CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 21, 2025

Linksys E8450 Buffer Overflow Vulnerability in DHCP Field Parsing

A buffer overflow vulnerability has been identified in the Linksys E8450 router, specifically in version 1.2.00.360516. The issue arises because the parsed field 'hidden_dhcp_num' is copied to the stack without proper length verification, creating the potential for memory corruption.

6.0
Jan 21, 2025

Linksys E8450 Buffer Overflow Vulnerability in LAN IP Address Parsing

A buffer overflow vulnerability has been identified in the Linksys E8450 router, specifically in version 1.2.00.360516. The issue arises because the parsed field 'lan_ipaddr' is copied to the stack without proper length verification, creating the potential for memory corruption.

6.0
Jan 21, 2025

Linksys E8450 Buffer Overflow Vulnerability in DHCP Start IP Parsing

A buffer overflow vulnerability has been identified in the Linksys E8450 router, specifically in version 1.2.00.360516. The issue arises in the JSON parsing function 'sub_422eb8', where the 'dhcpstart_ip' field is copied to the stack using 'strcpy' without proper length validation. This lack of verification creates an opportunity for a buffer overflow, potentially allowing for arbitrary code execution or causing the device to crash.

4.6
Jan 21, 2025

Linksys E8450 Command Injection Vulnerability

A command injection vulnerability has been identified in the Linksys E8450 router, specifically in firmware version 1.2.00.360516. The issue arises in the 'id_email_check_btn' field, where user-supplied input is improperly sanitized before being passed to the system function, allowing for arbitrary command execution.

6.0
Jan 21, 2025

Linksys E8450 Buffer Overflow Vulnerability in IPv6 Protection Status Field

A buffer overflow vulnerability has been identified in the Linksys E8450 router, specifically in version 1.2.00.360516. The issue arises because the IPv6 protection status field is copied to the stack without proper length verification, allowing for potential memory corruption.

6.0
Jan 21, 2025

Linksys E8450 Buffer Overflow Vulnerability

A buffer overflow vulnerability has been identified in the Linksys E8450 router, specifically in version 1.2.00.360516. The vulnerability arises because the parsed action field is copied to the stack without proper length verification, allowing for potential memory corruption.

6.0
Jan 21, 2025

Linksys E8450 Command Injection Vulnerability in Email Registration

A command injection vulnerability has been identified in the Linksys E8450 router, specifically in firmware version 1.2.00.360516. The issue arises in the JSON parsing function of the device's portal CGI script, where the 'userEmail' field can be manipulated to execute arbitrary commands on the system.

6.0
Jan 21, 2025

Linksys E8450 Buffer Overflow Vulnerability in Dashboard Configuration Security

A buffer overflow vulnerability has been identified in the Linksys E8450 router, specifically in firmware version 1.2.00.360516. The issue arises in the JSON parsing function 'sub_422eb8', where the 'anonymous_protect_status' field is copied to the stack using 'strncpy' without proper length validation. This flaw can be exploited by sending crafted data to the 'portal.cgi' URL, causing the device to crash.

4.6
Jan 21, 2025

Linksys E8450 Buffer Overflow Vulnerability

A buffer overflow vulnerability has been identified in the Linksys E8450 router, specifically in version 1.2.00.360516. The issue arises because the parsed field (page) is copied to the stack without proper length verification, allowing for potential memory corruption.

6.0
Jan 21, 2025

Linksys E8450 Command Injection Vulnerability

A command injection vulnerability has been identified in the Linksys E8450 router, specifically in version 1.2.00.360516. The vulnerability arises in the 'wizard_status' component, allowing attackers to inject and execute arbitrary commands on the device.

6.0
Jan 21, 2025

GNU Binutils Incorrect Access Control Vulnerability in 'nm' Command

A vulnerability has been identified in GNU Binutils 'nm' command versions 2.43 and later, related to incorrect access control. This vulnerability allows for local exploitation, specifically within the 'nm --without-symbol-version' function.

4.1
Jan 21, 2025

Northern.tech Mender Client Insecure Permissions Vulnerability in Private Key File

A vulnerability exists in Northern.tech Mender Client versions 4.0.0 through 4.0.4, where private key files generated on devices may be improperly accessible to other users due to lax file permissions. This issue arises because the Mender authentication process creates a private key file with read permissions for other users, and these permissions are not corrected, potentially allowing unauthorized access to the key.

