CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Go Variable Time Instruction Vulnerability in P-256 Implementation on ppc64le Architecture
A vulnerability exists in the Go programming language's assembly implementation of the P-256 elliptic curve cryptography, specifically on the ppc64le architecture. The issue arises from the use of a variable time instruction in an internal function, which inadvertently leaks a small number of bits from secret scalars. This leakage, however, is not believed to be sufficient for recovering private keys in well-known protocols that use P-256.
AppHouseKitchen AlDente Charge Limiter XPC Service Improper Authorization Vulnerability
A critical vulnerability has been identified in AppHouseKitchen AlDente Charge Limiter versions prior to 1.30 on macOS. The issue resides in the XPC service component, specifically within the 'shouldAcceptNewConnection' function of the 'com.apphousekitchen.aldente-pro.helper' file. This vulnerability allows improper authorization, enabling unauthorized access to privileged hardware operations through the application's Mach service. The flaw can be exploited locally, and a public proof-of-concept exploit is available.
DouPHP Cross-Site Scripting Vulnerability in Article Management
A cross-site scripting vulnerability has been identified in DouPHP version 1.8 Release 20231203. This issue allows attackers to execute arbitrary code by injecting a crafted payload into the description parameter of the article management page.
PHPJabbers Cinema Booking System SQL Injection Vulnerability in User Management Function
A SQL injection vulnerability has been identified in PHPJabbers Cinema Booking System version 2.0, specifically within the 'pjActionGetUser' function. This vulnerability allows attackers to manipulate database queries by exploiting the 'column' parameter. Successful exploitation could result in unauthorized access to sensitive information, privilege escalation, or manipulation of the database.
PHPJabbers Cinema Booking System Cross-Site Request Forgery Vulnerability Privilege Escalation
A cross-site request forgery (CSRF) vulnerability has been identified in PHPJabbers Cinema Booking System version 2.0. This vulnerability allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request. The issue arises in the 'pjActionUpdate' function, where attackers can forge requests that, if successful, could lead to unauthorized changes in admin user roles or passwords.
PHPJabbers Cinema Booking System Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in PHPJabbers Cinema Booking System version 2.0. This vulnerability arises from unsanitized input in file upload fields, specifically 'event_img' and 'seat_maps', as well as in seat number configurations. Attackers can exploit this flaw to inject persistent JavaScript, which could be used for phishing, malware injection, or session hijacking.
PHPJabbers Cinema Booking System Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in PHPJabbers Cinema Booking System version 2.0. This issue arises because multiple endpoints fail to properly sanitize user input, allowing the execution of malicious scripts in the context of the user's browser. Attackers can exploit this vulnerability by crafting harmful links that, when clicked, could steal session cookies or facilitate phishing attempts.
ClearML Enterprise Server Vault API Information Disclosure Vulnerability
A vulnerability allowing information disclosure exists in the Vault API of ClearML Enterprise Server versions 3.22.5-1533. This issue arises because the API can be manipulated to retrieve vaults that have been disabled, potentially exposing sensitive credentials. The vulnerability can be exploited by sending a series of crafted HTTP requests to the API endpoint that manages vaults.
ClearML Enterprise Server Cross-Site Scripting Vulnerability in Dataset Upload Functionality
A cross-site scripting vulnerability has been identified in ClearML Enterprise Server versions 3.22.5-1533. This issue arises in the dataset upload feature, where a specially crafted HTTP request can inject arbitrary HTML. Attackers can exploit this vulnerability by sending a series of HTTP requests to upload malicious HTML files into a dataset. These files may then be rendered in the browser of an authenticated ClearML user, executing any JavaScript contained within the HTML. This vulnerability could lead to the exfiltration of sensitive data from the user's local storage, particularly information related to storage providers like AWS S3.
Newgensoft OmniDocs Insecure Direct Object Reference Vulnerability Allowing PII Theft
A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in Newgensoft OmniDocs version 11.0_SP1_03_006. This vulnerability resides in the 'getuserproperty' function, where improper access control allows unauthorized users to access and steal configuration data and Personally Identifiable Information (PII) from other users.
Kaspersky Products Kernel Memory Buffer Vulnerability Allowing Data Write
A vulnerability has been identified in multiple Kaspersky products, including Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Security Cloud, Kaspersky Safe Kids, and Kaspersky Anti-Ransomware Tool. This vulnerability could enable an authenticated attacker to write data to a restricted area outside the designated kernel memory buffer. The issue has been automatically resolved in all Kaspersky Endpoint products.
