CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 28, 2025

Android PowerVR GPU Kernel Privilege Escalation Vulnerability

A race condition in the RGXMMUCacheInvalidate function of rgxmem.c can lead to arbitrary code execution, allowing for local privilege escalation in the kernel. This vulnerability does not require any additional execution privileges or user interaction for exploitation.

1.5
Jan 28, 2025

Rockwell Automation FactoryTalk View Machine Edition Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in Rockwell Automation's FactoryTalk View Machine Edition, versions prior to 15. This vulnerability arises from inadequate input sanitation, potentially allowing remote attackers to execute commands or code with high privileges.

2.6
Jan 28, 2025

Rockwell Automation FactoryTalk View Machine Edition Local Code Execution Vulnerability

A local code execution vulnerability has been identified in Rockwell Automation's FactoryTalk View Machine Edition, versions prior to 15. The issue arises from a default Windows setting that grants access to the Command Prompt with elevated privileges.

1.6
Jan 28, 2025

Rockwell Automation GuardLogix 5380 and 5580 Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in Rockwell Automation's GuardLogix 5380 SIL3 and GuardLogix 5580 products, specifically in version 33.011. This vulnerability allows a remote, non-privileged user to send malicious requests that cause a major, non-recoverable fault, leading to a denial-of-service condition.

2.5
Jan 28, 2025

VMware Avi Load Balancer Unauthenticated Blind SQL Injection Vulnerability

A blind SQL injection vulnerability has been identified in VMware Avi Load Balancer, affecting versions 30.1.1, 30.1.2, 30.2.1, and 30.2.2. This vulnerability allows a malicious user with network access to execute specially crafted SQL queries, potentially leading to unauthorized database access. The issue has been assigned a CVSSv3 base score of 8.6, indicating a high severity level.

2.5
Jan 28, 2025

Pankajindevops Scale Improper Access Control Vulnerability in API Endpoint

A vulnerability has been identified in Pankajindevops Scale versions up to 20241113, concerning the API Endpoint component. This vulnerability involves improper access controls, allowing users with lower privileges to perform actions reserved for higher privilege roles, such as superAdmin. The issue arises because the application fails to verify user permissions before granting access to certain functionalities. As a result, a member account can execute high-level requests, potentially compromising the entire organization by allowing control over critical resources and actions.

3.1
Jan 28, 2025

Rockwell Automation PowerFlex 755 Credential Exposure Vulnerability

A credential exposure vulnerability exists in Rockwell Automation PowerFlex 755 versions through 16.002.279. This vulnerability arises from the use of HTTP, which allows credentials to be transmitted in clear text.

2.0
Jan 28, 2025

HPE Aruba Networking Fabric Composer Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the web management interface of HPE Aruba Networking Fabric Composer. This issue allows authenticated remote attackers to inject and execute arbitrary script code in the web browsers of users interacting with the compromised interface.

1.9
Jan 28, 2025

HPE Aruba Networking Fabric Composer Authenticated Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the web management interface of HPE Aruba Networking Fabric Composer, specifically in versions 7.1.0 and below. This vulnerability allows authenticated remote attackers to inject and execute arbitrary scripts in the context of the user's browser session within the compromised interface.

1.9
Jan 28, 2025

HPE Aruba Networking Fabric Composer Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the web management interface of HPE Aruba Networking Fabric Composer, specifically in versions 7.1.0 and prior. This vulnerability allows authenticated remote attackers to inject and execute arbitrary scripts in the context of the victim's browser, using the compromised interface.

1.9
Jan 28, 2025

HPE Aruba Networking Fabric Composer Authenticated Privilege Escalation Vulnerability

A vulnerability exists in the web-based management interface of HPE Aruba Networking Fabric Composer, specifically in version 7.1.0 and prior. This vulnerability allows an authenticated low-privilege operator user to perform actions beyond their assigned privilege level. Exploitation of this issue could enable manipulation of user-generated files, potentially resulting in unauthorized modifications to critical system configurations.

