CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Android PowerVR GPU Kernel Privilege Escalation Vulnerability
A race condition in the RGXMMUCacheInvalidate function of rgxmem.c can lead to arbitrary code execution, allowing for local privilege escalation in the kernel. This vulnerability does not require any additional execution privileges or user interaction for exploitation.
Rockwell Automation FactoryTalk View Machine Edition Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in Rockwell Automation's FactoryTalk View Machine Edition, versions prior to 15. This vulnerability arises from inadequate input sanitation, potentially allowing remote attackers to execute commands or code with high privileges.
Rockwell Automation FactoryTalk View Machine Edition Local Code Execution Vulnerability
A local code execution vulnerability has been identified in Rockwell Automation's FactoryTalk View Machine Edition, versions prior to 15. The issue arises from a default Windows setting that grants access to the Command Prompt with elevated privileges.
Rockwell Automation GuardLogix 5380 and 5580 Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Rockwell Automation's GuardLogix 5380 SIL3 and GuardLogix 5580 products, specifically in version 33.011. This vulnerability allows a remote, non-privileged user to send malicious requests that cause a major, non-recoverable fault, leading to a denial-of-service condition.
VMware Avi Load Balancer Unauthenticated Blind SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in VMware Avi Load Balancer, affecting versions 30.1.1, 30.1.2, 30.2.1, and 30.2.2. This vulnerability allows a malicious user with network access to execute specially crafted SQL queries, potentially leading to unauthorized database access. The issue has been assigned a CVSSv3 base score of 8.6, indicating a high severity level.
Pankajindevops Scale Improper Access Control Vulnerability in API Endpoint
A vulnerability has been identified in Pankajindevops Scale versions up to 20241113, concerning the API Endpoint component. This vulnerability involves improper access controls, allowing users with lower privileges to perform actions reserved for higher privilege roles, such as superAdmin. The issue arises because the application fails to verify user permissions before granting access to certain functionalities. As a result, a member account can execute high-level requests, potentially compromising the entire organization by allowing control over critical resources and actions.
Rockwell Automation PowerFlex 755 Credential Exposure Vulnerability
A credential exposure vulnerability exists in Rockwell Automation PowerFlex 755 versions through 16.002.279. This vulnerability arises from the use of HTTP, which allows credentials to be transmitted in clear text.
HPE Aruba Networking Fabric Composer Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the web management interface of HPE Aruba Networking Fabric Composer. This issue allows authenticated remote attackers to inject and execute arbitrary script code in the web browsers of users interacting with the compromised interface.
HPE Aruba Networking Fabric Composer Authenticated Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the web management interface of HPE Aruba Networking Fabric Composer, specifically in versions 7.1.0 and below. This vulnerability allows authenticated remote attackers to inject and execute arbitrary scripts in the context of the user's browser session within the compromised interface.
HPE Aruba Networking Fabric Composer Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the web management interface of HPE Aruba Networking Fabric Composer, specifically in versions 7.1.0 and prior. This vulnerability allows authenticated remote attackers to inject and execute arbitrary scripts in the context of the victim's browser, using the compromised interface.
HPE Aruba Networking Fabric Composer Authenticated Privilege Escalation Vulnerability
A vulnerability exists in the web-based management interface of HPE Aruba Networking Fabric Composer, specifically in version 7.1.0 and prior. This vulnerability allows an authenticated low-privilege operator user to perform actions beyond their assigned privilege level. Exploitation of this issue could enable manipulation of user-generated files, potentially resulting in unauthorized modifications to critical system configurations.
HPE Aruba Networking Fabric Composer Privilege Escalation Vulnerability
A privilege escalation vulnerability has been identified in the web-based management interface of HPE Aruba Networking Fabric Composer, version 7.1.0 and prior. This vulnerability allows an authenticated low-privilege operator user to alter the state of certain settings on a vulnerable system. The issue arises from broken access control, which could be exploited to manipulate user-generated files and make unauthorized changes to critical system configurations.
Red Hat OpenShift GitOps Operator Namespace Isolation Vulnerability
A vulnerability exists in the OpenShift GitOps operator container, where the label 'openshift.io/cluster-monitoring' is automatically applied to all namespaces with an ArgoCD custom resource instance. This label allows the creation of a potentially harmful PrometheusRule that impacts the entire platform monitoring stack, as the rule is distributed cluster-wide. This vulnerability breaks namespace isolation, enabling broader effects on the cluster.
