CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
MicroWorld eScan Antivirus Command Injection Vulnerability in Quarantine Handler
A critical command injection vulnerability has been identified in MicroWorld eScan Antivirus version 7.0.32 for Linux. The issue arises from an unknown processing flaw in the rtscanner file within the Quarantine Handler component, allowing remote OS command injection. Exploitation of this vulnerability is considered difficult and has been publicly disclosed.
MicroWorld eScan Antivirus Quarantine Handler Incorrect Default Permissions Vulnerability
A vulnerability exists in MicroWorld eScan Antivirus for Linux, specifically in version 7.0.32. The issue arises within the Quarantine Handler component, where the default permissions of the quarantine folders are set to 777. This misconfiguration allows any unprivileged user to modify the contents of these folders. As a result, malicious files can be introduced into the quarantine, evading detection by the antivirus's real-time protection service, which excludes the quarantine folders from monitoring.
ESAFENET CDG V5 Cross-Site Scripting Vulnerability in todolistjump.jsp
A cross-site scripting vulnerability has been identified in ESAFENET CDG V5, specifically within the file todolistjump.jsp. The issue arises from the manipulation of the argument flowId, allowing for remote exploitation. This vulnerability has been publicly disclosed.
IBM Security Verify Governance Cryptographic Hash Vulnerability in Identity Manager
A vulnerability exists in IBM Security Verify Governance 10.0.2 Identity Manager, where a one-way cryptographic hash is applied to inputs like passwords without the use of a salt. This omission can make the hashing process reversible, potentially allowing for the original input to be retrieved.
ESAFENET CDG V5 Cross-Site Scripting Vulnerability in todoDetail.jsp
A cross-site scripting vulnerability has been identified in ESAFENET CDG V5. The issue arises in the file todoDetail.jsp, where the manipulation of the curpage argument allows for the injection of malicious scripts. This vulnerability can be exploited remotely.
ESAFENET CDG SQL Injection Vulnerability in todoDetail.jsp
A critical SQL injection vulnerability has been identified in ESAFENET CDG version 5. The issue arises in the file todoDetail.jsp, where the argument flowId can be manipulated to execute malicious SQL queries. This vulnerability can be exploited remotely.
ESAFENET CDG V5 SQL Injection Vulnerability in sdTodoDetail.jsp
A critical SQL injection vulnerability has been identified in ESAFENET CDG version 5. The issue arises in an unknown function of the file sdTodoDetail.jsp, where the manipulation of the argument flowId allows for SQL injection. This vulnerability can be exploited remotely.
ESAFENET CDG SQL Injection Vulnerability in sdDoneDetail.jsp
A critical SQL injection vulnerability has been identified in ESAFENET CDG version 5. The issue arises from the handling of the flowId argument in the sdDoneDetail.jsp file, allowing for remote exploitation. This vulnerability has been publicly disclosed.
ESAFENET CDG V5 Cross-Site Scripting Vulnerability in doneDetail.jsp
A cross-site scripting vulnerability has been identified in ESAFENET CDG V5, specifically within the doneDetail.jsp file. The issue arises from the manipulation of the curpage argument, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely.
IBM Security Verify Governance Identity Manager Clear Text Credential Transmission Vulnerability
A vulnerability exists in IBM Security Verify Governance Identity Manager 10.0.2, allowing user credentials to be transmitted in clear text. This exposure could be exploited by an attacker using man-in-the-middle techniques to intercept the credentials.
ESAFENET CDG V5 SQL Injection Vulnerability in /doneDetail.jsp
A critical SQL injection vulnerability has been identified in ESAFENET CDG version 5. The issue arises in the file '/doneDetail.jsp', where the 'flowId' argument can be manipulated to execute unauthorized SQL commands. This vulnerability can be exploited remotely.
ESAFENET CDG V5 SQL Injection Vulnerability in content_top.jsp
A critical SQL injection vulnerability has been identified in ESAFENET CDG V5. The issue arises in the file content_top.jsp, where the manipulation of the id argument allows for SQL injection. This vulnerability can be exploited remotely.
