CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Zyxel EX5601-T1 Post-Authentication Command Injection Vulnerability Allowing OS Command Execution
A post-authentication command injection vulnerability has been identified in the 'ZyEE' function of the Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and earlier. This vulnerability allows an authenticated attacker with administrator privileges to execute operating system commands on the affected device. It is important to note that WAN access is disabled by default on these devices, and exploitation can only succeed if the administrator passwords have been compromised.
Zyxel VMG8825-T50K Post-Authentication Command Injection Vulnerability in DNSServer Parameter
A post-authentication command injection vulnerability has been identified in the Zyxel VMG8825-T50K router, specifically in the DNSServer parameter of the diagnostic function. This vulnerability affects firmware versions through V5.50(ABOM.8.5)C0. An authenticated attacker with administrator privileges could exploit this vulnerability to execute operating system commands on the affected device. The vulnerability requires access to the device's management interface, and the attack can only be successful if the administrator's password has been compromised.
SAP S/4HANA Manage Bank Statements Access Control Vulnerability Allowing Attachment Deletion
A vulnerability exists in the Manage Bank Statements feature of SAP S/4HANA, where insufficient access control checks allow authenticated users to illegitimately delete attachments from posted bank statements. This flaw results in a low integrity impact, with no effect on data confidentiality or application availability.
SAP Commerce Swagger UI Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in SAP Commerce's Swagger UI component. This issue arises from inadequate input validation, allowing an unauthenticated attacker to inject malicious code from remote sources. Exploitation of this vulnerability could significantly impact the confidentiality, integrity, and availability of data within SAP Commerce.
SAP S/4HANA Manage Bank Statements Functionality Bypass Vulnerability
A vulnerability in the Manage Bank Statements feature of SAP S/4HANA allows authenticated attackers to bypass certain application functionality restrictions and upload files to a reversed bank statement. This issue impacts the application's integrity, while leaving confidentiality and availability unaffected.
SAP Electronic Invoicing eDocument Cockpit Unauthorized Access Vulnerability
A vulnerability in the eDocument Cockpit (Inbound NF-e) component of SAP Electronic Invoicing for Brazil allows an authenticated attacker with specific privileges to access transaction details without authorization. By invoking a particular ABAP method within the ABAP system, the attacker could retrieve information about inbound deliveries, potentially compromising transaction confidentiality. This issue does not affect the application's integrity or availability.
SAP NetWeaver Application Server Java Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the user management functionality of SAP NetWeaver Application Server Java. This issue allows an attacker to inject malicious payloads that are saved and executed when a user accesses the affected functionality. The vulnerability could lead to information disclosure or unauthorized modifications of data within the user's browser, but it does not impact the application's availability.
SAP CRM and SAP S/4HANA (Interaction Center) Server-Side Request Forgery Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in SAP CRM and SAP S/4HANA (Interaction Center). This vulnerability allows an attacker with low privileges to access restricted information by sending requests to internal network resources, thereby compromising the application's confidentiality. However, there is no impact on integrity or availability.
SAP NetWeaver Privilege Escalation Vulnerability in ABAP Class Builder
A privilege escalation vulnerability has been identified in SAP NetWeaver's ABAP Class Builder. The issue arises from a missing authorization check, which allows an attacker to gain higher access levels than intended. Successful exploitation of this vulnerability could lead to the disclosure of highly sensitive information and significantly impact the application's integrity and availability.
SAP Fiori Applications Posting Library Access Control Bypass Vulnerability
A vulnerability exists in SAP Fiori applications that utilize the posting library, where security settings are not properly configured during the initial setup. This oversight leaves the applications with default or poorly defined security parameters. As a result, an attacker with low privileges could exploit this vulnerability to bypass access controls, potentially allowing them to modify data within the application. This issue does not affect confidentiality or availability.
