CVE tracker
312 subscribers
4.42K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-7596 - Tenda FH1205 Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-7596
Published : July 14, 2025, 11:15 a.m. | 1 hour, 42 minutes ago
Description : A vulnerability was found in Tenda FH1205 2.0.0.7(775). It has been rated as critical. This issue affects the function formWifiExtraSet of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7597 - Tenda AX1803 Stack-Based Buffer Overflow

CVE ID : CVE-2025-7597
Published : July 14, 2025, 11:15 a.m. | 1 hour, 42 minutes ago
Description : A vulnerability classified as critical has been found in Tenda AX1803 1.0.0.1. Affected is the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7598 - Tenda AX1803 Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-7598
Published : July 14, 2025, 11:15 a.m. | 1 hour, 42 minutes ago
Description : A vulnerability classified as critical was found in Tenda AX1803 1.0.0.1. Affected by this vulnerability is the function formSetWifiMacFilterCfg of the file /goform/setWifiFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7618 - "ADM File Explorer and Text Editor Stored XSS"

CVE ID : CVE-2025-7618
Published : July 14, 2025, 11:15 a.m. | 1 hour, 42 minutes ago
Description : A stored Cross-Site Scripting (XSS) vulnerability vulnerability was found in the File Explorer and Text Editor of ADM. An attacker could exploit this vulnerability to inject malicious scripts into the applications, which may then access cookies or other sensitive information retained by the browser and used with the affected applications. Affected products and versions include: from ADM 4.1.0 to ADM 4.3.3.RH61 as well as ADM 5.0.0.RIN1 and earlier, and Text Editor 1.0.0.r112 and earlier.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7599 - PHPGurukul Dairy Farm Shop Management System SQL Injection Vulnerability

CVE ID : CVE-2025-7599
Published : July 14, 2025, 12:15 p.m. | 42 minutes ago
Description : A vulnerability, which was classified as critical, has been found in PHPGurukul Dairy Farm Shop Management System 1.3. Affected by this issue is some unknown functionality of the file /invoice.php. The manipulation of the argument del leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7600 - PHPGurukul Online Library Management System SQL Injection Vulnerability

CVE ID : CVE-2025-7600
Published : July 14, 2025, 12:15 p.m. | 42 minutes ago
Description : A vulnerability, which was classified as critical, was found in PHPGurukul Online Library Management System 3.0. This affects an unknown part of the file /admin/student-history.php. The manipulation of the argument stdid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7601 - PHPGurukul Online Library Management System Cross Site Scripting Vulnerability

CVE ID : CVE-2025-7601
Published : July 14, 2025, 12:15 p.m. | 42 minutes ago
Description : A vulnerability has been found in PHPGurukul Online Library Management System 3.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/student-history.php. The manipulation of the argument stdid leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7602 - D-Link DI-8100 HTTP Request Handler Stack-Based Buffer Overflow

CVE ID : CVE-2025-7602
Published : July 14, 2025, 12:15 p.m. | 42 minutes ago
Description : A vulnerability was found in D-Link DI-8100 16.07.26A1 and classified as critical. This issue affects some unknown processing of the file /arp_sys.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27582 - One Identity Password Manager Local Privilege Escalation Vulnerability

CVE ID : CVE-2025-27582
Published : July 14, 2025, 1:15 p.m. | 3 hours, 42 minutes ago
Description : The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issue arises from a flawed security hardening mechanism within the kiosk browser used to display the Password Self-Service site to end users. Specifically, the application attempts to restrict privileged actions by overriding the native window.print() function. However, this protection can be bypassed by an attacker who accesses the Password Self-Service site from the lock screen and navigates to an attacker-controlled webpage via the Help function. By hosting a crafted web page with JavaScript, the attacker can restore and invoke the window.print() function, launching a SYSTEM-privileged print dialog. From this dialog, the attacker can exploit standard Windows functionality - such as the Print to PDF or Add Printer wizard - to spawn a command prompt with SYSTEM privileges. Successful exploitation allows a local attacker (with access to a locked workstation) to gain SYSTEM-level privileges, granting full control over the affected device.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7603 - D-Link DI-8100 HTTP Request Handler Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-7603
Published : July 14, 2025, 1:15 p.m. | 3 hours, 42 minutes ago
Description : A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. Affected is an unknown function of the file /jingx.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7604 - PHPGurukul Hospital Management System SQL Injection Vulnerability