Open5GS Denial-of-Service Vulnerability via SUPI Validation Issue
A denial-of-service vulnerability has been identified in Open5GS version 2.7.2. The issue arises in the 'ogs_dbi_auth_info' function within 'lib/dbi/subscription.c', where the application crashes when a malformed SUPI (Subscription Permanent Identifier) is processed. This occurs because the function fails to validate the SUPI format before extraction, leading to assertion failures and application termination.
Mailcow Session Fixation Vulnerability in Web Panel
A session fixation vulnerability has been identified in the Mailcow web panel, affecting versions through 2024-11b. This vulnerability allows remote attackers to set a session identifier when HTTP Strict Transport Security (HSTS) is disabled in the victim's browser. The issue arises because the login page does not invalidate existing session identifiers; instead, it accepts and validates any session identifier stored in the browser. After a user logs in, the session identifier becomes valid, allowing the attacker to access the victim's web panel using the same identifier.
AutoLib Software Systems OPAC API Key Exposure Vulnerability
A vulnerability exists in AutoLib Software Systems OPAC version 20.10, where multiple API keys are exposed in the source code. This exposure allows attackers to access the backend API or other sensitive information. The vulnerability was introduced in the main.js file.
Audemium ERP Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in Audemium ERP versions through 0.9.0. This vulnerability allows remote attackers to execute arbitrary JavaScript in the context of the user's browser. The issue arises in list.php, where the 'type' parameter is not properly sanitized before being output, enabling the injection of malicious scripts.
ESAFENET CDG Cross-Site Scripting Vulnerability in appDetail.jsp
A cross-site scripting (XSS) vulnerability has been identified in ESAFENET CDG version 5. The issue arises in the file appDetail.jsp, where the curpage argument can be manipulated to inject malicious scripts. This vulnerability can be exploited remotely.
ESAFENET CDG SQL Injection Vulnerability in appDetail.jsp
A critical SQL injection vulnerability has been identified in ESAFENET CDG version 5. The issue arises in the file appDetail.jsp, where the flowId parameter can be manipulated to execute SQL injection attacks. This vulnerability can be exploited remotely, and details of the exploit have been publicly disclosed.
ESAFENET CDG V5 Cross-Site Scripting Vulnerability in SysConfig.jsp
A cross-site scripting (XSS) vulnerability has been identified in ESAFENET CDG version 5. The issue arises in the SysConfig.jsp file, where the help parameter can be manipulated to execute malicious scripts in the user's browser. This vulnerability could lead to information theft or other malicious activities.
TP-Link Archer A20 V3 Router Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in the TP-Link Archer A20 v3 router, specifically in version 1.0.6 Build 20231011 rel.85717(5553). The issue arises from improper handling of directory listing paths in the web interface, allowing attackers to execute arbitrary JavaScript by visiting a specially crafted URL. This injected script runs in the context of the user's browser, potentially leading to further malicious actions.
D-Link DSR Series Buffer Overflow Vulnerability Allowing Remote Code Execution
A buffer overflow vulnerability has been identified in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, and DSR-1000N routers, affecting firmware versions 3.13 to 3.17B901C. This vulnerability allows unauthenticated users to execute remote code on the affected devices.
DTEX Forwarder Privilege Escalation Vulnerability via Unvalidated XPC Connections
A privilege escalation vulnerability has been identified in DTEX DEC-M (DTEX Forwarder) version 6.1.1. The issue arises in the com.dtexsystems.helper service, which manages privileged operations for the macOS DTEX Event Forwarder agent. This service fails to perform essential client validation during XPC interprocess communication, allowing unauthorized clients to exploit the service's methods. Malicious actors can escalate privileges to root by abusing the DTConnectionHelperProtocol's submitQuery method over an unapproved XPC connection.
Apache Hive Credentials File Permission Vulnerability
A vulnerability exists in Apache Hive versions 1.1.0 prior to 4.0.1, where a credentials file is created in a temporary directory with default permissions of 644. This allows any unauthorized user with access to the directory to read the sensitive information in the file. The issue arises because the file permissions are not explicitly set, leaving the credentials exposed to unauthorized access.
Acronis Snap Deploy Local Privilege Escalation Vulnerability
A local privilege escalation vulnerability has been identified in Acronis Snap Deploy for Windows, affecting versions prior to build 4625. The issue arises from insecure folder permissions, which can be exploited to gain elevated privileges.
