CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Linksys E5600 Command Injection Vulnerability in Ping Test Function
A command injection vulnerability has been identified in the Linksys E5600 router, specifically in version 1.1.0.26. The issue arises within the Lua runtime file, where the pingTest function can be exploited through the pt['pkgsize'] parameter.
Linksys E5600 Command Injection Vulnerability in Ping Test Function
A command injection vulnerability has been identified in the Linksys E5600 router, specifically in version 1.1.0.26. The issue arises within the Lua runtime file, where the 'runtime.pingTest' function is vulnerable to injection through the 'pt["count"]' parameter.
Linksys E5600 Command Injection Vulnerability in traceRoute Function
A command injection vulnerability has been identified in the Linksys E5600 router, specifically in version 1.1.0.26. The issue arises within the traceRoute function, where the pt parameter can be manipulated to inject and execute arbitrary commands.
PipeCD Privilege Escalation Vulnerability via Service Account Token Access
A vulnerability in PipeCD versions through 0.49.3 allows attackers to access the service account's token due to insecure permissions. This access can lead to unauthorized privilege escalation. The vulnerability arises from incorrect access control, which could be exploited by malicious users to steal the ServiceAccount token. Once obtained, the token can be used to authenticate with the API Server, access all Secrets in the Kubernetes cluster, and potentially elevate privileges to take over the entire cluster.
KubeSlice Privilege Escalation Vulnerability
A vulnerability in KubeSlice version 1.3.1 allows attackers to access the service account's token due to insecure permissions, leading to unauthorized privilege escalation. This vulnerability could be exploited by stealing the token from a service account with elevated permissions, such as those granted by a cluster role allowing updates to node resources. Once obtained, the token could be used to authenticate with the Kubernetes API server and access all secrets in the cluster, potentially allowing an attacker to elevate privileges further or take over the entire cluster.
Kuadrant Privilege Escalation Vulnerability via Service Account Token Access
A vulnerability in Kuadrant version 0.11.3 allows attackers to access the service account's token due to insecure permissions. This access can lead to privilege escalation through the secrets component in the Kubernetes cluster, potentially allowing an attacker to take over the cluster.
LoxiLB Incorrect Access Control Vulnerability Allowing Privilege Escalation
An incorrect access control vulnerability has been identified in LoxiLB versions through 0.9.7. This vulnerability allows attackers to access sensitive information by exploiting inadequate permission management. Once attackers gain access to the service account's token, they can read any secrets within the Kubernetes cluster. This exploitation can lead to unauthorized privilege escalation at the cluster level, potentially allowing attackers to take over the entire cluster.
IBM Storage Virtualize vSphere Remote Plug-in Credential Disclosure Vulnerability
A vulnerability in IBM Storage Virtualize vSphere Remote Plug-in versions 1.0 and 1.1 could enable a remote user to access sensitive credential information after the plug-in has been deployed.
Fortinet FortiOS Improper Input Neutralization Vulnerability in Web Filtering Allowing Redirects or JavaScript Execution
A vulnerability exists in Fortinet FortiOS versions 6.4.1 and prior, as well as 6.2.9 and prior, due to improper neutralization of input during web page generation. This vulnerability may enable a remote, unauthenticated attacker to redirect users to malicious websites by sending a crafted 'Host' header, or to execute JavaScript code in the context of the victim's browser. The issue arises when the FortiGate device has web filtering and category override features enabled and configured.
Parse Server Third-Party Authentication Credential Misuse Vulnerability
A vulnerability in Parse Server's third-party authentication handling allows authentication credentials from certain providers to be used across multiple Parse Server applications. This issue affects Parse Server versions prior to 7.5.2 and 8.0.0 through 8.0.2. The vulnerability arises when a user signs up with the same authentication provider in two unrelated Parse Server apps. In such cases, credentials from one app can be used to authenticate the user in the other app. This issue specifically impacts Parse Server applications that utilize an affected third-party authentication provider for user authentication, as configured in the Parse Server options.
