Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-6620

A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been rated as critical. Affected by this issue is the function setUpgradeUboot of the file upgrade.so. The manipulation of the argument FileName leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
TOTOLINK
Product
CA300-PoE
Provider severity
MEDIUM
Conflicts
2

CVE-2025-66199

Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit. Impact summary: An attacker can cause per-connection memory allocations of up to approximately 22 MiB and extra CPU work, potentially leading to service degradation or resource exhaustion (Denial of Service). In affected configurations, the peer-supplied uncompressed certificate length from a CompressedCe

PUBLISHED
Vendor
OpenSSL
Product
OpenSSL
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6619

A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been declared as critical. Affected by this vulnerability is the function setUpgradeFW of the file upgrade.so. The manipulation of the argument FileName leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
TOTOLINK
Product
CA300-PoE
Provider severity
MEDIUM
Conflicts
2

CVE-2025-6618

A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been classified as critical. Affected is the function SetWLanApcliSettings of the file wps.so. The manipulation of the argument PIN leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
TOTOLINK
Product
CA300-PoE
Provider severity
MEDIUM
Conflicts
2

CVE-2025-66178

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow an authenticated attacked to execute arbitrary commands via a specialy crafted HTTP request.

PUBLISHED
Vendor
Fortinet
Product
FortiWeb
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66177

There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.

PUBLISHED
Vendor
Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision
Product
DS-86xxNXI-K8(/xP), DS-77xxNXI-Ix/VPro, DS-2CD2Dx5G1, iDS-81xxHQHI-M8/S, iDS-71xxHQHI-M1/T, DS-96xxxNI-Hx, iDS-96xxNXI-Px, DS-96xxxNI-Ix, iDS-73xxHUHI-M4/S(S), DS-76xxNXI-K2(/xP)/VPro, iDS-67xxNXI-S/T, iDS-96xxNXI-Mx/AI, HWI-xxxxHA, DS-2CD2xx1G0, DS-71xxNI-Q1(/xP)/M, iDS-96064NXI-I16, iDS-67xxxNXI-Mx/AI, iDS-6704NXI/AI, DS-71xxHGHI-M1(/T), iDS-96xxxNXI-Hx, DS-2CD3xx1G0, iDS-72xxHUHI-Mx/X, DS-86xxxNXI-Mx, DS-71xxNI-Q1(/xP)/M, iDS-ExxHUHI-xx, iDS-71xxHUHI-M1/S, iDS-72xxHQHI-Mx/XT, DS-77xxNXI-Kx(/xP)/Vpro, iDS-72xxHUHI-Mx/XT, DS-96xxNXI-Mx, DS-77xxNXI-Kx(/xP) including(D)、(E)、(B), iDS-96xxxNXI-Hx/AI, iDS-72xxHUHI-M1/E, iDS-72xxHUHI-M1/T, iDS-96xxxNXI-Ix/AI, iDS-90xxHUHI-M8/S, DS-96xxNXI-Ix/S, IPC-xxxxH, DS-76xxNXI-Ix/VPro, iDS-76xxNXI-Mx/X, DS-76xxNI-Qx(/xP) including(D)、(E), iDS-72xxHUHI-Mx/PXT, iDS-71xxHQHI-M1(/T), DS-96xxxNXI-Mx, DS-71xxNI-Q1(/xP), DS-76xxNI-Q2(/xP), DS-2CD1xxxG0(T), DS-2CD29xxG0, iDS-72xxHQHI-M1/E, iDS-67xxNXI-Mx/AI, iDS-73xxHQHI-M4/S, DS-96xxNXI-Mx/VPro, DS-77xxNI-Mx, iDS-71xxHQHI-M1/S, DS-96xxNXI-Sx, iDS-77xxNXI-P4, DS-ExxHGHI-xx, iDS-72xxHTHI-Mx/XT, IPC-xxxxHA, DS-77xxNXI-Ix/S, iDS-72xxHGHI-M1(/T), iDS-90xxHUHI-M8/S(S), iDS-96xxxNXI-Mx/X, iDS-81xxHUHI-M8/S(S), DS-76xxNXI-K1(/xP), DS-71xxNI-Q1(/xP), DS-2CD3xx1G2, iDS-72xxHQHI-M1/T, iDS-72xxHQHI-Mx/XT, DS-76xxNXI-K1(/xP)/VPro, DS-AT1000SI, DS-76xxNI-Q1(/xP), iDS-72xxHTHI-Mx/XT, HWI-xxxH(C), DS-77xxNXI-K4(/xP), iDS-67xxNXI-S, DS-2XE6xxxG0, DS-2CD1xx1, iDS-73xxHUHI-M4/S, DS-96xxxNXI-Sx, iDS-96xxNXI-Mx/X, iDS-77xxNXI-Mx/X, DS-76xxNXI-Ix/S, DS-A806xxSI, DS-86xxNXI-Ix/S, iDS-67xxNXI-P1, iDS-67xxNXI-Mx/X, DS-2XC6xxxG0, iDS-72xxHUHI-Mx/XT, DS-76xxNXI-Kx(/xP)/Vpro, DS-2CD64x5G1, DS-76xxNXI-Mx/VPro, iDS-71xxHGHI-M1(/T), iDS-90xxHQHI-M8/S, DS-76xxNXI-K2(/xP), DS-77xxNXI-K4(/xP)/VPro, iDS-ExxHQHI-xx, iDS-72xxHQHI-M1(/T), iDS-7608NXI-P2, DS-710xNI-G1/(xP)/M, DS-76xxNXI-Kx(/xP) including(D)、(E)、(B), DS-76xxNI-Mx, DS-2CD1xxxG2, DS-72xxHGHI-M1(/T)
Provider severity
HIGH
Conflicts
1

