CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 22, 2025

Open5GS MME Assertion-Related Denial-of-Service Vulnerability via Malformed ASN.1 Packets

A denial-of-service vulnerability has been identified in Open5GS MME versions through 2.6.4. The issue arises from an assertion that can be remotely triggered by sending a malformed 'UE Context Modification Response' message over the S1AP interface. The malformed message can omit a required 'MME_UE_S1AP_ID' field, causing the MME to crash. This vulnerability can be exploited repeatedly, leading to a persistent denial-of-service condition.

4.7
Jan 22, 2025

Open5GS MME Path Switch Request Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability has been identified in Open5GS MME versions through 2.6.4. The issue arises from an assertion that can be remotely triggered by sending a malformed ASN.1 packet over the S1AP interface. Specifically, an attacker can send a 'Path Switch Request' message that omits the required 'MME_UE_S1AP_ID' field, causing the MME to crash repeatedly.

4.7
Jan 22, 2025

Open5GS MME Assertion Failure Vulnerability in S1AP Interface Allowing Denial-of-Service

A denial-of-service vulnerability has been identified in Open5GS MME versions through 2.6.4. The issue arises from an assertion failure that can be remotely triggered by sending a malformed ASN.1 packet over the S1AP interface. Specifically, an attacker can exploit this vulnerability by sending a 'UE Context Release Request' message that omits the required 'MME_UE_S1AP_ID' field. This exploitation causes the MME to crash, disrupting service.

4.7
Jan 22, 2025

Open5GS MME Assertion Failure Vulnerability via Oversized ASN.1 Packets on S1AP Interface

A vulnerability exists in Open5GS MME versions through 2.6.4, where an assertion can be remotely triggered by sending a sufficiently large ASN.1 packet over the S1AP interface. This oversized packet causes the 'ogs_sctp_recvmsg' routine to enter an unexpected state, leading to a crash and a denial-of-service condition.

4.7
Jan 22, 2025

Open5GS MME Assertion Failure Vulnerability in S1AP Interface Allowing Denial-of-Service

A denial-of-service vulnerability has been identified in Open5GS MME versions through 2.6.4. The issue arises from an assertion failure that can be remotely triggered by sending a malformed ASN.1 packet over the S1AP interface. Specifically, an attacker can exploit this vulnerability by sending an 'Initial UE Message' that omits the required 'PLMN Identity' field. This exploitation causes the MME to crash repeatedly, leading to a persistent disruption of service.

4.7
Jan 22, 2025

Open5GS MME Buffer Overflow Vulnerability via Malformed ASN.1 Packets on S1AP Interface

A buffer overflow vulnerability has been identified in Open5GS MME versions through 2.6.4. This issue arises from an improper handling of ASN.1 packets on the S1AP interface, specifically in the processing of 'Handover Required' messages that lack a mandatory 'MME_UE_S1AP_ID' field. The vulnerability can be exploited remotely, leading to a denial-of-service condition by causing the MME to crash. This disruption can persist until the vulnerability is patched.

4.7
Jan 22, 2025

Open5GS MME Assertion Failure Vulnerability in S1AP Interface Allowing Denial-of-Service

A denial-of-service vulnerability has been identified in Open5GS MME versions through 2.6.4. The issue arises from an assertion failure that can be remotely triggered by sending a malformed ASN.1 packet over the S1AP interface. Specifically, an attacker can exploit this vulnerability by sending an 'eNB Status Transfer' message that omits the required 'MME_UE_S1AP_ID' field. This exploitation causes the MME to crash repeatedly, disrupting service.

4.7
Jan 22, 2025

Open5GS MME Assertion Failure Vulnerability in S1AP Handover Notification Handling

A vulnerability exists in Open5GS MME versions through 2.6.4, where an assertion can be remotely triggered by sending a malformed ASN.1 packet over the S1AP interface. The issue arises when a 'Handover Notification' message is sent without the required 'MME_UE_S1AP_ID' field, causing the MME to crash and leading to a denial-of-service condition.