CVE ID : CVE-2025-7604
Published : July 14, 2025, 1:15 p.m. | 3 hours, 42 minutes ago
Description : A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /user-login.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7605 - AVL Rooms SQL Injection Vulnerability

CVE ID : CVE-2025-7605
Published : July 14, 2025, 1:15 p.m. | 3 hours, 42 minutes ago
Description : A vulnerability was found in code-projects AVL Rooms 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /profile.php. The manipulation of the argument first_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7606 - AVL Rooms SQL Injection Vulnerability

CVE ID : CVE-2025-7606
Published : July 14, 2025, 1:15 p.m. | 3 hours, 42 minutes ago
Description : A vulnerability classified as critical has been found in code-projects AVL Rooms 1.0. This affects an unknown part of the file /city.php. The manipulation of the argument city leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7519 - Polkit XML Policy Parsing Out-of-Bounds Write Vulnerability

CVE ID : CVE-2025-7519
Published : July 14, 2025, 2:15 p.m. | 2 hours, 42 minutes ago
Description : A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. To exploit this flaw, a high-privilege account is needed as it's required to place the malicious policy file properly.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7607 - Apache Simple Shopping Cart SQL Injection Vulnerability

CVE ID : CVE-2025-7607
Published : July 14, 2025, 2:15 p.m. | 2 hours, 42 minutes ago
Description : A vulnerability, which was classified as critical, has been found in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file /Customers/save_order.php. The manipulation of the argument order_price leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7608 - Apache Code-projects Simple Shopping Cart SQL Injection Vulnerability

CVE ID : CVE-2025-7608
Published : July 14, 2025, 2:15 p.m. | 2 hours, 42 minutes ago
Description : A vulnerability, which was classified as critical, was found in code-projects Simple Shopping Cart 1.0. Affected is an unknown function of the file /userlogin.php. The manipulation of the argument user_email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7609 - "Code-projects Simple Shopping Cart SQL Injection Vulnerability"

CVE ID : CVE-2025-7609
Published : July 14, 2025, 2:15 p.m. | 2 hours, 42 minutes ago
Description : A vulnerability has been found in code-projects Simple Shopping Cart 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument ruser_email leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7610 - Apache Code-projects Electricity Billing System SQL Injection Vulnerability

CVE ID : CVE-2025-7610
Published : July 14, 2025, 2:15 p.m. | 2 hours, 42 minutes ago
Description : A vulnerability was found in code-projects Electricity Billing System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user/change_password.php. The manipulation of the argument new_password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-50756 - Wavlink WN535K3 Command Injection Vulnerability

CVE ID : CVE-2025-50756
Published : July 14, 2025, 3:15 p.m. | 1 hour, 42 minutes ago
Description : Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the newpass parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7611 - "Code-Projects Wedding Reservation SQL Injection"

CVE ID : CVE-2025-7611
Published : July 14, 2025, 3:15 p.m. | 1 hour, 42 minutes ago
Description : A vulnerability was found in code-projects Wedding Reservation 1.0. It has been classified as critical. This affects an unknown part of the file /global.php. The manipulation of the argument lu leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7612 - "Code-projects Mobile Shop SQL Injection Vulnerability"

CVE ID : CVE-2025-7612
Published : July 14, 2025, 3:15 p.m. | 1 hour, 42 minutes ago
Description : A vulnerability was found in code-projects Mobile Shop 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...