CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Vim Memory Corruption Vulnerability via Inaccessible Log File Path
A memory corruption vulnerability has been identified in Vim versions through 9.1.1096. The issue arises in the file 'src/main.c' when the '--log' option is used with a path that does not exist or is inaccessible. This vulnerability can be exploited locally, leading to a crash of the Vim application. The problem has been acknowledged in a public GitHub discussion.
CrowdStrike Falcon Products Man-in-the-Middle Vulnerability via Improper TLS Certificate Validation
A validation logic error has been identified in CrowdStrike Falcon Sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor. This error allows the TLS connection routine to improperly process server certificate validation, potentially enabling an attacker to conduct a man-in-the-middle (MiTM) attack. The vulnerability affects all versions prior to 7.21, excluding hotfix builds for supported sensor versions. Windows and Mac sensors are not affected.
HashiCorp Nomad Event Stream Namespace ACL Policy Bypass Vulnerability
A vulnerability exists in both Nomad Community and Nomad Enterprise event streams that are configured with a wildcard namespace. This vulnerability allows for an ACL policy bypass, enabling unauthorized reads from other namespaces. The issue arises from a flaw in how ACL wildcards are validated, creating a discrepancy that can be exploited when using the event stream endpoint with a wildcard namespace.
D-Link DIR-853 Stack-Based Buffer Overflow Vulnerability in IPv6 PPPoE Settings Module
A stack-based buffer overflow vulnerability has been identified in the D-Link DIR-853 A1 router running firmware 1.20B07. The issue arises in the SetIPv6PppoeSettings module, specifically through the IPv6_PppoePassword parameter.
Koa Denial-of-Service Vulnerability via Inefficient Header Parsing
A denial-of-service vulnerability has been identified in Koa, a Node.js middleware framework. The issue arises from the use of a problematic regular expression to parse the 'X-Forwarded-Proto' and 'X-Forwarded-Host' HTTP headers. This vulnerability can be exploited to cause memory exhaustion, leading to a denial-of-service condition. The affected versions of Koa are prior to 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3.
Microsoft Go Crypto Backend for Windows Memory Leak Vulnerability
A memory leak vulnerability has been identified in the Microsoft Go crypto backend for Windows, specifically in versions through 1.23.6-1 and 1.22.12-1. The issue arises because calls to 'cng.TLS1PRF' do not properly release the key handle, leading to a small but cumulative memory leak. This vulnerability has been patched in versions 1.23.6-2 and 1.22.12-2 of the Microsoft build of Go, as well as in the pseudoversion 0.0.0-20250211154640-f49c8e1379ea of the 'github.com/microsoft/go-crypto-winnative' Go package.
Mailcow: Dockerized Password Reset Link Manipulation Vulnerability Allowing Account Takeover
A vulnerability exists in mailcow: dockerized versions prior to 2025-01a, allowing attackers to exploit the password reset feature. By manipulating the Host HTTP header, an attacker can create a password reset link that directs to an attacker-controlled domain. If a user clicks this link, it could result in unauthorized account access. Mailcow version 2025-01a has addressed this vulnerability. As a temporary measure, users can disable the password reset feature by removing the 'Notification email sender' and 'Notification email subject' under System -> Configuration -> Options -> Password Settings.
PiHome Role-Based Access Control Vulnerability Allowing Unauthorized Admin Account Creation
A critical vulnerability exists in PiHome HVAC version 2.0, specifically within the role-based access control component. The issue is located in the '/user_accounts.php?uid' file, where the application fails to properly authorize users before allowing account creation. This flaw enables any authenticated user, regardless of their privilege level, to create new admin accounts. The vulnerability can be exploited remotely and has been publicly disclosed.
PiHome Cross-Site Scripting Vulnerability in index.php
A cross-site scripting (XSS) vulnerability has been identified in PiHome version 1.77. The issue arises in the file index.php, where user input is not properly sanitized before being outputted, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely by injecting a script payload into the URL, which could then be executed in the context of the user's browser, potentially leading to cookie theft if the appropriate cookie flags are not set.
