CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Feb 11, 2025

AMD SEV Firmware Privileged Memory Read Vulnerability Allowing Guest Data Exposure

A vulnerability in the SEV firmware could enable an attacker with privileges to access unencrypted memory, potentially leading to the exposure of guest private data.

1.1
Feb 11, 2025

AMD Processors SMM Handler Input Validation Vulnerability Allowing SMRAM Overwrite and Potential Arbitrary Code Execution

A vulnerability has been identified in the System Management Mode (SMM) handler of certain AMD processors. This issue arises from improper input validation, which may enable a privileged attacker to overwrite System Management RAM (SMRAM). Such an action could lead to arbitrary code execution.

1.1
Feb 11, 2025

AMD Processors SMM Handler Improper Input Validation Vulnerability Allowing SMRAM Overwrite and Potential Arbitrary Code Execution

A vulnerability has been identified in certain AMD processors, where improper input validation in the System Management Mode (SMM) handler could enable a privileged attacker to overwrite System Management RAM (SMRAM). This flaw has the potential to lead to arbitrary code execution.

1.1
Feb 11, 2025

Hostapd Wi-Fi Easy Connect PKEX Vulnerability Allows Future Association Subversion

A vulnerability in hostapd versions through 2.10 allows an attacker to subvert future public key bootstrapping in the Wi-Fi Easy Connect protocol. This is achieved by passively observing public keys exchanged during a previous successful association, reusing the encrypting element, and subtracting it from the captured message. The vulnerability arises because the PKEX code remains active even after a successful association, contrary to the protocol's intention.

7.5
Feb 11, 2025

WinZip 7Z File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in WinZip, specifically in the parsing of 7Z files. This issue arises from inadequate validation of user-supplied data, leading to an out-of-bounds write that can overwrite memory. As a result, attackers can execute arbitrary code on the affected system, with the executed code running in the context of the current process. Exploitation requires user interaction, such as opening a malicious 7Z file.

4.7
Feb 11, 2025

Ianproxy Directory Traversal Vulnerability Allowing Arbitrary File Read

A directory traversal vulnerability has been identified in Ianproxy versions through 0.1. This vulnerability allows remote attackers to read arbitrary files, potentially leading to the exposure of sensitive information. The issue arises from improper handling of file paths, particularly on Windows servers, where the traversal can bypass certain security measures.

3.9
Feb 11, 2025

Dedecms URL Redirection Vulnerability

A URL redirection vulnerability exists in Dedecms versions through 5.71sp1. The issue arises from a logic error in the web application's source code, which fails to properly validate input GET requests, allowing for unintended URL redirects.

5.9
Feb 11, 2025

DNNGo xBlog SQL Injection Vulnerability

A SQL injection vulnerability has been identified in DNNGo xBlog version 6.5.0. The issue arises in the Categorys parameter of the Resource_Service.aspx page. This vulnerability allows for blind SQL injection, where an attacker can manipulate SQL queries and infer database information based on the application's response.

3.9
Feb 11, 2025

Baidu Antivirus Process Termination Vulnerability via Bring Your Own Vulnerable Driver Attack

A vulnerability in the BdApiUtil driver of Baidu Antivirus version 5.2.3.116083 allows for arbitrary process termination. This issue can be exploited by executing a Bring Your Own Vulnerable Driver (BYOVD) attack. While administrative privileges are required to install the driver, once installed, it can be accessed by any user.

2.3
Feb 11, 2025

GeoNetwork Information Disclosure Vulnerability in Search Endpoint Response Headers

A vulnerability exists in GeoNetwork versions prior to 4.2.10 and 4.4.5, where the search endpoint response headers inadvertently reveal details about the Elasticsearch software in use. This information could be exploited to identify the server's software components, potentially leading to security risks.

4.1
Feb 11, 2025

AMD DRTM Firmware Improper Access Control Vulnerability Allowing Stack Memory Corruption

A vulnerability exists in the DRTM firmware due to improper access control, which could enable a privileged attacker to initiate multiple driver processes. This could lead to corruption of stack memory, with the potential to disrupt system integrity or availability.