Envoy WebSocket Handshake Failure Causes Denial-of-Service Vulnerability in ext_proc HTTP Filter
A denial-of-service vulnerability has been identified in Envoy versions prior to 1.34.0. The issue arises in the ext_proc HTTP filter, which can crash Envoy when a local reply is sent to an external server. This problem is linked to the filter's lifetime management. A specific scenario that triggers this crash is a failed WebSocket handshake, which prompts a local reply that ultimately leads to the Envoy crash.
AWS Cloud Development Kit CLI Credential Exposure Vulnerability
A vulnerability exists in the AWS Cloud Development Kit (CDK) Command Line Interface (CLI) versions 2.172.0 prior to 2.178.2. When used with a credential plugin that returns temporary AWS credentials including an expiration property, these credentials may be inadvertently printed to the console output. This issue does not affect plugins that omit the expiration property.
FastCMS SQL Injection Vulnerability in Article List API
A critical SQL injection vulnerability has been identified in FastCMS versions through 0.1.5. The issue resides in the '/api/client/article/list' and '/api/client/article/list/open' endpoints, where the 'orderBy' parameter is manipulated to execute arbitrary SQL commands. This vulnerability can be exploited remotely, and the injection is time-based, allowing an attacker to extract information from the database.
Next.js Authorization Bypass Vulnerability in Middleware
A vulnerability exists in Next.js, a React framework for full-stack web applications, allowing authorization checks to be bypassed in middleware. This issue affects Next.js versions 1.11.4 prior to 12.3.5, as well as versions 13.5.9, 14.2.25, and 15.2.3. The vulnerability arises because the 'x-middleware-subrequest' header, used to prevent recursive requests, can be exploited to skip critical checks like authorization cookie validation, potentially leading to unauthorized access.
Phpgurukul Vehicle Record Management System SQL Injection Vulnerability
A SQL injection vulnerability has been identified in Phpgurukul Vehicle Record Management System version 1.0. The issue resides in the 'searchinputdata' parameter of the 'index.php' file. This vulnerability allows attackers to inject malicious SQL queries, bypassing input validation and sanitation. As a result, attackers could manipulate SQL queries to gain unauthorized access to the database, leak sensitive information, alter or delete data, and potentially disrupt services.
Phpgurukul Human Metapneumovirus Testing Management System SQL Injection Vulnerability
A SQL injection vulnerability has been identified in Phpgurukul Human Metapneumovirus (HMPV) Testing Management System version 1.0. The issue resides in the 'searchdata' parameter of the '/patient-report.php' file. This vulnerability allows attackers to inject malicious SQL queries, bypassing input validation and sanitation. Exploitation of this flaw could lead to unauthorized database access, data manipulation, and exposure of sensitive information.
Youki Libcontainer Tenant Builder Capabilities Elevation Vulnerability
A vulnerability in the Youki libcontainer's tenant container builder allows for elevation of Linux process capabilities. This issue arises because the builder can unintentionally inherit and elevate capabilities from the main container, particularly if user-provided capabilities are added. The vulnerability is present in libcontainer versions prior to 0.5.3 and does not affect the Youki binary itself. The issue is similar to a previously reported vulnerability in runc, CVE-2022-29162, which also involved improper handling of inherited capabilities.
Tenable Nessus Agent Local Privilege Escalation Vulnerability
A local privilege escalation vulnerability exists in Tenable Nessus Agent for Windows, specifically in versions prior to 10.8.3. When installed in a non-default location, these versions failed to apply secure permissions to sub-directories. This oversight could allow users to escalate privileges locally, provided they had not already secured the directories in the chosen installation path.
LibreOffice Improper Certificate Validation Vulnerability Allowing Signature Forgery
A vulnerability in LibreOffice related to improper certificate validation has been identified, allowing an attacker to manipulate digital signatures on ODF documents. The attacker can self-sign a document with an untrusted signature, then alter it to use an invalid or unknown signature algorithm. LibreOffice erroneously accepts such signatures as valid, presenting them as trusted. This issue affects LibreOffice versions 7.0 prior to 7.0.5 and 7.1 prior to 7.1.1.
Open Asset Import Library Assimp Heap-Based Buffer Overflow Vulnerability in CSMImporter
A critical heap-based buffer overflow vulnerability has been identified in Open Asset Import Library (Assimp) version 5.4.3. The issue arises in the CSMImporter::InternReadFile function within the CSMLoader.cpp file. This vulnerability can be exploited remotely, potentially leading to arbitrary code execution if a victim is tricked into processing a malicious CSM file with Assimp.