4.7
Jan 22, 2025

Open5GS MME Buffer Overflow Vulnerability in S1AP ASN.1 Deserialization

A buffer overflow vulnerability has been identified in the Open5GS MME component, specifically in versions through 2.6.4. The issue arises within the S1AP handler's ASN.1 deserialization function, where improper handling of message lengths can lead to memory corruption. This vulnerability causes type confusion in the decoded fields, allowing for invalid parsing and manipulation of memory. An attacker could exploit this vulnerability to crash the MME or potentially execute arbitrary code under certain conditions.

4.8
Jan 22, 2025

Open5GS MME Assertion Failure Vulnerability in S1AP Handover Cancel Message

A denial-of-service vulnerability exists in Open5GS MME versions through 2.6.4. The issue arises from an assertion that can be remotely triggered by sending a malformed ASN.1 packet over the S1AP interface. Specifically, an attacker can send a 'Handover Cancel' message that omits the required 'MME_UE_S1AP_ID' field, causing the MME to crash. This vulnerability can be exploited repeatedly, leading to a persistent disruption of service.

4.7
Jan 22, 2025

Open5GS MME Assertion Failure Vulnerability in S1AP Interface Allowing Denial-of-Service

A denial-of-service vulnerability has been identified in Open5GS MME versions through 2.6.4. The issue arises from an assertion failure that can be remotely triggered by sending a malformed ASN.1 packet over the S1AP interface. Specifically, an attacker can send a 'Handover Request Ack' message that omits the required 'MME_UE_S1AP_ID' field, causing the MME to crash. This vulnerability disrupts cellular communications and could persist until network operators apply a patch.

4.7
Jan 22, 2025

Open5GS MME Assertion Failure Vulnerability in S1AP Interface Allowing Denial-of-Service

A denial-of-service vulnerability has been identified in Open5GS MME versions through 2.6.4. The issue arises from an assertion failure that can be remotely triggered by sending a malformed ASN.1 packet over the S1AP interface. Specifically, an attacker can exploit this vulnerability by sending an 'Initial Context Setup Failure' message that omits the required 'MME_UE_S1AP_ID' field. This exploitation causes the MME to crash, disrupting service.

4.3
Jan 22, 2025

Open5GS MME Assertion Failure Vulnerability in S1AP Interface Allowing Denial-of-Service

A denial-of-service vulnerability has been identified in Open5GS MME versions through 2.6.4. The issue arises from an assertion failure that can be remotely triggered by sending a malformed ASN.1 packet over the S1AP interface. Specifically, an attacker can exploit this vulnerability by sending an 'Initial Context Setup Response' message that omits the required 'MME_UE_S1AP_ID' field. This exploitation causes the MME to crash, disrupting service.

4.7
Jan 22, 2025

Open5GS MME Assertion Failure Vulnerability in S1AP Interface Allowing Denial-of-Service

A denial-of-service vulnerability has been identified in Open5GS MME versions through 2.6.4. The issue arises from an assertion failure that can be remotely triggered by sending a malformed ASN.1 packet over the S1AP interface. Specifically, an attacker can exploit this vulnerability by sending an 'E-RAB Setup Response' message that omits the required 'MME_UE_S1AP_ID' field. This exploitation causes the MME to crash, leading to a persistent disruption of service.

4.7
Jan 22, 2025

Open5GS MME Assertion Failure Vulnerability in S1AP Interface Allowing Denial-of-Service

A denial-of-service vulnerability has been identified in Open5GS MME versions through 2.6.4. The issue arises from an assertion failure that can be remotely triggered by sending a malformed ASN.1 packet over the S1AP interface. Specifically, an attacker can exploit this vulnerability by sending an 'E-RAB Modification Indication' message that omits the required 'MME_UE_S1AP_ID' field. This exploitation causes the MME to crash, disrupting service.