0.9
Feb 11, 2025

AMD IOMMU Vulnerability in SEV-SNP Allowing Privileged Attackers to Bypass RMP Checks and Induce PTE Faults

A vulnerability has been identified in the handling of invalid nested page table entries within the IOMMU, which may allow a privileged attacker to cause page table entry (PTE) faults. This could bypass RMP checks in SEV-SNP, potentially compromising the integrity of guest memory.

0.9
Feb 11, 2025

AMD IOMMU Improper Access Control Vulnerability Allowing RMP Check Bypass

A vulnerability has been identified in the AMD IOMMU related to improper access control. This issue may enable a privileged attacker to bypass RMP checks, potentially compromising the integrity of guest memory.

1.1
Feb 11, 2025

AMD fTPM Driver Improper Access Control Vulnerability Allowing Memory Corruption

A vulnerability has been identified in the fTPM driver within the trusted operating system, where improper access control could enable a privileged attacker to corrupt system memory. This memory corruption has the potential to compromise the integrity, confidentiality, or availability of the system.

1.0
Feb 11, 2025

WPGateway WordPress Plugin Privilege Escalation Vulnerability

A privilege escalation vulnerability has been identified in the WPGateway plugin for WordPress, affecting versions through 3.5. This vulnerability allows unauthenticated attackers to create malicious administrator accounts. The issue has been actively exploited in the wild.

3.9
Feb 11, 2025

AMD AmdPspP2CmboxV2 Driver SMRAM Overwrite Vulnerability Allowing Arbitrary Code Execution

A vulnerability has been identified in the AMD AmdPspP2CmboxV2 driver, where improper input validation could enable a privileged attacker to overwrite System Management RAM (SMRAM). This exploitation could lead to arbitrary code execution.

1.1
Feb 11, 2025

AMD AmdPlatformRasSspSmm Driver SMM Callout Vulnerability Allowing Arbitrary Code Execution

A vulnerability has been identified in the AmdPlatformRasSspSmm driver, related to SMM callouts. This vulnerability could enable a ring 0 attacker to alter boot services handlers, which may lead to arbitrary code execution.

1.1
Feb 11, 2025

AMD AmdCpmDisplayFeatureSMM Driver SMM Callout Vulnerability Allowing SMRAM Overwrite and Potential Arbitrary Code Execution

A vulnerability has been identified in the AmdCpmDisplayFeatureSMM driver, related to SMM callouts. This issue could enable locally authenticated attackers to overwrite SMRAM, which may lead to arbitrary code execution.

1.2
Feb 11, 2025

AMD ASP Integer Overflow Vulnerability Allowing Privileged Out-of-Bounds Write

A vulnerability has been identified in the AMD ASP component, where an integer overflow could enable a privileged attacker to execute an out-of-bounds write. This exploitation has the potential to disrupt data integrity.

0.9
Feb 11, 2025

Digital China DCBI-Netlog-LAB Gateway Buffer Overflow Vulnerability Allowing Remote Code Execution

A buffer overflow vulnerability has been identified in Digital China DCBI-Netlog-LAB Gateway version 1.0. The vulnerability arises from a lack of proper length verification when saving parental control configuration information. This oversight allows attackers to exploit the vulnerability, potentially causing the remote target device to crash or execute arbitrary commands.

4.4
Feb 11, 2025

Digital China DCBC Gateway Buffer Overflow Vulnerability Allowing Arbitrary Command Execution

A buffer overflow vulnerability has been identified in Digital China DCBC Gateway version 200-2.1.1. This vulnerability arises from a lack of proper length verification, particularly related to the configuration of static NAT rules. Attackers who successfully exploit this issue can cause the remote target device to crash or execute arbitrary commands.

4.0
Feb 11, 2025

Wavlink WL-WN575A3 Buffer Overflow Vulnerabilities Allowing Device Crash and Unauthorized Command Execution

Multiple buffer overflow vulnerabilities have been identified in the Wavlink WL-WN575A3 router, specifically in the firmware version RPT75A3.V4300. These vulnerabilities arise from inadequate length checks on user-controlled data, enabling attackers to either crash the device or execute arbitrary commands without any authorization verification. The issues are present in two binary files: 'wireless.cgi' and 'libwebutil.so'.