Open Asset Import Library Assimp Divide-By-Zero Vulnerability in MDL Importer
A divide-by-zero vulnerability has been identified in Open Asset Import Library (Assimp) version 5.4.3. The issue arises in the MDLImporter::InternReadFile_Quake1 function within the MDLLoader.cpp file. The vulnerability is triggered by manipulating the skinwidth and skinheight parameters, leading to a floating-point exception. This vulnerability can be exploited remotely, potentially causing a denial-of-service condition by crashing the application.
Guangzhou Hongfan Technology iOffice20 Any User Login Vulnerability
A vulnerability allowing any user to log in has been identified in Guangzhou Hongfan Technology Co., LTD. iOffice20. This issue arises from a logical flaw, enabling attackers to access any system account, including that of the system administrator.
Code-Projects Human Resource Management System Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in Code-Projects Human Resource Management System version 1.0.1. The issue arises in the UpdateRecruitmentById function within the handler recruitment.go file. This vulnerability allows for the injection of malicious scripts that are executed in the context of the user’s browser. The flaw can be exploited remotely and requires authenticated user interaction.
Code-Projects Human Resource Management System Improper Authorization Vulnerability in Account Handler
A critical improper authorization vulnerability has been identified in Code-Projects Human Resource Management System version 1.0.1. The issue resides in the Account handler file, specifically within the Index function. The vulnerability arises from inadequate authorization checks, allowing attackers to manipulate the user_cookie argument to bypass authentication and access restricted resources. Exploitation of this vulnerability is relatively easy, and a proof-of-concept exploit is publicly available.
ITIUM 6050 Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in ITIUM 6050, version 5.5.5.2-b3526, from Impact Technologies. This issue allows attackers to execute malicious JavaScript by injecting code into the 'id_session' parameter via GET and POST requests to the '/index.php' endpoint.
Hercules Augeas Null Pointer Dereference Vulnerability in Regular Expression Handling
A null pointer dereference vulnerability has been identified in Hercules Augeas version 1.14.1. The issue arises in the 're_case_expand' function within 'src/fa.c', where the 'fa_expand_nocase' function fails to validate a pointer before use. This oversight allows for a null pointer to be dereferenced, leading to a segmentation fault and potential application crash. The vulnerability requires local exploitation.
Jinher OA C6 SQL Injection Vulnerability in IncentivePlanFulfillAppprove.aspx
A critical SQL injection vulnerability has been identified in Jinher OA C6 version 1.0. The issue arises in the file IncentivePlanFulfillAppprove.aspx, where the httpOID argument can be manipulated to execute SQL injection attacks. This vulnerability can be exploited remotely, and details of the exploit have been made public.
Mattermost Search API Vulnerability Allowing MFA Bypass
A vulnerability exists in Mattermost versions 10.4.x through 10.4.2, 10.3.x through 10.3.3, and 9.11.x through 9.11.8, where multi-factor authentication (MFA) is not properly enforced on certain search APIs. This flaw enables authenticated attackers to bypass MFA protections by exploiting user search, channel search, or team search queries.
Mattermost Channel Conversion Restriction Bypass Vulnerability
A vulnerability exists in Mattermost versions 10.4.x through 10.4.2, 10.3.x through 10.3.3, and 9.11.x through 9.11.8, allowing users with permission to convert public channels to private ones to also convert private channels back to public. This issue arises from the application's failure to properly enforce channel conversion restrictions.
Mattermost Team Admin Privilege Escalation Vulnerability in Private Channels
A vulnerability exists in Mattermost versions 9.11.x prior to 9.11.8, where the application fails to require explicit approval before assigning a team admin to a private channel. This oversight allows team admins to join private channels through specially crafted permalink links without the consent of the channel admins.
Mattermost Command Execution Vulnerability in Archived Channels
A vulnerability exists in Mattermost versions 10.4.x through 10.4.2, 10.3.x through 10.3.3, and 9.11.x through 9.11.8. These versions fail to properly restrict command execution in archived channels, allowing authenticated users to execute commands in those channels.
