CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
lunasvg Segmentation Fault Vulnerability in Version 3.0.0
A segmentation fault vulnerability has been identified in lunasvg version 3.0.0. This issue arises in the gray_record_cell component, where improper handling of memory access leads to a crash. The vulnerability can be reproduced using the 'svg2png' command-line tool included with lunasvg, which is available on GitHub.
lunasvg Segmentation Fault Vulnerability in Version 3.0.0
A segmentation fault vulnerability has been identified in lunasvg version 3.0.0. This issue arises in the 'composition_source_over' component, where improper handling of memory access leads to a crash. The vulnerability can be reproduced using the 'svg2png' tool included with lunasvg, by processing a specially crafted SVG file that triggers the segmentation violation.
lunasvg Memory Corruption Vulnerability in Version 3.0.0
A vulnerability has been identified in lunasvg version 3.0.0, related to improper memory allocation handling in the 'plutovg_surface_create' component. This flaw can lead to a memory corruption issue, specifically a segmentation fault, by allowing excessively large allocation requests that exceed the maximum supported size. The vulnerability can be reproduced using the 'svg2png' tool included with lunasvg, which is available on GitHub.
lunasvg Segmentation Fault Vulnerability in Version 3.0.0
A segmentation fault vulnerability has been identified in lunasvg version 3.0.0. This issue arises from a null pointer dereference in the 'plutovg_path_add_path' function, leading to a read memory access violation. The vulnerability can be triggered by specific SVG files that cause the application to attempt to read from an invalid memory address, resulting in a crash.
lunasvg Segmentation Fault Vulnerability in Component plutovg_blend
A segmentation fault vulnerability has been identified in lunasvg version 3.0.0. The issue arises in the component plutovg_blend, where improper handling of memory access leads to a crash. This vulnerability can be triggered by specific SVG input that causes the application to attempt to read from an invalid memory address, resulting in a segmentation violation.
lunasvg Segmentation Fault Vulnerability in Version 3.0.0
A segmentation fault vulnerability has been identified in lunasvg version 3.0.0. This issue arises in the 'blend_transformed_tiled_argb.isra.0' component, where improper handling of memory access leads to a crash. The vulnerability is triggered by a read memory access violation, specifically referencing an address in the zero page, which is not permissible.
HCL BigFix Patch Download Plug-ins Server-Side Request Forgery Vulnerability
A Server-Side Request Forgery (SSRF) vulnerability has been identified in HCL BigFix Patch Download Plug-ins. This vulnerability allows the application to download files from an internally hosted server on localhost. It affects BigFix Patch and Patching Support, site versions prior to 1177.
Avada Builder Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Avada Builder plugin for WordPress, affecting all versions through 3.11.11. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's shortcodes. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users view the affected pages.
Code Astro Internet Banking System Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in Code Astro Internet Banking System version 2.0.0. This vulnerability allows remote attackers to execute arbitrary JavaScript on the admin account page. The issue arises from inadequate validation of user requests, enabling attackers to manipulate admin users into executing harmful scripts. Exploitation could lead to unauthorized changes in account settings or the theft of sensitive user information.
Silverpeas Core Stored Cross-Site Scripting Vulnerability in My Subscriptions Functionality
A stored cross-site scripting vulnerability has been identified in Silverpeas Core versions 6.3.1 through 6.4.1. This vulnerability allows remote attackers to execute arbitrary JavaScript by injecting malicious payloads into the Name field of subscriptions. The issue arises in the My Subscriptions feature, specifically within the Categorization option. When an admin user views the affected subscription, the injected script can execute, potentially leading to session hijacking, data theft, or unauthorized actions.
Google Chrome V8 Out-of-Bounds Memory Access Vulnerability Allowing Heap Corruption
A high-severity out-of-bounds memory access vulnerability has been identified in the V8 JavaScript engine of Google Chrome. This issue affects Chrome versions prior to 132.0.6834.110 and has been linked to improper handling of function arguments, which can lead to memory corruption. The vulnerability can be exploited by a remote attacker through a crafted HTML page, potentially causing heap corruption that could be exploited.
