CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 22, 2025

Fortinet Products Cache Poisoning Vulnerability via Crafted HTTP Requests

A vulnerability allowing web cache poisoning has been identified in multiple Fortinet products, including FortiManager, FortiMail, FortiAnalyzer, FortiVoice, FortiProxy, FortiRecorder, FortiAuthenticator, FortiNDR, FortiWLC, FortiPortal, FortiOS, FortiADC, FortiDDoS, FortiDDoS-F, FortiTester, FortiSOAR, and FortiSwitch. The vulnerability exists in FortiManager versions prior to 7.4.3, FortiMail versions prior to 7.0.3, FortiAnalyzer versions prior to 7.4.3, FortiVoice versions 7.0.0, 7.0.1, and prior to 6.4.8, FortiProxy versions prior to 7.0.4, FortiRecorder versions 6.4.0 through 6.4.2 and prior to 6.0.10, FortiAuthenticator versions 6.4.0 through 6.4.1 and prior to 6.3.3, FortiNDR versions 7.2.0 prior to 7.1.0, FortiWLC versions prior to 8.6.4, FortiPortal versions prior to 6.0.9, FortiOS versions 7.2.0 and prior to 7.0.5, FortiADC versions 7.0.0 through 7.0.1 and prior to 6.2.3, FortiDDoS versions prior to 5.5.1, FortiDDoS-F versions prior to 6.3.3, FortiTester versions prior to 7.2.1, FortiSOAR versions prior to 7.2.2, and FortiSwitch versions prior to 6.3.3. This vulnerability allows an attacker to poison web caches by sending crafted HTTP requests that direct to an arbitrary web server, exploiting the `Host` header.

5.0
Jan 22, 2025

AI Power: Complete AI Pack PHP Object Injection Vulnerability

A PHP Object Injection vulnerability has been identified in the 'AI Power: Complete AI Pack' WordPress plugin, affecting versions through 1.8.96. The vulnerability arises from the deserialization of untrusted data in the '$form['post_content']' variable, within the 'wpaicg_export_ai_forms()' function. This flaw allows authenticated attackers with administrative privileges to inject a PHP object. While the vulnerable plugin does not contain a direct 'Proof of Concept' chain, the presence of such a chain through an additional plugin or theme could enable the attacker to delete arbitrary files, access sensitive information, or execute code.

2.7
Jan 22, 2025

AI Power: Complete AI Pack WordPress Plugin PHP Object Injection Vulnerability

A PHP Object Injection vulnerability has been identified in the 'AI Power: Complete AI Pack' WordPress plugin, affecting versions through 1.8.96. The vulnerability arises from the deserialization of untrusted data in the 'post_content' variable, specifically within the 'wpaicg_export_prompts' function. This flaw allows authenticated attackers with administrative privileges to inject PHP objects. While the vulnerable plugin does not have an inherent Property-Oriented Programming (POP) chain, the presence of one through an additional plugin or theme could enable the attacker to delete arbitrary files, access sensitive information, or execute code.

2.7
Jan 22, 2025

AI Power: Complete AI Pack WordPress Plugin Missing Authorization Vulnerability Allowing Arbitrary Shortcode Execution

A vulnerability exists in the AI Power: Complete AI Pack plugin for WordPress, in all versions through 1.8.96. The issue arises from a missing capability check in the 'wpaicg_save_image_media' function, which allows authenticated attackers with Subscriber-level access and above to upload image files. Exploitation can be achieved by embedding shortcode attributes in the 'image_alt' value, which will execute when a POST request is sent to the attachment page.

2.4
Jan 22, 2025

AI Power: Complete AI Pack WordPress Plugin Server-Side Request Forgery Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability has been identified in the AI Power: Complete AI Pack plugin for WordPress, affecting all versions through 1.8.96. The vulnerability arises in the 'wpaicg_troubleshoot_add_vector' function, allowing authenticated attackers with subscriber-level access or higher to send web requests to arbitrary locations from the web application. This could be exploited to query and modify information from internal services.

2.7
Jan 22, 2025

Themify Builder Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Themify Builder plugin for WordPress, affecting all versions through 7.6.5. The issue arises from the use of add_query_arg without proper escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages. These scripts could execute if a user is tricked into clicking a link.

5.2
Jan 22, 2025

XML for Google Merchant Center WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the XML for Google Merchant Center plugin for WordPress, affecting all versions through 3.0.11. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the 'feed_id' parameter. These scripts could be executed if a user is tricked into clicking a link.

