CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Progress Telerik Document Processing Libraries Path Traversal Vulnerability Allowing Arbitrary File System Access
A path traversal vulnerability has been identified in Progress Telerik Document Processing Libraries, affecting versions prior to 2025 Q1 (2025.1.205). This vulnerability allows improper limitation of target paths, which can lead to decompressing archive contents into restricted directories, potentially causing arbitrary file system access.
GNU Emacs Command Injection Vulnerability via Custom 'man' URI Scheme
A command injection vulnerability has been identified in GNU Emacs, all released versions through 29.4. This vulnerability allows remote, unauthenticated attackers to execute arbitrary shell commands on vulnerable systems. The issue arises from improper handling of custom 'man' URI schemes, which can be exploited by tricking users into visiting specially crafted websites or HTTP URLs with redirects. This vulnerability has been addressed in Emacs version 30.1.
GitLab CE/EE Information Disclosure Vulnerability
A vulnerability allowing information disclosure exists in GitLab CE/EE versions 8.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. This vulnerability allows an attacker to send a crafted request to a backend server, potentially revealing sensitive information.
Codezips Gym Management System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Codezips Gym Management System version 1.0. The issue resides in the 'id' parameter of the '/dashboard/admin/viewdetailroutine.php' file. This vulnerability allows remote attackers to inject arbitrary SQL code, bypassing input validation, which could lead to unauthorized database access, data manipulation, and potentially a full system compromise.
SourceCodester Best Church Management Software SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in SourceCodester Best Church Management Software version 1.1. The issue resides in the file '/admin/edit_slider.php', where the 'id' parameter is manipulated to execute unauthorized SQL commands. This vulnerability can be exploited remotely, allowing attackers to perform time-based blind SQL injection and extract data from the application's database.
GitLab EE Insecure Direct Object Reference Vulnerability Allowing Unauthorized Repository Access
A vulnerability allowing insecure direct object references has been identified in GitLab EE. This issue affects all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. The vulnerability allows an attacker to view repositories without proper authorization.
GitLab CE/EE Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in GitLab Community Edition (CE) and Enterprise Edition (EE). This issue affects all versions from 13.3 prior to 17.6.5, as well as versions 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2. The vulnerability allows an attacker to execute unauthorized actions by exploiting a change page.
OpenSearch Dashboards Reporting Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the OpenSearch Dashboards Reporting plugin, specifically in versions prior to 2.19.0.0. The issue arises because the plugin allows users to inject untrusted HTML, including JavaScript, into report headers and footers. This injected script is executed when the report is viewed, potentially leading to the theft of sensitive information, such as keystrokes or cookies.
GitLab CE/EE Denial-of-Service Vulnerability via Unbounded Object Creation in Personal Access Token Scopes
A denial-of-service vulnerability exists in GitLab CE/EE versions 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. The vulnerability allows an attacker to disrupt GitLab's availability by creating an excessive number of symbols through the 'scopes' parameter in a Personal Access Token. This unbounded symbol creation leads to memory exhaustion, as symbols in Ruby are not garbage collected and remain in memory for the duration of the program's execution.
Progress Telerik UI for WinUI Command Injection Vulnerability
A command injection vulnerability exists in Progress Telerik UI for WinUI, affecting versions through 2024 Q4 (2.11.0). The issue arises from improper handling of hyperlink elements, which could allow an attacker to inject and execute arbitrary commands.
Q-Free MaxTime Password Reset Vulnerability in Users Routes
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to reset passwords, including those of administrator accounts, by sending crafted HTTP requests.
Q-Free MaxTime Missing Authorization Vulnerability Allowing User Deletion
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to delete users by sending crafted HTTP requests.
Q-Free MaxTime Missing Authorization Vulnerability Allowing Unauthorized User Data Modification
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to modify user data by sending crafted HTTP requests. The issue is located in the 'maxprofile/users/routes.lua' file.
Q-Free MaxTime Missing Authorization Vulnerability Allowing Arbitrary User Privilege Escalation
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to create users with arbitrary privileges by sending crafted HTTP requests. The issue is located in the 'maxprofile/users/routes.lua' file.
Q-Free MaxTime Missing Authorization Vulnerability in User Enumeration
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to enumerate users by sending crafted HTTP requests to the users endpoint.
Q-Free MaxTime Missing Authorization Vulnerability in User Enumeration
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to enumerate users by sending crafted HTTP requests to the user endpoint.
Q-Free MaxTime Missing Authorization Vulnerability in User Group Management
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to remove users from groups by sending crafted HTTP requests. The issue is located in the user-groups routing file.
Q-Free MaxTime Missing Authorization Vulnerability in User Groups Management
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to add users to groups by sending crafted HTTP requests. The issue is located in the user-groups routing file of the application.
Q-Free MaxTime Missing Authorization Vulnerability in User Groups Management
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to remove privileges from user groups by sending crafted HTTP requests. The issue is located in the user-groups route of the application.
Q-Free MaxTime Missing Authorization Vulnerability in User Groups Management
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to manipulate user group privileges by sending crafted HTTP requests. The issue is located in the user-groups routing file of the MaxProfile module.