Google Chrome V8 Object Corruption Vulnerability Allowing Heap Corruption Exploitation
A high-severity object corruption vulnerability has been identified in the V8 JavaScript engine used by Google Chrome. This issue affects Chrome versions prior to 132.0.6834.110. The vulnerability allows remote attackers to potentially exploit heap corruption by delivering a crafted HTML page.
D-Link DSL-3782 Buffer Overflow Vulnerability in Parental Control Interface
A buffer overflow vulnerability has been identified in the D-Link DSL-3782 router, specifically in version 1.01. The issue arises within the Parental Control section of the router's web interface.
Traffic Alert and Collision Avoidance System II Spoofing Vulnerability
A vulnerability exists in the Traffic Alert and Collision Avoidance System (TCAS) II) standard, specifically in versions 7.1 and prior. This vulnerability allows for the transmission of radio frequency signals with fake location data to aircraft, creating the illusion of non-existent aircraft on radar displays. Such spoofing can disrupt normal operations by triggering false Resolution Advisories, which are critical for maintaining safe distances between aircraft.
TCAS II Impersonation Vulnerability Leading to Denial-of-Service
A vulnerability exists in TCAS II systems with transponders compliant with MOPS prior to RTCA DO-181F. An attacker can impersonate a ground station and send a Comm-A Identity Request, which can lower the Sensitivity Level Control (SLC) and disable the Resolution Advisory (RA). This manipulation creates a denial-of-service condition by disrupting normal collision avoidance operations.
Cilium Hubble UI Cross-Origin Resource Sharing Misconfiguration Vulnerability
A vulnerability exists in Cilium Hubble UI deployments due to an insecure default 'Access-Control-Allow-Origin' header. This issue affects Cilium versions 1.14.0 through 1.14.7, 1.15.0 through 1.15.11, and 1.16.0 through 1.16.4. The misconfiguration could lead to unauthorized exposure of sensitive Kubernetes cluster data, including node names, IP addresses, and metadata about workloads and networking configurations. Exploitation requires a user to visit a malicious webpage.
Cloudflare WARP Improper Privilege Management Vulnerability on Windows Allowing File Manipulation
A vulnerability in Cloudflare WARP for Windows, prior to version 2024.12.492.0, involves improper privilege management that enables file manipulation. Users with low system privileges can create symlinks in the C:\ProgramData\Cloudflare\warp-diag-partials directory. When the 'Reset all settings' option is activated, the WARP service deletes the files linked by the symlinks. Since the WARP service runs with system privileges, this could result in the unintentional deletion of files owned by the System user.
Thermo Fisher Scientific Xcalibur and Foundation Local Privilege Escalation Vulnerability
A local privilege escalation vulnerability has been identified in Thermo Fisher Scientific Xcalibur versions prior to 4.7 SP1 and in Thermo Foundation Instrument Control Software (ICSW) versions prior to 3.1 SP10. This vulnerability arises from improper access control permissions on Windows systems, allowing unauthorized users to escalate privileges.
Jenkins Azure Service Fabric Plugin Missing Permission Check Vulnerability
A vulnerability exists in the Jenkins Azure Service Fabric Plugin in versions through 1.6, where a missing permission check allows attackers with Overall/Read permission to enumerate the IDs of Azure credentials stored in Jenkins. This vulnerability could be exploited to capture these credentials using another vulnerability.
Jenkins Azure Service Fabric Plugin Cross-Site Request Forgery Vulnerability
A cross-site request forgery (CSRF) vulnerability exists in Jenkins Azure Service Fabric Plugin versions through 1.6. This vulnerability allows attackers to connect to a Service Fabric URL using credentials IDs specified by the attacker, which could be obtained through other means. Additionally, the plugin does not perform proper permission checks in several HTTP endpoints, enabling credential ID enumeration of Azure credentials stored in Jenkins.
