CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Feb 10, 2025

SourceCodester Employee Management System Default Credentials Vulnerability

A critical vulnerability exists in SourceCodester Employee Management System version 1.0, specifically within the login functionality of index.php. The issue arises from the use of default credentials, allowing remote authentication bypass. Exploitation involves manipulating the username and password fields to gain unauthorized access.

3.9
Feb 10, 2025

Apache Netty Denial-of-Service Vulnerability in Windows Applications

A denial-of-service vulnerability has been identified in Apache Netty, an asynchronous, event-driven network application framework, in versions prior to and including 4.1.118.Final. When running on a Windows application, Netty improperly reads the environment file, leading to a crash if an attacker creates a large file that fills the application's buffer. This issue arises because the initial fix for a similar vulnerability, CVE-2024-47535, was incomplete; it failed to account for null bytes in the input limit. The vulnerability can be exploited by creating a file filled with null bytes, which Netty's input stream handling will mismanage, causing the application to crash.

2.5
Feb 10, 2025

ZOO-Project Web Processing Service EchoProcess Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the ZOO-Project Web Processing Service (WPS) Server, specifically within the EchoProcess service, in versions prior to the commit 7a5ae1a. This vulnerability arises because the EchoProcess service improperly sanitizes user input when processing complex data, such as XML, JSON, and SVG, allowing malicious JavaScript to be executed in the context of the victim's browser. The issue is particularly concerning as it involves a service designed to reflect user input, creating a reliable vector for XSS attacks, especially when SVG content is handled and returned with the image/svg+xml MIME type.

3.4
Feb 10, 2025

ZOO-Project Web Processing Service Reflective Cross-Site Scripting Vulnerability

A reflected Cross-Site Scripting vulnerability has been identified in the ZOO-Project Web Processing Service (WPS) publish.py CGI script, affecting versions prior to 7a5ae1a. The vulnerability arises because the script reflects user input from the 'jobid' parameter in the HTTP response without adequate HTML encoding or sanitization. This flaw allows attackers to execute arbitrary JavaScript in the context of the victim's browser. The issue is exacerbated by the fact that this endpoint is accessible from the main WPS interface, potentially facilitating phishing attacks against WPS users.

2.8
Feb 10, 2025

Apache Netty SslHandler Packet Validation Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability has been identified in Apache Netty, specifically in the SslHandler component, within versions 4.1.91.Final through 4.1.117.Final. The issue arises because SslHandler fails to properly validate certain crafted packets, particularly when using the native SSLEngine, which can result in a native crash.

7.6
Feb 10, 2025

CampCodes School Management Software Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in CampCodes School Management Software version 1.0. The issue arises from an unknown functionality in the file '/academic-calendar', allowing remote attackers to inject malicious scripts. This vulnerability has been publicly disclosed and could potentially be exploited.

2.9
Feb 10, 2025

ESAFENET CDG SQL Injection Vulnerability in addPolicyToSafetyGroup.jsp

A critical SQL injection vulnerability has been identified in ESAFENET CDG version 5.6.3.154.205_20250114. The issue arises in the file addPolicyToSafetyGroup.jsp, where an unknown function improperly handles the safetyGroupId argument. This vulnerability can be exploited remotely, allowing attackers to manipulate the argument and execute SQL injection attacks.

2.5
Feb 10, 2025

Allims Lab Online SQL Injection Vulnerability in Password Recovery Model Processing

A critical SQL injection vulnerability has been identified in Allims Lab Online versions prior to 20250201. The issue arises in the file 'model_recuperar_senha.php', where improper handling of the 'recuperacao' argument allows for SQL injection. This vulnerability can be exploited remotely.

1.7
Feb 10, 2025

Pix Software Vivaz SQL Injection Vulnerability in Login Servlet

A critical SQL injection vulnerability has been identified in Pix Software Vivaz version 6.0.10. The issue arises in the login servlet, specifically within the code that handles the 'usuario' argument. This vulnerability can be exploited remotely, allowing attackers to manipulate the input and execute arbitrary SQL commands. The exploit has been publicly disclosed, and although the vendor was notified, there has been no response.

2.5
Feb 10, 2025

MicroDicom DICOM Viewer Improper Certificate Validation Vulnerability Allowing Machine-in-the-Middle Attacks

A vulnerability exists in MicroDicom DICOM Viewer version 2024.03 due to improper validation of the update server's certificate. This flaw could enable attackers in a privileged network position to intercept and alter network traffic, executing a machine-in-the-middle (MITM) attack. Such an attack would allow the modification of the server's response to the user, potentially delivering a malicious update.

