CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Rockwell Automation FactoryTalk View SE Local Code Injection Vulnerability
A local code injection vulnerability has been identified in Rockwell Automation's FactoryTalk View Site Edition versions prior to 15.0. This vulnerability arises from incorrect default permissions, allowing DLLs to be executed with elevated privileges.
Rockwell Automation FactoryTalk View SE Incorrect Permission Assignment Vulnerability Allowing Unauthenticated Access to System Configuration
A vulnerability exists in FactoryTalk View Site Edition versions prior to 15.0, as well as in versions 12, 13, and 14 of the same product. This vulnerability is due to incorrect permissions assigned to the remote debugger port, which can lead to unauthenticated access to the system configuration.
Intelbras InControl Cleartext Transmission Vulnerability in Registered User Handler
A vulnerability exists in Intelbras InControl versions through 2.21.58, specifically within the Registered User Handler component. The issue arises in an unknown part of the code related to the file '/v1/usuario/', where sensitive information is transmitted in cleartext. This vulnerability can be exploited remotely, although the complexity of the attack is considered high, making exploitation difficult.
Android Settings App Elevation of Privilege Vulnerability
A vulnerability in the Android Settings application allows for a local elevation of privilege by bypassing factory reset protections. This issue arises from a missing permission check in the 'shouldSkipForInitialSUW' method of 'AdvancedPowerUsageDetail.java'. Exploitation of this vulnerability does not require any additional execution privileges or user interaction.
Android Account Manager Service Intent Security Bypass Vulnerability Allowing Privilege Escalation
A vulnerability in the AccountManagerService component of the Android framework has been identified, allowing for a potential bypass of intent security checks. This issue arises from a confused deputy scenario, where an unknown app could be installed without the user's consent. The vulnerability could lead to local escalation of privileges, with no additional execution rights required for exploitation.
Android Framework Intent Component Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the Android Framework's Intent component, specifically in the parseUriInternal function of Intent.java. This issue arises from inadequate input validation, which can lead to a potential infinite loop. The vulnerability can be exploited locally, without requiring any additional execution privileges or user interaction.
Android WiFi Module Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the Android WiFi module, specifically within the WifiConfigurationUtil component. The issue arises from a logic error that allows for an overflow of a system configuration file. This vulnerability can be exploited locally, without the need for additional execution privileges or user interaction.
Android Libcore ZipFile Dynamic Code Loading Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in the Android Libcore component, specifically within the ZipFile class. This issue arises from improper input validation, which creates a potential for attackers to manipulate dynamic code loading. The vulnerability affects several versions of Android and can be exploited without requiring additional execution privileges or user interaction.
Android Intent Resolver ChooserActivity Elevation of Privilege Vulnerability
A vulnerability in the ChooserActivity component of the Android Intent Resolver module allows for a local elevation of privilege. This issue arises from a missing permission check, which creates a potential bypass of factory reset protections. Exploitation of this vulnerability does not require any additional execution privileges or user interaction.
Android PowerVR GPU Components Privilege Escalation Vulnerability
A use-after-free vulnerability has been identified in Imagination Technologies PowerVR GPU components of Android devices. This vulnerability arises from a race condition, which could lead to local escalation of privilege. Notably, no additional execution privileges are required for exploitation, and user interaction is not needed.
Android PowerVR GPU Components Use-After-Free Vulnerability Leading to Privilege Escalation
A use-after-free vulnerability has been identified in the PowerVR GPU component of Android, caused by a race condition. This vulnerability allows for local escalation of privilege, with no additional execution privileges required. Exploitation does not require user interaction.
Android PowerVR GPU Privilege Escalation Vulnerability
A use-after-free vulnerability has been identified in the PowerVR GPU component of Android, allowing for local escalation of privileges in the kernel. This vulnerability arises from a logic error in the code and can be exploited without any additional execution privileges or user interaction.
Android PowerVR GPU Kernel Privilege Escalation Vulnerability
A use-after-free vulnerability has been identified in the PowerVR GPU component of the Android kernel. This issue arises from a logic error in the code, which could lead to local escalation of privileges. Notably, no additional execution privileges are required for exploitation, and user interaction is not needed.
Android PowerVR GPU Privilege Escalation Vulnerability
A use-after-free vulnerability has been identified in the PowerVR GPU component of Android devices, specifically within the devicemem_server.c file. This vulnerability arises from improper casting, which could lead to local escalation of privileges in the kernel. Notably, exploitation does not require any additional execution privileges or user interaction.