Jenkins Folder-based Authorization Strategy Plugin Incorrect Permission Grant Vulnerability
A vulnerability exists in the Jenkins Folder-based Authorization Strategy Plugin in versions through 217.vd5b_18537403e. The plugin fails to properly verify that granted permissions are enabled, which could allow users who previously had certain permissions, such as Overall/Manage, to access functionalities they are no longer entitled to.
Jenkins Eiffel Broadcaster Plugin Cache Confusion Vulnerability Allowing Credential Misuse
A vulnerability exists in the Jenkins Eiffel Broadcaster Plugin versions 2.8.0 to 2.10.2, where the plugin uses the credential ID as the cache key during signing operations. This flaw enables attackers to create a credential with the same ID as a legitimate one in a different credentials store, and use it to sign events published to RabbitMQ, impersonating the legitimate credentials. This vulnerability requires the plugin's signing feature to be enabled, which is not the default.
Jenkins OpenId Connect Authentication Plugin Case Sensitivity Vulnerability Allowing Unauthorized Access
A vulnerability exists in the Jenkins OpenId Connect Authentication Plugin in versions through 4.452.v2849b_d3945fa_ and earlier, except for 4.438.440.v3f5f201de5dc. The plugin incorrectly handles username case sensitivity, treating usernames as case-insensitive. This flaw allows attackers on Jenkins instances with a case-sensitive OpenID Connect provider to log in as any user by using a username that varies only in case. Exploitation of this vulnerability could lead to unauthorized administrative access on Jenkins.
Jenkins Bitbucket Server Integration Plugin Cross-Site Request Forgery Vulnerability
A cross-site request forgery (CSRF) vulnerability has been identified in the Jenkins Bitbucket Server Integration Plugin, versions 2.1.0 through 4.1.3. This vulnerability allows attackers to craft URLs that bypass CSRF protection for any target URL within Jenkins. The issue arises because the plugin's implementation of CSRF protection is overly permissive, enabling the creation of links that can manipulate Jenkins actions without proper authorization.
Jenkins GitLab Plugin Incorrect Permission Check Vulnerability Allowing Credential ID Enumeration
A vulnerability exists in Jenkins GitLab Plugin versions through 1.9.6, where an incorrect permission check allows attackers with global Item/Configure permission to enumerate credential IDs of GitLab API token and Secret text credentials stored in Jenkins. This issue arises because the plugin fails to properly validate permissions in an HTTP endpoint, enabling the enumeration of credential IDs that could be exploited to capture the credentials using another vulnerability.
Cilium Denial-of-Service Vulnerability via Crafted DNS Responses
A denial-of-service vulnerability has been identified in Cilium, a networking and security solution for Kubernetes, affecting versions 1.14.0 prior to 1.14.18, 1.15.0 prior to 1.15.12, and 1.16.0 prior to 1.16.5. The vulnerability arises when Cilium is configured to proxy DNS traffic. In this scenario, an attacker can disrupt Cilium agents by sending manipulated DNS responses to workloads from outside the cluster. This disruption can cause Cilium agents to crash, although for traffic that is allowed without DNS-based policy, the dataplane will continue to function as configured at the time of the attack. Workloads with DNS-based policy may experience disrupted connections that rely on DNS resolution, while existing connections and new ones that do not depend on DNS can continue to operate. Additionally, any configuration changes affecting the impacted agent will not be applied until the agent restarts.
Cisco BroadWorks SIP Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the SIP processing subsystem of Cisco BroadWorks. This issue allows an unauthenticated, remote attacker to disrupt the handling of incoming SIP requests, causing a DoS condition. The vulnerability arises from improper memory management for certain SIP requests. An attacker could exploit this by sending a large volume of SIP requests to the affected system, exhausting the memory allocated to Cisco BroadWorks Network Servers that manage SIP traffic. When the memory runs out, these servers can no longer process incoming requests, leading to a DoS condition that requires manual intervention to resolve.