4.7
Jan 22, 2025

NextEPC MME Stack-Based Buffer Overflow Vulnerability in Emergency Number List Decoding

A stack-based buffer overflow vulnerability has been identified in the NextEPC MME version 1.0.1 and prior. This vulnerability arises in the Emergency Number List decoding method, where an attacker can send a NAS message with an oversized Emergency Number List value. The exploitation of this vulnerability allows the attacker to overwrite the stack with arbitrary bytes. Notably, this issue can be exploited by an attacker with a cellphone connection to any base station managed by the MME, without the need for authentication with the LTE core.

3.5
Jan 22, 2025

GNU C Library Buffer Overflow Vulnerability in assert() Function

A buffer overflow vulnerability has been identified in the GNU C Library (glibc) versions 2.13 through 2.40, specifically within the assert() function. When an assertion fails, the library does not allocate sufficient space for the failure message and associated size information. This oversight can lead to a buffer overflow, particularly if the message size aligns with the page size. The vulnerability can be exploited by local attackers, especially in setuid programs that contain reachable assertion failures.

5.5
Jan 22, 2025

GamiPress WordPress Plugin Unauthenticated Arbitrary Shortcode Execution Vulnerability

A vulnerability exists in the GamiPress WordPress plugin, specifically in versions through 7.2.1, allowing for unauthenticated arbitrary shortcode execution. This issue arises because the plugin's 'gamipress_do_shortcode()' function fails to properly validate shortcode arguments before processing them, enabling attackers to execute arbitrary shortcodes on the site.

5.2
Jan 22, 2025

GamiPress WordPress Plugin Time-Based SQL Injection Vulnerability

A time-based SQL injection vulnerability has been identified in the GamiPress WordPress plugin, specifically in versions through 7.3.1. The issue arises from inadequate escaping of user-supplied data in the 'orderby' parameter, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to the extraction of sensitive information from the database.

6.3
Jan 22, 2025

GamiPress WordPress Plugin Arbitrary Shortcode Execution Vulnerability

A vulnerability exists in the GamiPress WordPress plugin, specifically in versions through 7.2.1, allowing for arbitrary shortcode execution. This issue arises in the gamipress_ajax_get_logs() function, where user-supplied values are not properly validated before being processed by do_shortcode. As a result, unauthenticated users can execute arbitrary shortcodes on the site.

5.6
Jan 22, 2025

WP Hotel Booking Missing Capability Check Vulnerability Allowing Unauthorized Email Access

A vulnerability exists in the WP Hotel Booking plugin for WordPress, in versions through 2.1.6. The issue arises from a lack of proper capability checks on the 'hotel_booking_load_order_user' AJAX action. This flaw enables authenticated attackers with Subscriber-level access or higher to access and retrieve a list of registered user emails, leading to unauthorized data exposure.

4.1
Jan 22, 2025

Fortinet Products Cache Poisoning Vulnerability via Crafted HTTP Requests

A vulnerability allowing web cache poisoning has been identified in multiple Fortinet products, including FortiManager, FortiMail, FortiAnalyzer, FortiVoice, FortiProxy, FortiRecorder, FortiAuthenticator, FortiNDR, FortiWLC, FortiPortal, FortiOS, FortiADC, FortiDDoS, FortiDDoS-F, FortiTester, FortiSOAR, and FortiSwitch. The vulnerability exists in FortiManager versions prior to 7.4.3, FortiMail versions prior to 7.0.3, FortiAnalyzer versions prior to 7.4.3, FortiVoice versions 7.0.0, 7.0.1, and prior to 6.4.8, FortiProxy versions prior to 7.0.4, FortiRecorder versions 6.4.0 through 6.4.2 and prior to 6.0.10, FortiAuthenticator versions 6.4.0 through 6.4.1 and prior to 6.3.3, FortiNDR versions 7.2.0 prior to 7.1.0, FortiWLC versions prior to 8.6.4, FortiPortal versions prior to 6.0.9, FortiOS versions 7.2.0 and prior to 7.0.5, FortiADC versions 7.0.0 through 7.0.1 and prior to 6.2.3, FortiDDoS versions prior to 5.5.1, FortiDDoS-F versions prior to 6.3.3, FortiTester versions prior to 7.2.1, FortiSOAR versions prior to 7.2.2, and FortiSwitch versions prior to 6.3.3. This vulnerability allows an attacker to poison web caches by sending crafted HTTP requests that direct to an arbitrary web server, exploiting the `Host` header.