Android PowerVR GPU Components Integer Overflow Vulnerability Leading to Arbitrary Code Execution
A vulnerability has been identified in the PowerVR GPU components of certain Android devices, allowing for arbitrary code execution. This issue arises from an integer overflow in the 'DevmemXIntMapPages' function of 'devicemem_server.c', which could facilitate local privilege escalation in the kernel without requiring additional execution privileges. Exploitation of this vulnerability does not involve user interaction.
Android PowerVR GPU Kernel Privilege Escalation Vulnerability
A race condition in the RGXMMUCacheInvalidate function of rgxmem.c can lead to arbitrary code execution, allowing for local privilege escalation in the kernel. This vulnerability does not require any additional execution privileges or user interaction for exploitation.
Rockwell Automation FactoryTalk View Machine Edition Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in Rockwell Automation's FactoryTalk View Machine Edition, versions prior to 15. This vulnerability arises from inadequate input sanitation, potentially allowing remote attackers to execute commands or code with high privileges.
Rockwell Automation FactoryTalk View Machine Edition Local Code Execution Vulnerability
A local code execution vulnerability has been identified in Rockwell Automation's FactoryTalk View Machine Edition, versions prior to 15. The issue arises from a default Windows setting that grants access to the Command Prompt with elevated privileges.
Rockwell Automation GuardLogix 5380 and 5580 Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Rockwell Automation's GuardLogix 5380 SIL3 and GuardLogix 5580 products, specifically in version 33.011. This vulnerability allows a remote, non-privileged user to send malicious requests that cause a major, non-recoverable fault, leading to a denial-of-service condition.
VMware Avi Load Balancer Unauthenticated Blind SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in VMware Avi Load Balancer, affecting versions 30.1.1, 30.1.2, 30.2.1, and 30.2.2. This vulnerability allows a malicious user with network access to execute specially crafted SQL queries, potentially leading to unauthorized database access. The issue has been assigned a CVSSv3 base score of 8.6, indicating a high severity level.
Pankajindevops Scale Improper Access Control Vulnerability in API Endpoint
A vulnerability has been identified in Pankajindevops Scale versions up to 20241113, concerning the API Endpoint component. This vulnerability involves improper access controls, allowing users with lower privileges to perform actions reserved for higher privilege roles, such as superAdmin. The issue arises because the application fails to verify user permissions before granting access to certain functionalities. As a result, a member account can execute high-level requests, potentially compromising the entire organization by allowing control over critical resources and actions.
Rockwell Automation PowerFlex 755 Credential Exposure Vulnerability
A credential exposure vulnerability exists in Rockwell Automation PowerFlex 755 versions through 16.002.279. This vulnerability arises from the use of HTTP, which allows credentials to be transmitted in clear text.
HPE Aruba Networking Fabric Composer Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the web management interface of HPE Aruba Networking Fabric Composer. This issue allows authenticated remote attackers to inject and execute arbitrary script code in the web browsers of users interacting with the compromised interface.
HPE Aruba Networking Fabric Composer Authenticated Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the web management interface of HPE Aruba Networking Fabric Composer, specifically in versions 7.1.0 and below. This vulnerability allows authenticated remote attackers to inject and execute arbitrary scripts in the context of the user's browser session within the compromised interface.
HPE Aruba Networking Fabric Composer Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the web management interface of HPE Aruba Networking Fabric Composer, specifically in versions 7.1.0 and prior. This vulnerability allows authenticated remote attackers to inject and execute arbitrary scripts in the context of the victim's browser, using the compromised interface.
HPE Aruba Networking Fabric Composer Authenticated Privilege Escalation Vulnerability
A vulnerability exists in the web-based management interface of HPE Aruba Networking Fabric Composer, specifically in version 7.1.0 and prior. This vulnerability allows an authenticated low-privilege operator user to perform actions beyond their assigned privilege level. Exploitation of this issue could enable manipulation of user-generated files, potentially resulting in unauthorized modifications to critical system configurations.
HPE Aruba Networking Fabric Composer Privilege Escalation Vulnerability
A privilege escalation vulnerability has been identified in the web-based management interface of HPE Aruba Networking Fabric Composer, version 7.1.0 and prior. This vulnerability allows an authenticated low-privilege operator user to alter the state of certain settings on a vulnerable system. The issue arises from broken access control, which could be exploited to manipulate user-generated files and make unauthorized changes to critical system configurations.
Red Hat OpenShift GitOps Operator Namespace Isolation Vulnerability
A vulnerability exists in the OpenShift GitOps operator container, where the label 'openshift.io/cluster-monitoring' is automatically applied to all namespaces with an ArgoCD custom resource instance. This label allows the creation of a potentially harmful PrometheusRule that impacts the entire platform monitoring stack, as the rule is distributed cluster-wide. This vulnerability breaks namespace isolation, enabling broader effects on the cluster.
