CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Q-Free MaxTime Missing Authorization Vulnerability in User Groups Management
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to remove user groups by sending crafted HTTP requests. The issue is located in the user-groups route of the application.
Q-Free MaxTime Missing Authorization Vulnerability Allowing Arbitrary User Group Creation
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to create arbitrary user groups by sending crafted HTTP requests. The issue is located in the 'maxprofile/user-groups/routes.lua' file.
Q-Free MaxTime Missing Authentication Vulnerability in Front Panel Authentication
A vulnerability allowing unauthenticated remote attackers to disable front panel authentication has been identified in Q-Free MaxTime versions through 2.11.0. This issue arises from a missing authentication for critical functions, specifically in the maxprofile/setup/routes.lua file. Exploitation of this vulnerability could make physical access to the device easier by bypassing front panel security measures.
Q-Free MaxTime Missing Authentication Vulnerability in Front Panel Authentication
A vulnerability allowing unauthenticated remote attackers to enable front panel authentication has been identified in Q-Free MaxTime versions through 2.11.0. This issue, categorized as CWE-306 'Missing Authentication for Critical Function', resides in the file maxprofile/setup/routes.lua. Exploitation of this vulnerability could lock out legitimate users by manipulating HTTP requests to activate front panel authentication.
Q-Free MaxTime Missing Authentication Vulnerability in Authentication Profile Server
A vulnerability allowing unauthenticated remote attackers to disable an authentication profile server has been identified in Q-Free MaxTime versions through 2.11.0. This issue, categorized as CWE-306 'Missing Authentication for Critical Function', arises in the maxprofile/setup/routes.lua file, where the lack of proper authentication allows for exploitation via crafted HTTP requests.
Q-Free MaxTime Missing Authentication Vulnerability in Authentication Profile Server
A vulnerability allowing missing authentication for critical functions has been identified in Q-Free MaxTime versions through 2.11.0. This issue resides in the maxprofile/setup/routes.lua file and allows an unauthenticated remote attacker to enable an authentication profile server by sending crafted HTTP requests.
Q-Free MaxTime Missing Authentication Vulnerability in Authentication Profile Management
A vulnerability allowing unauthenticated remote attackers to manipulate authentication profiles on Q-Free MaxTime versions through 2.11.0 has been identified. This issue arises from a missing authentication requirement for critical functions, specifically in the maxprofile/setup/routes.lua file. Exploitation can be achieved by sending crafted HTTP requests to the server, potentially bypassing authentication mechanisms.
Q-Free MaxTime Missing Authentication Vulnerability Allowing Unauthenticated Factory Reset
A vulnerability allowing unauthenticated remote attackers to factory reset devices running Q-Free MaxTime versions through 2.11.0 has been identified. This vulnerability, categorized as CWE-306 'Missing Authentication for Critical Function', resides in the file maxprofile/setup/routes.lua. Exploitation of this vulnerability erases all device configurations, leading to a denial-of-service condition.
Q-Free MaxTime Missing Authentication Vulnerability Allowing Dashboard Deletion
A vulnerability exists in Q-Free MaxTime versions through 2.11.0, specifically within the maxprofile/persistance/routes.lua file. This vulnerability, categorized as CWE-306 'Missing Authentication for Critical Function', enables an unauthenticated remote attacker to delete dashboards by sending crafted HTTP requests.
Q-Free MaxTime Missing Authentication Vulnerability Allowing User PIN Reset
A vulnerability allowing unauthenticated remote attackers to reset user PINs has been identified in Q-Free MaxTime versions through 2.11.0. This issue arises from a missing authentication for critical functions, specifically in the maxprofile/accounts/routes.lua file.
Q-Free MaxTime Improper Input Validation Vulnerability Allowing Configuration Modification
A vulnerability allowing improper input validation has been identified in the Q-Free MaxTime application, specifically in the ldbMT.so component, and affects versions through 2.11.0. This vulnerability allows authenticated remote attackers to modify system configurations by sending crafted HTTP requests.
Q-Free MaxTime Path Traversal Vulnerability Allowing Sensitive File Read
A path traversal vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated remote attackers to read sensitive files by sending crafted HTTP requests. The issue is located in the 'maxtime/api/database/database.lua' file.
