CVE tracker
237 subscribers
3.17K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-60557 - D-Link DIR600L Ax Buffer Overflow Vulnerability

CVE ID : CVE-2025-60557
Published : Oct. 24, 2025, 4:22 p.m. | 2 hours, 56 minutes ago
Description : D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEasy_Wizard.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60558 - D-Link DIR600L Ax Buffer Overflow Vulnerability

CVE ID : CVE-2025-60558
Published : Oct. 24, 2025, 4:22 p.m. | 2 hours, 56 minutes ago
Description : D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formVirtualServ.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60559 - D-Link DIR600L Ax Buffer Overflow Vulnerability

CVE ID : CVE-2025-60559
Published : Oct. 24, 2025, 4:22 p.m. | 2 hours, 56 minutes ago
Description : D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetDomainFilter.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60561 - D-Link DIR600L Ax Buffer Overflow in formSetEmail

CVE ID : CVE-2025-60561
Published : Oct. 24, 2025, 4:23 p.m. | 2 hours, 55 minutes ago
Description : D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEmail.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60562 - D-Link DIR600L Ax Buffer Overflow Vulnerability

CVE ID : CVE-2025-60562
Published : Oct. 24, 2025, 4:23 p.m. | 2 hours, 55 minutes ago
Description : D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formWlSiteSurvey.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60563 - D-Link DIR600L Ax Buffer Overflow

CVE ID : CVE-2025-60563
Published : Oct. 24, 2025, 4:24 p.m. | 2 hours, 54 minutes ago
Description : D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetPortTr.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60564 - D-Link DIR600L Ax Buffer Overflow

CVE ID : CVE-2025-60564
Published : Oct. 24, 2025, 4:24 p.m. | 2 hours, 54 minutes ago
Description : D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetLog.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60565 - D-Link DIR600L Ax Buffer Overflow Vulnerability

CVE ID : CVE-2025-60565
Published : Oct. 24, 2025, 4:25 p.m. | 2 hours, 53 minutes ago
Description : D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSchedule.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60566 - D-Link DIR600L Ax Buffer Overflow Vulnerability

CVE ID : CVE-2025-60566
Published : Oct. 24, 2025, 4:25 p.m. | 2 hours, 53 minutes ago
Description : D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetMACFilter.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60801 - jshERP Unauthenticated Remote Code Execution Vulnerability

CVE ID : CVE-2025-60801
Published : Oct. 24, 2025, 4:26 p.m. | 2 hours, 52 minutes ago
Description : jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60803 - Antabot White-Jotter RCE

CVE ID : CVE-2025-60803
Published : Oct. 24, 2025, 4:26 p.m. | 2 hours, 52 minutes ago
Description : Antabot White-Jotter up to commit 9bcadc was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the component /api/aaa;/../register.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-62714 - Karmada Dashboard API Unauthorized Access Vulnerability

CVE ID : CVE-2025-62714
Published : Oct. 24, 2025, 4:28 p.m. | 2 hours, 50 minutes ago
Description : Karmada Dashboard is a general-purpose, web-based control panel for Karmada which is a multi-cluster management project. Prior to version 0.2.0, there is an authentication bypass vulnerability in the Karmada Dashboard API. The backend API endpoints (e.g., /api/v1/secret, /api/v1/service) did not enforce authentication, allowing unauthenticated users to access sensitive cluster information such as Secrets and Services directly. Although the web UI required a valid JWT for access, the API itself remained exposed to direct requests without any authentication checks. Any user or entity with network access to the Karmada Dashboard service could exploit this vulnerability to retrieve sensitive data.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60729 - PerfreeBlog Arbitrary File Read Vulnerability

CVE ID : CVE-2025-60729
Published : Oct. 24, 2025, 6:15 p.m. | 1 hour, 3 minutes ago
Description : PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60730 - PerfreeBlog Uninstall Theme Arbitrary File Deletion Vulnerability

CVE ID : CVE-2025-60730
Published : Oct. 24, 2025, 6:15 p.m. | 1 hour, 3 minutes ago
Description : PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60731 - PerfreeBlog File Upload Vulnerability

CVE ID : CVE-2025-60731
Published : Oct. 24, 2025, 6:15 p.m. | 1 hour, 3 minutes ago
Description : PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60735 - PerfreeBlog File Upload Vulnerability

CVE ID : CVE-2025-60735
Published : Oct. 24, 2025, 6:15 p.m. | 1 hour, 3 minutes ago
Description : PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60419 - Tenda Denial of Service Vulnerability

CVE ID : CVE-2025-60419
Published : Oct. 24, 2025, 8:16 p.m. | 3 hours, 4 minutes ago
Description : An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authenticated attackers to send a crafted IOCTL request to the driver to cause a denial of service.
Severity: 6.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-62716 - Plane Vulnerable to Cross-Site Scripting via Open Redirect in ?next_path Parameter

CVE ID : CVE-2025-62716
Published : Oct. 24, 2025, 8:17 p.m. | 3 hours, 3 minutes ago
Description : Plane is open-source project management software. Prior to version 1.1.0, an open redirect vulnerability in the ?next_path query parameter allows attackers to supply arbitrary schemes (e.g., javascript:) that are passed directly to router.push. This results in a cross-site scripting (XSS) vulnerability, enabling attackers to execute arbitrary JavaScript in the victim’s browser. The issue can be exploited without authentication and has severe impact, including information disclosure, and privilege escalation and modifications of administrative settings. This issue has been patched in version 1.1.0.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52099 - "SQLite Integer Overflow Denial of Service"

CVE ID : CVE-2025-52099
Published : Oct. 24, 2025, 9:15 p.m. | 2 hours, 5 minutes ago
Description : Integer Overflow vulnerability in SQLite SQLite3 v.3.50.0 allows a remote attacker to cause a denial of service via the setupLookaside function
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60954 - Microweber CMS Weak Password Requirements Vulnerability

CVE ID : CVE-2025-60954
Published : Oct. 24, 2025, 9:16 p.m. | 2 hours, 5 minutes ago
Description : Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-62717 - Emlog Pro session verification code error due to clearing logic error

CVE ID : CVE-2025-62717
Published : Oct. 24, 2025, 9:16 p.m. | 2 hours, 4 minutes ago
Description : Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing logic error. This means the verification code could be reused anywhere an email verification code is required. This issue has been fixed in commit 1f726df.
Severity: 2.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...