2.0
Jan 28, 2025

HPE Aruba Networking Fabric Composer Privilege Escalation Vulnerability

A privilege escalation vulnerability has been identified in the web-based management interface of HPE Aruba Networking Fabric Composer, version 7.1.0 and prior. This vulnerability allows an authenticated low-privilege operator user to alter the state of certain settings on a vulnerable system. The issue arises from broken access control, which could be exploited to manipulate user-generated files and make unauthorized changes to critical system configurations.

2.0
Jan 28, 2025

Red Hat OpenShift GitOps Operator Namespace Isolation Vulnerability

A vulnerability exists in the OpenShift GitOps operator container, where the label 'openshift.io/cluster-monitoring' is automatically applied to all namespaces with an ArgoCD custom resource instance. This label allows the creation of a potentially harmful PrometheusRule that impacts the entire platform monitoring stack, as the rule is distributed cluster-wide. This vulnerability breaks namespace isolation, enabling broader effects on the cluster.

2.8
Jan 28, 2025

FlightGear and SimGear Sandboxing Bypass Vulnerability Allowing Arbitrary File Write

A vulnerability exists in both FlightGear and SimGear that allows an attacker to bypass the sandboxing of Nasal scripts. This exploitation enables arbitrary writing to any file path that the user is permitted to modify at the operating system level.

2.1
Jan 28, 2025

Schneider Electric EcoStruxure Power Products Cross-Site Scripting Vulnerability

A cross-site scripting vulnerability has been identified in Schneider Electric's EcoStruxure Power Monitoring Expert (PME) 2021, PME 2020, Power Operation (EPO) 2022, and Power Operation 2021. This vulnerability allows authenticated attackers to modify folder names, potentially leading to the execution of malicious web code or unintended software behavior.

2.5
Jan 28, 2025

Android Audio Policy Service Uninitialized Data Information Disclosure Vulnerability

A vulnerability allowing information disclosure has been identified in the Android Audio Policy Service. This issue arises from uninitialized data in the 'onTransact' method of 'IAudioPolicyService.cpp', which could lead to local information leakage. The vulnerability exists in various Android versions, including 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.

1.1
Jan 28, 2025

MediaTek WLAN TDLS Driver Elevation of Privilege Vulnerability

A critical elevation of privilege vulnerability has been identified in the MediaTek WLAN driver, specifically within the TDLS (Tunneled Direct Link Setup) functionality. The issue arises from a missing bounds check, which creates a potential for out-of-bounds write operations. This vulnerability could be exploited remotely, allowing an attacker to escalate privileges without requiring additional execution rights or user interaction. Devices running the Android 2018-06-01 security patch level or earlier are affected.

2.6
Jan 28, 2025

Google Android Information Disclosure Vulnerability in HEIF Decoder

A vulnerability allowing out-of-bounds read due to integer overflow has been identified in the HEIF decoder component of Google Android. This issue could lead to remote information disclosure without requiring additional execution privileges. Exploitation of this vulnerability does require user interaction.

2.0
Jan 28, 2025

Google Android Heif Decoder Out-of-Bounds Read Vulnerability Allowing Information Disclosure

A vulnerability in the HEIF decoder implementation in Google Android has been identified, where improper input validation can lead to a potential out-of-bounds read. This issue could result in remote information disclosure without requiring additional execution privileges. Exploitation of this vulnerability does require user interaction.

2.0
Jan 28, 2025

Hyperbridge ismp-grandpa Crate Vulnerability Allows Arbitrary Header Finality Verification

A critical vulnerability exists in the Hyperbridge ismp-grandpa crate, specifically in versions prior to 15.0.1. This vulnerability allows a malicious prover to deceive the verifier into accepting the finality of arbitrary headers. The issue arises because the verifier incorrectly accepts invalid signatures from GRANDPA precommits. This flaw could potentially be exploited to steal funds or disrupt other cross-chain applications.

3.6
Jan 28, 2025

JetBrains Products Local Privilege Escalation Vulnerability via ETW Host Service

A local privilege escalation vulnerability has been identified in multiple JetBrains products, including ReSharper, Rider, dotTrace, and the ETW Host Service. This vulnerability exists in specific versions of these products and allows unauthorized users to escalate privileges by exploiting the ETW Host Service.