3.6
Jan 22, 2025

AdForest WordPress Theme Authentication Bypass Vulnerability

A vulnerability allowing authentication bypass has been identified in the AdForest theme for WordPress, affecting all versions through 5.1.8. The issue arises because the theme fails to properly verify a user's identity before logging them in. This flaw enables unauthenticated attackers to authenticate as any user who has set up OTP login via phone number.

2.5
Jan 22, 2025

Stackable Page Builder Gutenberg Blocks Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Stackable – Page Builder Gutenberg Blocks plugin for WordPress, affecting all versions through 3.13.11. The issue arises in the Button block's 'title' parameter, where inadequate input sanitization and output escaping allow authenticated attackers with Contributor-level access or higher to inject arbitrary scripts. These scripts are executed when a user views the page containing the injected content.

2.4
Jan 22, 2025

I-O DATA UD-LT2 OS Command Injection Vulnerability

An OS command injection vulnerability has been identified in the I-O DATA UD-LT2 router, specifically in firmware versions through 1.00.008_SE. This vulnerability allows authenticated users to execute arbitrary OS commands via the command-line interface (CLI).

1.7
Jan 22, 2025

I-O Data UD-LT2 Inclusion of Undocumented Features Vulnerability

A vulnerability allowing the inclusion of undocumented features has been identified in I-O Data UD-LT2 routers with firmware version 1.00.008_SE and earlier. This vulnerability allows remote attackers to disable the LAN-side firewall and open specific ports on the affected devices.

2.5
Jan 22, 2025

I-O Data UD-LT2 OS Command Injection Vulnerability

An OS command injection vulnerability has been identified in I-O Data UD-LT2 routers, specifically in the firmware version 1.00.008_SE and earlier. This vulnerability allows an attacker with administrative access to execute arbitrary OS commands by manipulating requests related to certain screen operations.

1.7
Jan 22, 2025

WPBot Pro WordPress Chatbot Missing Authorization Vulnerability in Simple Text Response Creation

A vulnerability exists in the WPBot Pro WordPress Chatbot plugin, all versions through 13.5.5, due to a lack of proper capability checks in the 'qc_wp_latest_update_check_pro' function. This flaw allows authenticated attackers with Subscriber-level access or higher to create Simple Text Responses for chat queries, leading to unauthorized data modification.

3.8
Jan 22, 2025

Red Hat Podman and Buildah Container Breakout Vulnerability

A vulnerability allowing container breakout has been identified in Red Hat Podman and Buildah. This issue arises when using the '--jobs=2' option, creating a race condition while building a malicious Containerfile. Although SELinux may provide some mitigation, it still permits the enumeration of files and directories on the host.

4.4
Jan 22, 2025

Ketchup Shortcodes WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Ketchup Shortcodes plugin for WordPress, affecting all versions through 0.1.2. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'spacer' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.

3.0
Jan 22, 2025

WordPress Picture Gallery Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress. This issue affects all versions through 1.5.19 and arises from inadequate input sanitization and output escaping on user-supplied attributes. Authenticated attackers with contributor-level access or higher can exploit this vulnerability by injecting arbitrary web scripts into pages, which are then executed when users access the affected pages.

3.6
Jan 22, 2025

WP-Polls SQL Injection Vulnerability Leading to Stored Cross-Site Scripting

A SQL injection vulnerability has been identified in the WP-Polls plugin for WordPress, affecting all versions through 2.77.2. The vulnerability arises from inadequate escaping of user-supplied data in SQL queries, allowing unauthenticated attackers to inject additional SQL commands. While the injected SQL queries cannot be used to extract database information, a carefully crafted payload can introduce malicious JavaScript that is stored and executed later, resulting in a stored cross-site scripting vulnerability.

6.0
Jan 22, 2025

Node.js Internal Worker Leak Vulnerability Allowing Permission Bypass

A vulnerability exists in Node.js versions 20, 22, and 23 for users with the Permission Model enabled. By using the diagnostics_channel utility, it is possible to intercept events when a worker thread is created. This not only applies to regular worker threads but also reveals internal workers, allowing an instance to be accessed. The constructor of this internal worker can be extracted and reused for malicious purposes, effectively bypassing the permission model restrictions.