1.3
Feb 10, 2025

Wazuh Remote Code Execution Vulnerability via Unsafe Deserialization

A remote code execution vulnerability has been identified in Wazuh servers, affecting versions 4.4.0 prior to 4.9.1. The issue arises from an unsafe deserialization of DistributedAPI parameters, which are serialized as JSON and deserialized using the 'as_wazuh_object' method. An attacker can inject an unsanitized dictionary into DAPI request or response, allowing them to forge an unhandled exception that evaluates arbitrary Python code. This vulnerability can be exploited by anyone with API access, or in some cases, by a compromised agent.

6.0
Feb 10, 2025

Webkul QloApps Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in Webkul QloApps version 1.6.1. This issue occurs on the '/stores' page within the 'Your Location' search field, where unsanitized user input is directly reflected in the page response. This vulnerability allows remote attackers to execute arbitrary JavaScript in the context of the user's browser, potentially leading to data theft, phishing attacks, or session hijacking.

4.3
Feb 10, 2025

xxyopen Novel SQL Injection Vulnerability in Book Search API

A critical SQL injection vulnerability has been identified in xxyopen Novel versions through 3.4.1. The issue arises in the Book Search API, specifically within the 'sort' parameter, allowing for remote exploitation. The vulnerability is rooted in the application's trust in user input, which is improperly sanitized before being used in SQL queries. This flaw could potentially be leveraged to extract database information or, if the SQL database is misconfigured, execute arbitrary code via user-defined functions.

3.2
Feb 10, 2025

Stock-Forecaster SQL Injection Vulnerability

A SQL injection vulnerability has been identified in Stock-Forecaster versions through 01-04-2020. The issue arises in the portfolio() endpoint, where an attacker can send a specially crafted 'stock-symbol' parameter to execute arbitrary SQL commands. This exploitation could lead to unauthorized access to user data or manipulation of the application's behavior.

2.8
Feb 10, 2025

Perfood Couch-Auth Host Header Injection Vulnerability Allowing Server-Side Template Injection

A host header injection vulnerability has been identified in the Perfood Couch-Auth NPM package, specifically in versions through 0.21.2. This vulnerability allows for server-side template injection (SSTI) by sending a specially crafted host header in the email change confirmation request. Exploiting this vulnerability could enable an attacker to execute limited commands or leak server-side information.

1.7
Feb 10, 2025

Apple iOS and iPadOS USB Restricted Mode Vulnerability Allowing Bypassing on Locked Devices

A vulnerability has been identified in Apple iOS and iPadOS that allows a physical attack to disable USB Restricted Mode on locked devices. This issue arises from an authorization flaw that has been addressed with improved state management. The vulnerability is present in iOS 18.3.1, iPadOS 18.3.1, and iPadOS 17.7.5. Apple is aware of reports that this vulnerability may have been exploited in a highly sophisticated attack targeting specific individuals.

6.1
Feb 10, 2025

GNU Binutils Memory Corruption Vulnerability in Versions 2.43 and 2.44

A memory corruption vulnerability has been identified in GNU Binutils versions 2.43 and 2.44. The issue arises in the 'bfd_set_format' function within 'format.c', and can be exploited remotely, although the attack's complexity is considered high. Successful exploitation leads to a denial-of-service condition.

5.9
Feb 10, 2025

Modelscope Agentscope Local File Inclusion Vulnerability in Load-Workflow Endpoint

A local file inclusion (LFI) vulnerability has been identified in the Modelscope Agentscope application, specifically in version 0.0.4. The issue arises in the '/load-workflow' endpoint, where improper sanitization of user input allows attackers to manipulate the filename parameter and read arbitrary files from the server. This vulnerability can be exploited to access sensitive files, such as API keys, by leveraging the os.path.join function to navigate outside the intended directory.

3.9
Feb 10, 2025

Apple WebKit Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in the WebKit component of multiple Apple operating systems, including iOS 17.4, iPadOS 17.4, Safari 17.4, tvOS 17.4, watchOS 10.4, visionOS 1.1, and macOS Sonoma 14.4. This vulnerability arises from improper memory handling, which can be exploited by processing maliciously crafted web content, leading to unexpected application termination or resource exhaustion.

4.9
Feb 10, 2025

Tenda W18E Sensitive Information Disclosure Vulnerability

A vulnerability allowing sensitive information disclosure has been identified in the Tenda W18E router, specifically in version V16.01.0.8(1625). The issue resides in the web management portal, where an unauthenticated remote attacker can retrieve confidential configuration details. This includes the WiFi SSID, WiFi password, and base64-encoded administrator credentials. The vulnerability is exploited by sending a specially crafted HTTP POST request to the 'getQuickCfgWifiAndLogin' function, which bypasses authentication checks.

