CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Feb 11, 2025

SAP GUI for Windows Privilege Escalation Vulnerability via Insecure Credential Storage

A vulnerability exists in SAP GUI for Windows, where RFC service credentials are improperly stored in the program's memory. This flaw allows an unauthenticated attacker to access sensitive information within systems, potentially leading to privilege escalation. The issue does not affect the integrity or availability of the system.

4.1
Feb 11, 2025

SAP NetWeaver Application Server Java Information Disclosure Vulnerability

An information disclosure vulnerability has been identified in SAP NetWeaver Application Server Java. This vulnerability allows an attacker to access an endpoint that reveals details about deployed server components, including their XML definitions. Ideally, this information should be restricted to customer administrators. The exposed XML files, while not entirely internal to SAP, are deployed with the server. As a result, sensitive information could be leaked without compromising its integrity or availability.

4.9
Feb 11, 2025

SAP HANA XS Advanced Model User Account and Authentication Service Open Redirect Vulnerability

A vulnerability in the User Account and Authentication service for SAP HANA extended application services, advanced model, allows an unauthenticated attacker to create a malicious link that, when clicked by a victim, redirects the browser to a harmful site. This exploitation takes advantage of inadequate validation of redirect URLs. Successful exploitation could lead to a limited impact on the system's confidentiality, integrity, and availability.

3.3
Feb 11, 2025

SAP BusinessObjects Platform Cross-Site Scripting Vulnerability in BI Launchpad

A cross-site scripting (XSS) vulnerability has been identified in SAP BusinessObjects Platform, specifically within the BI Launchpad component. This issue arises because the application does not adequately sanitize user input, allowing an unauthenticated attacker to create a URL that includes a malicious script embedded in an unprotected parameter. When a user clicks on the link, the script is executed in their browser, potentially enabling the attacker to access or modify information related to the web client, without impacting the application's availability.

2.0
Feb 11, 2025

SAP NetWeaver Server ABAP User-Based Information Disclosure Vulnerability

An information disclosure vulnerability has been identified in SAP NetWeaver Server ABAP. This issue allows an unauthenticated attacker to exploit the server's response behavior based on the presence of a specific user, potentially leading to the revelation of sensitive information. The vulnerability does not permit data modification and does not affect server availability.

4.9
Feb 11, 2025

SAP Fiori for SAP ERP Host Header Injection Vulnerability Allowing OData Cache Poisoning

A vulnerability exists in the SAP OData endpoint within SAP Fiori for SAP ERP, where cached values can be poisoned by altering the Host header in an HTTP GET request. This manipulation could redirect the 'atom:link' values in the metadata response from the SAP server to a malicious link specified by the attacker. Exploitation of this vulnerability could lead to a low integrity impact on the application.

3.8
Feb 11, 2025

SAP Missing Authorization Check Vulnerability Allowing Unauthorized Data Access

A vulnerability exists in certain SAP products due to a lack of proper authorization checks. This flaw enables an authenticated attacker to invoke a remote-enabled function module, potentially accessing data that should be restricted. However, the attacker cannot alter data or affect system availability.

1.1
Feb 11, 2025

SAP RFC Authorization Bypass Vulnerability in Transaction SDCCN Allowing Integrity Impact

A vulnerability exists in an RFC-enabled function module within transaction SDCCN due to a lack of proper authorization checks. This flaw allows authenticated attackers to generate technical metadata, potentially leading to a low impact on data integrity. The vulnerability does not affect confidentiality or availability.

1.7
Feb 11, 2025

SAP NetWeaver Missing Authorization Check in RFC Function Module Vulnerability in Transaction SDCCN

A vulnerability exists in an RFC-enabled function module within the SAP NetWeaver platform, specifically in transaction SDCCN. The issue arises from a missing authorization check, allowing an unauthenticated attacker to generate technical metadata. This vulnerability has a low impact on integrity, with no effects on confidentiality or availability.

2.5
Feb 11, 2025

Lumsoft ERP Unrestricted File Upload Vulnerability

A critical unrestricted file upload vulnerability has been identified in Lumsoft ERP version 8. The issue resides in the DoUpload/DoWebUpload function of the FileUploadApi.ashx file. This vulnerability allows for remote exploitation by manipulating the file upload argument, potentially leading to unauthorized file uploads on the server.

