CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Feb 10, 2025

Linux Kernel USB Serial Quatech2 Null Pointer Dereference Vulnerability

A null pointer dereference vulnerability has been fixed in the Linux kernel's USB serial Quatech2 driver. The issue arose in the function 'qt2_process_read_urb()' due to an improper bounds check. The original condition failed to consider the valid range of the 'serial->port' buffer, leading to an out-of-bounds access when 'newport' equaled 'serial->num_ports'. This out-of-bounds access caused the 'port' variable to be assigned a NULL value, creating the potential for a null pointer dereference.

5.7
Feb 10, 2025

Linux Kernel V3D Driver NULL Pointer Dereference Vulnerability

A race condition vulnerability has been identified in the Linux kernel's V3D graphics driver. This issue arises from a conflict between the DRM scheduler workqueue and the IRQ execution thread. After a job is completed, the job pointer is set to NULL, indicating that the job is finished. However, this change creates a race condition: as the IRQ execution thread signals the completion of a job, a new job can be assigned to the same pointer. If the IRQ execution thread sets the pointer to NULL after a new job has been assigned, it can lead to a NULL pointer dereference. This dereference occurs when the completed job generates an interrupt, triggering a crash by accessing a NULL reference.

5.2
Feb 10, 2025

Linux Kernel vfio/platform Bounds Checking Vulnerability in Read/Write Syscalls

A vulnerability in the Linux kernel's vfio/platform component allows for out-of-bounds read and write operations through unchecked syscall parameters. While the offset is limited to 40 bits, this can still be exploited to access memory beyond the device's allocated bounds.

5.4
Feb 10, 2025

Linux Kernel Denial-of-Service Vulnerability in AMD Display Driver via Uninitialized Denominator

A denial-of-service vulnerability has been identified in the Linux kernel's AMD display driver. The issue arises from variables used as denominators that may not be properly assigned, potentially leading to a divide-by-zero error. This vulnerability has been addressed by ensuring that these variables are initialized to non-zero values. The fix is based on a Coverity report highlighting the risk of uninitialized variables causing division errors.

5.7
Feb 10, 2025

GnuTLS Denial-of-Service Vulnerability via Inefficient DER Decoding in libtasn1

A denial-of-service vulnerability has been identified in GnuTLS, which relies on libtasn1 for processing ASN.1 data. The issue arises from an inefficient algorithm in libtasn1 that can cause excessive delays when decoding certain DER-encoded certificate data. This flaw allows remote attackers to send specially crafted certificates that consume significant resources, making GnuTLS unresponsive or slow.

7.1
Feb 10, 2025

GNU Libtasn1 Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in GNU Libtasn1, a library for managing Abstract Syntax Notation One (ASN.1) data. This vulnerability affects all versions of Libtasn1 prior to 4.20.0. The issue arises from inefficient handling of certificates containing a large number of 'SEQUENCE OF' or 'SET OF' elements. When such a certificate is processed, the decoding time can increase significantly, leading to excessive CPU usage. This vulnerability can be exploited by sending a specially crafted certificate, causing applications that use Libtasn1 for certificate parsing and verification to slow down or crash.

5.5
Feb 10, 2025

npm serialize-javascript Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the npm package 'serialize-javascript', affecting versions prior to 6.0.2. The issue arises because the module fails to properly sanitize certain inputs, such as regular expressions and other JavaScript object types. This lack of sanitization allows attackers to inject malicious code that can be executed when the data is deserialized by a web browser. The vulnerability is particularly critical in environments where serialized data is sent to web clients, as it could compromise the security of the website or web application using this package.

3.0
Feb 10, 2025

GNU Binutils Memory Leak Vulnerability in ld Component

A memory leak vulnerability has been identified in GNU Binutils version 2.43, specifically within the ld component's xstrdup function in libiberty/xmalloc.c. This vulnerability allows for a remote memory leak, where the application fails to properly manage and release allocated memory, leading to increased memory consumption over time. The vulnerability has been publicly disclosed and is considered difficult to exploit, although a proof-of-concept exploit is available.

