CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Huawei HarmonyOS and EMUI Permission Verification Vulnerability in the Media Library Module
A permission verification vulnerability has been identified in the media library module of Huawei's HarmonyOS 5.0.0 and EMUI 14.0.0, 13.0.0, and 12.0.0 versions. This vulnerability could be exploited to improperly manage permissions, potentially leading to unauthorized access or manipulation of sensitive information.
Huawei HarmonyOS Package Management Module Multi-Thread Vulnerability
A multi-threading vulnerability has been identified in the package management module of Huawei HarmonyOS 5.0.0. This vulnerability could be exploited to affect the availability of the service.
Huawei HarmonyOS and EMUI Permission Verification Vulnerability in the Media Library Module
A permission verification vulnerability has been identified in the media library module of Huawei's HarmonyOS 5.0.0 and EMUI versions 12.0.0 through 14.0.0. This vulnerability could be exploited to improperly manage access permissions, potentially leading to unauthorized access to sensitive information or services.
Huawei HarmonyOS and EMUI Lock Screen Permission Management Vulnerability
A permission management vulnerability has been identified in the lock screen module of Huawei's HarmonyOS 5.0.0 and EMUI versions 12.0.0 through 14.0.0. This vulnerability could be exploited to affect the confidentiality of services.
Huawei HarmonyOS and EMUI Multi-Concurrency Vulnerability in Media Digital Copyright Protection Module
A multi-concurrency vulnerability has been identified in the media digital copyright protection module of Huawei's HarmonyOS 5.0.0 and EMUI 14.0.0, 13.0.0, and 12.0.0 versions. This vulnerability could lead to a denial-of-service condition, affecting the availability of the service.
Huawei EMUI Notification Module Permission Verification Bypass Vulnerability
A permission verification bypass vulnerability has been identified in the notification module of Huawei EMUI. This vulnerability allows for unauthorized actions by bypassing normal permission checks, potentially leading to unintended behavior or access. It affects several versions of HarmonyOS and EMUI.
Huawei EMUI and HarmonyOS Permission Bypass Vulnerability in the Window Module
A permission bypass vulnerability has been identified in the window module of Huawei's EMUI and HarmonyOS. This vulnerability affects several different versions and could lead to unauthorized access or manipulation of sensitive information, thereby impacting service confidentiality.
NAKIVO Backup & Replication Absolute Path Traversal Vulnerability Allowing Arbitrary File Read
An absolute path traversal vulnerability has been identified in NAKIVO Backup & Replication versions prior to 11.0.0.88174. The issue allows unauthenticated users to read arbitrary files by exploiting the 'getImageByPath' method in the 'STPreLoadManagement' action, accessed through the '/c/router' endpoint. This vulnerability could lead to remote code execution across the enterprise, as the 'PhysicalDiscovery' action contains cleartext credentials.
Axis VAPIX Device Configuration Framework Privilege Escalation Vulnerability
A vulnerability has been identified in the VAPIX Device Configuration framework of Axis products running AXIS OS 11.11 through AXIS OS 12.1. This flaw can lead to incorrect user privilege levels in the VAPIX service account D-Bus API. The vulnerability was discovered during a penetration test by Truesec, and has been assigned a CVSSv3.1 score of 7.8, indicating high severity.
Axis Communications AXIS OS ACAP Framework D-Bus Access Vulnerability
A vulnerability has been identified in the ACAP Application framework of Axis OS versions 11.11 prior to 12.1. This flaw allows applications to access restricted D-Bus methods, potentially leading to unauthorized actions within the framework. The vulnerability was discovered during a penetration test by Truesec.
Axis VAPIX API Race Condition Vulnerability Leading to Denial-of-Service
A race condition vulnerability has been identified in the VAPIX API param.cgi on Axis devices running AXIS OS versions 6.50 through 12.2. This vulnerability allows an attacker to disrupt access to the device's web interface. Other API endpoints or services that do not utilize param.cgi are not affected. Axis has released patched versions for this flaw.