CVE-2025-66176

There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.

PUBLISHED
Vendor
Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision, Hikvision
Product
DS-K1T320/DS-K1T321, DS-K1T804A, DS-K1T804A, DS-K5033, DS-K1T8003/8004, DS-K1T670/K1T673, DS-K1T341A/K1T341B, DS-K1T8003, DS-K1T671/K5671, DS-K1T8005/DS-K1T808, DS-K1T201A/K1T105A, DS-K1T342/K1T343/K1T344/DS-K1T6QT-F72/F43, DS-K1T323/DS-K1T510, DS-K1T672, DS-K1T331, DS-K1T341C, DS-K1T680, DS-K1T981, DS-K1T804B
Provider severity
HIGH
Conflicts
1

CVE-2025-66174

There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and run a series of commands.

PUBLISHED
Vendor
Hikvision, Hikvision
Product
DS-7104HGHI-F1, DS-7204HGHI-F1
Provider severity
MEDIUM
Conflicts
1

CVE-2025-66173

There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and gaining access to an unrestricted shell environment.

PUBLISHED
Vendor
Hikvision, Hikvision
Product
DS-7104HGHI-F1, DS-7204HGHI-F1
Provider severity
MEDIUM
Conflicts
1

CVE-2025-66172

The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and have access to specific APIs can restore a volume from any other user's backups and attach the volume to their own VMs. Backup plugin users using CloudStack 4.21.0.0+ are recommended to upgrade to CloudStack version 4.22.0.1, which fixes this issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache CloudStack
Provider severity
HIGH
Conflicts
0

CVE-2025-66171

The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and have access to specific APIs can create new VMs using backups of any other user of the environment. Backup plugin users using CloudStack 4.21.0.0+ are recommended to upgrade to CloudStack version 4.22.0.1, which fixes this issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache CloudStack
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66170

The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and has access to specific APIs can list backups from any account in the environment. This vulnerability does not allow them to see the contents of the backup. Users are recommended to upgrade to version 4.22.0.1, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache CloudStack
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6617

A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. This issue affects the function formAdvanceSetup of the file /goform/formAdvanceSetup. The manipulation of the argument webpage leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link
Product
DIR-619L
Provider severity
HIGH
Conflicts
2

CVE-2025-66169

Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0 Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Camel Neo4j
Provider severity
MEDIUM
Conflicts
1

CVE-2025-66168

WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the  following for more details: https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt https://www.cve.org/CVERecord?id=CVE-2026-40046 Original Report: Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectl

PUBLISHED
Vendor
Apache Software Foundation, Apache Software Foundation, Apache Software Foundation
Product
Apache ActiveMQ MQTT Module, Apache ActiveMQ, Apache ActiveMQ All Module
Provider severity
MEDIUM
Conflicts
1

CVE-2025-66167

Missing Authorization vulnerability in merkulove Lottier lottier-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lottier: from n/a through <= 1.1.1.