5.6
Jan 22, 2025

Node.js Worker Permission Bypass Vulnerability via InternalWorker Leak

A vulnerability exists in Node.js versions 20, 22, and 23 prior to the latest security releases, allowing Permission Model users to hook into events when worker threads are created. This issue not only pertains to regular workers but also exposes internal workers, enabling the fetching of an instance, extraction of its constructor, and potential misuse. Successful exploitation could lead to unauthorized access to internal worker functionalities, allowing for malicious manipulation or actions.

4.6
Jan 22, 2025

CampCodes School Management Software Attachment Resource Injection Vulnerability

A resource injection vulnerability has been identified in CampCodes School Management Software version 1.0, specifically within the Attachment Handler component. This vulnerability arises from improper management of resource identifiers, allowing for insecure direct object reference (IDOR) exploitation. The issue can be exploited remotely, although the attack's complexity is considered high.

3.3
Jan 22, 2025

WPBot Pro WordPress Chatbot Unauthenticated Arbitrary File Upload Vulnerability

A vulnerability allowing arbitrary file uploads has been identified in the WPBot Pro WordPress Chatbot plugin, affecting all versions through 13.5.4. The issue arises from inadequate file type validation in the 'qcld_wpcfb_file_upload' function, enabling unauthenticated attackers to upload arbitrary files to the server. This vulnerability could potentially lead to remote code execution. Exploitation requires the ChatBot Conversational Forms plugin and the Conversational Form Builder Pro addon plugin.

4.8
Jan 22, 2025

Magma Mobile Management Entity Null Pointer Dereference Vulnerability via Malformed Initial UE Message

A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP 'Initial UE Message' packet that omits the expected 'RRC Establishment Cause' field. The issue has been fixed in Magma version 1.9.

4.7
Jan 21, 2025

Android Libwebp Integer Overflow Vulnerability in DGifSlurp Function Leading to Out-of-Bounds Write and Potential Remote Code Execution

A vulnerability has been identified in the DGifSlurp function of the libwebp library, specifically within the dgif_lib.c file. This issue arises from an integer overflow, which creates a possible out-of-bounds write. Such a vulnerability could be exploited to execute remote code without requiring additional execution privileges. Notably, user interaction is not necessary for exploitation.

2.2
Jan 21, 2025

Android Bluetooth Stack Heap Buffer Overflow Vulnerability Allowing Remote Code Execution

A heap buffer overflow vulnerability has been identified in the Android Bluetooth stack, specifically in the function 'gatts_process_primary_service_req' of 'gatt_sr.cc'. This vulnerability allows for an out-of-bounds write, which could be exploited to execute remote code without requiring any additional privileges or user interaction.

1.7
Jan 21, 2025

Android Bluetooth Stack Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in the Android Bluetooth stack, specifically within the 'gatts_process_read_by_type_req' function of 'gatt_sr.cc'. This vulnerability arises from a logic error that creates a potential out-of-bounds write, allowing for remote code execution without the need for additional execution privileges or user interaction.

1.7
Jan 21, 2025

Android Framework and System Components Out-of-Bounds Write Vulnerability Allowing Local Privilege Escalation

A vulnerability has been identified in the Android framework and system components, specifically in the 'growData' function of 'Parcel.cpp'. This vulnerability arises from an incorrect bounds check, leading to a potential out-of-bounds write. Exploitation of this issue could result in local privilege escalation, with no additional execution privileges required. User interaction is not necessary for exploitation. This vulnerability affects several different versions and/or ranges of Android.

1.1
Jan 21, 2025

Android Framework Account Manager Service Elevation of Privilege Vulnerability

A vulnerability in the AccountManagerService component of the Android Framework allows for a local elevation of privilege. This issue arises from unsafe deserialization, which creates a potential bypass of parcel mismatch mitigations. Exploitation of this vulnerability requires user interaction.

1.5
Jan 21, 2025

Android Notification Access Privilege Escalation Vulnerability

A vulnerability in the Notification Access Confirmation Activity allows an app with notification access to be hidden in the Settings. This issue arises from a missing permission check, which could lead to local privilege escalation without requiring additional execution privileges. Exploitation of this vulnerability does require user interaction.

1.1
Jan 21, 2025

Android Framework and System Components Elevation of Privilege Vulnerability

A vulnerability in the Android framework and system components has been identified, allowing for a local elevation of privilege. This issue arises from a possible out-of-bounds write in the 'writeInplace' function of 'Parcel.cpp'. Exploitation of this vulnerability does not require any additional execution privileges or user interaction.