Axis VAPIX API Audio Clip Upload Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in the VAPIX API's mediaclip.cgi component, present in AXIS OS versions 9.80 prior to 12.2. This vulnerability arises from inadequate input validation, allowing users to upload more audio clips than intended, which can cause the device to exhaust its memory resources. The issue can be exploited by authenticated users with operator or administrator privileges.
Axis VAPIX API Command Injection Vulnerability in dynamicoverlay.cgi Allowing Resource Exhaustion
A command injection vulnerability has been identified in the VAPIX API component dynamicoverlay.cgi, present in AXIS OS versions 11.11 prior to 12.1. This vulnerability arises from inadequate input validation, allowing authenticated users with operator or administrator privileges to upload files to the Axis device. The uploaded files can be used to deplete system resources, potentially leading to a denial of service. Axis has acknowledged this vulnerability and released patches for it.
Admin and Site Enhancements WordPress Plugin Limit Login Attempt Bypass Vulnerability
A vulnerability in the Admin and Site Enhancements (ASE) WordPress plugin, affecting versions prior to 7.6.10, allows attackers to bypass the login limit feature. This is achieved by manipulating client IP addresses through untrusted headers, enabling the exploitation of the login limit functionality.
PHPGurukul Restaurant Table Booking System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in the PHPGurukul Restaurant Table Booking System version 1.0. The issue resides in the admin/profile.php file, where the mobilenumber parameter is manipulated to inject malicious SQL queries. This vulnerability can be exploited remotely, potentially affecting other parameters as well.
SourceCodester Employee Management System Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in SourceCodester Employee Management System version 1.0. The issue resides in the 'employee.php' file, where the 'Full Name' input field fails to properly validate or sanitize user input. This allows attackers to inject malicious scripts, which are then stored in the database and executed whenever the 'employee.php' page is accessed. The vulnerability could lead to session hijacking, unauthorized content modification, or other malicious activities.
Code-Projects Blood Bank System Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Code-Projects Blood Bank System version 1.0. The issue resides in the file '/Blood/A+.php', where the 'Availibility' parameter is not properly sanitized, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely, potentially leading to the theft of administrator credentials or facilitating phishing attacks.
Newscrunch WordPress Theme Arbitrary File Upload Vulnerability
A vulnerability allowing arbitrary file uploads has been identified in the Newscrunch theme for WordPress, affecting all versions through 1.8.4.1. The issue arises from a missing capability check in the 'newscrunch_install_and_activate_plugin' function, which allows authenticated users with Subscriber-level access and above to upload arbitrary files to the server. This vulnerability could potentially be exploited for remote code execution.
Newscrunch WordPress Theme Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Newscrunch theme for WordPress, affecting all versions through 1.8.4. The issue arises from inadequate nonce validation in the 'newscrunch_install_and_activate_plugin' function, allowing unauthenticated attackers to upload arbitrary files by tricking a site administrator into clicking a link.
OpenHarmony Out-of-Bounds Write Vulnerability in Pre-Installed Apps Allowing Arbitrary Code Execution
A vulnerability in OpenHarmony versions through 5.0.2 allows local attackers to execute arbitrary code in pre-installed applications. This issue arises from an out-of-bounds write, which can be exploited only under certain restricted conditions.
OpenHarmony Local Arbitrary Code Execution Vulnerability in Pre-Installed Apps
A use-after-free vulnerability allowing local attackers to execute arbitrary code in pre-installed applications has been identified in OpenHarmony versions through 5.0.2. This issue can only be exploited under certain restricted conditions.
OpenHarmony Out-of-Bounds Write Vulnerability Allowing Arbitrary Code Execution in Pre-Installed Apps
A vulnerability in OpenHarmony versions through 5.0.2 allows local attackers to execute arbitrary code in pre-installed applications. This issue arises from an out-of-bounds write, which can be exploited only under certain restricted conditions.
OpenHarmony Out-of-Bounds Read Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in OpenHarmony versions through 5.0.2. This issue allows a local attacker to cause a denial-of-service condition by exploiting an out-of-bounds read.