Q-Free MaxTime Path Traversal Vulnerability Allowing File Overwrite
A path traversal vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. The issue resides in the maxtime/api/database/database.lua file, specifically within the setActive endpoint. This vulnerability allows authenticated remote attackers to overwrite sensitive files by sending crafted HTTP requests.
Q-Free MaxTime Path Traversal Vulnerability Allowing File Deletion
A path traversal vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated remote attackers to delete sensitive files by sending crafted HTTP requests. The issue is located in the 'maxtime/api/database/database.lua' file.
Q-Free MaxTime Path Traversal Vulnerability Allowing File Overwrite
A path traversal vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. The issue resides in the 'maxtime/api/database/database.lua' file, specifically within the copy endpoint. This vulnerability allows authenticated remote attackers to overwrite sensitive files by sending crafted HTTP requests.
Q-Free MaxTime Path Traversal Vulnerability Allowing Sensitive File Read
A path traversal vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated remote attackers to read sensitive files by sending crafted HTTP requests. The issue is located in the maxtime/api/sql/sql.lua file.
Q-Free MaxTime Path Traversal Vulnerability Allowing File Deletion
A path traversal vulnerability has been identified in Q-Free MaxTime versions through 2.11.0, specifically within the template deletion mechanism. This vulnerability allows authenticated remote attackers to delete sensitive files by sending crafted HTTP requests. The issue could lead to system instability or data loss.
Q-Free MaxTime Path Traversal Vulnerability Allowing Sensitive File Read
A path traversal vulnerability has been identified in the template download mechanism of Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated remote attackers to read sensitive files by sending crafted HTTP requests.
Q-Free MaxTime Unrestricted File Upload Vulnerability Allowing Arbitrary File Overwrite
A vulnerability allowing unrestricted upload of files with dangerous types has been identified in Q-Free MaxTime versions through 2.11.0. This issue allows authenticated remote attackers to upload malicious files via crafted HTTP requests. The vulnerability could be exploited to overwrite arbitrary files, potentially leading to system compromise or denial-of-service conditions.
Q-Free MaxTime Relative Path Traversal Vulnerability in File Upload Mechanism
A relative path traversal vulnerability has been identified in the file upload feature of Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated remote attackers to overwrite arbitrary files by sending crafted HTTP requests.
Q-Free MaxTime SQL Injection Vulnerability in User Menu Management
A SQL injection vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. The issue resides in the 'editUserMenu' endpoint of 'maxprofile/menu/model.lua'. This vulnerability allows authenticated remote attackers to execute arbitrary SQL commands by sending crafted HTTP requests.
Q-Free MaxTime Missing Authentication Vulnerability in User Permissions Management
A vulnerability allowing unauthenticated remote attackers to edit user permissions has been identified in Q-Free MaxTime versions through 2.11.0. This issue arises from a missing authentication for critical functions, specifically in the file maxprofile/menu/routes.lua. Exploitation can be achieved by sending crafted HTTP requests to the application.
Q-Free MaxTime SQL Injection Vulnerability in User Group Management Endpoint
A SQL injection vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This issue, located in the user group management endpoint of the application, allows authenticated remote attackers to execute arbitrary SQL commands by sending crafted HTTP requests.
Q-Free MaxTime Missing Authentication Vulnerability in User Group Permissions Management
A vulnerability allowing unauthenticated remote attackers to edit user group permissions has been identified in Q-Free MaxTime versions through 2.11.0. This issue arises from a missing authentication for critical functions, specifically in the file maxprofile/menu/routes.lua. Exploitation of this vulnerability could lead to unauthorized changes in user access rights, potentially escalating privileges or restricting access for legitimate users.
Q-Free MaxTime Missing Authentication Vulnerability in Guest Mode
A vulnerability allowing unauthenticated remote attackers to enable passwordless guest mode has been identified in Q-Free MaxTime versions through 2.11.0. This issue arises from a missing authentication for critical functions, specifically in the maxprofile/guest-mode/routes.lua file. Exploitation involves sending crafted HTTP requests to the application.
Q-Free MaxTime Weak Authentication Vulnerability in PIN Mechanism Allowing Brute-Force Attacks
A weak authentication vulnerability has been identified in the PIN authentication system of Q-Free MaxTime versions through 2.11.0. This vulnerability allows unauthenticated remote attackers to brute-force user PINs by sending multiple crafted HTTP requests. Exploitation of this vulnerability could lead to unauthorized access to user accounts.