5.0
Jan 22, 2025

AI Power: Complete AI Pack PHP Object Injection Vulnerability

A PHP Object Injection vulnerability has been identified in the 'AI Power: Complete AI Pack' WordPress plugin, affecting versions through 1.8.96. The vulnerability arises from the deserialization of untrusted data in the '$form['post_content']' variable, within the 'wpaicg_export_ai_forms()' function. This flaw allows authenticated attackers with administrative privileges to inject a PHP object. While the vulnerable plugin does not contain a direct 'Proof of Concept' chain, the presence of such a chain through an additional plugin or theme could enable the attacker to delete arbitrary files, access sensitive information, or execute code.

2.7
Jan 22, 2025

AI Power: Complete AI Pack WordPress Plugin PHP Object Injection Vulnerability

A PHP Object Injection vulnerability has been identified in the 'AI Power: Complete AI Pack' WordPress plugin, affecting versions through 1.8.96. The vulnerability arises from the deserialization of untrusted data in the 'post_content' variable, specifically within the 'wpaicg_export_prompts' function. This flaw allows authenticated attackers with administrative privileges to inject PHP objects. While the vulnerable plugin does not have an inherent Property-Oriented Programming (POP) chain, the presence of one through an additional plugin or theme could enable the attacker to delete arbitrary files, access sensitive information, or execute code.

2.7
Jan 22, 2025

AI Power: Complete AI Pack WordPress Plugin Missing Authorization Vulnerability Allowing Arbitrary Shortcode Execution

A vulnerability exists in the AI Power: Complete AI Pack plugin for WordPress, in all versions through 1.8.96. The issue arises from a missing capability check in the 'wpaicg_save_image_media' function, which allows authenticated attackers with Subscriber-level access and above to upload image files. Exploitation can be achieved by embedding shortcode attributes in the 'image_alt' value, which will execute when a POST request is sent to the attachment page.

2.4
Jan 22, 2025

AI Power: Complete AI Pack WordPress Plugin Server-Side Request Forgery Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability has been identified in the AI Power: Complete AI Pack plugin for WordPress, affecting all versions through 1.8.96. The vulnerability arises in the 'wpaicg_troubleshoot_add_vector' function, allowing authenticated attackers with subscriber-level access or higher to send web requests to arbitrary locations from the web application. This could be exploited to query and modify information from internal services.

2.7
Jan 22, 2025

Themify Builder Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Themify Builder plugin for WordPress, affecting all versions through 7.6.5. The issue arises from the use of add_query_arg without proper escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages. These scripts could execute if a user is tricked into clicking a link.

5.2
Jan 22, 2025

XML for Google Merchant Center WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the XML for Google Merchant Center plugin for WordPress, affecting all versions through 3.0.11. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the 'feed_id' parameter. These scripts could be executed if a user is tricked into clicking a link.

3.6
Jan 22, 2025

AdForest WordPress Theme Authentication Bypass Vulnerability

A vulnerability allowing authentication bypass has been identified in the AdForest theme for WordPress, affecting all versions through 5.1.8. The issue arises because the theme fails to properly verify a user's identity before logging them in. This flaw enables unauthenticated attackers to authenticate as any user who has set up OTP login via phone number.

2.5
Jan 22, 2025

Stackable Page Builder Gutenberg Blocks Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Stackable – Page Builder Gutenberg Blocks plugin for WordPress, affecting all versions through 3.13.11. The issue arises in the Button block's 'title' parameter, where inadequate input sanitization and output escaping allow authenticated attackers with Contributor-level access or higher to inject arbitrary scripts. These scripts are executed when a user views the page containing the injected content.

