CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 30, 2025

Codezips Gym Management System SQL Injection Vulnerability in saveroutine.php

A critical SQL injection vulnerability has been identified in Codezips Gym Management System version 1.0. The issue resides in the rname parameter of the file saveroutine.php within the dashboard/admin directory. This vulnerability allows attackers to inject arbitrary SQL commands, potentially leading to unauthorized database access, data manipulation, and full system compromise.

3.4
Jan 30, 2025

Codezips Gym Management System SQL Injection Vulnerability in Update Plan Admin Dashboard

A critical SQL injection vulnerability has been identified in Codezips Gym Management System version 1.0. The issue arises in the file '/dashboard/admin/updateplan.php', where the 'planid' argument is improperly processed, allowing for SQL injection attacks to be executed remotely. This vulnerability has been publicly disclosed and is exploitable.

3.3
Jan 30, 2025

Sante PACS Server Memory Corruption Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in Sante PACS Server. This issue arises from the web server module's improper validation of user-supplied data in URL parsing, leading to memory corruption. Remote attackers can exploit this vulnerability to cause a denial-of-service condition on the affected system, without requiring authentication.

2.7
Jan 30, 2025

Sante PACS Server DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability

A directory traversal vulnerability allowing arbitrary file writes has been identified in Sante PACS Server. This issue arises from improper validation of user-supplied paths when parsing DCM files, enabling remote attackers to create files on the affected system without authentication. The vulnerability allows file creation in the context of the current user.

2.7
Jan 30, 2025

Sante PACS Server DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability

A directory traversal vulnerability allowing arbitrary file writes has been identified in the Sante PACS Server Web Portal. This issue arises from improper validation of user-supplied paths when parsing DCM files, enabling authenticated remote attackers to create files on the server in the context of the current user.

1.9
Jan 30, 2025

Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in Sante PACS Server Web Portal, specifically within the DCM file parsing process. This issue arises from inadequate validation of user-supplied data, leading to memory corruption. Remote attackers with authentication can exploit this vulnerability, causing a denial-of-service condition on the affected system.

1.9
Jan 30, 2025

Sante PACS Server Memory Corruption Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in Sante PACS Server Web Portal, specifically within the DCM file parsing process. This issue arises from inadequate validation of user-supplied data, leading to memory corruption. Remote attackers, with authentication, can exploit this vulnerability to disrupt service on affected installations.

1.9
Jan 30, 2025

Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in Sante PACS Server, specifically in the DCM file parsing process. This issue arises from inadequate validation of user-supplied data, leading to memory corruption. Remote attackers can exploit this vulnerability to cause a denial-of-service condition on the affected system, without the need for authentication.

2.7
Jan 30, 2025

Sante PACS Server Memory Corruption Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in Sante PACS Server, specifically in the DCM file parsing process. This issue arises from inadequate validation of user-supplied data, leading to memory corruption. Remote attackers can exploit this vulnerability to cause a denial-of-service condition on the affected system, without the need for authentication.

2.7
Jan 30, 2025

AutomationDirect C-More EA9 File Parsing Memory Corruption Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in AutomationDirect C-More EA9 programming software, all versions through 6.78. This issue arises from improper validation of user-supplied data during the parsing of EAP9 files, leading to memory corruption. Exploitation of this vulnerability requires user interaction, as the target must open a malicious file or visit a harmful webpage.

3.8
Jan 30, 2025

AutomationDirect C-More EA9 File Parsing Memory Corruption Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in AutomationDirect C-More EA9 programming software, all versions through 6.78. This issue arises from improper validation of user-supplied data during the parsing of EAP9 files, leading to memory corruption. Exploitation of this vulnerability requires user interaction, as the target must open a malicious file or visit a harmful webpage.

3.8
Jan 30, 2025

AutomationDirect C-More EA9 Stack-Based Buffer Overflow Remote Code Execution Vulnerability

A stack-based buffer overflow vulnerability allowing remote code execution has been identified in AutomationDirect C-More EA9 programming software, versions through 6.78. The issue arises in the parsing of EAP9 files, where user-supplied data is not properly validated before being copied to a fixed-length stack-based buffer. Exploitation of this vulnerability requires user interaction, such as visiting a malicious page or opening a harmful file.