FlightGear and SimGear Sandboxing Bypass Vulnerability Allowing Arbitrary File Write
A vulnerability exists in both FlightGear and SimGear that allows an attacker to bypass the sandboxing of Nasal scripts. This exploitation enables arbitrary writing to any file path that the user is permitted to modify at the operating system level.
Schneider Electric EcoStruxure Power Products Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been identified in Schneider Electric's EcoStruxure Power Monitoring Expert (PME) 2021, PME 2020, Power Operation (EPO) 2022, and Power Operation 2021. This vulnerability allows authenticated attackers to modify folder names, potentially leading to the execution of malicious web code or unintended software behavior.
Android Audio Policy Service Uninitialized Data Information Disclosure Vulnerability
A vulnerability allowing information disclosure has been identified in the Android Audio Policy Service. This issue arises from uninitialized data in the 'onTransact' method of 'IAudioPolicyService.cpp', which could lead to local information leakage. The vulnerability exists in various Android versions, including 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
MediaTek WLAN TDLS Driver Elevation of Privilege Vulnerability
A critical elevation of privilege vulnerability has been identified in the MediaTek WLAN driver, specifically within the TDLS (Tunneled Direct Link Setup) functionality. The issue arises from a missing bounds check, which creates a potential for out-of-bounds write operations. This vulnerability could be exploited remotely, allowing an attacker to escalate privileges without requiring additional execution rights or user interaction. Devices running the Android 2018-06-01 security patch level or earlier are affected.
Google Android Information Disclosure Vulnerability in HEIF Decoder
A vulnerability allowing out-of-bounds read due to integer overflow has been identified in the HEIF decoder component of Google Android. This issue could lead to remote information disclosure without requiring additional execution privileges. Exploitation of this vulnerability does require user interaction.
Google Android Heif Decoder Out-of-Bounds Read Vulnerability Allowing Information Disclosure
A vulnerability in the HEIF decoder implementation in Google Android has been identified, where improper input validation can lead to a potential out-of-bounds read. This issue could result in remote information disclosure without requiring additional execution privileges. Exploitation of this vulnerability does require user interaction.
Hyperbridge ismp-grandpa Crate Vulnerability Allows Arbitrary Header Finality Verification
A critical vulnerability exists in the Hyperbridge ismp-grandpa crate, specifically in versions prior to 15.0.1. This vulnerability allows a malicious prover to deceive the verifier into accepting the finality of arbitrary headers. The issue arises because the verifier incorrectly accepts invalid signatures from GRANDPA precommits. This flaw could potentially be exploited to steal funds or disrupt other cross-chain applications.
JetBrains Products Local Privilege Escalation Vulnerability via ETW Host Service
A local privilege escalation vulnerability has been identified in multiple JetBrains products, including ReSharper, Rider, dotTrace, and the ETW Host Service. This vulnerability exists in specific versions of these products and allows unauthorized users to escalate privileges by exploiting the ETW Host Service.
Tandoor Recipes Unrestricted File Upload Vulnerability Leading to Stored Cross-Site Scripting
A stored cross-site scripting vulnerability has been identified in Tandoor Recipes versions through 1.5.23. The issue arises from the file upload feature, which allows users to upload arbitrary files, including HTML and SVG files. These file types can contain malicious content, such as cross-site scripting payloads. The vulnerability has been addressed in version 1.5.28.
Tandoor Recipes Local File Disclosure Vulnerability
A local file disclosure vulnerability exists in Tandoor Recipes versions through 1.5.23. The issue arises from the external storage feature, which allows users to enumerate and access the content of files on the server. This vulnerability can be exploited to read files from various directories, including sensitive locations like '/etc' and user home directories.
Tandoor Recipes Jinja2 Server-Side Template Injection Vulnerability Allowing Remote Code Execution
A server-side template injection vulnerability has been identified in Tandoor Recipes versions through 1.5.23. This vulnerability allows users to execute commands on the server via Jinja2 template syntax. In environments using the provided Docker Compose file, the commands are executed with root privileges. The issue arises because user input is unsanitized and can be crafted to exploit the template rendering process.
Computer Vision Annotation Tool Nuclio Tracker Functions Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in the Computer Vision Annotation Tool (CVAT) versions 1.1.0 prior to 2.25.0. This issue arises in CVAT deployments running serverless functions of type 'tracker' from the CVAT Git repository, specifically the TransT and SiamMask functions. Additionally, deployments using custom 'tracker' functions may be vulnerable, depending on how they manage state serialization. Functions that utilize unsafe serialization libraries like 'pickle' or 'jsonpickle' are likely to be affected. The vulnerability allows an attacker with an account on the CVAT instance to execute arbitrary code within the Nuclio function container.