SAP NetWeaver Application Server ABAP DOM-Based Cross-Site Scripting Vulnerability
A DOM-based Cross-Site Scripting vulnerability has been identified in SAP NetWeaver Application Server ABAP. This issue arises because the application does not adequately encode user-controlled inputs, allowing an attacker to create a malicious web message that targets WEBGUI functionality. Exploitation of this vulnerability enables the execution of harmful JavaScript in the context of the victim's browser, potentially compromising their data or altering browser content. The vulnerability affects users with no special privileges.
SAP Business One Service Layer Improper Session Management Vulnerability Allowing User Impersonation and Privilege Escalation
A vulnerability in the Service Layer of SAP Business One could allow attackers to gain unauthorized access, impersonate other users, and perform unauthorized actions within the application. This issue arises from improper session management, enabling attackers to escalate privileges and access, read, modify, or create data. Although exploiting this vulnerability requires significant time and effort to obtain authenticated sessions of other users, it poses a high risk to the application's confidentiality and integrity, with no impact on availability.
SAP OData Service Privilege Escalation Vulnerability in Manage Purchasing Info Records
A vulnerability exists in the OData Service within the Manage Purchasing Info Records application, where necessary authorization checks are not properly enforced for authenticated users. This flaw allows attackers to escalate privileges, although it has a low impact on the application's integrity.
SAP Just In Time Privilege Escalation Vulnerability
A vulnerability in SAP Just In Time (JIT) exists due to insufficient authorization checks for authenticated users. This flaw allows attackers to escalate privileges, potentially leading to a low impact on the application's integrity. There are no effects on confidentiality or availability.
SAP BusinessObjects Business Intelligence Platform Web Intelligence Endpoint Security Vulnerability
A security vulnerability exists in SAP BusinessObjects Business Intelligence Platform, specifically within the Web Intelligence component. The issue arises from a deprecated web application endpoint that lacks proper security measures. This vulnerability allows an attacker to inject a malicious URL into the data returned to the user. If successfully exploited, it could lead to a limited impact on confidentiality and integrity within the victim's browser, although there is no effect on availability.
SAP Business Warehouse Process Chains Authorization Check Vulnerability Allowing Process Manipulation
A vulnerability in SAP Business Warehouse (Process Chains) allows an attacker to manipulate process execution by exploiting a missing authorization check. An attacker with display authorization for the process chain object could skip one or all processes, disrupting activities such as data loading, activation, or deletion. This manipulation could result in unexpected business reporting outcomes, significantly impacting data integrity, although confidentiality and availability remain unaffected.
SAP NetWeaver Application Server ABAP Cross-Site Scripting Vulnerability
A Cross-Site Scripting (XSS) vulnerability has been identified in SAP NetWeaver Application Server ABAP. This issue allows malicious scripts to be executed within the application. While the vulnerability does not affect the application's availability, it could have minor implications for its confidentiality and integrity.
SAP NetWeaver Enterprise Portal OBN Authentication Bypass Vulnerability Allowing Integrity Manipulation
An authentication bypass vulnerability has been identified in SAP NetWeaver Enterprise Portal OBN. The issue arises because the portal does not properly validate authentication for a specific configuration setting. As a result, a non-authenticated user can manipulate this setting, leading to a low impact on data integrity. The vulnerability does not affect the application's confidentiality or availability.
SAP FS-RBD Missing Authorization Check Vulnerability in IBS Module Allowing Privilege Escalation
A vulnerability exists in an IBS module of SAP FS-RBD, where an authenticated user with low privileges can exploit a missing authorization check. This flaw allows unauthorized access to perform actions beyond the user's intended permissions, leading to a low impact on integrity, with no effect on confidentiality or availability.
SAP Business Objects Business Intelligence Platform Improper Error Handling Vulnerability Allowing Information Disclosure
A vulnerability exists in SAP Business Objects Business Intelligence Platform due to inadequate error handling, which leads to the unintentional disclosure of technical application details. This information is revealed through exceptions presented to the user and in stack traces. The vulnerability is accessible only to users with administrator privileges, who could potentially use the disclosed information to develop further exploits. Fortunately, this issue does not affect the application's integrity or availability.