Tiny File Manager Session Fixation Vulnerability
A session fixation vulnerability exists in Tiny File Manager versions through 2.4.7. This issue allows an attacker to manipulate session identifiers, potentially leading to unauthorized actions within the application.
Tiny File Manager Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Tiny File Manager versions through 2.4.7. This issue allows attackers to execute arbitrary code by injecting a crafted payload into the name of an uploaded or existing file. The vulnerability arises when the application fails to properly sanitize file names, enabling the execution of malicious scripts in the user's browser.
Trimble Cityworks Deserialization Vulnerability Allowing Remote Code Execution
A deserialization vulnerability has been identified in Trimble Cityworks versions prior to 15.8.9, as well as in Cityworks with Office Companion versions prior to 23.10. This vulnerability could enable an authenticated user to execute remote code on a customer's Microsoft Internet Information Services (IIS) web server.
Honeywell OneWireless Wireless Device Manager Command Injection Vulnerability
A command injection vulnerability has been identified in Honeywell OneWireless Wireless Device Manager (WDM) versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, and R330.1. This vulnerability allows an authenticated attacker to exploit the firmware update process, potentially leading to command injection.
Apache ShardingSphere ElasticJob-UI Remote Code Execution Vulnerability via H2 JDBC URL
A remote code execution vulnerability exists in the Lite UI of Apache ShardingSphere ElasticJob-UI in versions through 3.0.1. The issue arises from the ability to craft a malicious JDBC URL for the H2 database, exploiting the application to execute arbitrary code. This attack requires the attacker to have valid account credentials.
Holded Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Holded application, specifically within the Activities functionality. This issue allows an attacker to inject and store a JavaScript payload in the editable 'name' and 'icon' fields. The vulnerability affects Holded, a cloud invoicing software for small and medium-sized businesses.
Webkul QloApps Cross-Site Request Forgery Vulnerability in Logout Function
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Webkul QloApps version 1.6.1. The issue arises in the logout function within the URL Handler component, specifically through the '/en/?mylogout' endpoint. This vulnerability allows an attacker to force an authenticated user to log out without their consent, potentially disrupting active sessions and causing issues for users and administrators alike.
Check Point Security Management Server and Domain Management Server cpca Process Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the cpca process on Check Point Security Management Server and Domain Management Server. In rare scenarios, this process may exit unexpectedly, leading to VPN and SIC connectivity issues, especially if the Certificate Revocation List (CRL) is not cached on the Security Gateway.
Huawei HarmonyOS VPN Service Module Incomplete Verification Vulnerability
An incomplete verification vulnerability has been identified in the VPN service module of Huawei HarmonyOS. This vulnerability, present in HarmonyOS 5.0.0, could be successfully exploited to impact the availability of the service.
Huawei HarmonyOS Out-of-Bounds Write Vulnerability in the Emcom Module
A vulnerability allowing out-of-bounds write has been identified in the emcom module of Huawei's HarmonyOS. This vulnerability is present in HarmonyOS versions 4.2.0, 3.0.0, and EMUI 13.0.0. Successful exploitation may lead to abnormal feature performance.
Huawei HarmonyOS and EMUI Input Verification Vulnerability in External Storage Provider Module
A vulnerability has been identified in the ExternalStorageProvider module of Huawei's HarmonyOS and EMUI versions. This vulnerability arises from inadequate input verification, which could be exploited to affect the confidentiality of services.
Huawei HarmonyOS Use-After-Free Vulnerability in the Display Module
A use-after-free vulnerability has been identified in the display module of Huawei's HarmonyOS. This vulnerability affects several versions, including HarmonyOS 5.0.0, 4.3.0, 4.2.0, 4.0.0, and EMUI 14.0.0. Successful exploitation of this vulnerability may lead to abnormal feature performance.
Huawei HarmonyOS Out-of-Bounds Array Read Vulnerability in FFRT Module
A vulnerability allowing out-of-bounds array read has been identified in the FFRT module of Huawei's HarmonyOS. This vulnerability is present in several versions, including HarmonyOS5.0.0, HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, and EMUI 14.0.0. Successful exploitation of this vulnerability may lead to abnormal feature performance.
Huawei HarmonyOS Improper Log Information Control Vulnerability in UI Framework Module
A vulnerability has been identified in the UI framework module of Huawei HarmonyOS, specifically in version 5.0.0. This vulnerability arises from improper control of log information, which could be exploited to affect the confidentiality of service.