5.8
Feb 10, 2025

ABB VideONet Vulnerability in System 800xA Versions 5.1.X, 6.0.3.X, 6.1.1.X, and 6.2.X Allowing Video Feed Manipulation

A vulnerability in the VideONet component of ABB's System 800xA is present in several versions, including 5.1.X, 6.0.3.X, 6.1.1.X, and 6.2.X. This vulnerability allows an attacker to stop or manipulate the video feed, potentially disrupting surveillance or monitoring activities.

2.6
Feb 10, 2025

Devolutions Remote Desktop Manager Windows Improper Host Validation Vulnerability Allowing Man-in-the-Middle Attacks

A vulnerability exists in Devolutions Remote Desktop Manager for Windows, specifically in versions through 2024.3.19, due to improper host validation in the certificate validation component. This flaw allows attackers to intercept and modify encrypted communications by presenting a certificate for a different host, effectively executing a man-in-the-middle attack.

2.3
Feb 10, 2025

GNU Binutils Memory Leak Vulnerability in ld Component

A memory leak vulnerability has been identified in GNU Binutils version 2.43, specifically within the ld component's link_order_scan function in ldelfgen.c. This vulnerability allows for a denial-of-service condition, as the application fails to properly manage and release memory, leading to increased memory consumption. The issue can be exploited remotely, but requires user interaction.

5.8
Feb 10, 2025

GNU Binutils Buffer Overflow Vulnerability in the 'nm' Component

A buffer overflow vulnerability has been identified in GNU Binutils version 2.43, specifically within the 'nm' component. The issue arises in the function '__sanitizer::internal_strlen' in 'binutils/nm.c', where improper manipulation of the argument const creates the potential for a buffer overflow. This vulnerability can be exploited remotely, although the complexity of the attack is considered high, making exploitation difficult.

5.9
Feb 10, 2025

Devolutions Remote Desktop Manager Missing Certificate Validation Vulnerability

A vulnerability exists in Devolutions Remote Desktop Manager across multiple platforms, including macOS, iOS, Android, and Linux, due to missing certificate validation. This flaw allows attackers to intercept and modify encrypted communications, facilitating a man-in-the-middle attack. The issue is present in Remote Desktop Manager versions for macOS through 2024.3.9.0, Linux through 2024.3.2.5, Android through 2024.3.3.7, iOS through 2024.3.3.0, and PowerShell through 2024.3.6.0.

2.2
Feb 10, 2025

Kelio Visio Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in Kelio Visio 1, Kelio Visio X7, and Kelio Visio X4, affecting versions 3.2C through 5.1K. This vulnerability allows an attacker to execute a JavaScript payload by making a POST request and injecting malicious code into the editable 'username' parameter of the '/PageLoginVisio.do' endpoint.

2.0
Feb 10, 2025

KUNBUS Revolution Pi Path Traversal Vulnerability

A path traversal vulnerability exists in KUNBUS Revolution Pi version 2022-07-28-revpi-buster. This vulnerability allows an authenticated attacker to list device directories through the '/pictory/php/getFileList.php' endpoint by manipulating the 'dir' parameter.

1.6
Feb 10, 2025

KUNBUS Revolution Pi OS Command Injection Vulnerability

An OS command injection vulnerability has been identified in KUNBUS Revolution Pi version 2022-07-28-revpi-buster. This vulnerability allows authenticated attackers to execute operating system commands on the device. The issue arises in the 'php/dal.php' endpoint, specifically within the 'arrSaveConfig' parameter.

1.8
Feb 10, 2025

Apache Felix Webconsole Cross-Site Scripting Vulnerability

A cross-site scripting vulnerability has been identified in Apache Felix Webconsole. This issue affects versions 4.x prior to 4.9.8 and 5.x prior to 5.0.8. The vulnerability arises from improper input neutralization during web page generation, allowing for the injection of malicious scripts.