3.0
Jan 21, 2025

Northern.tech CFEngine Enterprise Mission Portal Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Northern.tech CFEngine Enterprise Mission Portal versions 3.24.0, 3.21.5, and earlier. The issue arises from missing input validation, allowing authenticated users with administrator privileges to inject JavaScript into text fields. This injected script could be executed by other users who access the same form. While the vulnerability is limited to the settings area and requires specific actions to exploit, it could facilitate XSS between two administrator accounts.

1.5
Jan 21, 2025

OrangeScrum Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in OrangeScrum version 2.0.11. This issue allows attackers to inject malicious JavaScript into user email fields, exploiting inadequate input validation. The consequence of this vulnerability could be account takeover.

4.2
Jan 21, 2025

Oracle JD Edwards EnterpriseOne Tools Business Logic Infra SEC Vulnerability Allowing Unauthorized Data Access and Modification

A vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, specifically in the Business Logic Infra SEC component, affecting versions prior to 9.2.9.0. This vulnerability allows low-privileged attackers with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Exploitation requires human interaction from a third party. While the vulnerability is contained within JD Edwards EnterpriseOne Tools, successful attacks could significantly impact additional products. The vulnerability could lead to unauthorized updates, inserts, or deletions of accessible data within JD Edwards EnterpriseOne Tools, as well as unauthorized read access to certain subsets of that data.

2.5
Jan 21, 2025

Mjolnir Moderation Tool for Matrix Command Execution Vulnerability

A vulnerability in the Mjolnir moderation tool for Matrix, specifically in version 1.9.0, allows the bot to respond to management commands from any room it is a member of. This issue can enable users who are not bot operators to access the bot's functions, including server administration components if activated. The vulnerability arises from a feature that improperly manages command responses based on room membership.

2.6
Jan 21, 2025

Ruijie RG-EW300N Remote Code Execution Vulnerability via Modified MQTT Broker Message

A remote code execution vulnerability has been identified in the Ruijie RG-EW300N router running ReyeeOS firmware version 1.300.1422. The issue arises in the mqlink.elf service component, where intercepted and modified MQTT broker messages can be used to execute shell commands on the device.

4.4
Jan 21, 2025

Homarr Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in Homarr versions prior to 0.14.0. This issue arises in the Notebook widget, allowing for the injection of malicious scripts that are executed in the context of the user.

1.6
Jan 21, 2025

GitHub Enterprise Server Signature Spoofing Vulnerability via Improper SAML Validation

A vulnerability allowing signature spoofing has been identified in GitHub Enterprise Server. This issue arises from improper verification of cryptographic signatures in SAML responses, which could be exploited by unauthorized internal users to gain access to accounts with administrator privileges. The vulnerability affects all versions of GitHub Enterprise Server prior to 3.12.14, 3.13.10, 3.14.7, 3.15.2, and 3.16.0. Instances not using SAML single sign-on or where the attacker is not an existing user are not impacted.

2.9
Jan 21, 2025

RAR Extractor - Unarchiver Free and Pro Code Injection Vulnerability on MacOS

A code injection vulnerability has been identified in RAR Extractor - Unarchiver Free and Pro version 6.4.0. This issue allows local attackers to inject arbitrary code, potentially leading to remote control of the victim's machine and unauthorized access to sensitive user data. The vulnerability arises from the application's handling of dynamic libraries on MacOS, specifically through the exploit_combined.dylib component.

2.5
Jan 21, 2025

System.Linq.Dynamic.Core Reflection Access Vulnerability

A vulnerability in System.Linq.Dynamic.Core versions prior to 1.6.0 allows remote access to properties on reflection types and static properties or fields. This issue can be exploited to list the names and versions of installed NuGet packages, potentially leading to the exploitation of known vulnerabilities in those packages. The vulnerability arises from improper handling of reflection types and static members, which can be accessed through dynamic LINQ expressions.

3.9
Jan 21, 2025

JetBrains TeamCity Connection Secrets Decryption Vulnerability

A vulnerability in JetBrains TeamCity versions prior to 2024.12.1 allows for the decryption of connection secrets through the Test Connection endpoint, without the necessary permissions. This issue could lead to unauthorized access to sensitive information.

3.6
Jan 21, 2025

JetBrains TeamCity Improper Access Control Vulnerability in Agent Pool

A vulnerability in JetBrains TeamCity prior to version 2024.12.1 allowed improper access control, which enabled unauthorized users to view project names in the agent pool. This issue was related to the visibility of project information without appropriate permissions.

4.5
Jan 21, 2025

JetBrains TeamCity Reflected Cross-Site Scripting Vulnerability in Vault Connection Page

A reflected cross-site scripting vulnerability has been identified in JetBrains TeamCity versions prior to 2024.12.1. This issue occurs on the Vault Connection page, where user input is not properly sanitized, allowing for the injection of malicious scripts.