Cisco Meeting Management REST API Privilege Escalation Vulnerability
A vulnerability exists in the REST API of Cisco Meeting Management, allowing remote, authenticated attackers with low privileges to elevate their privileges to administrator level on affected devices. This issue arises because proper authorization is not enforced for REST API users. Exploitation involves sending API requests to a specific endpoint, which could result in gaining administrator control over edge nodes managed by Cisco Meeting Management.
ClamAV OLE2 Decryption Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in ClamAV's Object Linking and Embedding 2 (OLE2) decryption routine. This issue allows an unauthenticated, remote attacker to cause a DoS condition on affected devices. The vulnerability arises from an integer underflow in a bounds check, leading to a heap buffer overflow read. Exploitation involves submitting a crafted file with OLE2 content for ClamAV to scan. A successful exploit can crash the ClamAV scanning process, disrupting ongoing operations.
IBM Robotic Process Automation for Cloud Pak Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been identified in IBM Robotic Process Automation for Cloud Pak, affecting versions 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19. This vulnerability allows an authenticated user to inject arbitrary JavaScript into the Web UI, potentially altering functionality and leading to credential disclosure within a trusted session.
Leetoo Toocheke Companion Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Leetoo Toocheke Companion WordPress plugin, affecting versions through 1.166. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Muzaara Google Ads Report Plugin PHP Object Injection Vulnerability
A deserialization vulnerability allowing PHP object injection has been identified in the Muzaara Google Ads Report plugin for WordPress, affecting versions through 3.1. This vulnerability arises from the deserialization of untrusted data, which could lead to object injection exploits.
WordPress Blue Wrench Video Widget Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Blue Wrench Video Widget for WordPress, affecting versions through 2.1.0. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.
Routinator Denial-of-Service Vulnerability Due to Unchecked File Name Characters in RPKI Manifests
A denial-of-service vulnerability has been identified in Routinator versions prior to and including 0.14.0. The issue arises when non-ASCII characters in file names within an RPKI manifest are not properly validated. This oversight leads to a crash in Routinator, as later code segments assume the file names have been correctly checked and panic upon encountering illegal characters.
Umbraco CMS Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in Umbraco CMS versions through 14.3.1. This vulnerability allows authenticated users with access to the CMS to execute arbitrary web scripts or HTML by injecting a crafted payload. The issue arises from a lack of server-side input sanitization in the rich text editing feature, which uses TinyMCE as the editor. While the client-side editor attempts to sanitize input, the server-side API does not, leaving a gap that can be exploited by sending HTTP requests to update documents with malicious content.
GRAU DATA Blocky Client-Side Enforcement of Server-Side Security Vulnerability Allowing Privilege Escalation
A client-side enforcement of server-side security vulnerability has been identified in GRAU DATA Blocky versions prior to 3.1. This vulnerability allows an attacker with Windows administrative or debugging privileges to modify a binary either in memory or on disk. By doing so, the attacker can bypass the password login requirement, gaining unrestricted access to all program functions.
GRAU DATA Blocky Password Storage Vulnerability Allowing Local User Impersonation
A vulnerability exists in GRAU DATA Blocky versions 2.6.x and 2.7.x on Windows, where passwords are stored encrypted instead of hashed. During login, the encrypted password is decrypted and compared to the user's input. This flaw allows an attacker with Windows admin or debugging rights to steal the user's Blocky password and impersonate them locally.
IBM Sterling B2B Integrator Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in IBM Sterling B2B Integrator Standard Edition versions 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2. This vulnerability allows an attacker on the local network to execute arbitrary code on the system, due to the deserialization of untrusted data.
Open5GS Reachable Assertion Vulnerability in NGAP Packet Handling Allowing Denial-of-Service
A reachable assertion vulnerability has been identified in the 'nas_eps_send_emm_to_esm' function of Open5GS versions through 2.6.4. This vulnerability allows attackers to cause a denial-of-service (DoS) condition by sending a crafted NGAP packet that triggers the assertion. The vulnerability arises from improper handling of the packet, specifically in the processing of the 'InitialUEMessage' message, where a malformed mobile identity leads to a null pointer dereference.