Huawei HarmonyOS Out-of-Bounds Read Vulnerability in the Interpreter String Module
An out-of-bounds read vulnerability has been identified in the interpreter string module of Huawei's HarmonyOS. This vulnerability, present in HarmonyOS 5.0.0, could be successfully exploited to affect the operating system's availability.
Huawei HarmonyOS Gallery Module Arbitrary Write Vulnerability
An arbitrary write vulnerability has been identified in the Gallery module of Huawei's HarmonyOS. This vulnerability, present in HarmonyOS 5.0.0, could be exploited to write arbitrary data, potentially leading to unauthorized modifications or disruptions in service. Successful exploitation may also impact the confidentiality of user data or services.
Huawei HarmonyOS Media Library Module Permission Verification Vulnerability
A permission verification vulnerability has been identified in the media library module of Huawei HarmonyOS 5.0.0. This vulnerability could be exploited to improperly manage permissions, potentially leading to unauthorized access to sensitive information or services.
Huawei HarmonyOS ParamWatcher Module Identity Verification Vulnerability
An identity verification vulnerability has been identified in the ParamWatcher module of Huawei HarmonyOS. This vulnerability, present in HarmonyOS 5.0.0, could be exploited to affect the confidentiality of services.
Google Cloud Application Integration Sandbox Escape Vulnerability in JavaScript Task
A sandbox escape vulnerability has been identified in the JavaScript Task feature of Google Cloud Application Integration. This vulnerability allows an actor to execute arbitrary unsandboxed code by crafting specific JavaScript that is processed by the Rhino engine. Effective January 24, 2025, Google Cloud Application Integration will discontinue support for the Rhino engine, eliminating the vulnerability. Existing published JavaScript tasks can be manually migrated to use the V8 engine.
Apache James Server JMAP Unbounded Memory Consumption Leading to Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Apache James Server JMAP HTML to plain text conversion implementation, affecting versions 3.8.0 prior to 3.8.2 and 3.7.0 prior to 3.7.6. This vulnerability is caused by unbounded memory consumption, which can lead to service disruption.
Apache James IMAP Literals Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Apache James versions prior to 3.7.6 and 3.8.0 through 3.8.1. This vulnerability allows both authenticated and unauthenticated users to abuse IMAP literals, leading to unbounded memory allocation and prolonged computations. Versions 3.7.6 and 3.8.2 have addressed this issue by restricting improper use of IMAP literals.
Post and Page Builder by BoldGrid Path Traversal Vulnerability Allowing Arbitrary File Read
A path traversal vulnerability has been identified in the Post and Page Builder by BoldGrid plugin for WordPress, affecting all versions through 1.27.6. The issue arises in the template_via_url() function, where authenticated attackers with Contributor-level access or higher can exploit the vulnerability to read arbitrary files on the server, potentially accessing sensitive information.
Defense Platform Home Edition Argument Injection Vulnerability Leading to Denial-of-Service
A vulnerability allowing argument injection has been identified in Defense Platform Home Edition versions through 3.9.51.x. This issue arises from improper neutralization of argument delimiters in a command, which can be exploited by sending specially crafted data to a specific process on the Windows system where the product is installed. The exploitation of this vulnerability can cause a Blue Screen of Death (BSOD), leading to a denial-of-service condition.
Defense Platform Home Edition NULL Pointer Dereference Vulnerability Leading to Denial-of-Service
A NULL pointer dereference vulnerability has been identified in Defense Platform Home Edition versions through 3.9.51.x. This vulnerability can be exploited by an attacker who sends specially crafted data to a specific process on the Windows system where the product is installed. The exploitation of this vulnerability may lead to a Blue Screen of Death (BSOD), causing a denial-of-service condition.
Defense Platform Home Edition Buffer Overflow Vulnerability Allowing SYSTEM Privilege Escalation
A buffer overflow vulnerability has been identified in Defense Platform Home Edition versions through 3.9.51.x. This vulnerability allows an attacker to gain SYSTEM privileges on the Windows system where the product is installed by performing a specific operation.
Humming Heads Defense Platform Home Edition Windows Messaging Channel Vulnerability Allowing Arbitrary File Modification and DLL Execution with SYSTEM Privilege
A vulnerability exists in Humming Heads Defense Platform Home Edition versions through 3.9.51.x, related to the unprotected Windows messaging channel known as 'Shatter'. This vulnerability allows an attacker to send a specially crafted message to a specific process on the Windows system where the product is running. As a result, arbitrary files on the system may be altered, leading to the execution of an arbitrary DLL with SYSTEM privileges.