Mattermost Multi-Version Vulnerability Allowing MFA Bypass on Plugin Endpoints
A vulnerability exists in Mattermost versions 10.4.x through 10.4.2, 10.3.x through 10.3.3, and 9.11.x through 9.11.8, as well as in version 10.5.0. These versions fail to properly enforce multi-factor authentication (MFA) on plugin-specific API endpoints. This oversight enables authenticated attackers to bypass MFA protections by sending requests to these vulnerable plugin routes.
Mattermost Bookmark Management Vulnerability in Archived Channels
A vulnerability exists in Mattermost versions 10.4.x through 10.4.2, 10.3.x through 10.3.3, and 9.11.x through 9.11.8, allowing authenticated users to create or update bookmarks in archived channels. The issue arises because these versions do not properly restrict bookmark actions in channels that have been archived.
WebAssembly Wabt Heap-Based Buffer Overflow Vulnerability in Binary Reader Interp Function
A critical heap-based buffer overflow vulnerability has been identified in WebAssembly Wabt version 1.0.36. The issue arises in the BinaryReaderInterp::GetReturnCallDropKeepCount function, located in binary-reader-interp.cc. This vulnerability can be exploited remotely and is caused by improper boundary checking when the function processes files with certain formatting errors. The lack of adequate validation allows read operations to exceed allocated memory, potentially leading to application crashes.
Qt QDom Complex Algorithm Vulnerability in XML Processing
A vulnerability exists in the QDom component of Qt versions prior to 6.8.0, where the 'encodeText' function employs a complex algorithm for XML string processing. This algorithm involves copying the entire string and making inline replacements, which can lead to inefficiencies by requiring the relocation of data after each modification. The issue causes a significant slowdown in performance, particularly in Qt 6, where the 'encodeText' function is called more frequently, exacerbating the problem.
Varnish Enterprise Out-of-Bounds Read Vulnerability in MSE4 Stevedore Objects Allowing Information Disclosure
An out-of-bounds read vulnerability has been identified in Varnish Enterprise versions prior to 6.0.13r13. This vulnerability allows remote attackers to access sensitive information by exploiting range requests on ephemeral objects managed by the MSE4 stevedore. The issue arises from incorrect buffer boundary calculations, which can lead to arbitrary data from the server's memory being leaked to clients. This vulnerability is specific to Varnish Enterprise instances using the MSE4 storage engine, and it could potentially expose cached content from other objects or internal data structures, such as TLS certificates.
Varnish Cache and Varnish Enterprise Client-Side Desynchronization Vulnerability Allowing HTTP Request Smuggling
A client-side desynchronization vulnerability has been identified in Varnish Cache versions prior to 7.6.2 and Varnish Enterprise versions prior to 6.0.13r10. This vulnerability allows HTTP request smuggling by exploiting how certain malformed HTTP/1 requests are handled. When a request contains multiple 'Host' or 'Content-Length' headers, Varnish may respond with a '400 Bad Request' but then continue processing the connection with subsequent requests. This can lead to the misrouting of responses, as the server may incorrectly associate them with the wrong request.
SimpleMachines SMF Reflected Cross-Site Scripting Vulnerability in ManageNews.php
A reflected cross-site scripting vulnerability has been identified in SimpleMachines Forum (SMF) version 2.1.4. The issue resides in the 'subject' parameter of the 'ManageNews.php' file, where improper handling of input allows for the injection of malicious scripts. This vulnerability can be exploited remotely, potentially affecting users who view the injected content.
SimpleMachines SMF Stored Cross-Site Scripting Vulnerability in ManageAttachments.php
A stored cross-site scripting vulnerability has been identified in SimpleMachines Forum (SMF) version 2.1.4. The issue arises in the 'ManageAttachments.php' file, specifically within the 'notice' parameter. This vulnerability allows attackers to inject malicious scripts that are executed when other users view the affected web pages. Although the vendor does not consider this a security vulnerability due to authentication requirements for accessing file modification features, the existence of the vulnerability has been publicly disclosed and is available for exploitation.