3.8
Jan 30, 2025

Plonky2 Lookup Table Soundness Vulnerability

A vulnerability in Plonky2 version 1.0.0 allows a malicious prover to exploit lookup tables in a way that could deceive verifiers. The issue arises because lookup tables whose lengths are not divisible by 26 include a default '0 -> 0' input-output pair. This allows provers to falsely demonstrate knowledge of certain values in specific scenarios. The vulnerability is rooted in the 'LookupTableGate' padding with zeros, rather than with existing table pairs. The flaw is not present in the most common use cases, such as hash functions with table-based S-boxes, which typically do not allow for such exploitation.

3.5
Jan 30, 2025

Zoom Workplace App for Linux Privilege Escalation Vulnerability

A type confusion vulnerability has been identified in the Zoom Workplace App for Linux, in versions prior to 6.2.10. This vulnerability may allow an authorized user to escalate privileges through network access.

1.6
Jan 30, 2025

Zoom Workplace App Symlink Following Vulnerability Leading to Denial-of-Service on macOS

A symlink following vulnerability has been identified in the installer for the Zoom Workplace App on macOS, affecting versions prior to 6.2.10. This vulnerability may allow an authenticated user to conduct a denial-of-service attack through local access.

1.1
Jan 30, 2025

Zoom Workplace Apps Untrusted Search Path Vulnerability Allowing Privilege Escalation on Windows

A vulnerability exists in the installer for certain Zoom Workplace Apps on Windows, where an untrusted search path may enable an authorized user to escalate privileges through local access. This issue affects several different versions and/or ranges of the Zoom Workplace App, VDI Client, Zoom Rooms Client, Zoom Rooms Controller, and the Zoom Meeting and Video SDKs for Windows.

4.1
Jan 30, 2025

Zoom Workplace Apps Out-of-Bounds Write Vulnerability Allowing Integrity Loss

A vulnerability allowing out-of-bounds write has been identified in some Zoom Workplace Apps. This issue may enable an authorized user to cause a loss of integrity through network access. The vulnerability affects multiple platforms, including Windows, macOS, Linux, iOS, and Android, as well as Zoom's VDI Client, Rooms Client, Rooms Controller, and Meeting and Video SDKs.

4.1
Jan 30, 2025

Zoom Workplace App for Linux Out-of-Bounds Write Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability has been identified in the Zoom Workplace App for Linux, in versions prior to 6.2.5. The issue arises from an out-of-bounds write, which may allow an unauthorized user to disrupt service via network access.

3.6
Jan 30, 2025

Zoom Jenkins Marketplace Plugin Cleartext Storage of Sensitive Information Vulnerability

A vulnerability exists in the Zoom Jenkins Marketplace plugin in versions prior to 1.4, allowing authenticated users to disclose sensitive information over the network due to cleartext storage of that information.

1.7
Jan 30, 2025

Google Fuchsia and gVisor Network Stack Vulnerability Allows Predictable Protocol Header Fields

A vulnerability exists in the way Google Fuchsia, using the gVisor network stack, generates certain network protocol header fields. This issue affects the TCP initial sequence number, TCP timestamp, TCP and UDP source ports, and the IPv4/IPv6 fragment ID fields. The vulnerability arises because these values can be predicted under specific conditions, enabling potential network attacks and device tracking.

5.0
Jan 30, 2025

Google gVisor TCP and UDP Header Vulnerability Allows Predictable Source Ports

A vulnerability in the Google gVisor network stack used by the Fuchsia operating system allows for the prediction of TCP and UDP source ports by an external attacker. This issue arises from weaknesses in the algorithmic generation of these ports and certain header values, utilizing a pseudo-random number generator (PRNG) that is not cryptographically secure. The vulnerability can be exploited under specific conditions, particularly through the manipulation of network protocol headers.