Rockwell Automation DataEdge Platform DataMosaix Private Cloud Path Traversal Vulnerability
A path traversal vulnerability has been identified in Rockwell Automation's DataEdge Platform DataMosaix Private Cloud, affecting versions 7.11 and prior. This vulnerability allows an attacker with admin privileges to overwrite files outside the intended directory, including reports and user projects. The issue arises from the vulnerable endpoint accepting character sequences that can manipulate file paths.
HMS Networks Ewon Flexy 202 Cleartext Transmission of User Credentials Vulnerability
A vulnerability exists in the Ewon Flexy 202 device, where user credentials are transmitted in clear text without any encryption. This issue arises when users are added or when user credentials are modified through the device's web interface. The vulnerability affects all versions of the Ewon Flexy 202.
Arm Cortex and Neoverse CPUs Data Memory-Dependent Prefetch Engine Vulnerability Allowing Privileged Data Access
A vulnerability exists in certain Arm-based CPUs, including Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V2, Neoverse V3, and Neoverse V3AE. This vulnerability allows an unprivileged context to manipulate the data memory-dependent prefetch engine into fetching contents from privileged locations, which are normally inaccessible. The prefetched data can be consumed as addresses that are dereferenced, potentially leading to unauthorized access or exploitation.
Silicon Labs Ember ZNet Stack Zigbee Buffer Overflow Vulnerability in NWK/APS Layer
A buffer overflow vulnerability has been identified in the NWK/APS layer of the Ember ZNet stack, specifically within the Zigbee SDK version 8.0.0.0. This vulnerability arises from the processing of malformed packets, which can lead to an assertion failure.
Pimcore Customer Data Framework SQL Injection Vulnerability in Customer Management Endpoint
A critical SQL injection vulnerability has been identified in the Pimcore customer-data-framework versions prior to 4.2.0. The issue arises in the customer management framework's list endpoint, where the filterDefinition and filter parameters can be manipulated to execute arbitrary SQL commands. This vulnerability allows authenticated users to access sensitive data, modify data, or potentially gain complete control over the server.
Pimcore Stored Cross-Site Scripting Vulnerability in Search Document Component
A stored cross-site scripting vulnerability has been identified in Pimcore version 11.4.2. This issue arises in the Search Document component, where the application fails to properly sanitize PDF files uploaded by users. As a result, malicious scripts embedded in the PDFs can be executed in the context of the user's browser when the PDF is viewed. This vulnerability allows for session hijacking, defacement of web pages, and unauthorized access to sensitive information.
TeamViewer Clients Privilege Escalation Vulnerability
A vulnerability allowing local privilege escalation has been identified in the TeamViewer service component of TeamViewer Full Client and Host for Windows, prior to version 15.62. This issue arises from improper neutralization of argument delimiters, which allows an attacker with local unprivileged access to inject arguments and elevate privileges.
OpenShift Service Mesh Log Injection Vulnerability via HTTP Header Manipulation
A log injection vulnerability has been identified in OpenShift Service Mesh versions 2.6.3 and 2.5.6. This issue stems from improper sanitization of HTTP headers by Envoy, particularly the x-forwarded-for header. The vulnerability allows attackers to inject malicious payloads into service mesh logs, leading to log injection and spoofing attacks. Such injections can disrupt logging mechanisms, enabling manipulation of log entries or execution of reflected cross-site scripting (XSS) attacks.
OpenShift Service Mesh Envoy Improper HTTP Header Sanitization Vulnerability Allowing Access Control Bypass and Denial of Service
A vulnerability exists in OpenShift Service Mesh versions 2.6.3 and 2.5.6, where improper sanitization of HTTP headers in Envoy can lead to rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks. This flaw allows attackers to inject headers that manipulate request handling, potentially causing unauthorized access, request amplification, and denial-of-service conditions within the service mesh.
Red Hat OpenShift Container Platform CRI-O Path Traversal Vulnerability Allowing Arbitrary Unmounting
A path traversal vulnerability has been identified in CRI-O's log management functions, specifically UnMountPodLogs and LinkContainerLogs. This issue allows an attacker with the ability to create and delete Pods to unmount arbitrary host paths. The exploitation of this vulnerability could lead to a node-level denial-of-service by unmounting critical system directories.
Infinispan Sensitive Information Exposure Vulnerability
A vulnerability exists in Infinispan when JGroups is used with JDBC_PING. This flaw can lead to the unintentional logging of sensitive information, such as configuration details and credentials, in plaintext. If logs are accessible to low-privileged users or attackers, this exposure could result in unauthorized access. The issue arises from misconfigurations that leave external addresses unresolved, causing connection details, including database usernames and passwords, to be logged.