SAP Web Dispatcher and Internet Communication Manager Password Exposure Vulnerability
A vulnerability exists in SAP Web Dispatcher and Internet Communication Manager that allows an attacker with administrative privileges to activate a debugging trace mode. This mode, when combined with a specific parameter value, reveals unencrypted passwords in the logs, thereby significantly compromising the application's confidentiality. However, there is no impact on the integrity or availability of the application.
SAP BusinessObjects Business Intelligence Platform Web Intelligence Reports Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been identified in SAP BusinessObjects Business Intelligence Platform, specifically within Web Intelligence reports. This issue allows an attacker to inject JavaScript code that is executed in the browser of the victim each time the affected page is accessed. The vulnerability arises only when script or HTML execution is enabled by the administrator in the Central Management Console.
IBM Common Cryptographic Architecture Denial-of-Service Vulnerability in Hardware Security Module
A denial-of-service vulnerability has been identified in IBM Common Cryptographic Architecture (CCA) versions 7.0.0 through 7.5.51. This vulnerability allows an authenticated user to disrupt services in the Hardware Security Module (HSM) by sending a specially crafted sequence of valid requests.
IBM Common Cryptographic Architecture Timing Attack Vulnerability in RSA Operations
A timing attack vulnerability has been identified in IBM Common Cryptographic Architecture (CCA) versions 7.0.0 through 7.5.51. This vulnerability could allow an attacker to obtain sensitive information by exploiting timing discrepancies during certain RSA operations.
IBM Common Cryptographic Architecture ECDSA Timing Attack Vulnerability
A vulnerability in IBM Common Cryptographic Architecture (CCA) versions 7.0.0 through 7.5.51 could allow remote attackers to obtain sensitive information by exploiting a timing-based attack during the creation of ECDSA signatures. This vulnerability is present in CCA 7.x MTM for 4769, as well as the IBM 4769 Developers Toolkit.
Crypt::Random Perl Package Insecure Randomness Provider Vulnerability
A vulnerability exists in the Crypt::Random Perl package, specifically in versions 1.05 through 1.55, where the rand() function, known to be cryptographically weak, is used for cryptographic purposes. This issue is particularly prevalent in the default configuration on Windows versions of Perl, where the rand provider is insecure. If /dev/urandom or an Entropy Gathering Daemon (egd) service is not available, Crypt::Random defaults to the insecure rand provider, which is not suitable for any cryptographic use or situations where randomness is crucial for security.
Nintex Automation Password Exposure Vulnerability in K2 SmartForms Designer
A vulnerability exists in Nintex Automation versions 5.6 and 5.7 prior to 5.8, where the K2 SmartForms Designer folder contains web.config files with passwords that can be accessed by unauthorized users.
Nintex Automation Insecure Deserialization Vulnerability
A vulnerability allowing insecure deserialization of user input has been identified in Nintex Automation versions 5.6 and 5.7 prior to 5.8.
Nintex Automation Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in Nintex Automation versions 5.6 and 5.7 prior to 5.8. This issue is associated with the 'Navigate to a URL' action, allowing for the injection of malicious scripts that could be executed in the context of the user.
Rack Local File Inclusion Vulnerability in Rack::Static Component
A local file inclusion vulnerability has been identified in the Rack web application interface for Ruby. This issue affects Rack versions prior to 2.2.13, as well as versions 3.0.0 through 3.0.14 and 3.1.0 through 3.1.12. The vulnerability arises because the Rack::Static component does not properly sanitize user-supplied paths before serving files, allowing encoded path traversal sequences to be exploited. As a result, attackers can access files outside the designated static file directory, potentially exposing sensitive information.
Tianti Cross-Site Request Forgery Vulnerability in User Status Update Component
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Tianti version 2.3. This issue allows attackers to perform arbitrary actions by sending crafted GET or POST requests to the '/user/ajax/upd/status' component. The vulnerability arises from the absence of CSRF protection, such as verification tokens or same-origin policy checks, enabling exploitation by inducing users to unknowingly execute actions on their behalf.