OpenHarmony Local Arbitrary Code Execution Vulnerability in Pre-Installed Apps
A use-after-free vulnerability allowing local attackers to execute arbitrary code in pre-installed applications has been identified in OpenHarmony versions through 5.0.2. This issue can only be exploited under certain restricted conditions.
OpenHarmony Local Arbitrary Code Execution Vulnerability in Pre-Installed Apps
A use-after-free vulnerability allowing local attackers to execute arbitrary code in pre-installed applications has been identified in OpenHarmony versions through 5.0.2. This issue can only be exploited under certain restricted conditions.
OpenHarmony Out-of-Bounds Write Vulnerability in Arkcompiler ETS Runtime Allowing Arbitrary Code Execution
A vulnerability allowing arbitrary code execution has been identified in OpenHarmony versions through 5.0.2. This issue arises from an out-of-bounds write in the arkcompiler_ets_runtime component, which can be exploited by local attackers in certain restricted scenarios, particularly within pre-installed applications.
OpenHarmony Buffer Overflow Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in OpenHarmony versions through 5.0.2. This issue allows local attackers to cause a denial-of-service condition by exploiting a buffer overflow.
OpenHarmony Local Denial-of-Service Vulnerability via Buffer Overflow
A denial-of-service vulnerability has been identified in OpenHarmony versions through 5.0.2. This issue allows a local attacker to cause a denial-of-service condition by exploiting a buffer overflow.
OpenHarmony Out-of-Bounds Read Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in OpenHarmony versions through 5.0.2. This issue allows a local attacker to cause a denial-of-service condition by exploiting an out-of-bounds read.
OpenHarmony Local Denial-of-Service Vulnerability via Out-of-Bounds Read
A denial-of-service vulnerability has been identified in OpenHarmony versions through 5.0.2. This issue allows a local attacker to cause a denial-of-service condition by exploiting an out-of-bounds read.
OpenHarmony Local Denial-of-Service Vulnerability via NULL Pointer Dereference
A denial-of-service vulnerability has been identified in OpenHarmony versions through 5.0.2. This issue allows a local attacker to cause a system crash or unresponsiveness by exploiting a NULL pointer dereference.
OpenHarmony Out-of-Bounds Write Vulnerability Allowing Arbitrary Code Execution in Pre-Installed Apps
A vulnerability in OpenHarmony versions through 5.0.2 allows local attackers to execute arbitrary code in pre-installed applications. This issue arises from an out-of-bounds write, and exploitation is possible only in certain restricted scenarios.
OpenHarmony Out-of-Bounds Read Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in OpenHarmony versions through 5.0.2. This issue allows a local attacker to cause a denial-of-service condition by exploiting an out-of-bounds read.
OpenHarmony Out-of-Bounds Read Vulnerability Allowing Information Leak
A vulnerability in OpenHarmony versions through 5.0.2 allows local attackers to bypass permission checks, leading to an out-of-bounds read that causes information leakage.
OpenHarmony Local Denial-of-Service Vulnerability via NULL Pointer Dereference
A denial-of-service vulnerability has been identified in OpenHarmony versions through 5.0.2. This issue allows a local attacker to cause a system crash or unresponsiveness by exploiting a NULL pointer dereference.
OpenHarmony Local Denial-of-Service Vulnerability via Out-of-Bounds Read
A denial-of-service vulnerability has been identified in OpenHarmony versions through 5.0.2. This issue allows a local attacker to cause a denial-of-service condition by exploiting an out-of-bounds read.
OpenHarmony Arbitrary Code Execution Vulnerability in Pre-installed Apps via NULL Pointer Dereference
A vulnerability in OpenHarmony versions through 5.0.2 allows local attackers to execute arbitrary code in pre-installed applications. This issue arises from a NULL pointer dereference and can only be exploited in certain restricted scenarios.
OpenHarmony Local Arbitrary Code Execution Vulnerability in Pre-Installed Apps
A use-after-free vulnerability allowing local attackers to execute arbitrary code in pre-installed applications has been identified in OpenHarmony versions through 5.0.2. This vulnerability can only be exploited in certain restricted scenarios.