Q-Free MaxTime Missing Authentication Vulnerability Allowing Arbitrary User Creation
A vulnerability allowing missing authentication for critical functions has been identified in Q-Free MaxTime versions through 2.11.0. This issue resides in the file maxprofile/accounts/routes.lua and allows unauthenticated remote attackers to create arbitrary users, including those with administrative privileges, by sending crafted HTTP requests.
Q-Free MaxTime Password Reset Vulnerability Due to Missing Authentication
A vulnerability allowing password resets for arbitrary users has been identified in Q-Free MaxTime versions through 2.11.0. This issue arises from a missing authentication mechanism in the 'maxprofile/accounts/routes.lua' file, which enables unauthenticated remote attackers to exploit the vulnerability by sending crafted HTTP requests.
Q-Free MaxTime Hard-Coded Cryptographic Key Vulnerability Allowing Authentication Bypass
A vulnerability exists in Q-Free MaxTime versions through 2.11.0, where a hard-coded cryptographic key is used in JSON Web Token (JWT) signing. This flaw allows an unauthenticated remote attacker to bypass authentication by sending crafted HTTP requests.
Q-Free MaxTime Missing Authentication Vulnerability in HTTP Request Handling
A vulnerability allowing missing authentication for critical functions has been identified in Q-Free MaxTime versions through 2.11.0. This issue, located in the file maxtime/handleRoute.lua, enables an unauthenticated remote attacker to impact the device's confidentiality, integrity, or availability in various unspecified ways by sending crafted HTTP requests.
Linux Kernel GFS2 Address Space Truncation Vulnerability
A vulnerability in the Linux kernel's GFS2 file system has been addressed, which involved improper handling of an inode's address space when the GFS2_DIF_JDATA flag was changed. This flag determines whether the address space pages utilize buffer heads or iomap_folio_state structures, and mixing these two can lead to issues.
Linux Kernel V3D Driver Job Pointer Nullification Vulnerability
A vulnerability in the Linux kernel's V3D driver has been addressed, which involved not properly nullifying the job pointer after a job was completed. This oversight could lead to a warning when unloading the driver, as it would mistakenly indicate that the job was still active. The vulnerability has been resolved by ensuring the job pointer is set to NULL after the job's completion, clearly signaling that the job has finished.
Linux Kernel Userfaultfd Write-Protect Flag Inconsistency Vulnerability in Memory Remapping
A vulnerability in the Linux kernel's memory management can lead to inconsistencies when remapping memory regions that are registered with userfaultfd as write-protected. This issue arises because the flags indicating the write-protected state are not properly synchronized between the virtual memory area (VMA) and the page table entries (PTE/PMD). As a result, a subsequent attempt to change the protection to writable can trigger a warning, creating potential disruptions in memory management.
Linux Kernel Dell UART Backlight Serdev Race Condition Vulnerability
A vulnerability in the Linux kernel's handling of the Dell UART backlight serdev can lead to a NULL pointer dereference. This issue arises because the 'dell_uart_bl_serdev_probe()' function opens the serdev device before fully initializing the client operations. As a result, the serdev controller's receive buffer handler can encounter a NULL pointer dereference, assuming that the operations are valid when the port is activated. This vulnerability is similar to a previously addressed issue in the Chrome platform's cros_ec_uart handling, where the device was not properly initialized before being opened.
Linux Kernel Softlockup Vulnerability in __read_vmcore
A softlockup vulnerability has been identified in the Linux kernel's __read_vmcore function, particularly during kdump operations. This issue arises in memory-constrained environments, where such softlockups can disrupt critical processes like RCU memory management, causing crash dumps to freeze. Although recent changes have reduced the frequency of these softlockups, they still occur sporadically. The vulnerability stems from the second loop in __read_vmcore, which, despite having more natural sleep points, can still lead to prolonged execution times.
SourceCodester Best Church Management Software SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in SourceCodester Best Church Management Software version 1.1. The issue arises in the file '/admin/app/profile_crud.php', where improper handling of the 'username' parameter allows remote attackers to execute time-based blind SQL injection, potentially leading to unauthorized data extraction from the database.
SourceCodester Best Church Management Software SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in SourceCodester Best Church Management Software version 1.1. The issue resides in the file '/admin/app/slider_crud.php', where the 'del_id' parameter can be manipulated to execute unauthorized SQL commands. This vulnerability allows remote attackers to perform time-based blind SQL injection, potentially leading to data extraction from the application's database.