Tianti Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in Tianti version 2.3. This vulnerability allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the coverImageURL parameter of the article save AJAX endpoint. The injected script is executed on the front end, affecting all users who access the homepage.
Tianti Cross-Site Request Forgery Vulnerability in User Management Functions
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Tianti CMS version 2.3. The issue resides in the user management component, specifically within the 'Add', 'Delete', 'Edit', and 'Restore' user functions'. The vulnerability allows attackers to perform arbitrary actions by sending crafted GET or POST requests, exploiting the absence of CSRF protection in the application's code.
Google Chrome V8 Out-of-Bounds Read Vulnerability Allowing Memory Access
A vulnerability allowing out-of-bounds read in the V8 JavaScript engine has been identified in Google Chrome versions prior to 134.0.6998.88. This flaw could enable a remote attacker to access memory outside the intended boundaries by using a specially crafted HTML page.
Google Chrome Heap Corruption Vulnerability in Inspector Component Allowing Potential Exploitation
A use-after-free vulnerability has been identified in the Inspector component of Google Chrome. This issue, present in versions prior to 134.0.6998.88, could allow a remote attacker to exploit heap corruption by using a specially crafted HTML page.
Google Chrome V8 Type Confusion Vulnerability Allowing Heap Corruption
A type confusion vulnerability has been identified in the V8 engine of Google Chrome, in versions prior to 134.0.6998.88. This vulnerability could allow a remote attacker to exploit heap corruption by using a specially crafted HTML page.
Google Chrome V8 Type Confusion Vulnerability Allowing Heap Corruption
A type confusion vulnerability has been identified in the V8 engine of Google Chrome, in versions prior to 134.0.6998.88. This vulnerability could allow a remote attacker to exploit heap corruption by using a specially crafted HTML page.
Concrete CMS Stored Cross-Site Scripting Vulnerability in Folder Function
A stored cross-site scripting vulnerability has been identified in Concrete CMS versions 9.0.0 through 9.3.9, within the Folder Function's 'Add Folder' feature. This issue arises because the functionality does not properly sanitize input, allowing a malicious admin to inject XSS payloads into folder names. Versions prior to 9.0 are not affected.
Google Pixel Watch Elevation of Privilege Vulnerability in wl_notify_gscan_event
A vulnerability allowing local elevation of privilege has been identified in Google Pixel Watch devices. This issue arises from an out-of-bounds write in the wl_notify_gscan_event function of wl_cfgscan.c, caused by a missing bounds check. Exploitation of this vulnerability does not require additional execution privileges or user interaction.
Google Pixel Watch Elevation of Privilege Vulnerability in dhd Process Full Gscan Result
A vulnerability allowing local elevation of privilege has been identified in Google Pixel Watch devices. This issue arises from an integer overflow in the 'dhd_process_full_gscan_result' function within 'dhd_pno.c', potentially leading to unauthorized access to elevated privileges. Notably, this vulnerability does not require any additional execution privileges or user interaction for exploitation.
Passbolt API Host Header Injection Vulnerability Allowing Email Spoofing
A host header injection vulnerability has been identified in Passbolt API versions prior to 5, specifically in version 4.11.1 and earlier. This vulnerability arises when the server is misconfigured, such as not setting the 'fullBaseUrl' or 'server_name', allowing an attacker to manipulate the host header. Exploitation of this vulnerability enables the attacker to send emails containing malicious links that appear to come from a trusted domain, potentially leading to further exploitation if the recipient clicks the link.
Apple Maps Privacy Vulnerability Allowing Access to User-Sensitive Data
A vulnerability in the Maps application on various Apple platforms, including macOS Ventura 13.1, watchOS 9.2, iOS 16.2, and iPadOS 16.2, may allow apps to access user-sensitive data. This issue was caused by inadequate state management, which has been improved in the latest software updates.