FlightGear and SimGear Sandboxing Bypass Vulnerability Allowing Arbitrary File Write
A vulnerability exists in both FlightGear and SimGear that allows an attacker to bypass the sandboxing of Nasal scripts. This exploitation enables arbitrary writing to any file path that the user is permitted to modify at the operating system level.
Schneider Electric EcoStruxure Power Products Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been identified in Schneider Electric's EcoStruxure Power Monitoring Expert (PME) 2021, PME 2020, Power Operation (EPO) 2022, and Power Operation 2021. This vulnerability allows authenticated attackers to modify folder names, potentially leading to the execution of malicious web code or unintended software behavior.
Android Audio Policy Service Uninitialized Data Information Disclosure Vulnerability
A vulnerability allowing information disclosure has been identified in the Android Audio Policy Service. This issue arises from uninitialized data in the 'onTransact' method of 'IAudioPolicyService.cpp', which could lead to local information leakage. The vulnerability exists in various Android versions, including 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
MediaTek WLAN TDLS Driver Elevation of Privilege Vulnerability
A critical elevation of privilege vulnerability has been identified in the MediaTek WLAN driver, specifically within the TDLS (Tunneled Direct Link Setup) functionality. The issue arises from a missing bounds check, which creates a potential for out-of-bounds write operations. This vulnerability could be exploited remotely, allowing an attacker to escalate privileges without requiring additional execution rights or user interaction. Devices running the Android 2018-06-01 security patch level or earlier are affected.
Google Android Information Disclosure Vulnerability in HEIF Decoder
A vulnerability allowing out-of-bounds read due to integer overflow has been identified in the HEIF decoder component of Google Android. This issue could lead to remote information disclosure without requiring additional execution privileges. Exploitation of this vulnerability does require user interaction.
Google Android Heif Decoder Out-of-Bounds Read Vulnerability Allowing Information Disclosure
A vulnerability in the HEIF decoder implementation in Google Android has been identified, where improper input validation can lead to a potential out-of-bounds read. This issue could result in remote information disclosure without requiring additional execution privileges. Exploitation of this vulnerability does require user interaction.
Hyperbridge ismp-grandpa Crate Vulnerability Allows Arbitrary Header Finality Verification
A critical vulnerability exists in the Hyperbridge ismp-grandpa crate, specifically in versions prior to 15.0.1. This vulnerability allows a malicious prover to deceive the verifier into accepting the finality of arbitrary headers. The issue arises because the verifier incorrectly accepts invalid signatures from GRANDPA precommits. This flaw could potentially be exploited to steal funds or disrupt other cross-chain applications.
JetBrains Products Local Privilege Escalation Vulnerability via ETW Host Service
A local privilege escalation vulnerability has been identified in multiple JetBrains products, including ReSharper, Rider, dotTrace, and the ETW Host Service. This vulnerability exists in specific versions of these products and allows unauthorized users to escalate privileges by exploiting the ETW Host Service.
Tandoor Recipes Unrestricted File Upload Vulnerability Leading to Stored Cross-Site Scripting
A stored cross-site scripting vulnerability has been identified in Tandoor Recipes versions through 1.5.23. The issue arises from the file upload feature, which allows users to upload arbitrary files, including HTML and SVG files. These file types can contain malicious content, such as cross-site scripting payloads. The vulnerability has been addressed in version 1.5.28.
Tandoor Recipes Local File Disclosure Vulnerability
A local file disclosure vulnerability exists in Tandoor Recipes versions through 1.5.23. The issue arises from the external storage feature, which allows users to enumerate and access the content of files on the server. This vulnerability can be exploited to read files from various directories, including sensitive locations like '/etc' and user home directories.
Tandoor Recipes Jinja2 Server-Side Template Injection Vulnerability Allowing Remote Code Execution
A server-side template injection vulnerability has been identified in Tandoor Recipes versions through 1.5.23. This vulnerability allows users to execute commands on the server via Jinja2 template syntax. In environments using the provided Docker Compose file, the commands are executed with root privileges. The issue arises because user input is unsanitized and can be crafted to exploit the template rendering process.