2.0
Feb 10, 2025

TP-Link Tapo C500 Wi-Fi Camera Hard-Coded RSA Private Key Vulnerability Allowing Cryptographic Key Extraction

A vulnerability exists in the TP-Link Tapo C500 Wi-Fi camera, specifically in version 1.1.4 Build 240506 Rel.39487n and earlier for V1, and version 1.0.2 Build 240605 Rel.32561n and earlier for V2. The issue arises from a hard-coded RSA private key embedded in the device firmware. An attacker with physical access could exploit this vulnerability to extract the private keys, which could then be used for impersonation, data decryption, and man-in-the-middle attacks on the affected device.

1.1
Feb 9, 2025

Linux Kernel Serdev Race Condition Vulnerability in Lenovo Yoga Tab 2 Pro Fast Charger

A race condition vulnerability has been identified in the Linux kernel's handling of the serdev device for the Lenovo Yoga Tab 2 Pro 1380 Fast Charger. The issue arises in the yt2_1380_fc_serdev_probe() function, which calls devm_serdev_device_open() before properly setting the client operations. This misordering can lead to a NULL pointer dereference in the serdev controller's receive_buf handler, as it relies on the serdev operations being valid when the SERPORT_ACTIVE state is applied. This vulnerability mirrors a previously addressed race condition in a different component of the Linux kernel.

5.2
Feb 9, 2025

Linux Kernel GPIO Xilinx Raw Spinlock Vulnerability

A vulnerability in the Linux kernel's GPIO Xilinx driver has been addressed by converting the GPIO lock to a raw spinlock. This change was necessary because IRQ chip functions can be called in a raw spinlock context, requiring internal locking to also use raw spinlocks. The vulnerability was identified by a lockdep splat, indicating an invalid wait context issue. The problem arose when a worker thread attempted to acquire a lock while holding other locks that restricted the wait context, leading to a potential deadlock situation.

5.7
Feb 9, 2025

Linux Kernel GICv3 ITS Interrupt Handling Vulnerability

A vulnerability in the Linux kernel's GICv3 ITS interrupt handling has been addressed. The issue involved enabling interrupts within a nested interrupt-disabled section, which could lead to unexpected behavior. This vulnerability was introduced in a previous commit that altered the interrupt handling mechanism, and it has been resolved by restoring the original locking approach.

5.3
Feb 9, 2025

Super Store Finder WordPress Plugin SQL Injection Vulnerability Allowing Stored Cross-Site Scripting

A SQL injection vulnerability has been identified in the Super Store Finder plugin for WordPress, affecting all versions through 7.0. The issue arises from inadequate escaping of user-supplied data in the 'ssf_wp_user_name' parameter, coupled with a lack of proper preparation in the SQL query. This vulnerability enables unauthenticated attackers to inject additional SQL commands into existing queries, potentially leading to the storage of cross-site scripting payloads in store reviews.

4.4
Feb 8, 2025

DWT Directory and Listing WordPress Theme Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the DWT - Directory & Listing WordPress Theme, affecting versions through 3.3.4. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in shortcodes. This vulnerability allows authenticated attackers with contributor-level or higher permissions to inject arbitrary scripts into pages, which are executed when users access the affected pages.

1.6
Feb 8, 2025

WP Directorybox Manager Authentication Bypass Vulnerability

A vulnerability allowing authentication bypass has been identified in the WP Directorybox Manager plugin for WordPress, affecting versions through 2.5. The issue arises from improper authentication in the 'wp_dp_enquiry_agent_contact_form_submit_callback' function, enabling unauthenticated attackers to log in as any existing user, including administrators, provided they know the username.