4.2
Feb 10, 2025

Tenda W18E Hardcoded Credentials Vulnerability Allowing Root Access via Telnet

A vulnerability exists in the Tenda W18E router, specifically in version V16.01.0.8(1625), due to hardcoded credentials that enable unauthenticated remote attackers to gain root access to the device through the telnet service.

3.9
Feb 10, 2025

Tenda W18E Stack Overflow Vulnerability in Web Management Portal Allowing Denial-of-Service and Potential Arbitrary Code Execution

A stack overflow vulnerability has been identified in the Tenda W18E router, specifically in version V16.01.0.8(1625). This vulnerability resides within the web management portal, where improper input validation in the delFacebookPic function allows authenticated remote attackers to cause a denial-of-service condition or potentially execute arbitrary code.

3.1
Feb 10, 2025

Tenda W18E Authentication Bypass Vulnerability in Web Management Portal

An authentication bypass vulnerability has been identified in the Tenda W18E router, specifically in version 16.01.0.8(1625). This vulnerability allows unauthorized remote attackers to gain administrative access by sending specially crafted HTTP requests to the web management portal.

3.9
Feb 10, 2025

Tenda W18E Default Credentials Vulnerability Allowing Unauthenticated Access to Web Management Portal

A vulnerability exists in the Tenda W18E router, specifically in version V16.01.0.8(1625), due to default credentials that allow unauthenticated remote attackers to access the web management portal. The default rzadmin account, which has administrative privileges, can be used to gain access.

3.9
Feb 10, 2025

Tenda W18E Incorrect Access Control Vulnerability Allowing Unauthorized WiFi and Admin Credential Changes

An incorrect access control vulnerability has been identified in the Tenda W18E router, specifically in version V16.01.0.8(1625). The issue allows attackers to send specially crafted HTTP POST requests to the setQuickCfgWifiAndLogin function. This exploitation can lead to unauthorized modifications of WiFi configuration settings and administrative credentials.

3.9
Feb 10, 2025

Tenda W18E Buffer Overflow Vulnerability in Web Management Portal

A buffer overflow vulnerability has been identified in the Tenda W18E router, specifically in version V16.01.0.8(1625). This vulnerability can be exploited by an attacker with access to the web management portal, who sends specially crafted data to the delWewifiPic function.

3.0
Feb 10, 2025

Tenda W18E Incorrect Access Control Vulnerability Allowing Unauthorized Password Changes

An incorrect access control vulnerability has been identified in the Tenda W18E router, specifically in version 16.01.0.8(1625). This vulnerability allows an unauthenticated remote attacker to change the administrator password through the web management portal. The issue arises by sending a specially crafted HTTP POST request to the setLoginPassword function, effectively bypassing the authentication mechanism.

4.3
Feb 10, 2025

Tenda W18E Hardcoded Credentials Vulnerability Allowing Unauthenticated Access to Web Management Portal

A vulnerability exists in the Tenda W18E router, specifically in version V16.01.0.8(1625), due to hardcoded credentials that allow unauthenticated remote attackers to access the web management portal. This is achieved by using a default guest account that has administrative privileges.

3.9
Feb 10, 2025

OPC Foundation .NET Standard Stack Authentication Bypass Vulnerability via HTTPS Endpoints

An authentication bypass vulnerability has been identified in the OPC UA .NET Standard Stack, affecting versions prior to 1.5.374.158. This vulnerability allows unauthorized attackers to bypass application authentication when HTTPS endpoints are enabled and use a security policy other than None.

3.0
Feb 10, 2025

OPC Foundation .NET Standard Stack Authentication Bypass Vulnerability in OPC UA

An authentication bypass vulnerability has been identified in the OPC UA .NET Standard Stack, affecting versions prior to 1.5.374.158. When the deprecated Basic128Rsa15 security policy is enabled, an unauthorized attacker can exploit this vulnerability to bypass application authentication. Although Basic128Rsa15 is disabled by default, this vulnerability could be a concern for applications that have explicitly enabled it.

3.5
Feb 10, 2025

Apple WebKit Arbitrary Code Execution Vulnerability

A buffer overflow vulnerability in the WebKit component of multiple Apple operating systems, including iOS 17.4, iPadOS 17.4, tvOS 17.4, watchOS 10.4, visionOS 1.1, and macOS Sonoma 14.4, has been identified. This vulnerability allows for arbitrary code execution when processing web content. The issue arises from improper memory handling, which can be exploited by maliciously crafted web content.

