CVE tracker
389 subscribers
5.53K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-6872 - SourceCodester Simple Company Website Unrestricted File Upload Vulnerability

CVE ID : CVE-2025-6872
Published : June 29, 2025, 9:15 p.m. | 3 hours, 3 minutes ago
Description : A vulnerability classified as critical was found in SourceCodester Simple Company Website 1.0. This vulnerability affects unknown code of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument img leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6873 - SourceCodester Simple Company Website File Upload Vulnerability

CVE ID : CVE-2025-6873
Published : June 29, 2025, 10:15 p.m. | 2 hours, 3 minutes ago
Description : A vulnerability, which was classified as critical, has been found in SourceCodester Simple Company Website 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6874 - SourceCodester Best Salon Management System SQL Injection Vulnerability

CVE ID : CVE-2025-6874
Published : June 29, 2025, 10:15 p.m. | 2 hours, 3 minutes ago
Description : A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/add_subscribe.php. The manipulation of the argument user_id/plan_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6875 - SourceCodester Best Salon Management System SQL Injection

CVE ID : CVE-2025-6875
Published : June 29, 2025, 11:15 p.m. | 1 hour, 3 minutes ago
Description : A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /panel/edit-subscription.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6876 - SourceCodester Best Salon Management System SQL Injection Vulnerability

CVE ID : CVE-2025-6876
Published : June 29, 2025, 11:15 p.m. | 1 hour, 3 minutes ago
Description : A vulnerability was found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /panel/add-category.php. The manipulation of the argument Name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6877 - SourceCodester Best Salon Management System SQL Injection Vulnerability

CVE ID : CVE-2025-6877
Published : June 30, 2025, 12:15 a.m. | 4 hours, 4 minutes ago
Description : A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /panel/edit-category.php. The manipulation of the argument editid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6878 - SourceCodester Best Salon Management System SQL Injection

CVE ID : CVE-2025-6878
Published : June 30, 2025, 1:15 a.m. | 3 hours, 3 minutes ago
Description : A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /panel/search-appointment.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6879 - "SourceCodester Best Salon Management System SQL Injection"

CVE ID : CVE-2025-6879
Published : June 30, 2025, 1:15 a.m. | 3 hours, 3 minutes ago
Description : A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /panel/add-tax.php. The manipulation of the argument Name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6880 - SourceCodester Best Salon Management System SQL Injection Vulnerability

CVE ID : CVE-2025-6880
Published : June 30, 2025, 1:15 a.m. | 3 hours, 3 minutes ago
Description : A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit-tax.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-0634 - Samsung rLottie After Free Remote Code Inclusion Vulnerability

CVE ID : CVE-2025-0634
Published : June 30, 2025, 2:15 a.m. | 2 hours, 4 minutes ago
Description : Use After Free vulnerability in Samsung Open Source rLottie allows Remote Code Inclusion.This issue affects rLottie: V0.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46014 - Honor PC Manager Named Pipe Privilege Escalation Vulnerability

CVE ID : CVE-2025-46014
Published : June 30, 2025, 2:15 a.m. | 2 hours, 4 minutes ago
Description : Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or overly permissive security attributes, leading to a privilege escalation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-53075 - Samsung Open Source rLottie Path Traversal Vulnerability

CVE ID : CVE-2025-53075
Published : June 30, 2025, 2:15 a.m. | 2 hours, 4 minutes ago
Description : Improper Input Validation vulnerability in Samsung Open Source rLottie allows Path Traversal.This issue affects rLottie: V0.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6881 - D-Link jhttpd PPPoE Buffer Overflow Vulnerability

CVE ID : CVE-2025-6881
Published : June 30, 2025, 2:15 a.m. | 2 hours, 4 minutes ago
Description : A vulnerability was found in D-Link DI-8100 16.07.21. It has been rated as critical. Affected by this issue is some unknown functionality of the file /pppoe_base.asp of the component jhttpd. The manipulation of the argument mschap_en leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-53074 - Samsung Open Source rLottie Out-of-bounds Read Overflow

CVE ID : CVE-2025-53074
Published : June 30, 2025, 3:15 a.m. | 1 hour, 3 minutes ago
Description : Out-of-bounds Read vulnerability in Samsung Open Source rLottie allows Overflow Buffers.This issue affects rLottie: V0.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-53076 - Samsung Open Source rLottie Overread Buffer Vulnerability

CVE ID : CVE-2025-53076
Published : June 30, 2025, 3:15 a.m. | 1 hour, 3 minutes ago
Description : Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers.This issue affects rLottie: V0.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6882 - D-Link DIR-513 Buffer Overflow Vulnerability

CVE ID : CVE-2025-6882
Published : June 30, 2025, 3:15 a.m. | 1 hour, 3 minutes ago
Description : A vulnerability classified as critical has been found in D-Link DIR-513 1.0. This affects an unknown part of the file /goform/formSetWanPPTP. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6883 - Code-Projects Staff Audit System SQL Injection

CVE ID : CVE-2025-6883
Published : June 30, 2025, 3:15 a.m. | 1 hour, 3 minutes ago
Description : A vulnerability classified as critical was found in code-projects Staff Audit System 1.0. This vulnerability affects unknown code of the file /update_index.php. The manipulation of the argument updateid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6884 - Apache Code-projects Staff Audit System SQL Injection Vulnerability

CVE ID : CVE-2025-6884
Published : June 30, 2025, 3:15 a.m. | 1 hour, 3 minutes ago
Description : A vulnerability, which was classified as critical, has been found in code-projects Staff Audit System 1.0. This issue affects some unknown processing of the file /search_index.php. The manipulation of the argument Search leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6885 - PHPGurukul Teachers Record Management System SQL Injection Vulnerability

CVE ID : CVE-2025-6885
Published : June 30, 2025, 4:15 a.m. | 4 hours, 3 minutes ago
Description : A vulnerability, which was classified as critical, was found in PHPGurukul Teachers Record Management System 2.1. Affected is an unknown function of the file /admin/edit-teacher-detail.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6886 - Tenda AC5 Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-6886
Published : June 30, 2025, 5:15 a.m. | 3 hours, 3 minutes ago
Description : A vulnerability has been found in Tenda AC5 15.03.06.47 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime/schedEndTime leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6887 - Tenda AC5 Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-6887
Published : June 30, 2025, 5:15 a.m. | 3 hours, 3 minutes ago
Description : A vulnerability was found in Tenda AC5 15.03.06.47 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/SetSysTimeCfg. The manipulation of the argument time/timeZone leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...