2.6
Feb 8, 2025

IBM DevOps Deploy and UrbanCode Deploy Sensitive Information Disclosure Vulnerability

A vulnerability allowing authenticated users to access sensitive information about other users has been identified in IBM DevOps Deploy versions 8.0 prior to 8.0.1.4, 8.1 prior to 8.1.0.0, and in IBM UrbanCode Deploy (UCD) versions 7.0 prior to 7.0.5.25, 7.1 prior to 7.1.2.21, 7.2 prior to 7.2.3.14, and 7.3 prior to 7.3.2.9. This issue arises from missing authorization for a function, which could allow users to obtain sensitive information about other users on the system.

1.7
Feb 8, 2025

CoinRemitter OpenCart Plugin SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in the CoinRemitter OpenCart plugin, specifically in versions 0.0.1 and 0.0.2. The vulnerability arises from the manipulation of the 'coin' argument, allowing remote attackers to execute arbitrary SQL commands. This exploitation can lead to unauthorized access to the database, including sensitive information such as API credentials for CoinRemitter wallets, which could be used to steal funds. Additionally, the vulnerability could be used to exfiltrate admin session details and any personally identifiable information or payment details stored in the database.

3.9
Feb 8, 2025

WordPress Simple Add Pages or Posts Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Simple Add Pages or Posts plugin for WordPress, affecting all versions prior to and including 2.0.0. The vulnerability arises from inadequate input sanitization and output escaping, allowing authenticated attackers with administrator-level access to inject arbitrary web scripts into pages. These scripts would execute when a user accesses the compromised page. This issue is present in multi-site installations and those where unfiltered HTML has been disabled.

2.2
Feb 8, 2025

Dreamvention Live Ajax Search OpenCart Module SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in the Dreamvention Live Ajax Search OpenCart module, free versions through 1.0.6. The issue resides in the 'searchresults/search' function, where the 'keyword' parameter is manipulated to execute arbitrary SQL commands. This vulnerability allows remote, unauthenticated attackers to access and exfiltrate all database content, including admin session details, credentials, and any Personally Identifiable Information (PII) or payment details stored in the database.

3.9
Feb 8, 2025

RT-Thread Information Disclosure Vulnerability in System Call Parameter Handling

An information disclosure vulnerability has been identified in RT-Thread versions through 5.1.0. The issue arises in the system call implementations within the file 'rt-thread/components/lwp/lwp_syscall.c'. Affected functions include 'sys_thread_create', 'sys_device_write', and several others related to synchronization, messaging, and timer management. The vulnerability stems from insufficient validation of pointer parameters, allowing a malicious user thread to manipulate arguments and access sensitive kernel memory, thereby leaking confidential information.

2.5
Feb 7, 2025

Joplin Desktop Cross-Site Scripting Vulnerability Allowing Arbitrary Code Execution

A cross-site scripting (XSS) vulnerability has been identified in Joplin Desktop versions through 3.1.23. This issue arises from the application using React's 'dangerouslySetInnerHTML' to insert note titles into the document without properly escaping HTML entities. The absence of a restrictive Content-Security-Policy allows the execution of arbitrary JavaScript via inline event handlers in unsanitized HTML. Furthermore, with 'nodeIntegration' enabled, this arbitrary JavaScript execution can lead to arbitrary code execution. The vulnerability affects users who receive notes from unknown sources and use 'ctrl+p' to search.

5.5
Feb 7, 2025

Joplin HTML Sanitizer Comment Handling Vulnerability Leading to Cross-Site Scripting

A cross-site scripting (XSS) vulnerability has been identified in Joplin, a note-taking application, specifically in versions 3.2.6 through 3.2.11. This vulnerability arises from a discrepancy between Joplin's HTML sanitizer and how browsers process comments, affecting both the Rich Text Editor and the Markdown viewer. However, the Markdown viewer's cross-origin isolation prevents direct access to the Joplin window, a vulnerability that allows arbitrary code execution from the Rich Text Editor. The issue was not present in Joplin 3.1.24 and may have been introduced in a previous version.

