
Description : A vulnerability classified as problematic was found in vstakhov libucl up to 0.9.2. Affected by this vulnerability is the function ucl_parse_multiline_string of the file src/ucl_parser.c. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6500 - Code-projects Inventory Management System SQL Injection

CVE ID : CVE-2025-6500
Published : June 23, 2025, 3:15 a.m. | 59 minutes ago
Description : A vulnerability, which was classified as critical, has been found in code-projects Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /php_action/editCategories.php. The manipulation of the argument editCategoriesName leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6501 - Apache Code-projects Inventory Management System SQL Injection

CVE ID : CVE-2025-6501
Published : June 23, 2025, 3:15 a.m. | 59 minutes ago
Description : A vulnerability, which was classified as critical, was found in code-projects Inventory Management System 1.0. This affects an unknown part of the file /php_action/createCategories.php. The manipulation of the argument categoriesStatus leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6502 - Code-projects Inventory Management System SQL Injection Critical Vulnerability

CVE ID : CVE-2025-6502
Published : June 23, 2025, 4:15 a.m. | 3 hours, 59 minutes ago
Description : A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php_action/changePassword.php. The manipulation of the argument user_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6503 - Code-projects Inventory Management System SQL Injection

CVE ID : CVE-2025-6503
Published : June 23, 2025, 4:15 a.m. | 3 hours, 59 minutes ago
Description : A vulnerability was found in code-projects Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /php_action/fetchSelectedCategories.php. The manipulation of the argument categoriesId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-3511 - WSO2 Registry Unauthorized File Access Vulnerability

CVE ID : CVE-2024-3511
Published : June 23, 2025, 9:15 a.m. | 3 hours ago
Description : An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console can exploit a specific bypass method to retrieve versioned files without proper authorization. Successful exploitation of this vulnerability could lead to unauthorized disclosure of configuration or resource files that may be stored as registry versions, potentially aiding further attacks or system reconnaissance.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-45347 - Xiaomi Mi Connect Service APP Unauthorized Access Vulnerability

CVE ID : CVE-2024-45347
Published : June 23, 2025, 10:15 a.m. | 2 hours ago
Description : An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to Unauthorized access to the victim’s device.
Severity: 9.6 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27387 - OPPO Clone Phone Weak Password WiFi Hotspot Information Disclosure

CVE ID : CVE-2025-27387
Published : June 23, 2025, 10:15 a.m. | 2 hours ago
Description : OPPO Clone Phone uses a weak password WiFi hotspot to transfer files, resulting in Information disclosure.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...