2.4
Jan 22, 2025

I-O DATA UD-LT2 OS Command Injection Vulnerability

An OS command injection vulnerability has been identified in the I-O DATA UD-LT2 router, specifically in firmware versions through 1.00.008_SE. This vulnerability allows authenticated users to execute arbitrary OS commands via the command-line interface (CLI).

1.7
Jan 22, 2025

I-O Data UD-LT2 Inclusion of Undocumented Features Vulnerability

A vulnerability allowing the inclusion of undocumented features has been identified in I-O Data UD-LT2 routers with firmware version 1.00.008_SE and earlier. This vulnerability allows remote attackers to disable the LAN-side firewall and open specific ports on the affected devices.

2.5
Jan 22, 2025

I-O Data UD-LT2 OS Command Injection Vulnerability

An OS command injection vulnerability has been identified in I-O Data UD-LT2 routers, specifically in the firmware version 1.00.008_SE and earlier. This vulnerability allows an attacker with administrative access to execute arbitrary OS commands by manipulating requests related to certain screen operations.

1.7
Jan 22, 2025

WPBot Pro WordPress Chatbot Missing Authorization Vulnerability in Simple Text Response Creation

A vulnerability exists in the WPBot Pro WordPress Chatbot plugin, all versions through 13.5.5, due to a lack of proper capability checks in the 'qc_wp_latest_update_check_pro' function. This flaw allows authenticated attackers with Subscriber-level access or higher to create Simple Text Responses for chat queries, leading to unauthorized data modification.

3.8
Jan 22, 2025

Red Hat Podman and Buildah Container Breakout Vulnerability

A vulnerability allowing container breakout has been identified in Red Hat Podman and Buildah. This issue arises when using the '--jobs=2' option, creating a race condition while building a malicious Containerfile. Although SELinux may provide some mitigation, it still permits the enumeration of files and directories on the host.

4.4
Jan 22, 2025

Ketchup Shortcodes WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Ketchup Shortcodes plugin for WordPress, affecting all versions through 0.1.2. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'spacer' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.

3.0
Jan 22, 2025

WordPress Picture Gallery Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress. This issue affects all versions through 1.5.19 and arises from inadequate input sanitization and output escaping on user-supplied attributes. Authenticated attackers with contributor-level access or higher can exploit this vulnerability by injecting arbitrary web scripts into pages, which are then executed when users access the affected pages.

3.6
Jan 22, 2025

WP-Polls SQL Injection Vulnerability Leading to Stored Cross-Site Scripting

A SQL injection vulnerability has been identified in the WP-Polls plugin for WordPress, affecting all versions through 2.77.2. The vulnerability arises from inadequate escaping of user-supplied data in SQL queries, allowing unauthenticated attackers to inject additional SQL commands. While the injected SQL queries cannot be used to extract database information, a carefully crafted payload can introduce malicious JavaScript that is stored and executed later, resulting in a stored cross-site scripting vulnerability.

6.0
Jan 22, 2025

Node.js Internal Worker Leak Vulnerability Allowing Permission Bypass

A vulnerability exists in Node.js versions 20, 22, and 23 for users with the Permission Model enabled. By using the diagnostics_channel utility, it is possible to intercept events when a worker thread is created. This not only applies to regular worker threads but also reveals internal workers, allowing an instance to be accessed. The constructor of this internal worker can be extracted and reused for malicious purposes, effectively bypassing the permission model restrictions.

5.6
Jan 22, 2025

Node.js Worker Permission Bypass Vulnerability via InternalWorker Leak

A vulnerability exists in Node.js versions 20, 22, and 23 prior to the latest security releases, allowing Permission Model users to hook into events when worker threads are created. This issue not only pertains to regular workers but also exposes internal workers, enabling the fetching of an instance, extraction of its constructor, and potential misuse. Successful exploitation could lead to unauthorized access to internal worker functionalities, allowing for malicious manipulation or actions.