1.6
Jan 21, 2025

Android Framework Elevation of Privilege Vulnerability in Window Organizer Controller

A logic error in the WindowOrganizerController.java file allows for the potential launching of arbitrary activities as the system UID. This vulnerability could lead to local elevation of privilege, with no additional execution privileges required. Exploitation does not involve user interaction.

1.2
Jan 21, 2025

Android Factory Reset Trigger Vulnerability in Settings App

A logic error in the onClick method of MainClear.java in the Android Settings application creates a vulnerability that allows a factory reset to be triggered without explicit user consent. This issue could lead to a local denial-of-service condition, as it requires no additional execution privileges and does not involve user interaction for exploitation.

1.5
Jan 21, 2025

Android Permission Persistence Vulnerability Leading to Local Privilege Escalation

A vulnerability exists in multiple Android components that may cause a failure to properly maintain permission settings, potentially due to resource exhaustion. This issue could allow for local privilege escalation without requiring additional execution privileges or user interaction.

1.2
Jan 21, 2025

Android Connectivity Service Wi-Fi VPN Side Channel Information Disclosure Vulnerability

A vulnerability exists in the ConnectivityService component of Android, specifically in multiple functions of ConnectivityService.java. This vulnerability allows a Wi-Fi access point to infer which websites a device has visited while connected to a VPN, based on leaked side channel information. The issue could result in remote information disclosure without requiring any additional privileges or user interaction for exploitation. This vulnerability affects several Android versions, including 12, 12L, 13, 14, and 15.

1.6
Jan 21, 2025

Android Information Disclosure Vulnerability in Service Listing Component

A logic error in the ServiceListing component of Android allows a malicious app to conceal a Network Location Service (NLS) entry from the device's Settings. This vulnerability could lead to unauthorized local access to information, without requiring additional execution privileges or user interaction for exploitation. The issue affects several different versions of Android.

1.5
Jan 21, 2025

Android Companion Device Manager Service Elevation of Privilege Vulnerability

A vulnerability has been identified in the CompanionDeviceManagerService.java file, where certain functions may improperly grant permissions without user consent. This issue arises from a lack of necessary permission checks, potentially allowing for local elevation of privilege. Exploitation of this vulnerability does not require any additional execution privileges or user interaction.

1.5
Jan 21, 2025

Android AccountManagerService Race Condition Vulnerability Allowing Permission Bypass and Privilege Escalation

A vulnerability has been identified in the AccountManagerService component of Android. This issue arises from a race condition that creates a potential to bypass permissions and initiate protected activities. Exploiting this vulnerability could lead to local escalation of privileges, with no additional execution rights required. However, user interaction is necessary for the exploitation to occur.

1.4
Jan 21, 2025

Android Bluetooth Stack Out-of-Bounds Write Vulnerability Allowing Remote Code Execution

A vulnerability has been identified in the Android Bluetooth stack, specifically in the 'gatts_process_read_req' function of 'gatt_sr.cc'. This issue arises from a missing bounds check, which creates a potential for out-of-bounds write operations. Exploitation of this vulnerability could lead to remote code execution, with no additional privileges required. Notably, user interaction is not necessary for exploitation.

1.7
Jan 21, 2025

Android Bluetooth Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in the Bluetooth GATT server implementation of Android. This issue arises from an out-of-bounds write in the 'gatts_process_find_info' function, gatt_sr.cc, due to a missing bounds check. The vulnerability allows for code execution on the affected device, requiring no additional privileges and no user interaction. It affects several Android versions, including 12, 12L, 13, 14, and 15.

1.7
Jan 21, 2025

Android Documents UI Tapjacking Vulnerability Leading to Privilege Escalation

A tapjacking vulnerability has been identified in the Android Documents UI, allowing for a possible overlay attack. This issue could lead to local escalation of privilege, requiring user interaction for exploitation. The vulnerability is present in multiple versions of Android, specifically 12, 12L, 13, 14, and 15.

0.9
Jan 21, 2025

Android Bluetooth Stack Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in the Android Bluetooth stack, specifically within the 'build_read_multi_rsp' function of 'gatt_sr.cc'. This issue arises from a logic error, which could be exploited to cause a remote (proximal/adjacent) denial-of-service condition. The vulnerability does not require any additional execution privileges and can be exploited without user interaction.

1.6
Jan 21, 2025

Android Bluetooth Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in the Android Bluetooth module, specifically within the 'build_read_multi_rsp' function of 'gatt_sr.cc'. This issue arises from a missing bounds check, which creates a potential for out-of-bounds write. Exploitation of this vulnerability does not require any additional execution privileges and can be carried out remotely, provided the attacker is in close proximity to the affected device.

