Aggregator
CVE-2007-4522 | Ripe Website Manager delete_menu.php ID cross site scripting (EDB-30518 / XFDB-36179)
3 weeks 4 days ago
A vulnerability labeled as problematic has been found in Ripe Website Manager. Affected by this issue is some unknown functionality of the file navigation/delete_menu.php. Such manipulation of the argument ID leads to basic cross site scripting.
This vulnerability is traded as CVE-2007-4522. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-4522 | Ripe Website Manager delete_item.php ID cross site scripting (EDB-30518 / XFDB-36179)
3 weeks 4 days ago
A vulnerability marked as problematic has been reported in Ripe Website Manager. This affects an unknown part of the file navigation/delete_item.php. Performing manipulation of the argument ID results in basic cross site scripting.
This vulnerability is known as CVE-2007-4522. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
CVE-2007-4522 | Ripe Website Manager do_new_item.php cross site scripting (EDB-30518 / XFDB-36179)
3 weeks 4 days ago
A vulnerability described as problematic has been identified in Ripe Website Manager. This vulnerability affects unknown code of the file admin/navigation/do_new_item.php. Executing manipulation can lead to basic cross site scripting.
This vulnerability is handled as CVE-2007-4522. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2007-4522 | Ripe Website Manager do_new_nav.php new_menuname cross site scripting (EDB-30518 / XFDB-36179)
3 weeks 4 days ago
A vulnerability classified as problematic has been found in Ripe Website Manager. This issue affects some unknown processing of the file admin/navigation/do_new_nav.php. The manipulation of the argument new_menuname leads to basic cross site scripting.
This vulnerability is uniquely identified as CVE-2007-4522. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
CVE-2007-4522 | Ripe Website Manager up to 0.8.4 new_menuname cross site scripting (EDB-30518 / XFDB-36180)
3 weeks 4 days ago
A vulnerability categorized as problematic has been discovered in Ripe Website Manager up to 0.8.4. Impacted is an unknown function. Executing manipulation of the argument new_menuname can lead to basic cross site scripting.
The identification of this vulnerability is CVE-2007-4522. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-2207 | Ripe Website Manager up to 0.8.4 contact/index.php ripeformpost sql injection (EDB-29877 / XFDB-33818)
3 weeks 4 days ago
A vulnerability categorized as critical has been discovered in Ripe Website Manager up to 0.8.4. Affected by this vulnerability is an unknown functionality of the file contact/index.php. The manipulation of the argument ripeformpost results in sql injection.
This vulnerability is identified as CVE-2007-2207. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2025-14187 | UGREEN DH2100+ up to 5.3.0.251125 nas_svr /v1/file/backup/create handler_file_backup_create path buffer overflow (EUVD-2025-201596)
3 weeks 4 days ago
A vulnerability was found in UGREEN DH2100+ up to 5.3.0.251125. It has been declared as critical. This affects the function handler_file_backup_create of the file /v1/file/backup/create of the component nas_svr. Executing manipulation of the argument path can lead to buffer overflow.
This vulnerability is handled as CVE-2025-14187. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-21879 | Linux Kernel up to 6.13.5 btrfs_scan_root use after free (EUVD-2025-8487 / WID-SEC-2025-0649)
3 weeks 4 days ago
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.13.5. Affected is the function btrfs_scan_root. Such manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2025-21879. Local access is required to approach this attack. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-21877 | Linux Kernel up to 6.13.5 gl620a Driver drivers/usb/core/urb.c genelink_bind information disclosure (Nessus ID 234309 / WID-SEC-2025-0649)
3 weeks 4 days ago
A vulnerability was found in Linux Kernel up to 6.13.5. It has been classified as problematic. The impacted element is the function genelink_bind of the file drivers/usb/core/urb.c of the component gl620a Driver. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2025-21877. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-21878 | Linux Kernel up to 6.13.5 npcm devm_request_irq denial of service (Nessus ID 234309 / WID-SEC-2025-0649)
3 weeks 4 days ago
A vulnerability was found in Linux Kernel up to 6.13.5. It has been rated as critical. This impacts the function devm_request_irq of the component npcm. This manipulation causes denial of service.