4.6
Jan 22, 2025

CampCodes School Management Software Attachment Resource Injection Vulnerability

A resource injection vulnerability has been identified in CampCodes School Management Software version 1.0, specifically within the Attachment Handler component. This vulnerability arises from improper management of resource identifiers, allowing for insecure direct object reference (IDOR) exploitation. The issue can be exploited remotely, although the attack's complexity is considered high.

3.3
Jan 22, 2025

WPBot Pro WordPress Chatbot Unauthenticated Arbitrary File Upload Vulnerability

A vulnerability allowing arbitrary file uploads has been identified in the WPBot Pro WordPress Chatbot plugin, affecting all versions through 13.5.4. The issue arises from inadequate file type validation in the 'qcld_wpcfb_file_upload' function, enabling unauthenticated attackers to upload arbitrary files to the server. This vulnerability could potentially lead to remote code execution. Exploitation requires the ChatBot Conversational Forms plugin and the Conversational Form Builder Pro addon plugin.

4.8
Jan 22, 2025

Magma Mobile Management Entity Null Pointer Dereference Vulnerability via Malformed Initial UE Message

A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP 'Initial UE Message' packet that omits the expected 'RRC Establishment Cause' field. The issue has been fixed in Magma version 1.9.

4.7
Jan 21, 2025

Android Libwebp Integer Overflow Vulnerability in DGifSlurp Function Leading to Out-of-Bounds Write and Potential Remote Code Execution

A vulnerability has been identified in the DGifSlurp function of the libwebp library, specifically within the dgif_lib.c file. This issue arises from an integer overflow, which creates a possible out-of-bounds write. Such a vulnerability could be exploited to execute remote code without requiring additional execution privileges. Notably, user interaction is not necessary for exploitation.

2.2
Jan 21, 2025

Android Bluetooth Stack Heap Buffer Overflow Vulnerability Allowing Remote Code Execution

A heap buffer overflow vulnerability has been identified in the Android Bluetooth stack, specifically in the function 'gatts_process_primary_service_req' of 'gatt_sr.cc'. This vulnerability allows for an out-of-bounds write, which could be exploited to execute remote code without requiring any additional privileges or user interaction.

1.7
Jan 21, 2025

Android Bluetooth Stack Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in the Android Bluetooth stack, specifically within the 'gatts_process_read_by_type_req' function of 'gatt_sr.cc'. This vulnerability arises from a logic error that creates a potential out-of-bounds write, allowing for remote code execution without the need for additional execution privileges or user interaction.

1.7
Jan 21, 2025

Android Framework and System Components Out-of-Bounds Write Vulnerability Allowing Local Privilege Escalation

A vulnerability has been identified in the Android framework and system components, specifically in the 'growData' function of 'Parcel.cpp'. This vulnerability arises from an incorrect bounds check, leading to a potential out-of-bounds write. Exploitation of this issue could result in local privilege escalation, with no additional execution privileges required. User interaction is not necessary for exploitation. This vulnerability affects several different versions and/or ranges of Android.

1.1
Jan 21, 2025

Android Framework Account Manager Service Elevation of Privilege Vulnerability

A vulnerability in the AccountManagerService component of the Android Framework allows for a local elevation of privilege. This issue arises from unsafe deserialization, which creates a potential bypass of parcel mismatch mitigations. Exploitation of this vulnerability requires user interaction.

1.5
Jan 21, 2025

Android Notification Access Privilege Escalation Vulnerability

A vulnerability in the Notification Access Confirmation Activity allows an app with notification access to be hidden in the Settings. This issue arises from a missing permission check, which could lead to local privilege escalation without requiring additional execution privileges. Exploitation of this vulnerability does require user interaction.

1.1
Jan 21, 2025

Android Framework and System Components Elevation of Privilege Vulnerability

A vulnerability in the Android framework and system components has been identified, allowing for a local elevation of privilege. This issue arises from a possible out-of-bounds write in the 'writeInplace' function of 'Parcel.cpp'. Exploitation of this vulnerability does not require any additional execution privileges or user interaction.

1.6