5.3
Feb 11, 2025

Ruijie RG-NBR2600S Gateway Buffer Overflow Vulnerability Allowing Denial-of-Service and Arbitrary Command Execution

A buffer overflow vulnerability has been identified in the Ruijie RG-NBR2600S Gateway, specifically in version 10.3(4b12). The vulnerability arises from inadequate length verification related to the configuration of source address NAT rules. Attackers who successfully exploit this issue can cause the device to crash or execute arbitrary commands.

4.0
Feb 11, 2025

Mercury MIPC552W Camera Buffer Overflow Vulnerability Allowing Arbitrary Command Execution

A buffer overflow vulnerability has been identified in the Mercury MIPC552W Camera, version 1.0. This vulnerability arises from inadequate length verification related to the configuration of the PPTP server. Successful exploitation of this issue can lead to the remote device crashing or executing arbitrary commands.

3.9
Feb 11, 2025

H3C FA3010L Access Points Buffer Overflow Vulnerability Allowing Arbitrary Command Execution

A buffer overflow vulnerability has been identified in H3C FA3010L access points running SWFA1B0V100R005. The vulnerability arises from inadequate length verification related to firewall rule settings. Successful exploitation of this vulnerability can lead to a crash of the remote device or allow the execution of arbitrary commands.

4.0
Feb 11, 2025

Mintty Sixel Image Parsing Heap-Based Buffer Overflow Remote Code Execution Vulnerability

A heap-based buffer overflow vulnerability allowing remote code execution has been identified in Mintty. This issue arises from improper validation of user-supplied data lengths when parsing sixel images, leading to arbitrary code execution in the context of the current user. Exploitation requires user interaction, such as visiting a malicious page or opening a harmful file.

3.7
Feb 11, 2025

Logsign Unified SecOps Platform Authentication Bypass Vulnerability

An authentication bypass vulnerability has been identified in Logsign Unified SecOps Platform. This issue allows remote attackers to bypass authentication on affected systems. The vulnerability arises from improper implementation of the authentication algorithm in the web service, which by default listens on TCP port 443. Notably, authentication is not required to exploit this vulnerability.

2.8
Feb 11, 2025

PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

An out-of-bounds read vulnerability allowing information disclosure has been identified in PDF-XChange Editor. This issue arises from improper validation of user-supplied data when parsing U3D files, leading to the potential for reading past the end of an allocated object. Remote attackers can exploit this vulnerability to disclose sensitive information on affected systems. User interaction is required, as the target must open a malicious U3D file or visit a compromised page. Additionally, this vulnerability could be leveraged alongside others to execute arbitrary code within the current process context.

4.0
Feb 11, 2025

PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in PDF-XChange Editor, specifically within the U3D file parsing process. This issue arises from inadequate validation of user-supplied data, leading to an out-of-bounds write that allows attackers to execute arbitrary code on the affected system. Exploitation of this vulnerability requires user interaction, as the target must open a malicious file or visit a harmful webpage.

4.2
Feb 11, 2025

PDF-XChange Editor Out-of-Bounds Read Vulnerability in XPS File Parsing Allowing Information Disclosure

An out-of-bounds read vulnerability has been identified in PDF-XChange Editor, specifically within the XPS file parsing component. This flaw arises from inadequate validation of user-supplied data, leading to the potential for reading past the end of an allocated object. As a result, remote attackers could exploit this vulnerability to disclose sensitive information on affected installations. User interaction is required, as the target must open a malicious XPS file. Additionally, this vulnerability could be leveraged, in conjunction with others, to execute arbitrary code within the context of the current process.

4.0
Feb 11, 2025

PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

An out-of-bounds read vulnerability allowing information disclosure has been identified in PDF-XChange Editor. This issue arises from improper validation of user-supplied data when parsing U3D files, leading to a read past the end of an allocated buffer. Remote attackers can exploit this vulnerability to disclose sensitive information on affected installations. User interaction is required, as the target must open a malicious U3D file or visit a harmful webpage. Additionally, this vulnerability could be leveraged, in conjunction with others, to execute arbitrary code within the current process context.