3.5
Jan 21, 2025

JetBrains YouTrack Account Takeover Vulnerability via Spoofed Email and Helpdesk Integration

A vulnerability allowing account takeover was identified in JetBrains YouTrack versions prior to 2024.3.55417. This issue arose from the improper handling of email headers, which enabled spoofing attacks. The vulnerability was exacerbated by the integration of YouTrack with Helpdesk, allowing unauthorized users to manipulate issue comments and attachments.

4.5
Jan 21, 2025

JetBrains YouTrack Permanent Token Exposure Vulnerability

A vulnerability exists in JetBrains YouTrack versions prior to 2024.3.55417, where permanent tokens could be inadvertently logged and exposed in the application logs. This issue could potentially lead to unauthorized access or actions, depending on the context in which the tokens are used.

4.4
Jan 21, 2025

JetBrains Hub Privilege Escalation Vulnerability via LDAP Authentication Mapping

A privilege escalation vulnerability has been identified in JetBrains Hub versions prior to 2024.3.55417. This vulnerability arises from improper handling of LDAP authentication mapping, which could be exploited to gain elevated privileges.

2.0
Jan 21, 2025

WeGIA Open Redirect Vulnerability in Control.php Endpoint

A vulnerability allowing open redirection has been identified in the WeGIA application, specifically in the control.php endpoint of versions prior to 3.2.10. This vulnerability allows authenticated users to be redirected to arbitrary external URLs via the nextPage parameter, which is not properly validated. As a result, this issue could be exploited for phishing attacks or to direct users to malicious websites. Unauthenticated users will receive a 'Client not authorized' message.

2.8
Jan 21, 2025

YesWiki Authenticated Arbitrary File Deletion Vulnerability

A vulnerability allowing authenticated users to delete any file owned by the user running the FastCGI Process Manager (FPM) has been identified in YesWiki versions through 4.4.5. This issue arises from the filemanager's lack of restrictions on the filesystem's scope, enabling the deletion of files attached to wiki pages or files in the /tmp directory. In standard installations, this could also include critical PHP files, potentially disrupting access to the wiki.

3.9
Jan 21, 2025

WordPress AnyRoad Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress AnyRoad plugin, affecting versions through 1.3.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 21, 2025

Estatebud Properties & Listings Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Estatebud Properties & Listings WordPress plugin, affecting versions through 5.5.0. This vulnerability arises from improper input neutralization during web page generation, allowing malicious users to inject harmful scripts that are executed when the affected page is viewed.

2.0
Jan 21, 2025

WordPress BizLibrary Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress BizLibrary plugin, affecting versions through 1.1. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 21, 2025

WordPress SexBundle Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress SexBundle plugin, affecting versions through 1.4. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected page.

2.0
Jan 21, 2025

WordPress WP-Announcements Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress WP-Announcements plugin, specifically in versions through 1.8. This issue allows attackers to inject malicious scripts that are executed when users visit the affected page.

2.0
Jan 21, 2025

Realty Workstation Broken Access Control Vulnerability

A broken access control vulnerability has been identified in the Realty Workstation WordPress plugin, affecting versions through 1.0.45. This vulnerability allows users to access functionalities that are not properly restricted by access control lists (ACLs), potentially leading to unauthorized actions or data exposure.

2.9
Jan 21, 2025

WordPress Social2Blog Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Social2Blog plugin, specifically in versions through 0.2.990. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 21, 2025

Nature FlipBook Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Nature FlipBook WordPress plugin, affecting versions through 1.7. This issue allows for improper neutralization of input, enabling the injection of malicious scripts that could be executed when users visit the affected site.

2.0
Jan 21, 2025

WordPress Widget Options Plugin Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the WordPress Widget Options plugin, specifically in versions through 4.0.8. This vulnerability allows exploitation of improperly configured access control security levels, potentially leading to unauthorized actions by users with lower privileges.

1.8
Jan 21, 2025

WordPress ApplyOnline Plugin Broken Access Control Vulnerability

A broken access control vulnerability has been identified in the WordPress ApplyOnline – Application Form Builder and Manager plugin, affecting versions through 2.6.7.1. This vulnerability arises from missing authorization checks, allowing unprivileged users to perform actions reserved for higher privileges.

1.8
Jan 21, 2025

vcita Online Payments Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the vcita Online Payments WordPress plugin, specifically in versions through 3.20.0. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.