4.0
Feb 11, 2025

SAP BusinessObjects Business Intelligence Central Management Console Secret Passphrase Vulnerability Allowing User Impersonation

A vulnerability exists in the Central Management Console of the SAP BusinessObjects Business Intelligence platform. Under certain conditions, an attacker with admin rights can generate or retrieve a secret passphrase. This passphrase can be used to impersonate any user in the system, leading to significant breaches of confidentiality and integrity.

3.5
Feb 11, 2025

SAP NetWeaver Application Server Java Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in SAP NetWeaver Application Server Java. This issue arises because the application does not adequately sanitize user input, allowing attackers with basic user privileges to inject a JavaScript payload that is saved on the server. When executed in a victim's web browser, this payload could potentially be used to read or modify information related to the affected web page.

3.7
Feb 11, 2025

Police FIR Record Management System Stack-Based Buffer Overflow Vulnerability

A stack-based buffer overflow vulnerability has been identified in the Police FIR Record Management System version 1.0. The issue arises in the Add Record Handler component, where an unknown processing flaw allows for manipulation that leads to the buffer overflow. This vulnerability requires local access to exploit.

2.8
Feb 11, 2025

Vehicle Parking Management System Stack-Based Buffer Overflow Vulnerability

A critical stack-based buffer overflow vulnerability has been identified in the Vehicle Parking Management System version 1.0. This issue arises in the Authentication component, specifically within the login function, where improper handling of the username argument creates the potential for memory corruption. The vulnerability requires local exploitation.

2.6
Feb 10, 2025

Lemmy Server-Side Request Forgery Vulnerability in ActivityPub Federation Dependency

A server-side request forgery (SSRF) vulnerability has been identified in Lemmy, a link aggregator and forum for the fediverse. This issue arises from a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. The vulnerability is present in Lemmy versions through 0.19.8 and in activitypub_federation versions through 0.6.2. The flaw allows users to bypass hardcoded URL path restrictions and security measures intended to prevent access to localhost services, enabling arbitrary GET requests to any host, port, and URL via a Webfinger request.

5.2
Feb 10, 2025

Code-Projects Job Recruitment SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Code-Projects Job Recruitment version 1.0. The issue arises in the file '_parse/load_user-profile.php', where improper handling of the 'userhash' argument allows for SQL injection. This vulnerability can be exploited remotely.

2.5
Feb 10, 2025

SourceCodester Employee Management System Default Credentials Vulnerability

A critical vulnerability exists in SourceCodester Employee Management System version 1.0, specifically within the login functionality of index.php. The issue arises from the use of default credentials, allowing remote authentication bypass. Exploitation involves manipulating the username and password fields to gain unauthorized access.

3.9
Feb 10, 2025

Apache Netty Denial-of-Service Vulnerability in Windows Applications

A denial-of-service vulnerability has been identified in Apache Netty, an asynchronous, event-driven network application framework, in versions prior to and including 4.1.118.Final. When running on a Windows application, Netty improperly reads the environment file, leading to a crash if an attacker creates a large file that fills the application's buffer. This issue arises because the initial fix for a similar vulnerability, CVE-2024-47535, was incomplete; it failed to account for null bytes in the input limit. The vulnerability can be exploited by creating a file filled with null bytes, which Netty's input stream handling will mismanage, causing the application to crash.

2.5
Feb 10, 2025

ZOO-Project Web Processing Service EchoProcess Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the ZOO-Project Web Processing Service (WPS) Server, specifically within the EchoProcess service, in versions prior to the commit 7a5ae1a. This vulnerability arises because the EchoProcess service improperly sanitizes user input when processing complex data, such as XML, JSON, and SVG, allowing malicious JavaScript to be executed in the context of the victim's browser. The issue is particularly concerning as it involves a service designed to reflect user input, creating a reliable vector for XSS attacks, especially when SVG content is handled and returned with the image/svg+xml MIME type.

3.4
Feb 10, 2025

ZOO-Project Web Processing Service Reflective Cross-Site Scripting Vulnerability

A reflected Cross-Site Scripting vulnerability has been identified in the ZOO-Project Web Processing Service (WPS) publish.py CGI script, affecting versions prior to 7a5ae1a. The vulnerability arises because the script reflects user input from the 'jobid' parameter in the HTTP response without adequate HTML encoding or sanitization. This flaw allows attackers to execute arbitrary JavaScript in the context of the victim's browser. The issue is exacerbated by the fact that this endpoint is accessible from the main WPS interface, potentially facilitating phishing attacks against WPS users.