4.0
Feb 11, 2025

PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

An out-of-bounds read vulnerability allowing information disclosure has been identified in PDF-XChange Editor. This issue arises from improper validation of user-supplied data when parsing JB2 files, leading to a read past the end of an allocated object. Remote attackers can exploit this vulnerability to disclose sensitive information on affected installations, but user interaction is required, as the target must open a malicious JB2 file. Additionally, this vulnerability could be leveraged, in conjunction with others, to execute arbitrary code in the context of the current process.

4.0
Feb 11, 2025

PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

An out-of-bounds read vulnerability allowing information disclosure has been identified in PDF-XChange Editor. This issue arises from improper validation of user-supplied data when parsing JB2 files, leading to a read past the end of an allocated buffer. Remote attackers can exploit this vulnerability to disclose sensitive information on affected installations, but user interaction is required, as the target must open a malicious JB2 file. Additionally, this vulnerability could be leveraged, in conjunction with others, to execute arbitrary code in the context of the current process.

4.0
Feb 11, 2025

PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

An out-of-bounds read vulnerability allowing information disclosure has been identified in PDF-XChange Editor. This issue arises from improper validation of user-supplied data when parsing JB2 files, leading to a read past the end of an allocated object. Remote attackers can exploit this vulnerability to disclose sensitive information on affected installations, but user interaction is required, as the target must open a malicious file or visit a harmful page. Additionally, this vulnerability could be leveraged, in conjunction with others, to execute arbitrary code within the current process context.

4.5
Feb 11, 2025

PDF-XChange Editor Out-of-Bounds Read Vulnerability in XPS File Parsing Allowing Information Disclosure

A vulnerability allowing out-of-bounds read has been identified in PDF-XChange Editor, specifically within the XPS file parsing process. This flaw arises from inadequate validation of user-supplied data, leading to the potential for reading past the end of an allocated object. As a result, remote attackers could exploit this vulnerability to disclose sensitive information on affected installations. User interaction is required, as the target must open a malicious XPS file or visit a harmful webpage. Furthermore, this vulnerability could be leveraged alongside others to execute arbitrary code within the current process context.

4.5
Feb 11, 2025

PDF-XChange Editor Heap-Based Buffer Overflow Vulnerability Leading to Remote Code Execution

A heap-based buffer overflow vulnerability has been identified in PDF-XChange Editor, specifically within the RTF file parsing component. This vulnerability allows remote attackers to execute arbitrary code on affected installations. The issue arises from inadequate validation of user-supplied data lengths before copying them into fixed-length heap-based buffers. Exploitation of this vulnerability requires user interaction, as the target must open a malicious file or visit a harmful webpage.

4.6
Feb 11, 2025

PDF-XChange Editor Out-of-Bounds Read Vulnerability in XPS File Parsing Allowing Information Disclosure

An out-of-bounds read vulnerability has been identified in PDF-XChange Editor, specifically within the XPS file parsing component. This flaw arises from inadequate validation of user-supplied data, enabling a read past the end of an allocated object. As a result, remote attackers could exploit this vulnerability to disclose sensitive information on affected installations. User interaction is necessary for exploitation, as the target must open a malicious XPS file or visit a harmful webpage. Furthermore, this vulnerability could be leveraged alongside others to execute arbitrary code within the current process context.

4.0
Feb 11, 2025

PDF-XChange Editor Out-of-Bounds Read Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in PDF-XChange Editor. This issue arises from an out-of-bounds read related to the handling of Doc objects, caused by inadequate validation of user-supplied data. As a result, it is possible to read past the end of an allocated buffer, allowing attackers to execute arbitrary code in the context of the current process. Exploitation requires user interaction, such as visiting a malicious page or opening a harmful file.

4.6
Feb 11, 2025

PDF-XChange Editor AcroForm Use-After-Free Remote Code Execution Vulnerability

A use-after-free vulnerability has been identified in PDF-XChange Editor, specifically within the handling of AcroForms. This flaw allows remote attackers to execute arbitrary code on affected installations. The vulnerability arises from the absence of proper validation of an object's existence before performing operations on it. Exploitation requires user interaction, as the target must open a malicious file or visit a harmful webpage.