Progress Telerik Reporting Absolute Path Vulnerability Allowing Information Disclosure
A vulnerability allowing information disclosure through absolute path traversal has been identified in Progress Telerik Reporting versions prior to 2025 Q1 (19.0.25.211). This issue affects the Windows desktop standalone Report Designer and can be exploited by a local threat actor.
D-Link DIR-853 A1 Stack-Based Buffer Overflow Vulnerability in WAN Settings Module
A stack-based buffer overflow vulnerability has been identified in the D-Link DIR-853 A1 router running firmware 1.20B07. The issue arises in the SetWanSettings module, where the Password parameter is improperly handled, leading to the potential for memory corruption.
D-Link DIR-853 A1 Stack-Based Buffer Overflow Vulnerability in Dynamic DNS Settings Module
A stack-based buffer overflow vulnerability has been identified in the D-Link DIR-853 A1 router running firmware 1.20B07. The issue arises in the SetDynamicDNSSettings module, where the Password parameter is improperly handled, leading to the potential for arbitrary code execution.
D-Link DIR-853 Command Injection Vulnerability in SetVirtualServerSettings Module
A command injection vulnerability has been identified in the D-Link DIR-853 A1 router running firmware 1.20B07. The issue arises in the SetVirtualServerSettings module, allowing for unauthorized command execution.
D-Link DIR-853 Stack-Based Buffer Overflow Vulnerability in Email Settings Module
A stack-based buffer overflow vulnerability has been identified in the D-Link DIR-853 A1 router running firmware 1.20B07. The issue arises in the SetSysEmailSettings module, specifically through the AccountPassword parameter.
Rack Log Injection Vulnerability in CommonLogger Component
A log injection vulnerability has been identified in the Rack web application interface for Ruby, specifically within the CommonLogger component. This issue affects Rack versions prior to 2.2.11, as well as versions 3.0.0 through 3.0.12 and 3.1.0 through 3.1.10. The vulnerability arises when a server allows usernames containing newline characters and whitespace to be logged. An attacker can exploit this by injecting a username with CRLF characters, disrupting the log format or introducing false entries, which could obscure genuine activity or inject harmful data into the logs.
Stroom Authentication Bypass Vulnerability with AWS ALB Integration
A vulnerability allowing authentication bypass has been identified in Stroom versions 7.2-beta.53 prior to 7.4.4, and 7.5-beta.1. This issue arises when the application is configured to use AWS Application Load Balancer (ALB) Authentication integration, but is accessible outside of the ALB. The vulnerability could also enable server-side request forgery (SSRF) attacks, potentially leading to code execution or privilege escalation via the AWS metadata URL.
Wazifa System SQL Injection Vulnerability in Control.php
A critical SQL injection vulnerability has been identified in Wazifa System version 1.0. The issue arises in the file '/controllers/control.php', where an unknown functionality allows for the manipulation of arguments, leading to SQL injection. This vulnerability can be exploited remotely.
Code-Projects Wazifa System Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Code-Projects Wazifa System version 1.0. The issue arises in the searchuser function within the search_results.php file, where improper handling of the firstname and lastname arguments allows for the injection of malicious scripts. This vulnerability can be exploited remotely.
Progress Telerik Document Processing Libraries Arbitrary File Export Vulnerability
A vulnerability exists in Progress Telerik Document Processing Libraries, in versions prior to 2025 Q1 (2025.1.205), that allows the contents of a file from an arbitrary path to be exported to RTF format. This issue is present in libraries using .NET Standard 2.0.
Progress Telerik Kendo UI for Vue Prototype Pollution Vulnerability Allowing Denial-of-Service or Command Injection
A prototype pollution vulnerability has been identified in Progress Telerik Kendo UI for Vue, affecting versions 2.4.0 prior to 6.0.1. This vulnerability allows an attacker to introduce or modify properties within the global prototype chain, potentially leading to denial-of-service conditions or command injection.
PHPGurukul Daily Expense Tracker SQL Injection Vulnerability in Expense Addition Feature
A SQL injection vulnerability has been identified in PHPGurukul Daily Expense Tracker System version 1.1. The issue arises in the 'add-expense.php' file, specifically through the 'dateexpense' parameter. This vulnerability allows attackers to manipulate SQL queries, potentially leading to unauthorized data access or modification.