3.2
Jan 28, 2025

Tandoor Recipes Unrestricted File Upload Vulnerability Leading to Stored Cross-Site Scripting

A stored cross-site scripting vulnerability has been identified in Tandoor Recipes versions through 1.5.23. The issue arises from the file upload feature, which allows users to upload arbitrary files, including HTML and SVG files. These file types can contain malicious content, such as cross-site scripting payloads. The vulnerability has been addressed in version 1.5.28.

3.7
Jan 28, 2025

Tandoor Recipes Local File Disclosure Vulnerability

A local file disclosure vulnerability exists in Tandoor Recipes versions through 1.5.23. The issue arises from the external storage feature, which allows users to enumerate and access the content of files on the server. This vulnerability can be exploited to read files from various directories, including sensitive locations like '/etc' and user home directories.

3.8
Jan 28, 2025

Tandoor Recipes Jinja2 Server-Side Template Injection Vulnerability Allowing Remote Code Execution

A server-side template injection vulnerability has been identified in Tandoor Recipes versions through 1.5.23. This vulnerability allows users to execute commands on the server via Jinja2 template syntax. In environments using the provided Docker Compose file, the commands are executed with root privileges. The issue arises because user input is unsanitized and can be crafted to exploit the template rendering process.

3.9
Jan 28, 2025

Computer Vision Annotation Tool Nuclio Tracker Functions Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in the Computer Vision Annotation Tool (CVAT) versions 1.1.0 prior to 2.25.0. This issue arises in CVAT deployments running serverless functions of type 'tracker' from the CVAT Git repository, specifically the TransT and SiamMask functions. Additionally, deployments using custom 'tracker' functions may be vulnerable, depending on how they manage state serialization. Functions that utilize unsafe serialization libraries like 'pickle' or 'jsonpickle' are likely to be affected. The vulnerability allows an attacker with an account on the CVAT instance to execute arbitrary code within the Nuclio function container.

4.8
Jan 28, 2025

Rockwell Automation DataEdge Platform DataMosaix Private Cloud Path Traversal Vulnerability

A path traversal vulnerability has been identified in Rockwell Automation's DataEdge Platform DataMosaix Private Cloud, affecting versions 7.11 and prior. This vulnerability allows an attacker with admin privileges to overwrite files outside the intended directory, including reports and user projects. The issue arises from the vulnerable endpoint accepting character sequences that can manipulate file paths.

1.5
Jan 28, 2025

HMS Networks Ewon Flexy 202 Cleartext Transmission of User Credentials Vulnerability

A vulnerability exists in the Ewon Flexy 202 device, where user credentials are transmitted in clear text without any encryption. This issue arises when users are added or when user credentials are modified through the device's web interface. The vulnerability affects all versions of the Ewon Flexy 202.

3.7
Jan 28, 2025

Arm Cortex and Neoverse CPUs Data Memory-Dependent Prefetch Engine Vulnerability Allowing Privileged Data Access

A vulnerability exists in certain Arm-based CPUs, including Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V2, Neoverse V3, and Neoverse V3AE. This vulnerability allows an unprivileged context to manipulate the data memory-dependent prefetch engine into fetching contents from privileged locations, which are normally inaccessible. The prefetched data can be consumed as addresses that are dereferenced, potentially leading to unauthorized access or exploitation.

4.2
Jan 28, 2025

Silicon Labs Ember ZNet Stack Zigbee Buffer Overflow Vulnerability in NWK/APS Layer

A buffer overflow vulnerability has been identified in the NWK/APS layer of the Ember ZNet stack, specifically within the Zigbee SDK version 8.0.0.0. This vulnerability arises from the processing of malformed packets, which can lead to an assertion failure.