Q-Free MaxTime Missing Authorization Vulnerability in User Groups Management
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to remove user groups by sending crafted HTTP requests. The issue is located in the user-groups route of the application.
Q-Free MaxTime Missing Authorization Vulnerability Allowing Arbitrary User Group Creation
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to create arbitrary user groups by sending crafted HTTP requests. The issue is located in the 'maxprofile/user-groups/routes.lua' file.
Q-Free MaxTime Missing Authentication Vulnerability in Front Panel Authentication
A vulnerability allowing unauthenticated remote attackers to disable front panel authentication has been identified in Q-Free MaxTime versions through 2.11.0. This issue arises from a missing authentication for critical functions, specifically in the maxprofile/setup/routes.lua file. Exploitation of this vulnerability could make physical access to the device easier by bypassing front panel security measures.
Q-Free MaxTime Missing Authentication Vulnerability in Front Panel Authentication
A vulnerability allowing unauthenticated remote attackers to enable front panel authentication has been identified in Q-Free MaxTime versions through 2.11.0. This issue, categorized as CWE-306 'Missing Authentication for Critical Function', resides in the file maxprofile/setup/routes.lua. Exploitation of this vulnerability could lock out legitimate users by manipulating HTTP requests to activate front panel authentication.
Q-Free MaxTime Missing Authentication Vulnerability in Authentication Profile Server
A vulnerability allowing unauthenticated remote attackers to disable an authentication profile server has been identified in Q-Free MaxTime versions through 2.11.0. This issue, categorized as CWE-306 'Missing Authentication for Critical Function', arises in the maxprofile/setup/routes.lua file, where the lack of proper authentication allows for exploitation via crafted HTTP requests.
Q-Free MaxTime Missing Authentication Vulnerability in Authentication Profile Server
A vulnerability allowing missing authentication for critical functions has been identified in Q-Free MaxTime versions through 2.11.0. This issue resides in the maxprofile/setup/routes.lua file and allows an unauthenticated remote attacker to enable an authentication profile server by sending crafted HTTP requests.
Q-Free MaxTime Missing Authentication Vulnerability in Authentication Profile Management
A vulnerability allowing unauthenticated remote attackers to manipulate authentication profiles on Q-Free MaxTime versions through 2.11.0 has been identified. This issue arises from a missing authentication requirement for critical functions, specifically in the maxprofile/setup/routes.lua file. Exploitation can be achieved by sending crafted HTTP requests to the server, potentially bypassing authentication mechanisms.
Q-Free MaxTime Missing Authentication Vulnerability Allowing Unauthenticated Factory Reset
A vulnerability allowing unauthenticated remote attackers to factory reset devices running Q-Free MaxTime versions through 2.11.0 has been identified. This vulnerability, categorized as CWE-306 'Missing Authentication for Critical Function', resides in the file maxprofile/setup/routes.lua. Exploitation of this vulnerability erases all device configurations, leading to a denial-of-service condition.
Q-Free MaxTime Missing Authentication Vulnerability Allowing Dashboard Deletion
A vulnerability exists in Q-Free MaxTime versions through 2.11.0, specifically within the maxprofile/persistance/routes.lua file. This vulnerability, categorized as CWE-306 'Missing Authentication for Critical Function', enables an unauthenticated remote attacker to delete dashboards by sending crafted HTTP requests.
Q-Free MaxTime Missing Authentication Vulnerability Allowing User PIN Reset
A vulnerability allowing unauthenticated remote attackers to reset user PINs has been identified in Q-Free MaxTime versions through 2.11.0. This issue arises from a missing authentication for critical functions, specifically in the maxprofile/accounts/routes.lua file.
Q-Free MaxTime Improper Input Validation Vulnerability Allowing Configuration Modification
A vulnerability allowing improper input validation has been identified in the Q-Free MaxTime application, specifically in the ldbMT.so component, and affects versions through 2.11.0. This vulnerability allows authenticated remote attackers to modify system configurations by sending crafted HTTP requests.
Q-Free MaxTime Path Traversal Vulnerability Allowing Sensitive File Read
A path traversal vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated remote attackers to read sensitive files by sending crafted HTTP requests. The issue is located in the 'maxtime/api/database/database.lua' file.
Q-Free MaxTime Path Traversal Vulnerability Allowing File Overwrite
A path traversal vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. The issue resides in the maxtime/api/database/database.lua file, specifically within the setActive endpoint. This vulnerability allows authenticated remote attackers to overwrite sensitive files by sending crafted HTTP requests.
Q-Free MaxTime Path Traversal Vulnerability Allowing File Deletion
A path traversal vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated remote attackers to delete sensitive files by sending crafted HTTP requests. The issue is located in the 'maxtime/api/database/database.lua' file.
Q-Free MaxTime Path Traversal Vulnerability Allowing File Overwrite
A path traversal vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. The issue resides in the 'maxtime/api/database/database.lua' file, specifically within the copy endpoint. This vulnerability allows authenticated remote attackers to overwrite sensitive files by sending crafted HTTP requests.