5.1
Feb 10, 2025

Mintplex Anything-LLM Path Traversal Vulnerability Leading to Arbitrary File Write and Remote Code Execution

A path traversal vulnerability has been identified in Mintplex Labs' Anything-LLM, in versions prior to 1.3.1. This issue arises from improper handling of non-ASCII filenames by the Multer library, allowing attackers with manager or admin roles to write files to arbitrary locations on the server. The vulnerability can be exploited by crafting a filename that includes '../' sequences, which Multer fails to sanitize. This arbitrary file write capability can lead to remote code execution, as overwritten files could be executed by the server.

2.5
Feb 10, 2025

WP Foodbakery Plugin Unauthenticated Arbitrary File Upload Vulnerability

A vulnerability allowing arbitrary file uploads has been identified in the WP Foodbakery plugin for WordPress, in versions through and including 4.7. This issue arises from inadequate validation of file types in the 'upload_publisher_profile_image' function. As a result, unauthenticated attackers can upload arbitrary files to the server hosting the affected site, potentially leading to remote code execution.

2.7
Feb 10, 2025

WP Foodbakery Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WP Foodbakery plugin for WordPress, affecting versions through 4.8. The issue arises from inadequate input sanitization and output escaping of the 'search_type' parameter. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts into pages, which could be executed if a user is tricked into clicking a link.

2.0
Feb 10, 2025

Wandb OpenUI Unauthenticated File Upload Vulnerability Allowing S3 Bucket Abuse

A vulnerability in wandb/openui, specifically in the latest commit, allows unauthenticated users to upload and download files from an AWS S3 bucket via the '/v1/share/{id:str}' endpoint. This lack of authentication could lead to various security issues, including denial of service, stored cross-site scripting, and information disclosure. The vulnerability arises because any user can upload and overwrite files, potentially filling up the S3 bucket's storage, injecting harmful scripts, or accessing sensitive data.

2.6
Feb 10, 2025

Hickory DNS DNSSEC Validation Vulnerability Allowing Trust Mismanagement

A vulnerability in Hickory DNS, affecting versions 0.8.0 and prior to 0.24.3 and 0.25.0-alpha.5, mismanages trust in DNSSEC validation. The issue arises because the validation process treats entire sets of DNSKEY records as trusted once any single DNSKEY is verified. Consequently, if a zone's DNSKEY matches a trust anchor, all DNSKEYs in that zone are trusted to authenticate other records, potentially leading to incorrect validations. A similar issue exists with DS records, where an authenticated DS record for one DNSKEY can improperly extend trust to an unrelated DNSKEY in the same zone. This vulnerability impacts users relying on DNSSEC verification in the client library, stub resolver, or recursive resolver.

3.8
Feb 10, 2025

GNU Binutils Memory Leak Vulnerability in ld Component

A memory leak vulnerability has been identified in GNU Binutils version 2.43, specifically within the ld component's xstrdup function. This issue allows for a remote attack, although it requires user interaction from the victim. The vulnerability arises because the software does not properly manage and release allocated memory, leading to increased memory consumption over time. While the exploitation of this vulnerability is considered difficult, technical details and a public proof-of-concept exploit are available.

5.8
Feb 10, 2025

Cool-Admin-Java Stored Cross-Site Scripting Vulnerability in Parameter List Module

A stored cross-site scripting vulnerability has been identified in the Parameter List module of Cool-Admin-Java version 1.0. This vulnerability allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the 'internet pictures' field.

3.3
Feb 10, 2025

Cool-Admin-Java Arbitrary File Upload Vulnerability Allowing Remote Code Execution

A vulnerability allowing arbitrary file upload has been identified in Cool-Admin-Java version 1.0. This issue resides in the file upload component, specifically within the '/comm/upload' endpoint. Attackers can exploit this vulnerability by uploading a crafted file that is then executed on the server.

3.5
Feb 10, 2025

Timo Arbitrary File Upload Vulnerability Allowing Code Execution

An arbitrary file upload vulnerability has been identified in Timo version 2.0.3, specifically within the userPicture component. This vulnerability allows attackers to execute arbitrary code by uploading a crafted file.

2.2
Feb 10, 2025

OneBlog Template Injection Vulnerability in Version 2.3.6 Allowing Code Execution

A template injection vulnerability has been identified in OneBlog version 2.3.6, specifically within the template management section. This issue arises from the 'spring-boot-starter-freemarker' component, which lacks proper rule restrictions, enabling arbitrary code execution.

3.5
Feb 10, 2025

PHPGurukul Small CRM Cross-Site Scripting Vulnerability in Profile Management

A cross-site scripting (XSS) vulnerability has been identified in PHPGurukul Small CRM version 3.0. The issue arises in the profile.php file, where a crafted payload can be injected into the name field, allowing for the execution of malicious scripts.