Q-Free MaxTime CORS Origin Validation Error Vulnerability
A vulnerability allowing origin validation errors in the CORS configuration has been identified in Q-Free MaxTime versions through 2.11.0. This flaw allows an unauthenticated remote attacker to manipulate the device's confidentiality, integrity, or availability by sending crafted URLs or HTTP requests.
Q-Free MaxTime Username Enumeration Vulnerability
A vulnerability allowing username enumeration has been identified in Q-Free MaxTime versions through 2.11.0. This issue arises from an observable response discrepancy on the login page, which enables unauthenticated remote attackers to identify valid usernames by sending crafted HTTP requests.
Q-Free MaxTime Hard-Coded Password Vulnerability in Root Account Allowing Arbitrary Code Execution via SSH
A vulnerability exists in Q-Free MaxTime versions through 2.11.0, where a hard-coded password for the root account enables unauthenticated remote attackers to execute arbitrary code with root privileges via SSH.
Linux Kernel Directory Offset Vulnerability in 32-Bit Systems
A vulnerability in the Linux kernel's directory offset allocation mechanism can lead to persistent loss of directory entries on 32-bit systems. The issue arises when the offset allocator wraps around to a low value, causing existing directory entries to become invisible during readdir operations. This problem was introduced by a commit that incorrectly treated directory offsets as monotonically increasing integers, rather than opaque cookies, leading to a permanent disappearance of certain entries from readdir output.
Linux Kernel Hotplug CPU State Handling Vulnerability in HRTimers
A vulnerability in the Linux kernel's handling of CPU hotplug events can lead to incorrect assumptions about the state of high-resolution timers (HRTimers) on certain CPUs. When a CPU is unplugged and then reconnected, the system may mistakenly believe that the timer is already active, causing the clockevent device to miss the opportunity to switch to one-shot mode. This issue arises because the CPU's per-state information is not properly reset during the hotplug process, leaving behind outdated pointers that can disrupt timer management.
HCL Connections Docs Sensitive Information Disclosure Vulnerability
A vulnerability in HCL Connections Docs 2.0.2 allows users to access sensitive information they are not authorized to see, due to improper handling of request data. This issue could lead to unauthorized disclosure of information.
SourceCodester Best Church Management Software SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in SourceCodester Best Church Management Software version 1.1. The issue arises in the file '/admin/app/role_crud.php', where improper handling of the 'id' argument allows for SQL injection. This vulnerability can be exploited remotely.
Code-Projects Real Estate Property Management System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Code-Projects Real Estate Property Management System version 1.0. The issue arises in the file '/_parse/load_user-profile.php', where the 'userhash' argument can be manipulated to execute unauthorized SQL commands. This vulnerability can be exploited remotely.
Brizy Page Builder Stored Cross-Site Scripting Vulnerability via SVG File Upload
A stored cross-site scripting vulnerability has been identified in the Brizy Page Builder plugin for WordPress, affecting all versions through 2.6.8. This vulnerability arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Author-level access or higher to inject arbitrary scripts into pages. The injected scripts execute when a user accesses the SVG file, exploiting the REST API's handling of SVG uploads.
Code-Projects Real Estate Property Management System Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Code-Projects Real Estate Property Management System version 1.0. The issue arises in an unknown function of the file search.php, where the PropertyName argument can be manipulated to inject malicious scripts. This vulnerability can be exploited remotely, and there are indications that other parameters may also be affected.
Code-Projects Real Estate Property Management System Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Code-Projects Real Estate Property Management System version 1.0. The issue arises in the file '/Admin/EditCategory', where the 'CategoryId' argument is improperly processed, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely.
Welcart e-Commerce Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Welcart e-Commerce plugin for WordPress, affecting all versions through 2.11.9. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary scripts into pages. These scripts are executed when users access the compromised pages.
Small Package Quotes – Purolator Edition WordPress Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the Small Package Quotes – Purolator Edition plugin for WordPress, affecting all versions through 3.6.4. The vulnerability arises from inadequate escaping of user-supplied parameters in the SQL query, allowing unauthenticated attackers to inject additional SQL commands. Exploitation of this vulnerability could lead to unauthorized access to sensitive information in the database.