Arm Cortex-A72, Cortex-A73, and Cortex-A75 Spectre-BSE Vulnerability Allowing Weak Control Over Branch History
A vulnerability known as Spectre-BSE (Branch Status Eviction) has been identified in Arm Cortex-A72 (revisions prior to r1p0), Cortex-A73, and Cortex-A75. This issue may allow an adversary to gain a weak form of control over the victim's branch history, despite existing protections. The vulnerability arises because the adversary must first find an exploitable leak gadget, have control over the relevant registers, and maintain an unchanged manipulated branch predictor state between the priming and exploitation phases.
Synnefo Internet Management Software SQL Injection Vulnerability Allowing Unauthorized Database Access and OS Command Execution
A SQL injection vulnerability has been identified in Synnefo Internet Management Software (IMS) versions through 2023. The issue arises from inadequate input validation in a specific API endpoint, which allows attackers to manipulate SQL queries by sending crafted input. Exploitation of this vulnerability could result in unauthorized access to database records with administrative privileges, potentially leading to further privilege escalation and the execution of arbitrary operating system commands.
PrestaShop ps_contactinfo Module Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in the PrestaShop ps_contactinfo module, specifically in versions through 3.3.2. This vulnerability arises from the module's use of the 'nofilter' tag in templates, which can be exploited to execute stored XSS payloads. However, it is important to note that this issue cannot be triggered in a fresh installation of PrestaShop; it only affects shops that have been compromised by certain third-party modules, such as those vulnerable to SQL injection. In such cases, ps_contactinfo may inadvertently execute a stored XSS in formatted objects.
A Gateway for Pasargad Bank on WooCommerce Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress plugin 'A Gateway for Pasargad Bank on WooCommerce', affecting versions through 2.5.2. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.
Good Old Gallery Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Good Old Gallery WordPress plugin, affecting versions through 2.1.2. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Innovative Solutions User Files Plugin Arbitrary File Upload Vulnerability
A vulnerability allowing unrestricted upload of files with dangerous types has been identified in the Innovative Solutions User Files WordPress plugin, affecting versions through 2.4.2. This vulnerability could be exploited to upload a web shell to the server, potentially leading to unauthorized access or control over the website.
WordPress Improved Sale Badges Local File Inclusion Vulnerability
A local file inclusion vulnerability has been identified in the WordPress plugin Improved Sale Badges – Free Version, affecting versions through 1.0.1. This vulnerability arises from improper control of filenames in include or require statements, allowing PHP remote file inclusion.
WordPress Background Animation Blocks Local File Inclusion Vulnerability
A local file inclusion vulnerability has been identified in the WordPress Background Animation Blocks plugin, affecting versions through 2.1.5. This issue arises from improper control of filenames in include or require statements, allowing PHP remote file inclusion that could be exploited for local file inclusion instead.
WOOEXIM WordPress Plugin PHP Object Injection Vulnerability
A deserialization vulnerability allowing object injection has been identified in the WOOEXIM WordPress plugin, affecting versions through 5.0.0. This vulnerability could lead to various injection attacks, including code injection, SQL injection, and path traversal, among other issues, if a suitable property-oriented programming (POP) chain is available.
NgocCode WP Load Gallery Unrestricted File Upload Vulnerability Allowing Web Shell Upload
A vulnerability allowing unrestricted file upload has been identified in the NgocCode WP Load Gallery plugin, versions through 2.1.6. This vulnerability could be exploited to upload a web shell to the server, potentially leading to unauthorized access or control over the website.
NotFound Image Gallery Box by CRUDLab Local File Inclusion Vulnerability
A local file inclusion vulnerability has been identified in the NotFound Image Gallery Box by CRUDLab, affecting versions through 1.0.3. This vulnerability arises from improper control of filenames in include or require statements, allowing PHP remote file inclusion that could be exploited for local file inclusion instead.