1.7
Jan 21, 2025

Android Permission Controller Elevation of Privilege Vulnerability

A logic error in the Android Permission Controller allows for the potential acquisition of any system permission. This vulnerability could lead to local elevation of privilege, requiring user interaction for exploitation. It affects multiple Android versions, including 12, 12L, 13, 14, and 15.

1.5
Jan 21, 2025

Android Bluetooth HIDs User Consent Bypass Vulnerability Allowing Privilege Escalation

A vulnerability exists in the Android Bluetooth module that allows for a bypass of user consent when enabling new Bluetooth Human Interface Devices (HIDs). This issue arises from a logic error in the code, which could lead to local escalation of privilege. Notably, exploitation of this vulnerability does not require any additional execution privileges or user interaction.

1.6
Jan 21, 2025

OpenAirInterface CN5G AMF Uninitialized Pointer Dereference Vulnerability in NGAP PDU Session Resource Setup Response Handling

A vulnerability allowing for a denial-of-service (DoS) condition has been identified in OpenAirInterface CN5G AMF versions through 2.0.0. The issue arises from an uninitialized pointer dereference in the ngap_handle_pdu_session_resource_setup_response function. This vulnerability can be exploited by sending a crafted PDU Session Resource Setup Response over the N2 interface, causing the AMF to crash.

4.0
Jan 21, 2025

Open5GS 5G NAS Reachable Assertion Vulnerability in oai_nas_5gmm_decode Function Allowing Denial-of-Service

A reachable assertion vulnerability has been identified in the Open5GS 5G core network component, specifically in versions through 2.6.4. The issue arises in the oai_nas_5gmm_decode function, where a crafted NAS packet can trigger an assertion failure. This vulnerability allows attackers to cause a denial-of-service condition by disrupting normal service operations.

4.7
Jan 21, 2025

Open5GS Reachable Assertion Vulnerability in amf_ue_set_suci Function Allowing Denial-of-Service

A reachable assertion vulnerability has been identified in the Open5GS 5G Access and Mobility Management Function (AMF) versions through 2.6.4. The vulnerability arises in the amf_ue_set_suci function, where a malformed SUCI (Subscription Concealed Identifier) within a NAS (Non-Access Stratum) 5GMM (5G Mobility Management) message can lead to a parsing error. This error causes the assertion to be triggered, resulting in a denial-of-service condition.

4.0
Jan 21, 2025

Magma Reachable Assertion Vulnerability in Access Point Name Decoding Function Allowing Denial-of-Service

A reachable assertion vulnerability has been identified in the Magma 5G core network implementation, specifically in versions through 1.8.0. This vulnerability resides in the 'decode_access_point_name_ie' function, where the absence of proper length checks allows attackers to craft NAS packets that, when received, trigger an assertion failure. This exploitation causes a denial-of-service condition by disrupting normal network operations.

4.4
Jan 21, 2025

The Linux Foundation Magma Buffer Overflow Vulnerability in NAS Packet Processing Allowing Denial-of-Service

A buffer overflow vulnerability has been identified in The Linux Foundation Magma version 1.8.0 and prior. This issue arises in the 'decode_esm_message_container' function within the 'EsmMessageContainer.cpp' file. The vulnerability allows attackers to craft specific NAS packets that, when processed, cause a denial-of-service condition by crashing the Mobility Management Entity (MME) or Access and Mobility Management Function (AMF) in the cellular network.

4.7
Jan 21, 2025

The Linux Foundation Magma Stack Overflow Vulnerability in Protocol Configuration Options Decoding

A stack overflow vulnerability has been identified in The Linux Foundation Magma versions through 1.8.0. This issue arises in the 'decode_protocol_configuration_options' function within the file '3gpp/3gpp_24.008_sm_ies.c'. The vulnerability allows attackers to cause a denial-of-service (DoS) by sending a crafted NAS packet, leading to a stack overflow condition.

4.7
Jan 21, 2025

Magma Type Confusion Vulnerability in NAS Message Decoding Allows Arbitrary Code Execution or Denial-of-Service

A type confusion vulnerability has been identified in the NAS message decoding function of Magma versions through 1.8.0. This vulnerability allows attackers to execute arbitrary code or cause a denial-of-service condition by sending a crafted NAS packet. The issue arises from improper handling of the packet's contents, leading to memory corruption that can be exploited under certain conditions.

4.5