2.8
Feb 10, 2025

Apache Netty SslHandler Packet Validation Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability has been identified in Apache Netty, specifically in the SslHandler component, within versions 4.1.91.Final through 4.1.117.Final. The issue arises because SslHandler fails to properly validate certain crafted packets, particularly when using the native SSLEngine, which can result in a native crash.

7.6
Feb 10, 2025

CampCodes School Management Software Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in CampCodes School Management Software version 1.0. The issue arises from an unknown functionality in the file '/academic-calendar', allowing remote attackers to inject malicious scripts. This vulnerability has been publicly disclosed and could potentially be exploited.

2.9
Feb 10, 2025

ESAFENET CDG SQL Injection Vulnerability in addPolicyToSafetyGroup.jsp

A critical SQL injection vulnerability has been identified in ESAFENET CDG version 5.6.3.154.205_20250114. The issue arises in the file addPolicyToSafetyGroup.jsp, where an unknown function improperly handles the safetyGroupId argument. This vulnerability can be exploited remotely, allowing attackers to manipulate the argument and execute SQL injection attacks.

2.5
Feb 10, 2025

Allims Lab Online SQL Injection Vulnerability in Password Recovery Model Processing

A critical SQL injection vulnerability has been identified in Allims Lab Online versions prior to 20250201. The issue arises in the file 'model_recuperar_senha.php', where improper handling of the 'recuperacao' argument allows for SQL injection. This vulnerability can be exploited remotely.

1.7
Feb 10, 2025

Pix Software Vivaz SQL Injection Vulnerability in Login Servlet

A critical SQL injection vulnerability has been identified in Pix Software Vivaz version 6.0.10. The issue arises in the login servlet, specifically within the code that handles the 'usuario' argument. This vulnerability can be exploited remotely, allowing attackers to manipulate the input and execute arbitrary SQL commands. The exploit has been publicly disclosed, and although the vendor was notified, there has been no response.

2.5
Feb 10, 2025

MicroDicom DICOM Viewer Improper Certificate Validation Vulnerability Allowing Machine-in-the-Middle Attacks

A vulnerability exists in MicroDicom DICOM Viewer version 2024.03 due to improper validation of the update server's certificate. This flaw could enable attackers in a privileged network position to intercept and alter network traffic, executing a machine-in-the-middle (MITM) attack. Such an attack would allow the modification of the server's response to the user, potentially delivering a malicious update.

1.3
Feb 10, 2025

Wazuh Remote Code Execution Vulnerability via Unsafe Deserialization

A remote code execution vulnerability has been identified in Wazuh servers, affecting versions 4.4.0 prior to 4.9.1. The issue arises from an unsafe deserialization of DistributedAPI parameters, which are serialized as JSON and deserialized using the 'as_wazuh_object' method. An attacker can inject an unsanitized dictionary into DAPI request or response, allowing them to forge an unhandled exception that evaluates arbitrary Python code. This vulnerability can be exploited by anyone with API access, or in some cases, by a compromised agent.

6.0
Feb 10, 2025

Webkul QloApps Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in Webkul QloApps version 1.6.1. This issue occurs on the '/stores' page within the 'Your Location' search field, where unsanitized user input is directly reflected in the page response. This vulnerability allows remote attackers to execute arbitrary JavaScript in the context of the user's browser, potentially leading to data theft, phishing attacks, or session hijacking.

4.3
Feb 10, 2025

xxyopen Novel SQL Injection Vulnerability in Book Search API

A critical SQL injection vulnerability has been identified in xxyopen Novel versions through 3.4.1. The issue arises in the Book Search API, specifically within the 'sort' parameter, allowing for remote exploitation. The vulnerability is rooted in the application's trust in user input, which is improperly sanitized before being used in SQL queries. This flaw could potentially be leveraged to extract database information or, if the SQL database is misconfigured, execute arbitrary code via user-defined functions.

3.2
Feb 10, 2025

Stock-Forecaster SQL Injection Vulnerability

A SQL injection vulnerability has been identified in Stock-Forecaster versions through 01-04-2020. The issue arises in the portfolio() endpoint, where an attacker can send a specially crafted 'stock-symbol' parameter to execute arbitrary SQL commands. This exploitation could lead to unauthorized access to user data or manipulation of the application's behavior.