Apple Kernel Double Free Vulnerability Allowing Arbitrary Code Execution with Kernel Privileges
A double free vulnerability has been identified in the kernel of multiple Apple operating systems, including macOS Ventura 13.1, watchOS 9.2, iOS 16.2, iPadOS 16.2, and tvOS 16.2. This vulnerability allows an application to execute arbitrary code with kernel privileges. The issue arises from improper memory management, which has been addressed in the mentioned updates.
Go Vela Webhook Spoofing Vulnerability Allows Repository Ownership Transfer and Secret Exfiltration
A vulnerability in Go Vela's webhook handling can lead to unauthorized transfer of repository ownership and exfiltration of repository-level CI secrets. This issue affects versions prior to 0.25.3 and 0.26.0 through 0.26.2. The vulnerability arises from insufficient verification of webhook payload data, allowing an attacker to spoof a webhook with specific headers and body content. This can result in the unauthorized transfer of a repository and its associated secrets to another repository, from which the secrets can be extracted during subsequent CI/CD builds.
umatiGateway Web Interface Exposure Vulnerability
A vulnerability exists in umatiGateway, a software that connects OPC Unified Architecture servers with an MQTT broker using JSON messages. The issue arises from the user interface being potentially publicly accessible when the provided docker-compose file is used. This access allows for viewing and modifying the configuration. The vulnerability is present in the umatiGateway version corresponding to the commit 'abe73096a17307327f0d6dc0ed4db1fb93464521', and was introduced by publishing the UI on all interfaces, which could lead to unauthorized access to the application's configuration settings.
LocalS3 XML External Entity Injection Vulnerability Allowing Server-Side Request Forgery
A vulnerability in LocalS3, an Amazon S3 mock service, prior to version 1.21, allows for XML External Entity (XXE) injection during the bucket creation process. The service's XML parser, when handling the CreateBucketConfiguration XML document, is configured to resolve external entities. This flaw enables an attacker to declare an external entity that points to an internal URL, which the server fetches while parsing the XML. The vulnerability arises in the location constraint processing, where the XML parser improperly validates external entities. Exploiting this issue can lead to server-side request forgery (SSRF) attacks, allowing access to internal services or resources that should be off-limits to external networks. The responses from these internal requests are included in the bucket configuration, potentially leaking sensitive information.
Mozilla Thunderbird OpenPGP Message Misrepresentation Vulnerability
A vulnerability exists in certain versions of Mozilla Thunderbird where crafted MIME email messages were incorrectly displayed as encrypted. This issue arises when a message claims to contain an encrypted OpenPGP message but actually includes an OpenPGP signed message instead. The vulnerability affects Thunderbird versions prior to 136 and prior to 128.8.
Mozilla Thunderbird OpenPGP Key Request Padding Size Vulnerability
A vulnerability exists in Mozilla Thunderbird versions prior to 136 and prior to 128.8, where an incorrect padding size was used when requesting OpenPGP keys from a WKD server. This flaw allowed a network observer to infer the length of the email address being requested.
Misskey ActivityPub Object Forgery Vulnerability
A vulnerability in Misskey's ActivityPub implementation allows for the forgery of objects by improperly validating the relationship between the 'id' and 'url' fields. This issue is present in Misskey versions through 2025.2.0. An attacker can exploit this vulnerability to claim authority in the 'url' field, even when the ActivityPub object type requires authority in the 'id' field. This flaw arises from an incomplete patch for a previous vulnerability, CVE-2024-52591.
AutoGPT Server-Side Request Forgery Vulnerability in Web Request Component
A server-side request forgery (SSRF) vulnerability has been identified in AutoGPT versions prior to autogpt-platform-beta-v0.4.2. The issue arises in the 'Send Web Request' component, where IPv6 addresses are not properly restricted or filtered. This oversight allows attackers to exploit the vulnerability by directing requests to IPv6 services, potentially accessing internal resources or services that should be protected.