4.6
Feb 11, 2025

AMD Ryzen Master Utility DLL Hijacking Vulnerability Allowing Privilege Escalation and Potential Arbitrary Code Execution

A DLL hijacking vulnerability has been identified in the AMD Ryzen Master Utility. This vulnerability could enable an attacker to escalate privileges, potentially leading to arbitrary code execution.

4.3
Feb 11, 2025

Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability

An authentication bypass vulnerability has been identified in Paessler PRTG Network Monitor, specifically within the SNMP module. This issue arises from improper validation of user-supplied data in the web interface, allowing network-adjacent attackers to inject arbitrary scripts. Exploitation of this vulnerability requires some user interaction from an administrator.

3.8
Feb 11, 2025

Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in Tungsten Automation Power PDF, specifically in the parsing of JP2 files. This issue arises from inadequate validation of user-supplied data, leading to out-of-bounds read conditions that can be exploited to execute arbitrary code within the context of the current process. Exploitation requires user interaction, as the target must open a malicious file or visit a harmful webpage.

1.6
Feb 11, 2025

Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

An out-of-bounds read vulnerability allowing information disclosure has been identified in Tungsten Automation Power PDF. This issue arises from improper validation of user-supplied data when parsing JP2 files, leading to a read past the end of an allocated object. Remote attackers can exploit this vulnerability to disclose sensitive information on affected installations, but user interaction is required, as the target must open a malicious file or visit a harmful webpage. Additionally, this vulnerability could be leveraged, in conjunction with others, to execute arbitrary code within the current process context.

1.4
Feb 11, 2025

Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in Tungsten Automation Power PDF, specifically in the parsing of JP2 files. This issue arises from inadequate validation of user-supplied data, leading to out-of-bounds read conditions that can be exploited to execute arbitrary code within the context of the current process. Exploitation requires user interaction, as the target must open a malicious file or visit a harmful webpage.

1.4
Feb 11, 2025

Tungsten Automation Power PDF JP2 File Parsing Use-After-Free Information Disclosure Vulnerability

A use-after-free vulnerability has been identified in Tungsten Automation Power PDF, specifically within the JP2 file parsing component. This vulnerability allows remote attackers to disclose sensitive information on affected systems. Exploitation requires user interaction, as the target must open a malicious JP2 file. The vulnerability arises from improper validation of object existence before performing operations, potentially allowing attackers to execute arbitrary code in the context of the current process.

1.4
Feb 11, 2025

Tungsten Automation Power PDF Out-of-Bounds Write Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in Tungsten Automation Power PDF, specifically in the parsing of JPF files. This issue arises from inadequate validation of user-supplied data, leading to an out-of-bounds write that can be exploited to execute arbitrary code within the context of the current process. Exploitation requires user interaction, as the target must open a malicious file or visit a harmful webpage.

1.6
Feb 11, 2025

AMD Integrated Management Technology DLL Hijacking Vulnerability Allowing Privilege Escalation and Potential Arbitrary Code Execution

A DLL hijacking vulnerability has been identified in the AMD Integrated Management Technology (AIM-T) Manageability Service. This vulnerability could allow an attacker to escalate privileges, potentially leading to arbitrary code execution.

1.3
Feb 11, 2025

AMD Integrated Management Technology Privilege Escalation Vulnerability in Manageability Service

A vulnerability exists in the AMD Integrated Management Technology (AIM-T) Manageability Service due to incorrect default permissions in the installation directory. This flaw could enable an attacker to escalate privileges, potentially leading to arbitrary code execution.

1.3
Feb 11, 2025

TOTOLink X6000R Buffer Overflow Vulnerability Allowing Arbitrary Command Execution

A buffer overflow vulnerability has been identified in TOTOLink X6000R routers running version V9.4.0cu.652_B20230116. The vulnerability arises from inadequate length verification when adding Wi-Fi filtering rules. Attackers exploiting this issue can cause the device to crash or execute arbitrary commands.

4.3
Feb 11, 2025

Trendnet TEG-40128 Web Smart Switch Buffer Overflow Vulnerability

A buffer overflow vulnerability has been identified in the Trendnet TEG-40128 Web Smart Switch, version 1.00.023. This vulnerability arises from a lack of proper length verification during the mobile access point setup operation. An attacker can exploit this flaw to gain direct control over the affected device.

3.9