Humming Heads Defense Platform Home Edition Windows Messaging Channel Vulnerability Allowing Arbitrary Code Execution
A vulnerability exists in Humming Heads Defense Platform Home Edition versions through 3.9.51.x, related to the unprotected Windows messaging channel known as 'Shatter'. This vulnerability allows an attacker to send a specially crafted message to a specific process on the Windows system where the product is running, potentially leading to arbitrary code execution with SYSTEM privileges.
Defense Platform Home Edition Privilege Escalation Vulnerability
A vulnerability allowing execution with unnecessary privileges has been identified in Defense Platform Home Edition versions through 3.9.51.x. This vulnerability could allow an attacker to gain SYSTEM privileges on the Windows system where the product is installed.
CURCY WooCommerce Multi-Currency Plugin Unauthenticated Shortcode Execution Vulnerability
A vulnerability exists in the CURCY - Multi Currency for WooCommerce plugin, specifically in versions through 2.2.5. The issue allows unauthenticated users to execute arbitrary shortcodes via the get_products_price() function. This vulnerability arises because the plugin fails to properly validate values before processing shortcodes, enabling unauthorized shortcode execution.
LikeBot WordPress Plugin Cross-Site Scripting Vulnerability via CSRF
A stored cross-site scripting vulnerability has been identified in the LikeBot WordPress plugin, affecting versions through 0.85. The issue arises from the plugin's lack of proper cross-site request forgery (CSRF) checks in certain areas, combined with inadequate data sanitization and escaping. This vulnerability could enable attackers to exploit logged-in administrators by injecting malicious scripts that are stored and executed later.
ABB ASPECT-Enterprise, NEXUS Series, and MATRIX Series Hard-Coded Credentials Vulnerability
A vulnerability exists in ABB ASPECT-Enterprise, NEXUS Series, and MATRIX Series due to the use of hard-coded credentials. This issue affects ASPECT-Enterprise versions through 3.*, NEXUS Series versions through 3.*, and MATRIX Series versions through 3.*.
IBM App Connect Enterprise Arbitrary File Write Vulnerability During BAR Configuration Deployment
A vulnerability exists in IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1. This vulnerability could allow an authenticated user to write arbitrary files to the system during the deployment of BAR configuration. The issue arises from improper restrictions on pathnames in certain directories.
IBM Security Verify Directory Command Injection Vulnerability
A command injection vulnerability has been identified in IBM Security Verify Directory versions 10.0.0 through 10.0.3. This vulnerability allows remote authenticated attackers to execute arbitrary commands on the system by sending specially crafted requests.
IBM Security Verify Access Appliance Privilege Escalation Vulnerability
A vulnerability in IBM Security Verify Access Appliance versions 10.0.0 to 10.0.3 allows locally authenticated users to escalate privileges. This issue arises from the application executing with excessive privileges, potentially enabling users to gain unauthorized access or rights.
OpenPLC V3 Arbitrary File Upload Vulnerability
A vulnerability allowing arbitrary file uploads has been identified in OpenPLC V3. This issue could be exploited for malvertising or phishing campaigns. The vulnerability arises from insufficient validation of uploaded files, allowing any file type to be uploaded as a profile picture.
IBM ApplinX Sensitive Information Disclosure Vulnerability
A vulnerability exists in IBM ApplinX version 11.1, where sensitive information is stored in cleartext in memory. This data could potentially be accessed by an authenticated user.
IBM ApplinX Information Disclosure Vulnerability via Detailed Error Messages
An information disclosure vulnerability has been identified in IBM ApplinX version 11.1. This vulnerability allows remote attackers to obtain sensitive information when a detailed technical error message is displayed in the browser. The extracted information could be leveraged for further attacks against the system.
IBM ApplinX HTTP Strict Transport Security Vulnerability Allowing Information Disclosure
A vulnerability in IBM ApplinX version 11.1 exists due to improper implementation of HTTP Strict Transport Security (HSTS). This flaw could enable a remote attacker to intercept communications and access sensitive information using man-in-the-middle techniques.
IBM ApplinX Clickjacking Vulnerability
A vulnerability in IBM ApplinX 11.1 could allow a remote attacker to hijack the clicking actions of a victim. By convincing the victim to visit a malicious website, the attacker could exploit this vulnerability to take control of the victim's click actions, potentially leading to further attacks against the victim.