5.6
Jan 28, 2025

Pimcore Customer Data Framework SQL Injection Vulnerability in Customer Management Endpoint

A critical SQL injection vulnerability has been identified in the Pimcore customer-data-framework versions prior to 4.2.0. The issue arises in the customer management framework's list endpoint, where the filterDefinition and filter parameters can be manipulated to execute arbitrary SQL commands. This vulnerability allows authenticated users to access sensitive data, modify data, or potentially gain complete control over the server.

3.0
Jan 28, 2025

Pimcore Stored Cross-Site Scripting Vulnerability in Search Document Component

A stored cross-site scripting vulnerability has been identified in Pimcore version 11.4.2. This issue arises in the Search Document component, where the application fails to properly sanitize PDF files uploaded by users. As a result, malicious scripts embedded in the PDFs can be executed in the context of the user's browser when the PDF is viewed. This vulnerability allows for session hijacking, defacement of web pages, and unauthorized access to sensitive information.

4.2
Jan 28, 2025

TeamViewer Clients Privilege Escalation Vulnerability

A vulnerability allowing local privilege escalation has been identified in the TeamViewer service component of TeamViewer Full Client and Host for Windows, prior to version 15.62. This issue arises from improper neutralization of argument delimiters, which allows an attacker with local unprivileged access to inject arguments and elevate privileges.

4.8
Jan 28, 2025

OpenShift Service Mesh Log Injection Vulnerability via HTTP Header Manipulation

A log injection vulnerability has been identified in OpenShift Service Mesh versions 2.6.3 and 2.5.6. This issue stems from improper sanitization of HTTP headers by Envoy, particularly the x-forwarded-for header. The vulnerability allows attackers to inject malicious payloads into service mesh logs, leading to log injection and spoofing attacks. Such injections can disrupt logging mechanisms, enabling manipulation of log entries or execution of reflected cross-site scripting (XSS) attacks.

4.6
Jan 28, 2025

OpenShift Service Mesh Envoy Improper HTTP Header Sanitization Vulnerability Allowing Access Control Bypass and Denial of Service

A vulnerability exists in OpenShift Service Mesh versions 2.6.3 and 2.5.6, where improper sanitization of HTTP headers in Envoy can lead to rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks. This flaw allows attackers to inject headers that manipulate request handling, potentially causing unauthorized access, request amplification, and denial-of-service conditions within the service mesh.

4.7
Jan 28, 2025

Red Hat OpenShift Container Platform CRI-O Path Traversal Vulnerability Allowing Arbitrary Unmounting

A path traversal vulnerability has been identified in CRI-O's log management functions, specifically UnMountPodLogs and LinkContainerLogs. This issue allows an attacker with the ability to create and delete Pods to unmount arbitrary host paths. The exploitation of this vulnerability could lead to a node-level denial-of-service by unmounting critical system directories.

1.1
Jan 28, 2025

Infinispan Sensitive Information Exposure Vulnerability

A vulnerability exists in Infinispan when JGroups is used with JDBC_PING. This flaw can lead to the unintentional logging of sensitive information, such as configuration details and credentials, in plaintext. If logs are accessible to low-privileged users or attackers, this exposure could result in unauthorized access. The issue arises from misconfigurations that leave external addresses unresolved, causing connection details, including database usernames and passwords, to be logged.

1.7
Jan 28, 2025

GitLab CI Artifacts Metadata Processing Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in GitLab CE/EE versions 15.0 prior to 17.5.5, 17.6 prior to 17.6.3, and 17.7 prior to 17.7.1. Under certain conditions, the processing of CI artifacts metadata can cause background jobs to become unresponsive.

4.5
Jan 28, 2025

Apache Hive Timing Attack Vulnerability in Signature Verification

A timing attack vulnerability has been identified in Apache Hive versions 2.2.0 prior to 4.0.0. The issue arises in the LlapSignerImpl component, where the use of Arrays.equals() for comparing message signatures allows an authorized attacker to forge a valid signature for an arbitrary message, byte by byte. This vulnerability could enable malicious users to submit work with selected signatures to the LLAP (Live Long And Process) service without requiring privileged access, potentially leading to a denial-of-service condition.