Rockwell Automation FactoryTalk View SE Local Code Injection Vulnerability
A local code injection vulnerability has been identified in Rockwell Automation's FactoryTalk View Site Edition versions prior to 15.0. This vulnerability arises from incorrect default permissions, allowing DLLs to be executed with elevated privileges.
Rockwell Automation FactoryTalk View SE Incorrect Permission Assignment Vulnerability Allowing Unauthenticated Access to System Configuration
A vulnerability exists in FactoryTalk View Site Edition versions prior to 15.0, as well as in versions 12, 13, and 14 of the same product. This vulnerability is due to incorrect permissions assigned to the remote debugger port, which can lead to unauthenticated access to the system configuration.
Intelbras InControl Cleartext Transmission Vulnerability in Registered User Handler
A vulnerability exists in Intelbras InControl versions through 2.21.58, specifically within the Registered User Handler component. The issue arises in an unknown part of the code related to the file '/v1/usuario/', where sensitive information is transmitted in cleartext. This vulnerability can be exploited remotely, although the complexity of the attack is considered high, making exploitation difficult.
Android Settings App Elevation of Privilege Vulnerability
A vulnerability in the Android Settings application allows for a local elevation of privilege by bypassing factory reset protections. This issue arises from a missing permission check in the 'shouldSkipForInitialSUW' method of 'AdvancedPowerUsageDetail.java'. Exploitation of this vulnerability does not require any additional execution privileges or user interaction.
Android Account Manager Service Intent Security Bypass Vulnerability Allowing Privilege Escalation
A vulnerability in the AccountManagerService component of the Android framework has been identified, allowing for a potential bypass of intent security checks. This issue arises from a confused deputy scenario, where an unknown app could be installed without the user's consent. The vulnerability could lead to local escalation of privileges, with no additional execution rights required for exploitation.
Android Framework Intent Component Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the Android Framework's Intent component, specifically in the parseUriInternal function of Intent.java. This issue arises from inadequate input validation, which can lead to a potential infinite loop. The vulnerability can be exploited locally, without requiring any additional execution privileges or user interaction.
Android WiFi Module Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the Android WiFi module, specifically within the WifiConfigurationUtil component. The issue arises from a logic error that allows for an overflow of a system configuration file. This vulnerability can be exploited locally, without the need for additional execution privileges or user interaction.
Android Libcore ZipFile Dynamic Code Loading Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in the Android Libcore component, specifically within the ZipFile class. This issue arises from improper input validation, which creates a potential for attackers to manipulate dynamic code loading. The vulnerability affects several versions of Android and can be exploited without requiring additional execution privileges or user interaction.
Android Intent Resolver ChooserActivity Elevation of Privilege Vulnerability
A vulnerability in the ChooserActivity component of the Android Intent Resolver module allows for a local elevation of privilege. This issue arises from a missing permission check, which creates a potential bypass of factory reset protections. Exploitation of this vulnerability does not require any additional execution privileges or user interaction.
Android PowerVR GPU Components Privilege Escalation Vulnerability
A use-after-free vulnerability has been identified in Imagination Technologies PowerVR GPU components of Android devices. This vulnerability arises from a race condition, which could lead to local escalation of privilege. Notably, no additional execution privileges are required for exploitation, and user interaction is not needed.
Android PowerVR GPU Components Use-After-Free Vulnerability Leading to Privilege Escalation
A use-after-free vulnerability has been identified in the PowerVR GPU component of Android, caused by a race condition. This vulnerability allows for local escalation of privilege, with no additional execution privileges required. Exploitation does not require user interaction.
Android PowerVR GPU Privilege Escalation Vulnerability
A use-after-free vulnerability has been identified in the PowerVR GPU component of Android, allowing for local escalation of privileges in the kernel. This vulnerability arises from a logic error in the code and can be exploited without any additional execution privileges or user interaction.
Android PowerVR GPU Kernel Privilege Escalation Vulnerability
A use-after-free vulnerability has been identified in the PowerVR GPU component of the Android kernel. This issue arises from a logic error in the code, which could lead to local escalation of privileges. Notably, no additional execution privileges are required for exploitation, and user interaction is not needed.