PUBLISHED
Vendor
merkulove
Product
Lottier
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66166

Missing Authorization vulnerability in merkulove Lottier for Elementor lottier-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lottier for Elementor: from n/a through <= 1.0.9.

PUBLISHED
Vendor
merkulove
Product
Lottier for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66165

Missing Authorization vulnerability in merkulove Lottier for WPBakery lottier-wpbakery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lottier for WPBakery: from n/a through <= 1.1.7.

PUBLISHED
Vendor
merkulove
Product
Lottier for WPBakery
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66164

Missing Authorization vulnerability in merkulove Laser laser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Laser: from n/a through <= 1.1.1.

PUBLISHED
Vendor
merkulove
Product
Laser
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66163

Missing Authorization vulnerability in merkulove Masker for Elementor masker-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Masker for Elementor: from n/a through <= 1.1.4.

PUBLISHED
Vendor
merkulove
Product
Masker for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66162

Missing Authorization vulnerability in merkulove Spoter for Elementor spoter-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spoter for Elementor: from n/a through <= 1.04.

PUBLISHED
Vendor
merkulove
Product
Spoter for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66161

Missing Authorization vulnerability in merkulove Grider for Elementor grider-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grider for Elementor: from n/a through <= 1.0.8.

PUBLISHED
Vendor
merkulove
Product
Grider for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66160

Missing Authorization vulnerability in merkulove Select Graphist for Elementor Graphist for Elementor graphist-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Select Graphist for Elementor Graphist for Elementor: from n/a through <= 1.2.10.

PUBLISHED
Vendor
merkulove
Product
Select Graphist for Elementor Graphist for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6616

A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. This vulnerability affects the function formSetWAN_Wizard51 of the file /goform/formSetWAN_Wizard51. The manipulation of the argument curTime leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link
Product
DIR-619L
Provider severity
HIGH
Conflicts
2

CVE-2025-66159

Missing Authorization vulnerability in merkulove Walker for Elementor walker-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Walker for Elementor: from n/a through <= 1.1.6.

PUBLISHED
Vendor
merkulove
Product
Walker for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66158

Missing Authorization vulnerability in merkulove Gmaper for Elementor gmaper-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gmaper for Elementor: from n/a through <= 1.0.9.

PUBLISHED
Vendor
merkulove
Product
Gmaper for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66157

Missing Authorization vulnerability in merkulove Sliper for Elementor sliper-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sliper for Elementor: from n/a through <= 1.0.10.

PUBLISHED
Vendor
merkulove
Product
Sliper for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66156

Missing Authorization vulnerability in merkulove Watcher for Elementor watcher-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Watcher for Elementor: from n/a through <= 1.0.9.

PUBLISHED
Vendor
merkulove
Product
Watcher for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66155

Missing Authorization vulnerability in merkulove Questionar for Elementor questionar-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Questionar for Elementor: from n/a through <= 1.1.7.

PUBLISHED
Vendor
merkulove
Product
Questionar for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66154

Missing Authorization vulnerability in merkulove Couponer for Elementor couponer-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Couponer for Elementor: from n/a through <= 1.1.7.

PUBLISHED
Vendor
merkulove
Product
Couponer for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66153

Missing Authorization vulnerability in merkulove Headinger for Elementor headinger-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Headinger for Elementor: from n/a through <= 1.1.4.

PUBLISHED
Vendor
merkulove
Product
Headinger for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66152

Missing Authorization vulnerability in merkulove Criptopayer for Elementor criptopayer-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Criptopayer for Elementor: from n/a through <= 1.0.1.