Computer Vision Annotation Tool Nuclio Tracker Functions Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in the Computer Vision Annotation Tool (CVAT) versions 1.1.0 prior to 2.25.0. This issue arises in CVAT deployments running serverless functions of type 'tracker' from the CVAT Git repository, specifically the TransT and SiamMask functions. Additionally, deployments using custom 'tracker' functions may be vulnerable, depending on how they manage state serialization. Functions that utilize unsafe serialization libraries like 'pickle' or 'jsonpickle' are likely to be affected. The vulnerability allows an attacker with an account on the CVAT instance to execute arbitrary code within the Nuclio function container.
Rockwell Automation DataEdge Platform DataMosaix Private Cloud Path Traversal Vulnerability
A path traversal vulnerability has been identified in Rockwell Automation's DataEdge Platform DataMosaix Private Cloud, affecting versions 7.11 and prior. This vulnerability allows an attacker with admin privileges to overwrite files outside the intended directory, including reports and user projects. The issue arises from the vulnerable endpoint accepting character sequences that can manipulate file paths.
HMS Networks Ewon Flexy 202 Cleartext Transmission of User Credentials Vulnerability
A vulnerability exists in the Ewon Flexy 202 device, where user credentials are transmitted in clear text without any encryption. This issue arises when users are added or when user credentials are modified through the device's web interface. The vulnerability affects all versions of the Ewon Flexy 202.
Arm Cortex and Neoverse CPUs Data Memory-Dependent Prefetch Engine Vulnerability Allowing Privileged Data Access
A vulnerability exists in certain Arm-based CPUs, including Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V2, Neoverse V3, and Neoverse V3AE. This vulnerability allows an unprivileged context to manipulate the data memory-dependent prefetch engine into fetching contents from privileged locations, which are normally inaccessible. The prefetched data can be consumed as addresses that are dereferenced, potentially leading to unauthorized access or exploitation.
Silicon Labs Ember ZNet Stack Zigbee Buffer Overflow Vulnerability in NWK/APS Layer
A buffer overflow vulnerability has been identified in the NWK/APS layer of the Ember ZNet stack, specifically within the Zigbee SDK version 8.0.0.0. This vulnerability arises from the processing of malformed packets, which can lead to an assertion failure.
Pimcore Customer Data Framework SQL Injection Vulnerability in Customer Management Endpoint
A critical SQL injection vulnerability has been identified in the Pimcore customer-data-framework versions prior to 4.2.0. The issue arises in the customer management framework's list endpoint, where the filterDefinition and filter parameters can be manipulated to execute arbitrary SQL commands. This vulnerability allows authenticated users to access sensitive data, modify data, or potentially gain complete control over the server.
Pimcore Stored Cross-Site Scripting Vulnerability in Search Document Component
A stored cross-site scripting vulnerability has been identified in Pimcore version 11.4.2. This issue arises in the Search Document component, where the application fails to properly sanitize PDF files uploaded by users. As a result, malicious scripts embedded in the PDFs can be executed in the context of the user's browser when the PDF is viewed. This vulnerability allows for session hijacking, defacement of web pages, and unauthorized access to sensitive information.
TeamViewer Clients Privilege Escalation Vulnerability
A vulnerability allowing local privilege escalation has been identified in the TeamViewer service component of TeamViewer Full Client and Host for Windows, prior to version 15.62. This issue arises from improper neutralization of argument delimiters, which allows an attacker with local unprivileged access to inject arguments and elevate privileges.
OpenShift Service Mesh Log Injection Vulnerability via HTTP Header Manipulation
A log injection vulnerability has been identified in OpenShift Service Mesh versions 2.6.3 and 2.5.6. This issue stems from improper sanitization of HTTP headers by Envoy, particularly the x-forwarded-for header. The vulnerability allows attackers to inject malicious payloads into service mesh logs, leading to log injection and spoofing attacks. Such injections can disrupt logging mechanisms, enabling manipulation of log entries or execution of reflected cross-site scripting (XSS) attacks.
OpenShift Service Mesh Envoy Improper HTTP Header Sanitization Vulnerability Allowing Access Control Bypass and Denial of Service
A vulnerability exists in OpenShift Service Mesh versions 2.6.3 and 2.5.6, where improper sanitization of HTTP headers in Envoy can lead to rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks. This flaw allows attackers to inject headers that manipulate request handling, potentially causing unauthorized access, request amplification, and denial-of-service conditions within the service mesh.
Red Hat OpenShift Container Platform CRI-O Path Traversal Vulnerability Allowing Arbitrary Unmounting
A path traversal vulnerability has been identified in CRI-O's log management functions, specifically UnMountPodLogs and LinkContainerLogs. This issue allows an attacker with the ability to create and delete Pods to unmount arbitrary host paths. The exploitation of this vulnerability could lead to a node-level denial-of-service by unmounting critical system directories.