3.7
Jan 28, 2025

Philantro Donations and Donor Management WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Philantro Donations and Donor Management plugin for WordPress, affecting all versions through 5.3. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's shortcodes, such as 'donate'. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.3
Jan 28, 2025

ElementsKit Pro DOM-Based Stored Cross-Site Scripting Vulnerability

A DOM-based stored cross-site scripting vulnerability has been identified in the ElementsKit Pro plugin for WordPress, affecting all versions through 3.7.8. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts via the 'url' parameter. These scripts are executed when a user accesses the compromised page.

3.7
Jan 28, 2025

MailUp Auto Subscription WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the MailUp Auto Subscription plugin for WordPress, affecting all versions through 1.1.0. The vulnerability arises from inadequate nonce validation in the 'mas_options' function, allowing unauthenticated attackers to manipulate settings and inject malicious scripts. Exploitation requires tricking a site administrator into clicking a link that initiates the forged request.

3.0
Jan 28, 2025

WS Form LITE and PRO Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WS Form LITE and PRO plugins for WordPress, affecting all versions through 1.10.13. The vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the url parameter. These injected scripts are executed when a user accesses the affected page.

4.1
Jan 28, 2025

ThemeREX Addons WordPress Plugin Unauthenticated Arbitrary File Upload Vulnerability

A vulnerability allowing arbitrary file uploads has been identified in the ThemeREX Addons plugin for WordPress, affecting all versions through 2.32.3. The issue arises from inadequate file type validation in the 'trx_addons_uploads_save_data' function, enabling unauthenticated attackers to upload arbitrary files to the server, potentially leading to remote code execution.

4.8
Jan 28, 2025

Social Share Buttons for WordPress Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Social Share Buttons for WordPress plugin, affecting versions through 2.7. The issue arises because the plugin fails to properly sanitize and escape certain settings. This flaw enables high-privilege users, such as administrators, to execute stored XSS attacks, even in environments where the unfiltered_html capability is restricted, such as multisite setups.

2.8
Jan 28, 2025

Infility Global WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Infility Global WordPress plugin, affecting versions through 2.9.8. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.

3.8
Jan 28, 2025

WordPress Plugin Simple Image Sizes Cross-Site Scripting Vulnerability

A cross-site scripting vulnerability has been identified in the WordPress plugin Simple Image Sizes, affecting versions through 3.2.3. This vulnerability allows an arbitrary script to be executed in the web browser of an administrator accessing the settings screen.

1.5
Jan 28, 2025

Node.js Path Traversal Vulnerability via Drive Name Handling on Windows

A path traversal vulnerability has been identified in Node.js, specifically in the way drive names are managed in the Windows environment. Certain Node.js functions fail to recognize drive names as special cases on Windows. Consequently, while Node.js assumes a path is relative, it actually points to the root directory. This issue arises because, on Windows, a path that does not begin with the file separator is considered relative to the current directory. The vulnerability affects users of the 'path.join' API on Windows.

4.2
Jan 28, 2025

Eventer WordPress Plugin SQL Injection Vulnerability in Attendee Management Function

A SQL injection vulnerability has been identified in the Eventer plugin for WordPress, affecting all versions through 3.9.8. The issue arises in the 'eventer_get_attendees' function, where insufficient escaping of user-supplied data in the 'event' parameter allows unauthenticated attackers to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information within the database.

3.0
Jan 28, 2025

NVIDIA vGPU Software Denial-of-Service Vulnerability via Interrupt Storm

A denial-of-service vulnerability has been identified in NVIDIA vGPU software, specifically in the host driver. This issue allows a guest to create an interrupt storm on the host, potentially leading to a denial-of-service condition. The vulnerability affects several different versions and branches of the vGPU software.

1.1
Jan 28, 2025

NVIDIA Unified Memory Driver Information Disclosure Vulnerability

A vulnerability in the NVIDIA Unified Memory driver for Linux allows an attacker to leak uninitialized memory, potentially leading to unauthorized information disclosure. This issue is present in several different driver versions prior to the latest updates.

1.1