QuickJS Stack-Based Buffer Overflow Vulnerability in Versions Prior to 0.8.0
A stack-based buffer overflow vulnerability has been identified in QuickJS versions prior to 0.8.0. The issue arises in the function JS_GetRuntime within the file quickjs.c, part of the qjs component. This vulnerability can be exploited remotely, leading to a stack overflow error, particularly when the AddressSanitizer is active.
OpenSlides HTML Injection Vulnerability in Chat Names
A vulnerability allowing HTML injection has been identified in OpenSlides versions prior to 4.2.5. When users create new chats through the chat_group.create action, they can specify the chat name. While certain HTML elements, such as SCRIPT tags, are filtered out, others are not. Generally, HTML entities are encoded correctly, except when deleting chats or messages, which can lead to interference with the website's layout. However, it is unlikely that users would engage with deleted chats or messages.
OpenSlides Timing Sidechannel Vulnerability Allows User Enumeration
A timing sidechannel vulnerability has been identified in OpenSlides versions prior to 4.2.5. During the login process at the '/system/auth/login/' endpoint, the response times vary based on whether a user exists in the system. This discrepancy arises because the password hashing is omitted for non-existing users, leading to a timing difference of approximately 15 milliseconds for non-existing users compared to 200 milliseconds for existing users. This vulnerability can be exploited to infer the existence of users in the system.
OpenSlides Directory Traversal Vulnerability Allowing File Overwrite
A directory traversal vulnerability has been identified in OpenSlides versions prior to 4.2.5. This issue allows files to be uploaded to OpenSlides meetings and organized into folders. Users can download a ZIP archive containing all files in a selected folder and its subfolders. However, if an attacker includes a relative or absolute path in the title of a file or folder, the ZIP archive will convert that title into a path. Depending on the extraction tool used, this could overwrite files locally outside of the chosen directory.
OpenSlides Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in OpenSlides versions prior to 4.2.5. The issue arises when users submit descriptions for Moderator Notes or Agenda Topics. An editor interface allows the insertion of various HTML elements. While <script> tags are properly encoded when reflected, links can be manipulated by adding attributes such as 'onmouseover', enabling the execution of JavaScript in the user's session.
ManageEngine ServiceDesk Plus Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in ManageEngine ServiceDesk Plus versions prior to 14920, as well as in ServiceDesk Plus MSP and SupportCentre Plus versions prior to 14910. This vulnerability allows authenticated technicians to upload malicious HTML files during task creation. The injected scripts are executed when other technicians, administrators, or SDAdmins interact with the file.
xmedcon Integer Underflow Vulnerability in DICOM File Handler
An integer underflow vulnerability has been identified in xmedcon version 0.25.0, specifically within the DICOM File Handler component's malloc function. This vulnerability allows for remote exploitation, where an attacker can manipulate input to cause the integer underflow, potentially leading to memory corruption. The issue has been acknowledged to impact the application's availability.
Dell Chassis Management Controller Stack-Based Buffer Overflow Vulnerability Allowing Remote Code Execution
A stack-based buffer overflow vulnerability has been identified in Dell Chassis Management Controller (CMC) Firmware for PowerEdge FX2, versions prior to 2.40.200.202101130302, and for PowerEdge VRTX, versions prior to 3.41.200.202209300499. This vulnerability allows an unauthenticated attacker with remote access to potentially execute code remotely.
EBM Technologies EBM Maintenance Center SQL Injection Vulnerability
A SQL injection vulnerability has been identified in EBM Maintenance Center by EBM Technologies, affecting versions prior to 25.04.31435. This vulnerability allows remote attackers with regular privileges to inject arbitrary SQL commands, potentially leading to unauthorized reading, modification, or deletion of database contents.
Microsoft Partner Center Improper Authorization Vulnerability Allowing Privilege Escalation
A vulnerability has been identified in Microsoft Partner Center that involves improper authorization, allowing an authorized attacker to elevate privileges over a network. This issue could lead to unauthorized access or actions within the application, potentially affecting other users or system components.
Microsoft Dataverse Deserialization Vulnerability Allowing Remote Code Execution
A deserialization vulnerability in Microsoft Dataverse permits an authorized attacker to execute code over a network. This issue arises from the improper handling of untrusted data, which could be exploited to execute malicious code remotely.