5.5
Feb 7, 2025

Newbee Mall Stored Cross-Site Scripting Vulnerability in Add Category Page

A stored cross-site scripting vulnerability has been identified in Newbee Mall version 1.0. The issue arises in the Add Category Page, specifically within the save function of the admin/categories/save file. The vulnerability is triggered by manipulating the categoryName argument, allowing for the injection of XSS payloads. This vulnerability can be exploited remotely and requires user interaction.

3.3
Feb 7, 2025

Joplin DOM Clobbering Vulnerability Leading to Denial-of-Service

A DOM clobbering vulnerability has been identified in Joplin, a note-taking and to-do application. This vulnerability allows the 'name' attribute to be set in a way that overwrites existing document properties, such as 'querySelector'. The only known impact of this vulnerability is a denial-of-service condition, where the note viewer fails to refresh until the note is closed and reopened. This issue affects Joplin versions 3.2.3 and prior.

5.3
Feb 7, 2025

SFTPGo Command Injection Vulnerability in Rsync Feature Allows Unauthorized File Access or Modification

A command injection vulnerability has been identified in SFTPGo, an open-source file transfer solution, versions 0.9.5 through 2.6.4. The issue arises from insufficient sanitization of user-provided 'rsync' commands, allowing authenticated remote users to manipulate files with the same permissions as the SFTPGo server process. This vulnerability is particularly concerning because it could be exploited to read or write files on the server.

4.0
Feb 7, 2025

Taisan Tarzan-CMS Deserialization Vulnerability in Add Theme Handler

A critical deserialization vulnerability has been identified in Taisan Tarzan-CMS versions through 1.0.0. This issue arises in the Add Theme Handler component, specifically within the upload function of the admin themes section. The vulnerability can be exploited remotely, allowing for potential unauthorized actions or access.

3.2
Feb 7, 2025

JeecgBoot SQL Injection Vulnerability in TotalData Component

A SQL injection vulnerability has been identified in JeecgBoot version 3.7.2, developed by Beijing Guoju Information Technology Co., Ltd. This vulnerability allows remote attackers to access sensitive information through the getTotalData component. Although this version includes some validation measures, they can be bypassed, leaving the application susceptible to injection attacks.

4.5
Feb 7, 2025

TP-Link TL-WPA8630 V2.2.4 Build 20230427 Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in the TP-Link TL-WPA8630 (US) version V2.2.4 Build 20230427. The issue arises from a command injection vulnerability in the function sub_4256CC, which allows attackers to execute arbitrary code by injecting specific commands.

3.9
Feb 7, 2025

LDAP User Manager Reflected Cross-Site Scripting Vulnerability

A reflected Cross-Site Scripting (XSS) vulnerability exists in LDAP User Manager versions through ce92321. The issue is located in the /setup/index.php endpoint, where the returnto parameter is not properly sanitized, allowing attackers to inject malicious JavaScript. This vulnerability can be exploited by sending a POST request with a crafted delete_user parameter that includes a script payload, which is then executed in the user's browser.

3.4
Feb 7, 2025

QingScan Reflected Cross-Site Scripting Vulnerability

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in QingScan versions through 1.8.0. The issue resides in the `/webscan/sqlmap/index.html` endpoint, where improper input sanitization of the `dasta` query parameter allows attackers to inject malicious JavaScript payloads. When a victim accesses a crafted URL with the injected payload, the script executes in the context of the victim's browser.

2.8
Feb 7, 2025

Brainasoft Braina Sensitive Information Disclosure Vulnerability

A vulnerability in Brainasoft Braina version 2.8 allows remote attackers to access sensitive information through the chat window function.

2.5
Feb 7, 2025

Jrohy Trojan Privilege Escalation Vulnerability

A privilege escalation vulnerability exists in Jrohy Trojan versions 2.0.0 through 2.15.3. The issue arises in the web application's initialization interface at '/auth/register', where improper handling of user input allows remote attackers to modify the administrator password without authorization.