Android PowerVR GPU Privilege Escalation Vulnerability
A use-after-free vulnerability has been identified in the PowerVR GPU component of Android devices, specifically within the devicemem_server.c file. This vulnerability arises from improper casting, which could lead to local escalation of privileges in the kernel. Notably, exploitation does not require any additional execution privileges or user interaction.
Android PowerVR GPU Components Integer Overflow Vulnerability Leading to Arbitrary Code Execution
A vulnerability has been identified in the PowerVR GPU components of certain Android devices, allowing for arbitrary code execution. This issue arises from an integer overflow in the 'DevmemXIntMapPages' function of 'devicemem_server.c', which could facilitate local privilege escalation in the kernel without requiring additional execution privileges. Exploitation of this vulnerability does not involve user interaction.
Android PowerVR GPU Kernel Privilege Escalation Vulnerability
A race condition in the RGXMMUCacheInvalidate function of rgxmem.c can lead to arbitrary code execution, allowing for local privilege escalation in the kernel. This vulnerability does not require any additional execution privileges or user interaction for exploitation.
Rockwell Automation FactoryTalk View Machine Edition Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in Rockwell Automation's FactoryTalk View Machine Edition, versions prior to 15. This vulnerability arises from inadequate input sanitation, potentially allowing remote attackers to execute commands or code with high privileges.
Rockwell Automation FactoryTalk View Machine Edition Local Code Execution Vulnerability
A local code execution vulnerability has been identified in Rockwell Automation's FactoryTalk View Machine Edition, versions prior to 15. The issue arises from a default Windows setting that grants access to the Command Prompt with elevated privileges.
Rockwell Automation GuardLogix 5380 and 5580 Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Rockwell Automation's GuardLogix 5380 SIL3 and GuardLogix 5580 products, specifically in version 33.011. This vulnerability allows a remote, non-privileged user to send malicious requests that cause a major, non-recoverable fault, leading to a denial-of-service condition.
VMware Avi Load Balancer Unauthenticated Blind SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in VMware Avi Load Balancer, affecting versions 30.1.1, 30.1.2, 30.2.1, and 30.2.2. This vulnerability allows a malicious user with network access to execute specially crafted SQL queries, potentially leading to unauthorized database access. The issue has been assigned a CVSSv3 base score of 8.6, indicating a high severity level.
Pankajindevops Scale Improper Access Control Vulnerability in API Endpoint
A vulnerability has been identified in Pankajindevops Scale versions up to 20241113, concerning the API Endpoint component. This vulnerability involves improper access controls, allowing users with lower privileges to perform actions reserved for higher privilege roles, such as superAdmin. The issue arises because the application fails to verify user permissions before granting access to certain functionalities. As a result, a member account can execute high-level requests, potentially compromising the entire organization by allowing control over critical resources and actions.
Rockwell Automation PowerFlex 755 Credential Exposure Vulnerability
A credential exposure vulnerability exists in Rockwell Automation PowerFlex 755 versions through 16.002.279. This vulnerability arises from the use of HTTP, which allows credentials to be transmitted in clear text.
HPE Aruba Networking Fabric Composer Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the web management interface of HPE Aruba Networking Fabric Composer. This issue allows authenticated remote attackers to inject and execute arbitrary script code in the web browsers of users interacting with the compromised interface.
HPE Aruba Networking Fabric Composer Authenticated Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the web management interface of HPE Aruba Networking Fabric Composer, specifically in versions 7.1.0 and below. This vulnerability allows authenticated remote attackers to inject and execute arbitrary scripts in the context of the user's browser session within the compromised interface.
HPE Aruba Networking Fabric Composer Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the web management interface of HPE Aruba Networking Fabric Composer, specifically in versions 7.1.0 and prior. This vulnerability allows authenticated remote attackers to inject and execute arbitrary scripts in the context of the victim's browser, using the compromised interface.
HPE Aruba Networking Fabric Composer Authenticated Privilege Escalation Vulnerability
A vulnerability exists in the web-based management interface of HPE Aruba Networking Fabric Composer, specifically in version 7.1.0 and prior. This vulnerability allows an authenticated low-privilege operator user to perform actions beyond their assigned privilege level. Exploitation of this issue could enable manipulation of user-generated files, potentially resulting in unauthorized modifications to critical system configurations.