2.8
Feb 10, 2025

Perfood Couch-Auth Host Header Injection Vulnerability Allowing Server-Side Template Injection

A host header injection vulnerability has been identified in the Perfood Couch-Auth NPM package, specifically in versions through 0.21.2. This vulnerability allows for server-side template injection (SSTI) by sending a specially crafted host header in the email change confirmation request. Exploiting this vulnerability could enable an attacker to execute limited commands or leak server-side information.

1.7
Feb 10, 2025

Apple iOS and iPadOS USB Restricted Mode Vulnerability Allowing Bypassing on Locked Devices

A vulnerability has been identified in Apple iOS and iPadOS that allows a physical attack to disable USB Restricted Mode on locked devices. This issue arises from an authorization flaw that has been addressed with improved state management. The vulnerability is present in iOS 18.3.1, iPadOS 18.3.1, and iPadOS 17.7.5. Apple is aware of reports that this vulnerability may have been exploited in a highly sophisticated attack targeting specific individuals.

6.1
Feb 10, 2025

GNU Binutils Memory Corruption Vulnerability in Versions 2.43 and 2.44

A memory corruption vulnerability has been identified in GNU Binutils versions 2.43 and 2.44. The issue arises in the 'bfd_set_format' function within 'format.c', and can be exploited remotely, although the attack's complexity is considered high. Successful exploitation leads to a denial-of-service condition.

5.9
Feb 10, 2025

Modelscope Agentscope Local File Inclusion Vulnerability in Load-Workflow Endpoint

A local file inclusion (LFI) vulnerability has been identified in the Modelscope Agentscope application, specifically in version 0.0.4. The issue arises in the '/load-workflow' endpoint, where improper sanitization of user input allows attackers to manipulate the filename parameter and read arbitrary files from the server. This vulnerability can be exploited to access sensitive files, such as API keys, by leveraging the os.path.join function to navigate outside the intended directory.

3.9
Feb 10, 2025

Apple WebKit Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in the WebKit component of multiple Apple operating systems, including iOS 17.4, iPadOS 17.4, Safari 17.4, tvOS 17.4, watchOS 10.4, visionOS 1.1, and macOS Sonoma 14.4. This vulnerability arises from improper memory handling, which can be exploited by processing maliciously crafted web content, leading to unexpected application termination or resource exhaustion.

4.9
Feb 10, 2025

Tenda W18E Sensitive Information Disclosure Vulnerability

A vulnerability allowing sensitive information disclosure has been identified in the Tenda W18E router, specifically in version V16.01.0.8(1625). The issue resides in the web management portal, where an unauthenticated remote attacker can retrieve confidential configuration details. This includes the WiFi SSID, WiFi password, and base64-encoded administrator credentials. The vulnerability is exploited by sending a specially crafted HTTP POST request to the 'getQuickCfgWifiAndLogin' function, which bypasses authentication checks.

4.2
Feb 10, 2025

Tenda W18E Hardcoded Credentials Vulnerability Allowing Root Access via Telnet

A vulnerability exists in the Tenda W18E router, specifically in version V16.01.0.8(1625), due to hardcoded credentials that enable unauthenticated remote attackers to gain root access to the device through the telnet service.

3.9
Feb 10, 2025

Tenda W18E Stack Overflow Vulnerability in Web Management Portal Allowing Denial-of-Service and Potential Arbitrary Code Execution

A stack overflow vulnerability has been identified in the Tenda W18E router, specifically in version V16.01.0.8(1625). This vulnerability resides within the web management portal, where improper input validation in the delFacebookPic function allows authenticated remote attackers to cause a denial-of-service condition or potentially execute arbitrary code.

3.1
Feb 10, 2025

Tenda W18E Authentication Bypass Vulnerability in Web Management Portal

An authentication bypass vulnerability has been identified in the Tenda W18E router, specifically in version 16.01.0.8(1625). This vulnerability allows unauthorized remote attackers to gain administrative access by sending specially crafted HTTP requests to the web management portal.

3.9
Feb 10, 2025

Tenda W18E Default Credentials Vulnerability Allowing Unauthenticated Access to Web Management Portal

A vulnerability exists in the Tenda W18E router, specifically in version V16.01.0.8(1625), due to default credentials that allow unauthenticated remote attackers to access the web management portal. The default rzadmin account, which has administrative privileges, can be used to gain access.