Q-Free MaxTime Path Traversal Vulnerability Allowing Sensitive File Read
A path traversal vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated remote attackers to read sensitive files by sending crafted HTTP requests. The issue is located in the maxtime/api/sql/sql.lua file.
Q-Free MaxTime Path Traversal Vulnerability Allowing File Deletion
A path traversal vulnerability has been identified in Q-Free MaxTime versions through 2.11.0, specifically within the template deletion mechanism. This vulnerability allows authenticated remote attackers to delete sensitive files by sending crafted HTTP requests. The issue could lead to system instability or data loss.
Q-Free MaxTime Path Traversal Vulnerability Allowing Sensitive File Read
A path traversal vulnerability has been identified in the template download mechanism of Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated remote attackers to read sensitive files by sending crafted HTTP requests.
Q-Free MaxTime Unrestricted File Upload Vulnerability Allowing Arbitrary File Overwrite
A vulnerability allowing unrestricted upload of files with dangerous types has been identified in Q-Free MaxTime versions through 2.11.0. This issue allows authenticated remote attackers to upload malicious files via crafted HTTP requests. The vulnerability could be exploited to overwrite arbitrary files, potentially leading to system compromise or denial-of-service conditions.
Q-Free MaxTime Relative Path Traversal Vulnerability in File Upload Mechanism
A relative path traversal vulnerability has been identified in the file upload feature of Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated remote attackers to overwrite arbitrary files by sending crafted HTTP requests.
Q-Free MaxTime SQL Injection Vulnerability in User Menu Management
A SQL injection vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. The issue resides in the 'editUserMenu' endpoint of 'maxprofile/menu/model.lua'. This vulnerability allows authenticated remote attackers to execute arbitrary SQL commands by sending crafted HTTP requests.
Q-Free MaxTime Missing Authentication Vulnerability in User Permissions Management
A vulnerability allowing unauthenticated remote attackers to edit user permissions has been identified in Q-Free MaxTime versions through 2.11.0. This issue arises from a missing authentication for critical functions, specifically in the file maxprofile/menu/routes.lua. Exploitation can be achieved by sending crafted HTTP requests to the application.
Q-Free MaxTime SQL Injection Vulnerability in User Group Management Endpoint
A SQL injection vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This issue, located in the user group management endpoint of the application, allows authenticated remote attackers to execute arbitrary SQL commands by sending crafted HTTP requests.
Q-Free MaxTime Missing Authentication Vulnerability in User Group Permissions Management
A vulnerability allowing unauthenticated remote attackers to edit user group permissions has been identified in Q-Free MaxTime versions through 2.11.0. This issue arises from a missing authentication for critical functions, specifically in the file maxprofile/menu/routes.lua. Exploitation of this vulnerability could lead to unauthorized changes in user access rights, potentially escalating privileges or restricting access for legitimate users.
Q-Free MaxTime Missing Authentication Vulnerability in Guest Mode
A vulnerability allowing unauthenticated remote attackers to enable passwordless guest mode has been identified in Q-Free MaxTime versions through 2.11.0. This issue arises from a missing authentication for critical functions, specifically in the maxprofile/guest-mode/routes.lua file. Exploitation involves sending crafted HTTP requests to the application.
Q-Free MaxTime Weak Authentication Vulnerability in PIN Mechanism Allowing Brute-Force Attacks
A weak authentication vulnerability has been identified in the PIN authentication system of Q-Free MaxTime versions through 2.11.0. This vulnerability allows unauthenticated remote attackers to brute-force user PINs by sending multiple crafted HTTP requests. Exploitation of this vulnerability could lead to unauthorized access to user accounts.
Q-Free MaxTime Missing Authentication Vulnerability Allowing Arbitrary User Creation
A vulnerability allowing missing authentication for critical functions has been identified in Q-Free MaxTime versions through 2.11.0. This issue resides in the file maxprofile/accounts/routes.lua and allows unauthenticated remote attackers to create arbitrary users, including those with administrative privileges, by sending crafted HTTP requests.
Q-Free MaxTime Password Reset Vulnerability Due to Missing Authentication
A vulnerability allowing password resets for arbitrary users has been identified in Q-Free MaxTime versions through 2.11.0. This issue arises from a missing authentication mechanism in the 'maxprofile/accounts/routes.lua' file, which enables unauthenticated remote attackers to exploit the vulnerability by sending crafted HTTP requests.
Q-Free MaxTime Hard-Coded Cryptographic Key Vulnerability Allowing Authentication Bypass
A vulnerability exists in Q-Free MaxTime versions through 2.11.0, where a hard-coded cryptographic key is used in JSON Web Token (JWT) signing. This flaw allows an unauthenticated remote attacker to bypass authentication by sending crafted HTTP requests.
Q-Free MaxTime Missing Authentication Vulnerability in HTTP Request Handling
A vulnerability allowing missing authentication for critical functions has been identified in Q-Free MaxTime versions through 2.11.0. This issue, located in the file maxtime/handleRoute.lua, enables an unauthenticated remote attacker to impact the device's confidentiality, integrity, or availability in various unspecified ways by sending crafted HTTP requests.