GitLab CI Artifacts Metadata Processing Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in GitLab CE/EE versions 15.0 prior to 17.5.5, 17.6 prior to 17.6.3, and 17.7 prior to 17.7.1. Under certain conditions, the processing of CI artifacts metadata can cause background jobs to become unresponsive.
Apache Hive Timing Attack Vulnerability in Signature Verification
A timing attack vulnerability has been identified in Apache Hive versions 2.2.0 prior to 4.0.0. The issue arises in the LlapSignerImpl component, where the use of Arrays.equals() for comparing message signatures allows an authorized attacker to forge a valid signature for an arbitrary message, byte by byte. This vulnerability could enable malicious users to submit work with selected signatures to the LLAP (Live Long And Process) service without requiring privileged access, potentially leading to a denial-of-service condition.
Philantro Donations and Donor Management WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Philantro Donations and Donor Management plugin for WordPress, affecting all versions through 5.3. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's shortcodes, such as 'donate'. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
ElementsKit Pro DOM-Based Stored Cross-Site Scripting Vulnerability
A DOM-based stored cross-site scripting vulnerability has been identified in the ElementsKit Pro plugin for WordPress, affecting all versions through 3.7.8. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts via the 'url' parameter. These scripts are executed when a user accesses the compromised page.
MailUp Auto Subscription WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the MailUp Auto Subscription plugin for WordPress, affecting all versions through 1.1.0. The vulnerability arises from inadequate nonce validation in the 'mas_options' function, allowing unauthenticated attackers to manipulate settings and inject malicious scripts. Exploitation requires tricking a site administrator into clicking a link that initiates the forged request.
WS Form LITE and PRO Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WS Form LITE and PRO plugins for WordPress, affecting all versions through 1.10.13. The vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the url parameter. These injected scripts are executed when a user accesses the affected page.
ThemeREX Addons WordPress Plugin Unauthenticated Arbitrary File Upload Vulnerability
A vulnerability allowing arbitrary file uploads has been identified in the ThemeREX Addons plugin for WordPress, affecting all versions through 2.32.3. The issue arises from inadequate file type validation in the 'trx_addons_uploads_save_data' function, enabling unauthenticated attackers to upload arbitrary files to the server, potentially leading to remote code execution.
Social Share Buttons for WordPress Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Social Share Buttons for WordPress plugin, affecting versions through 2.7. The issue arises because the plugin fails to properly sanitize and escape certain settings. This flaw enables high-privilege users, such as administrators, to execute stored XSS attacks, even in environments where the unfiltered_html capability is restricted, such as multisite setups.
Infility Global WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Infility Global WordPress plugin, affecting versions through 2.9.8. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
WordPress Plugin Simple Image Sizes Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been identified in the WordPress plugin Simple Image Sizes, affecting versions through 3.2.3. This vulnerability allows an arbitrary script to be executed in the web browser of an administrator accessing the settings screen.
Node.js Path Traversal Vulnerability via Drive Name Handling on Windows
A path traversal vulnerability has been identified in Node.js, specifically in the way drive names are managed in the Windows environment. Certain Node.js functions fail to recognize drive names as special cases on Windows. Consequently, while Node.js assumes a path is relative, it actually points to the root directory. This issue arises because, on Windows, a path that does not begin with the file separator is considered relative to the current directory. The vulnerability affects users of the 'path.join' API on Windows.
Eventer WordPress Plugin SQL Injection Vulnerability in Attendee Management Function
A SQL injection vulnerability has been identified in the Eventer plugin for WordPress, affecting all versions through 3.9.8. The issue arises in the 'eventer_get_attendees' function, where insufficient escaping of user-supplied data in the 'event' parameter allows unauthenticated attackers to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information within the database.
NVIDIA vGPU Software Denial-of-Service Vulnerability via Interrupt Storm
A denial-of-service vulnerability has been identified in NVIDIA vGPU software, specifically in the host driver. This issue allows a guest to create an interrupt storm on the host, potentially leading to a denial-of-service condition. The vulnerability affects several different versions and branches of the vGPU software.
NVIDIA Unified Memory Driver Information Disclosure Vulnerability
A vulnerability in the NVIDIA Unified Memory driver for Linux allows an attacker to leak uninitialized memory, potentially leading to unauthorized information disclosure. This issue is present in several different driver versions prior to the latest updates.