3.9
Feb 7, 2025

vLLM Hash Collision Vulnerability in Prefix Caching Allowing Cache Poisoning

A vulnerability in vLLM, a high-throughput inference engine for large language models, arises from hash collisions in prefix caching. This issue, present in vLLM versions prior to 0.7.2, is exploited by using maliciously crafted prompts that take advantage of Python's built-in hash function. As of Python 3.12, the hash value for 'None' has become a predictable constant, increasing the risk of collisions. Exploiting this vulnerability could lead to unintended behavior by reusing cached responses generated from different content, potentially disrupting the accuracy of the model's output.

2.9
Feb 7, 2025

Pimcore Admin UI Classic Bundle User Enumeration Vulnerability

A user enumeration vulnerability has been identified in the Pimcore Admin UI Classic Bundle, affecting versions prior to 1.7.4. This vulnerability arises from the 'Forgot Password' function, which does not provide a generic error message. Instead, it discloses whether an account exists based on the email input, allowing attackers to enumerate valid accounts. This issue could lead to unauthorized access if combined with password spraying attacks.

5.6
Feb 7, 2025

Flexera RISC Platform Import/Export Interface Authorization Vulnerability

A vulnerability exists in Flexera RISC Platform versions prior to the saas-2021-12-29 release, related to authorization management for the import and export interfaces. This flaw can be exploited to access the import/export functionality with limited privileges.

1.7
Feb 7, 2025

Flexera RISC Platform Two-Factor Authentication Bypass Vulnerability

A vulnerability allowing the bypass of two-factor authentication (2FA) has been identified in the Flexera RISC Platform, in versions prior to the saas-2021-12-29 release. This issue arises from an error related to 2FA, which can be exploited if the 2FA setup has not been completed.

3.4
Feb 7, 2025

Puppet Agent Deserialization of Untrusted Data Vulnerability

A vulnerability in Puppet Agent prior to 7.4.0 allows for the deserialization of untrusted or user-supplied data, creating a potential security risk. This issue has been addressed in the Puppet Agent 7.4.0 release.

3.2
Feb 7, 2025

CmsEasy Path Traversal Vulnerability in Database Administration Library

A critical path traversal vulnerability has been identified in CmsEasy version 7.7.7.9. The issue arises in the database administration library, specifically within the deletedir_action and restore_action functions. This vulnerability allows remote attackers to manipulate input in a way that traverses the file path, potentially leading to unauthorized access to files or directories outside of the intended restrictions. The vulnerability has been publicly disclosed and is accompanied by a proof-of-concept exploit.

4.4
Feb 7, 2025

SiberianCMS Cross-Site Scripting Vulnerability in HTTP GET Request Handler

A cross-site scripting vulnerability has been identified in SiberianCMS version 4.20.6. The issue arises in an unknown functionality of the file '/app/sae/design/desktop/flat', within the HTTP GET request handler component. This vulnerability can be exploited remotely, and has been disclosed publicly. The vendor was contacted prior to this disclosure but did not respond.

2.5
Feb 7, 2025

D-Link DHP-W310AV Authentication Bypass Vulnerability

A critical vulnerability allowing authentication bypass has been identified in the D-Link DHP-W310AV model 1.04. This issue arises from an unknown code manipulation that enables spoofing attacks, allowing unauthorized access to the device. The vulnerability can be exploited remotely without any authentication requirements.

3.9
Feb 7, 2025

WP All Export Pro Privilege Escalation Vulnerability

A vulnerability in the WP All Export Pro plugin for WordPress, present in all versions through 1.9.1, allows for unauthorized data modification that could lead to privilege escalation. This issue arises from inadequate validation and sanitization of user input, enabling authenticated attackers with Shop Manager-level access or higher to alter arbitrary options on the WordPress site. Exploitation of this vulnerability could involve changing the default registration role to administrator and activating user registration, thereby granting administrative access to the attacker on the compromised site.

1.8