3.1
Jan 21, 2025

WordPress Related Post Shortcode Plugin Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Related Post Shortcode plugin, specifically in versions through 1.2. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.5
Jan 21, 2025

Weaver Themes Shortcode Compatibility Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Weaver Themes Shortcode Compatibility plugin, affecting versions through 1.0.4. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.7
Jan 21, 2025

Undici HTTP Client Boundary Manipulation Vulnerability in Multipart Requests

A vulnerability exists in the Undici HTTP/1.1 client, specifically in versions 4.5.0 prior to 5.28.5, 6.0.0 prior to 6.21.1, and 7.0.0 prior to 7.2.3. The issue arises because Undici uses Math.random() to generate the boundary for multipart/form-data requests. This randomness can be predicted if an attacker knows several generated values. If an application sends multipart requests to an attacker-controlled server, the attacker could exploit this to intercept the boundary values and manipulate the request data sent to backend APIs.

4.4
Jan 21, 2025

SpagoBI Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in SpagoBI version 3.5.1. This issue resides within the worksheet designer function, specifically in the create and edit forms, where user input is not properly sanitized, allowing for the injection of malicious scripts.

3.2
Jan 21, 2025

SpagoBI Command Injection Vulnerability Allowing Arbitrary Code Execution

A command injection vulnerability has been identified in SpagoBI version 3.5.1. This issue arises in the script input feature, where an authenticated user can execute arbitrary code on the server. The vulnerability is exploited by writing a Groovy script that executes operating system commands, potentially leading to unauthorized access or manipulation of the server.

3.4
Jan 21, 2025

SpagoBI Cross-Site Request Forgery Vulnerability in User Administration Panel

A Cross-Site Request Forgery (CSRF) vulnerability exists in SpagoBI version 3.5.1, specifically within the user administration panel. This vulnerability allows an authenticated user to manipulate another user into performing unintended actions, such as adding, editing, or deleting users, while they are logged into the application.

3.6
Jan 21, 2025

YesWiki Authenticated Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in YesWiki versions through 4.4.5. This issue allows authenticated users with permission to edit or create pages and comments to inject malicious scripts. The vulnerability arises from improper sanitization of file names in the 'attach' component, which is used to upload files or media to pages. When a non-existent file is referenced, the server generates a file upload button that includes the file name, creating an opportunity for script injection. Exploiting this vulnerability could lead to account takeover by stealing password reset links through the injected script, according to the vulnerability advisory.

3.8
Jan 21, 2025

Payara Platform Payara Server and Payara Micro HTTP Request/Response Splitting Vulnerability

A vulnerability allowing HTTP request/response splitting has been identified in Payara Platform Payara Server (Grizzly, REST Management Interface modules) and Payara Platform Payara Micro (Grizzly modules). This vulnerability, present in several versions, including Payara Server 4.1.151 prior to 4.1.2.191.51, 5.20.0 prior to 5.70.0, 5.2020.2 prior to 5.2022.5, 6.2022.1 prior to 6.2024.12, and 6.0.0 prior to 6.21.0, as well as Payara Micro versions 4.1.152 prior to 4.1.2.191.51, 5.20.0 prior to 5.70.0, 5.2020.2 prior to 5.2022.5, 6.2022.1 prior to 6.2024.12, and 6.0.0 prior to 6.21.0, arises from improper handling of carriage return and line feed (CRLF) sequences in HTTP headers. This flaw can be exploited to manipulate state and spoof identity.

2.6
Jan 21, 2025

YesWiki DOM-Based Cross-Site Scripting Vulnerability Allowing Account Takeover

A DOM-based cross-site scripting (XSS) vulnerability has been identified in YesWiki versions through 4.4.5. This issue allows any end-user to craft a malicious link that triggers XSS on all YesWiki pages, particularly exploiting the search by tag feature. When a non-existent tag is searched, the tag name is reflected on the page without proper server-side sanitization. This flaw enables a user to create a link that, when clicked, executes client-side scripts. The vulnerability can lead to account takeover by stealing session information from users, including administrators, through a weak password recovery mechanism.

4.2
Jan 21, 2025

Umbraco Cross-Site Scripting Vulnerability in Localized Backoffice Components

A cross-site scripting vulnerability has been identified in Umbraco, a .NET content management system, affecting versions 14.0.0 prior to 14.3.2 and 15.1.2. This vulnerability allows authenticated users to inject malicious scripts when viewing certain localized backoffice components. The issue arises because user input is not properly sanitized before being displayed, particularly in the dictionary workspace.

5.2