3.8
Jan 30, 2025

Broadcom Appliances Boot-Time Compromise Vulnerability

A vulnerability exists in certain Broadcom appliances, allowing for compromise at boot time. This issue could lead to unauthorized access or manipulation of the appliance during the boot process.

1.1
Jan 30, 2025

Broadcom PAM User ID Disclosure Vulnerability via Authentication Strategy

A vulnerability exists in certain authentication strategies that allows the identification of PAM user IDs linked to specific authentication types. This issue is present in Broadcom products, although the exact products and versions affected are not specified.

3.4
Jan 30, 2025

Broadcom PAM Remote Command Execution Vulnerability for High-Privileged Authenticated Users

A vulnerability in Broadcom's PAM system allows high-privileged authenticated users to execute remote commands by uploading a specially crafted upgrade file. This issue arises from improper handling of upgrade files, enabling unauthorized command execution on the affected system.

2.6
Jan 30, 2025

Broadcom Symantec Products Logging Vulnerability Due to Improper Input Validation in CSRF Filter

A vulnerability exists in certain Broadcom Symantec products, where the Cross-Site Request Forgery (CSRF) filter fails to properly validate input. This flaw allows unsanitized user input to be recorded in the application logs, potentially leading to information disclosure or other security issues.

2.0
Jan 30, 2025

Broadcom PAM Server Session Fixation Vulnerability

A session fixation vulnerability has been identified in the Broadcom PAM server. This issue allows a malicious actor to manipulate the session of a PAM user by enticing them to click on a specially crafted link. Once the link is clicked, the attacker's session can be established with the targeted PAM user.

2.9
Jan 30, 2025

Broadcom Products Improper Session Validation Vulnerability Allowing Request Spoofing

A vulnerability exists in certain Broadcom products due to improper session validation, which allows an unauthenticated attacker to spoof the client IP address and execute request notifications in the context of an incorrect user.

2.2
Jan 30, 2025

Broadcom PAM Improper Input Validation Vulnerability Allowing Log Manipulation

A vulnerability exists in Broadcom's Privileged Access Management (PAM) solution due to improper input validation. This flaw allows an unauthenticated attacker to modify PAM logs by sending a specially crafted HTTP request.

3.4
Jan 30, 2025

Broadcom PAM Database Information Disclosure Vulnerability

A vulnerability exists that allows an unauthenticated attacker to access sensitive information stored in the PAM database. This issue is related to improper access controls, enabling unauthorized information retrieval.

3.4
Jan 30, 2025

Contec Health CMS8000 Patient Monitor Privacy Leakage Vulnerability

A vulnerability exists in the Contec Health CMS8000 Patient Monitor, all versions, allowing for the unauthorized transmission of plain-text patient data to a hard-coded public IP address in China. This data exfiltration occurs when the monitor is in use, potentially leading to privacy violations and unauthorized access to sensitive health information. The issue has been linked to a backdoor in the device's firmware, which could allow for remote code execution and manipulation of the device.

2.5
Jan 30, 2025

New Rock Technologies Cloud Connected Devices Wildcard Topic Subscription Vulnerability

A vulnerability exists in the Cloud MQTT service of New Rock Technologies Cloud Connected Devices, including the OM500 IP-PBX, MX8G VoIP Gateway, and NRP1302/P Desktop IP Phone, all versions. The vulnerability arises from improper neutralization of wildcards in topic subscriptions, allowing attackers to intercept and access sensitive information from the service's communications.

1.6
Jan 30, 2025

New Rock Technologies Cloud Connected Devices OS Command Injection Vulnerability

A command injection vulnerability has been identified in New Rock Technologies Cloud Connected Devices, including the OM500 IP-PBX, MX8G VoIP Gateway, and NRP1302/P Desktop IP Phone, all versions. This vulnerability allows remote attackers to take control of devices connected to the cloud by improperly handling special elements in the device cloud RPC command process.