PUBLISHED
Vendor
merkulove
Product
Criptopayer for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66151

Missing Authorization vulnerability in merkulove Countdowner for Elementor countdowner-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Countdowner for Elementor: from n/a through <= 1.0.4.

PUBLISHED
Vendor
merkulove
Product
Countdowner for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66150

Missing Authorization vulnerability in merkulove Appender appender allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Appender: from n/a through <= 1.1.1.

PUBLISHED
Vendor
merkulove
Product
Appender
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6615

A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.06B01. This affects the function formAutoDetecWAN_wizard4 of the file /goform/formAutoDetecWAN_wizard4. The manipulation of the argument curTime leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link
Product
DIR-619L
Provider severity
HIGH
Conflicts
2

CVE-2025-66149

Missing Authorization vulnerability in merkulove UnGrabber ungrabber allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UnGrabber: from n/a through <= 3.1.3.

PUBLISHED
Vendor
merkulove
Product
UnGrabber
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66148

Missing Authorization vulnerability in merkulove Conformer for Elementor conformer-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Conformer for Elementor: from n/a through <= 1.0.7.

PUBLISHED
Vendor
merkulove
Product
Conformer for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66147

Missing Authorization vulnerability in merkulove Coder for Elementor coder-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Coder for Elementor: from n/a through <= 1.0.13.

PUBLISHED
Vendor
merkulove
Product
Coder for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66146

Missing Authorization vulnerability in merkulove Logger for Elementor logger-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Logger for Elementor: from n/a through <= 1.0.9.

PUBLISHED
Vendor
merkulove
Product
Logger for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66145

Missing Authorization vulnerability in merkulove Worker for WPBakery worker-wpbakery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Worker for WPBakery: from n/a through <= 1.1.1.

PUBLISHED
Vendor
merkulove
Product
Worker for WPBakery
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66144

Missing Authorization vulnerability in merkulove Worker for Elementor worker-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Worker for Elementor: from n/a through <= 1.0.10.

PUBLISHED
Vendor
merkulove
Product
Worker for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66143

Missing Authorization vulnerability in merkulove Crumber crumber-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crumber: from n/a through <= 1.0.10.

PUBLISHED
Vendor
merkulove
Product
Crumber
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66142

Missing Authorization vulnerability in merkulove Comparimager for Elementor comparimager-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comparimager for Elementor: from n/a through <= 1.0.1.

PUBLISHED
Vendor
merkulove
Product
Comparimager for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66141

Missing Authorization vulnerability in merkulove Scroller scroller allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scroller: from n/a through <= 2.0.2.

PUBLISHED
Vendor
merkulove
Product
Scroller
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66140

Missing Authorization vulnerability in merkulove Uper for Elementor uper-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uper for Elementor: from n/a through <= 1.0.5.

PUBLISHED
Vendor
merkulove
Product
Uper for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6614

A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.06B01. Affected by this issue is the function formSetWANType_Wizard5 of the file /goform/formSetWANType_Wizard5. The manipulation of the argument curTime leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link
Product
DIR-619L
Provider severity
HIGH
Conflicts
2

CVE-2025-66139

Missing Authorization vulnerability in merkulove Audier For Elementor audier-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Audier For Elementor: from n/a through <= 1.0.9.

PUBLISHED
Vendor
merkulove
Product
Audier For Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66138

Missing Authorization vulnerability in merkulove Motionger for Elementor motionger-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motionger for Elementor: from n/a through <= 2.0.4.

PUBLISHED
Vendor
merkulove
Product
Motionger for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66137

Missing Authorization vulnerability in merkulove Searcher for Elementor searcher-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Searcher for Elementor: from n/a through <= 1.0.3.

PUBLISHED
Vendor
merkulove
Product
Searcher for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66136

Missing Authorization vulnerability in merkulove Carter for Elementor carter-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Carter for Elementor: from n/a through <= 1.0.2.

PUBLISHED
Vendor
merkulove
Product
Carter for Elementor
Provider severity
MEDIUM
Conflicts
0