OpenHarmony Local Arbitrary Code Execution Vulnerability in Pre-Installed Apps
A use-after-free vulnerability allowing local attackers to execute arbitrary code in pre-installed applications has been identified in OpenHarmony versions through 5.0.2. This issue can only be exploited under certain restricted conditions.
OpenHarmony Local Arbitrary Code Execution Vulnerability in Pre-Installed Apps
A use-after-free vulnerability allowing local attackers to execute arbitrary code in pre-installed applications has been identified in OpenHarmony versions through 5.0.2. This issue can only be exploited under certain restricted conditions.
OpenHarmony Out-of-Bounds Read Vulnerability Allowing Information Leak
A vulnerability in OpenHarmony versions through 5.0.2 allows local attackers to cause an information leak by exploiting an out-of-bounds read. This flaw could potentially be used to access sensitive information that should not be available.
OpenHarmony Integer Overflow Vulnerability in Pre-Installed Apps Allowing Arbitrary Code Execution
A vulnerability in OpenHarmony versions through 5.0.2 allows local attackers to execute arbitrary code in pre-installed applications due to the presence of an integer overflow. This issue can only be exploited under certain restricted conditions.
OpenHarmony Out-of-Bounds Read Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in OpenHarmony versions through 5.0.2. This issue allows a local attacker to cause a denial-of-service condition by exploiting an out-of-bounds read.
OpenHarmony Local Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in OpenHarmony versions through 5.0.2. This issue allows local attackers to cause a denial-of-service condition by exploiting a flaw related to improper memory management, which leads to a failure to release memory resources.
Codezips Online Shopping Website SQL Injection Vulnerability in cart_add.php
A critical SQL injection vulnerability has been identified in Codezips Online Shopping Website version 1.0. The issue arises in the cart_add.php file, where insufficient validation of the 'id' parameter allows attackers to inject malicious SQL queries. This vulnerability can be exploited remotely, leading to unauthorized database access, data manipulation, and potential leakage of sensitive information.
PHPGurukul Student Record System SQL Injection Vulnerability in Password Recovery Feature
A critical SQL injection vulnerability has been identified in the PHPGurukul Student Record System version 3.2. The issue resides in the password recovery feature, specifically within the 'password-recovery.php' file. The vulnerability allows remote attackers to inject malicious SQL queries through the 'emailid' parameter, exploiting inadequate input validation. This injection could lead to unauthorized database access, data manipulation, and exposure of sensitive information.
PHPGurukul Restaurant Table Booking System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in the PHPGurukul Restaurant Table Booking System version 1.0. The issue resides in the file '/admin/check_availability.php', where the 'username' parameter is manipulated, allowing attackers to inject malicious SQL queries. This vulnerability can be exploited remotely, leading to unauthorized database access, data manipulation, and potential system control.
PHPGurukul Restaurant Table Booking System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in the PHPGurukul Restaurant Table Booking System version 1.0. The issue resides in the '/add-table.php' file, where the 'tableno' parameter is manipulated, allowing attackers to inject malicious SQL queries. This vulnerability can be exploited remotely, leading to unauthorized database access, data manipulation, and potential system control.
Animation Addons for Elementor Pro Missing Authorization Vulnerability Allows Arbitrary Plugin Installation
A vulnerability exists in the Animation Addons for Elementor Pro plugin for WordPress, in all versions through 1.6. The issue arises from a lack of proper capability checks in the install_elementor_plugin_handler() function, allowing authenticated attackers with Subscriber-level access or higher to install and activate arbitrary plugins. This could be exploited to further compromise a site, particularly when Elementor is not active on a vulnerable installation.
teachPress SQL Injection Vulnerability in WordPress Plugin
A SQL injection vulnerability has been identified in the teachPress WordPress plugin, affecting all versions through 9.0.7. The issue arises in the 'tpsearch' shortcode, where the 'order' parameter is not properly escaped, allowing authenticated attackers with Contributor-level access or higher to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive database information.