2.6
Jan 30, 2025

Contec Health CMS8000 Patient Monitor Backdoor Vulnerability

A backdoor vulnerability has been identified in the Contec Health CMS8000 patient monitor, as well as in the Epsimed MN-120 patient monitor, which is a rebranded version of the CMS8000. This vulnerability allows unauthorized remote access to the device, enabling the execution of files and overwriting of existing ones. The issue arises from a hidden function in the 'monitor' binary of the device's firmware, which bypasses normal network settings to connect to a hard-coded IP address associated with a Chinese university. This connection facilitates the exfiltration of patient data, including personal identifiers and health information, to the same external IP address.

1.9
Jan 30, 2025

Apple GarageBand Arbitrary Code Execution Vulnerability

A vulnerability in Apple GarageBand has been identified, allowing for arbitrary code execution. This issue arises from insufficient bounds checks when processing certain images. The vulnerability is present in GarageBand versions prior to 10.4.12, and it affects users on macOS Sonoma 14.4 and later.

4.2
Jan 30, 2025

Contec Health CMS8000 Patient Monitor Out-of-Bounds Write Vulnerability Allowing Remote Code Execution

A vulnerability allowing an out-of-bounds write has been identified in the Contec Health CMS8000 Patient Monitor. This issue could enable an attacker to send specially crafted UDP requests that write arbitrary data, potentially leading to remote code execution. The vulnerability exists in all versions of the CMS8000 Patient Monitor firmware, including the Epsimed MN-120 Patient Monitor, which is a rebranded version of the CMS8000.

1.6
Jan 30, 2025

Code-Projects Simple Plugins Car Rental Management SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Code-Projects Simple Plugins Car Rental Management version 1.0. The issue resides in the 'approve.php' file within the admin directory. This vulnerability allows remote attackers to inject malicious SQL queries through the 'id' parameter, potentially leading to unauthorized database access, data manipulation, and exposure of sensitive information.

2.9
Jan 30, 2025

Rockwell Automation FactoryTalk AssetCentre Data Exposure Vulnerability

A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk AssetCentre. This vulnerability arises from the insecure storage of FactoryTalk Security user tokens, which could enable a threat actor to steal a token and impersonate another user.

2.2
Jan 30, 2025

Rockwell Automation FactoryTalk AssetCentre Data Exposure Vulnerability

A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk AssetCentre. This vulnerability arises from the insecure storage of credentials in the configuration files of certain packages, which could allow unauthorized access to sensitive information.

2.2
Jan 30, 2025

Rockwell Automation FactoryTalk AssetCentre Encryption Vulnerability Allowing Password Extraction

A vulnerability exists in all versions of Rockwell Automation FactoryTalk AssetCentre prior to V15.00.001, due to a weak encryption methodology. This encryption vulnerability could allow a threat actor to extract passwords of other users within the application.

3.4
Jan 30, 2025

Revenera InstallShield Privilege Escalation Vulnerability

A privilege escalation vulnerability has been identified in Revenera InstallShield versions 2022 R2 and 2021 R2. This vulnerability arises from the addition of InstallScript custom actions to Basic MSI or InstallScript MSI projects, which extract certain binaries to a predefined writable folder during installation. Standard user accounts can write to these files and folders, allowing them to be replaced during installation and potentially leading to a DLL hijacking vulnerability.

4.5
Jan 30, 2025

Apple PackageKit Privilege Escalation Vulnerability

A vulnerability in the PackageKit component of macOS Sequoia 15.3, macOS Ventura 13.7.3, and macOS Sonoma 14.7.3 allows local attackers to elevate privileges. This issue was addressed with improved validation checks.

4.5
Jan 30, 2025

Itsourcecode Tailoring Management System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in the Tailoring Management System Project in PHP, version 1.0. The issue resides in the customeredit.php file, where user-supplied POST parameters are inadequately validated, allowing attackers to inject malicious SQL queries. This vulnerability can be exploited remotely, potentially leading to unauthorized database access, data manipulation, and leakage of sensitive information.