2.0
Feb 10, 2025

GNU Binutils Memory Leak Vulnerability in ld Component

A memory leak vulnerability has been identified in GNU Binutils version 2.43. This issue arises in the ld component, specifically within the xmemdup function of xmemdup.c. The vulnerability allows for a remote memory leak, where the application fails to properly manage and release allocated memory, leading to increased memory consumption over time. Although the vulnerability can be exploited remotely, it requires user interaction and is considered to have a high attack complexity.

5.8
Feb 10, 2025

GNU Binutils Memory Leak Vulnerability in ld Component

A memory leak vulnerability has been identified in GNU Binutils version 2.43. This issue arises in the ld component, specifically within the bfd_malloc function of libbfd.c. The vulnerability allows for a remote memory leak, where the application fails to properly manage and release allocated memory, leading to increased memory consumption over time. Although the vulnerability is publicly known and has a proof-of-concept exploit available, its exploitation is considered difficult and requires user interaction.

5.8
Feb 10, 2025

Ruby Net::IMAP Denial-of-Service Vulnerability via Memory Exhaustion

A denial-of-service vulnerability has been identified in the Ruby library Net::IMAP, which implements Internet Message Access Protocol (IMAP) client functionality. This issue is present in versions 0.3.2 prior to 0.3.8, as well as in versions 0.4.0 prior to 0.4.19 and 0.5.0 prior to 0.5.6. The vulnerability arises in the response parser, where a malicious server can send highly compressed 'uid-set' data. This data is automatically processed by the client's receiver thread, expanding the ranges into arrays of integers without any size limitations. As a result, the vulnerability can lead to significant memory exhaustion on the client side.

4.4
Feb 10, 2025

OpenProject Stored Cross-Site Scripting Vulnerability in Group Management

A stored cross-site scripting vulnerability has been identified in OpenProject, an open-source web-based project management software, in versions prior to 15.2.1. The issue arises in the Group Management section, where user input is not properly sanitized before being displayed. Groups created with HTML script tags can execute scripts when rendered in a project.

3.0
Feb 10, 2025

OpenSC PAM-PKCS#11 Authentication Bypass Vulnerability

An authentication bypass vulnerability has been identified in the OpenSC PAM-PKCS#11 module, prior to version 0.6.13. This module allows X.509 certificate-based user login. When the 'cert_policy' is set to 'none' (the default), the module only verifies if a user can log into the token. This creates an opportunity for an attacker to craft a token using the user's public data, such as their certificate, and a PIN known to them. If the private key's signature is not required for authentication, the attacker can log in as the user with the forged token. This vulnerability affects all versions of PAM-PKCS#11 starting from 0.6.0, with the exception of 0.6.13, which includes the necessary fix.

2.5
Feb 10, 2025

OpenSC PAM-PKCS#11 Segmentation Fault Vulnerability in Versions Prior to 0.6.12

A segmentation fault vulnerability has been identified in the OpenSC PAM-PKCS#11 module, specifically in versions through 0.6.12. This issue arises when a user interrupts the PIN entry process by pressing Ctrl-C or Ctrl-D. The root cause is an attempt to clear an uninitialized password buffer, which leads to a crash. This vulnerability can impact the availability of systems using this PAM module, as it may cause related daemons to crash. As of now, no patch is available for this issue.

2.9
Feb 10, 2025

Linux Kernel Zswap Resource Management Vulnerability During CPU Hot Unplug

A use-after-free vulnerability has been identified in the Linux kernel's zswap feature, specifically in the compression and decompression functions. This issue arises because the per-CPU context for asynchronous compression operations is not properly synchronized during CPU hot unplug events. When a CPU is hot unplugged, resources associated with the compression context can be freed while still in use, leading to a use-after-free condition. This vulnerability was introduced when zswap switched to the crypto_acomp API for hardware acceleration, allowing operations to migrate between CPUs without proper synchronization. The vulnerability affects several versions of the Linux kernel.

5.2
Feb 10, 2025

Linux Kernel Privilege Escalation Vulnerability in ETS Qdisc

A vulnerability allowing local privilege escalation has been identified in the Linux kernel's Ethernet Traffic Scheduling (ETS) class handling. The issue arises in the 'net/sched/sch_ets.c' file, where the 'ets_class_from_arg()' function can index an out-of-bounds class when given a class ID of zero. This out-of-bounds access, detected by the Undefined Behavior Sanitizer, could potentially be exploited to escalate privileges.

5.7