PHPGurukul Daily Expense Tracker SQL Injection Vulnerability in add-expense.php
A SQL injection vulnerability has been identified in PHPGurukul Daily Expense Tracker System version 1.1. The issue occurs in the add-expense.php file, specifically through the costitem parameter.
Code-Projects Wazifa System Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Code-Projects Wazifa System version 1.0. The issue arises from an unknown processing in the file Profile.php, where the postcontent argument can be manipulated to inject malicious scripts. This vulnerability can be exploited remotely.
phjounin TFTPD64 Denial-of-Service Vulnerability in DNS Handler
A denial-of-service vulnerability has been identified in phjounin TFTPD64 version 4.64, the latest release. This issue arises in the DNS Handler component, where the application can be made to terminate unexpectedly. The vulnerability is triggered by sending a large DNS request, similar to the one provided in a proof-of-concept script available on GitHub. This exploitation needs to be performed within the local network, and the complexity of the attack is considered high.
Progress Telerik Report Server Unencrypted Communication Vulnerability Allowing Local Traffic Sniffing
A vulnerability exists in Progress Telerik Report Server versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation. This vulnerability allows for the transmission of non-sensitive information between the service agent process and the app host process over an unencrypted channel, which can be intercepted by local network traffic sniffing. The affected communication does not involve sensitive customer data but relates to commands exchanged between the background agent service and the main application. In default installations, both processes run on the same system and do not communicate over remote networks.
GitLab CE/EE Improper Authorization Vulnerability in Incident Management
A vulnerability exists in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2. This vulnerability allows users with the Planner role to improperly close and delete incidents, bypassing the established role-based access control (RBAC) requirements. Closing incidents should require at least a Reporter role, while deleting them necessitates an Owner role.
Progress Telerik UI for WinForms Path Traversal Vulnerability
A path traversal vulnerability has been identified in Progress Telerik UI for WinForms, affecting versions prior to 2025 Q1 (2025.1.211). The issue arises from improper limitations on target paths, which can allow an archive's contents to be decompressed into a restricted directory.
GitLab EE External Service Interaction Vulnerability Allowing Server-Side Request Forgery
A server-side request forgery (SSRF) vulnerability has been identified in GitLab EE versions 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. This vulnerability allows an attacker to send requests from the GitLab server to unintended external services. The issue arises when a workspace is created, and GitLab parses the .devfile.yaml file. During this process, an internal Golang binary makes HTTP requests to any URI defined in an OpenShift or Kubernetes component, without proper validation of the URL.
Progress Telerik KendoReact Prototype Pollution Vulnerability Allowing Denial-of-Service or Command Injection
A vulnerability exists in Progress Telerik KendoReact versions 3.5.0 prior to 9.4.0, allowing attackers to introduce or modify properties within the global prototype chain. This manipulation can lead to denial-of-service conditions or command injection vulnerabilities.
Progress Telerik Document Processing Libraries Path Traversal Vulnerability Allowing Arbitrary File System Access
A path traversal vulnerability has been identified in Progress Telerik Document Processing Libraries, affecting versions prior to 2025 Q1 (2025.1.205). This vulnerability allows improper limitation of target paths, which can lead to decompressing archive contents into restricted directories, potentially causing arbitrary file system access.
GNU Emacs Command Injection Vulnerability via Custom 'man' URI Scheme
A command injection vulnerability has been identified in GNU Emacs, all released versions through 29.4. This vulnerability allows remote, unauthenticated attackers to execute arbitrary shell commands on vulnerable systems. The issue arises from improper handling of custom 'man' URI schemes, which can be exploited by tricking users into visiting specially crafted websites or HTTP URLs with redirects. This vulnerability has been addressed in Emacs version 30.1.
GitLab CE/EE Information Disclosure Vulnerability
A vulnerability allowing information disclosure exists in GitLab CE/EE versions 8.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. This vulnerability allows an attacker to send a crafted request to a backend server, potentially revealing sensitive information.