This vulnerability is handled as CVE-2025-21878. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-21880 | Linux Kernel up to 6.12.17/6.13.5 EFAULT hmm_range_fault memory corruption (Nessus ID 265986 / WID-SEC-2025-0649)
3 weeks 4 days ago
A vulnerability was found in Linux Kernel up to 6.12.17/6.13.5. It has been rated as critical. Affected by this issue is the function hmm_range_fault of the component EFAULT Handler. Performing manipulation results in memory corruption.
This vulnerability is known as CVE-2025-21880. Access to the local network is required for this attack. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-21875 | Linux Kernel up to 6.13.5 /include/net/sock.h sock_owned_by_me state issue (Nessus ID 234309 / WID-SEC-2025-0649)
3 weeks 4 days ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.13.5. This issue affects the function sock_owned_by_me in the library /include/net/sock.h. Such manipulation leads to state issue.
This vulnerability is documented as CVE-2025-21875. The attack requires being on the local network. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2025-21874 | Linux Kernel up to 6.12.17/6.13.5 dm-integrity journal_sectors divide by zero (Nessus ID 236983 / WID-SEC-2025-0649)
3 weeks 4 days ago
A vulnerability was found in Linux Kernel up to 6.12.17/6.13.5. It has been declared as problematic. This affects the function journal_sectors of the component dm-integrity. The manipulation results in divide by zero.
This vulnerability is known as CVE-2025-21874. Access to the local network is required for this attack. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21876 | Linux Kernel up to 6.12.17/6.13.5 vt-d enable_drhd_fault_handling deadlock (Nessus ID 236983 / WID-SEC-2025-0649)
3 weeks 4 days ago
A vulnerability classified as critical was found in Linux Kernel up to 6.12.17/6.13.5. This affects the function enable_drhd_fault_handling of the component vt-d. The manipulation results in deadlock.
This vulnerability is cataloged as CVE-2025-21876. The attack must be initiated from a local position. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-21873 | Linux Kernel up to 6.6.80/6.12.17/6.13.5 bsg_transport_sg_io_fn denial of service (Nessus ID 236983 / WID-SEC-2025-0649)
3 weeks 4 days ago
A vulnerability was found in Linux Kernel up to 6.6.80/6.12.17/6.13.5 and classified as critical. The affected element is the function bsg_transport_sg_io_fn. Executing manipulation can lead to denial of service.
This vulnerability appears as CVE-2025-21873. The attacker needs to be present on the local network. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-21872 | Linux Kernel up to 5.10.234/6.6.82/6.12.17/6.13.5 mm/early_ioremap.c early_memmap iteration (Nessus ID 236983 / WID-SEC-2025-0649)
3 weeks 4 days ago
A vulnerability classified as problematic has been found in Linux Kernel up to 5.10.234/6.6.82/6.12.17/6.13.5. Affected by this issue is the function early_memmap of the file mm/early_ioremap.c. The manipulation leads to excessive iteration.
This vulnerability is listed as CVE-2025-21872. The attack must be carried out from within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21871 | Linux Kernel up to 6.13.4 optee denial of service (Nessus ID 234058 / WID-SEC-2025-0649)
3 weeks 4 days ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.13.4. Affected by this vulnerability is an unknown functionality of the component optee. The manipulation leads to denial of service.
This vulnerability is documented as CVE-2025-21871. The attack requires being on the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-21869 | Linux Kernel up to 6.12.16/6.13.4 Kernel Memory copy_to_kernel_nofault stack-based overflow (Nessus ID 236983 / WID-SEC-2025-0649)
3 weeks 4 days ago
A vulnerability marked as critical has been reported in Linux Kernel up to 6.12.16/6.13.4. The impacted element is the function copy_to_kernel_nofault of the component Kernel Memory Handler. This manipulation causes stack-based buffer overflow.
This vulnerability is tracked as CVE-2025-21869. The attack is only possible within the local network. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-21870 | Linux Kernel up to 6.12.16/6.13.4 ipc4-topology sof_ipc4_prepare_copier_module null pointer dereference (Nessus ID 234058 / WID-SEC-2025-0649)
3 weeks 4 days ago
A vulnerability described as critical has been identified in Linux Kernel up to 6.12.16/6.13.4. This affects the function sof_ipc4_prepare_copier_module of the component ipc4-topology. Such manipulation leads to null pointer dereference.
This vulnerability is listed as CVE-2025-21870. The attack must be carried out from within the local network. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com