3.0
Jan 30, 2025

Splunk Supporting Add-on for Active Directory Regular Expression Denial-of-Service Vulnerability

A Regular Expression Denial-of-Service (ReDoS) vulnerability has been identified in versions 3.1.0 and earlier of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch. The issue arises from a vulnerable regular expression pattern that can be exploited to cause a denial-of-service condition by degrading the performance of the application.

1.7
Jan 30, 2025

FlexNet Publisher Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

A local privilege escalation vulnerability has been identified in FlexNet Publisher versions prior to 2024 R1 (11.19.6.0). The issue arises from a misconfiguration in lmadmin.exe, which allows the OpenSSL configuration file to be loaded from a non-existent directory. An unauthorized, locally authenticated user with low privileges could potentially create the directory and load a specially crafted openssl.conf file, leading to the execution of a malicious DLL with elevated privileges.

4.0
Jan 30, 2025

go-ethereum Denial-of-Service Vulnerability via Malicious Peer-to-Peer Message

A denial-of-service vulnerability has been identified in go-ethereum (geth) versions 1.14.0 prior to 1.14.13. This issue allows a vulnerable node to be forced to shut down or crash by sending a specially crafted message. The problem arises during the peer-to-peer connection handshake, where the EC public key from the remote party is not properly validated. By transmitting an all-zero public key, a crash can be triggered due to unexpected outcomes from the handshake process.

5.7
Jan 30, 2025

Kubewarden AdmissionPolicyGroup Context-Aware Resource Information Leak Vulnerability

A vulnerability in the Kubewarden controller's AdmissionPolicyGroup resource allows non-admin users to create context-aware policies that can query the Kubernetes API and access sensitive information, such as Secrets, beyond their permissions. This issue arises because the AdmissionPolicyGroup, introduced in version 1.17.0, can be managed by users in their own namespaces. The vulnerability depends on the privileges of the ServiceAccount used by the Policy Server, with the default Helm chart granting broad access to cluster resources. The issue is present in Kubewarden versions 1.17.0 and later, and has been patched in version 1.21.0.

2.7
Jan 30, 2025

Kubewarden Admission Policies Vulnerability Allows Manipulation of PolicyReport Resources

A vulnerability exists in the Kubewarden controller for Kubernetes, specifically in versions 1.7.0 and above, prior to 1.21.0. This issue arises from the ability of AdmissionPolicy and AdmissionPolicyGroup to evaluate namespaced resources, including sensitive ones like PolicyReport, which tracks non-compliant objects within a namespace. An attacker could exploit this by using these policies to block the creation or update of PolicyReport resources, effectively concealing non-compliant items. Additionally, a mutating AdmissionPolicy could be employed to modify the contents of existing PolicyReports. The vulnerability stems from inadequate validation rules that allowed interactions with sensitive resources.

3.5
Jan 30, 2025

Argo CD Secret Exposure Vulnerability in Kubernetes Resource Sync

A vulnerability in Argo CD, a GitOps continuous delivery tool for Kubernetes, allows for the exposure of secret values in error messages and the diff view. This issue arises when an invalid Kubernetes Secret resource is synced from a repository. The vulnerability affects Argo CD versions through 2.13.3, 2.12.9, and 2.11.12. It requires the user to have write access to the repository, where they can commit an invalid Secret and trigger a sync. Once the vulnerability is exploited, any user with read access to Argo CD can access the exposed secret data.

3.8
Jan 30, 2025

VMware Aria Operations Information Disclosure Vulnerability

A vulnerability allowing information disclosure has been identified in VMware Aria Operations. This issue arises from a malicious user with non-administrative privileges being able to retrieve credentials for an outbound plugin, provided they know a valid service credential ID. VMware has assigned a severity level of 'Important' to this vulnerability, with a CVSSv3 base score of 7.7.

3.6
Jan 30, 2025

VMware Aria Operations for Logs Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in VMware Aria Operations for Logs. This vulnerability allows a malicious actor with admin privileges to inject a script that could be executed in the browser of a victim performing a delete action in the Agent Configuration.

3.4