Codezips Gym Management System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Codezips Gym Management System version 1.0. The issue resides in the 'id' parameter of the '/dashboard/admin/viewdetailroutine.php' file. This vulnerability allows remote attackers to inject arbitrary SQL code, bypassing input validation, which could lead to unauthorized database access, data manipulation, and potentially a full system compromise.
SourceCodester Best Church Management Software SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in SourceCodester Best Church Management Software version 1.1. The issue resides in the file '/admin/edit_slider.php', where the 'id' parameter is manipulated to execute unauthorized SQL commands. This vulnerability can be exploited remotely, allowing attackers to perform time-based blind SQL injection and extract data from the application's database.
GitLab EE Insecure Direct Object Reference Vulnerability Allowing Unauthorized Repository Access
A vulnerability allowing insecure direct object references has been identified in GitLab EE. This issue affects all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. The vulnerability allows an attacker to view repositories without proper authorization.
GitLab CE/EE Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in GitLab Community Edition (CE) and Enterprise Edition (EE). This issue affects all versions from 13.3 prior to 17.6.5, as well as versions 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2. The vulnerability allows an attacker to execute unauthorized actions by exploiting a change page.
OpenSearch Dashboards Reporting Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the OpenSearch Dashboards Reporting plugin, specifically in versions prior to 2.19.0.0. The issue arises because the plugin allows users to inject untrusted HTML, including JavaScript, into report headers and footers. This injected script is executed when the report is viewed, potentially leading to the theft of sensitive information, such as keystrokes or cookies.
GitLab CE/EE Denial-of-Service Vulnerability via Unbounded Object Creation in Personal Access Token Scopes
A denial-of-service vulnerability exists in GitLab CE/EE versions 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. The vulnerability allows an attacker to disrupt GitLab's availability by creating an excessive number of symbols through the 'scopes' parameter in a Personal Access Token. This unbounded symbol creation leads to memory exhaustion, as symbols in Ruby are not garbage collected and remain in memory for the duration of the program's execution.
Progress Telerik UI for WinUI Command Injection Vulnerability
A command injection vulnerability exists in Progress Telerik UI for WinUI, affecting versions through 2024 Q4 (2.11.0). The issue arises from improper handling of hyperlink elements, which could allow an attacker to inject and execute arbitrary commands.
Q-Free MaxTime Password Reset Vulnerability in Users Routes
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to reset passwords, including those of administrator accounts, by sending crafted HTTP requests.
Q-Free MaxTime Missing Authorization Vulnerability Allowing User Deletion
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to delete users by sending crafted HTTP requests.
Q-Free MaxTime Missing Authorization Vulnerability Allowing Unauthorized User Data Modification
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to modify user data by sending crafted HTTP requests. The issue is located in the 'maxprofile/users/routes.lua' file.
Q-Free MaxTime Missing Authorization Vulnerability Allowing Arbitrary User Privilege Escalation
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to create users with arbitrary privileges by sending crafted HTTP requests. The issue is located in the 'maxprofile/users/routes.lua' file.
Q-Free MaxTime Missing Authorization Vulnerability in User Enumeration
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to enumerate users by sending crafted HTTP requests to the users endpoint.
Q-Free MaxTime Missing Authorization Vulnerability in User Enumeration
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to enumerate users by sending crafted HTTP requests to the user endpoint.
Q-Free MaxTime Missing Authorization Vulnerability in User Group Management
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to remove users from groups by sending crafted HTTP requests. The issue is located in the user-groups routing file.
Q-Free MaxTime Missing Authorization Vulnerability in User Groups Management
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to add users to groups by sending crafted HTTP requests. The issue is located in the user-groups routing file of the application.
Q-Free MaxTime Missing Authorization Vulnerability in User Groups Management
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to remove privileges from user groups by sending crafted HTTP requests. The issue is located in the user-groups route of the application.
Q-Free MaxTime Missing Authorization Vulnerability in User Groups Management
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to manipulate user group privileges by sending crafted HTTP requests. The issue is located in the user-groups routing file of the MaxProfile module.
Q-Free MaxTime Missing Authorization Vulnerability in User Groups Management
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to remove user groups by sending crafted HTTP requests. The issue is located in the user-groups route of the application.