3.9
Feb 10, 2025

Tenda W18E Incorrect Access Control Vulnerability Allowing Unauthorized WiFi and Admin Credential Changes

An incorrect access control vulnerability has been identified in the Tenda W18E router, specifically in version V16.01.0.8(1625). The issue allows attackers to send specially crafted HTTP POST requests to the setQuickCfgWifiAndLogin function. This exploitation can lead to unauthorized modifications of WiFi configuration settings and administrative credentials.

3.9
Feb 10, 2025

Tenda W18E Buffer Overflow Vulnerability in Web Management Portal

A buffer overflow vulnerability has been identified in the Tenda W18E router, specifically in version V16.01.0.8(1625). This vulnerability can be exploited by an attacker with access to the web management portal, who sends specially crafted data to the delWewifiPic function.

3.0
Feb 10, 2025

Tenda W18E Incorrect Access Control Vulnerability Allowing Unauthorized Password Changes

An incorrect access control vulnerability has been identified in the Tenda W18E router, specifically in version 16.01.0.8(1625). This vulnerability allows an unauthenticated remote attacker to change the administrator password through the web management portal. The issue arises by sending a specially crafted HTTP POST request to the setLoginPassword function, effectively bypassing the authentication mechanism.

4.3
Feb 10, 2025

Tenda W18E Hardcoded Credentials Vulnerability Allowing Unauthenticated Access to Web Management Portal

A vulnerability exists in the Tenda W18E router, specifically in version V16.01.0.8(1625), due to hardcoded credentials that allow unauthenticated remote attackers to access the web management portal. This is achieved by using a default guest account that has administrative privileges.

3.9
Feb 10, 2025

OPC Foundation .NET Standard Stack Authentication Bypass Vulnerability via HTTPS Endpoints

An authentication bypass vulnerability has been identified in the OPC UA .NET Standard Stack, affecting versions prior to 1.5.374.158. This vulnerability allows unauthorized attackers to bypass application authentication when HTTPS endpoints are enabled and use a security policy other than None.

3.0
Feb 10, 2025

OPC Foundation .NET Standard Stack Authentication Bypass Vulnerability in OPC UA

An authentication bypass vulnerability has been identified in the OPC UA .NET Standard Stack, affecting versions prior to 1.5.374.158. When the deprecated Basic128Rsa15 security policy is enabled, an unauthorized attacker can exploit this vulnerability to bypass application authentication. Although Basic128Rsa15 is disabled by default, this vulnerability could be a concern for applications that have explicitly enabled it.

3.5
Feb 10, 2025

Apple WebKit Arbitrary Code Execution Vulnerability

A buffer overflow vulnerability in the WebKit component of multiple Apple operating systems, including iOS 17.4, iPadOS 17.4, tvOS 17.4, watchOS 10.4, visionOS 1.1, and macOS Sonoma 14.4, has been identified. This vulnerability allows for arbitrary code execution when processing web content. The issue arises from improper memory handling, which can be exploited by maliciously crafted web content.

5.1
Feb 10, 2025

Mintplex Anything-LLM Path Traversal Vulnerability Leading to Arbitrary File Write and Remote Code Execution

A path traversal vulnerability has been identified in Mintplex Labs' Anything-LLM, in versions prior to 1.3.1. This issue arises from improper handling of non-ASCII filenames by the Multer library, allowing attackers with manager or admin roles to write files to arbitrary locations on the server. The vulnerability can be exploited by crafting a filename that includes '../' sequences, which Multer fails to sanitize. This arbitrary file write capability can lead to remote code execution, as overwritten files could be executed by the server.

2.5
Feb 10, 2025

WP Foodbakery Plugin Unauthenticated Arbitrary File Upload Vulnerability

A vulnerability allowing arbitrary file uploads has been identified in the WP Foodbakery plugin for WordPress, in versions through and including 4.7. This issue arises from inadequate validation of file types in the 'upload_publisher_profile_image' function. As a result, unauthenticated attackers can upload arbitrary files to the server hosting the affected site, potentially leading to remote code execution.

2.7
Feb 10, 2025

WP Foodbakery Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WP Foodbakery plugin for WordPress, affecting versions through 4.8. The issue arises from inadequate input sanitization and output escaping of the 'search_type' parameter. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts into pages, which could be executed if a user is tricked into clicking a link.

2.0