CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Umbraco.Forms Server-Side Validation Vulnerability for Character Limits in Short and Long Answer Fields
A vulnerability exists in Umbraco.Forms versions through 10.5.7 and prior to 8.13.16, allowing character limits set by editors for short and long answer fields to be validated only on the client side, with no server-side enforcement. This could lead to fields being submitted with excessive characters, potentially causing issues downstream. The vulnerability arises because the framework does not properly validate input lengths on the server, leaving room for overlong submissions that could disrupt application functionality.
Adobe Illustrator on iPad Integer Underflow Vulnerability Leading to Arbitrary Code Execution
A vulnerability allowing arbitrary code execution has been identified in Adobe Illustrator on iPad, specifically in versions 3.0.7 and earlier. This issue arises from an integer underflow vulnerability that could be exploited if a user opens a malicious file. The exploitation occurs within the context of the current user.
Adobe Illustrator for iPad Integer Underflow Vulnerability Leading to Arbitrary Code Execution
A vulnerability allowing arbitrary code execution has been identified in Adobe Illustrator on iPad, affecting versions 3.0.7 and earlier. This issue arises from an integer underflow vulnerability that could be exploited if a user opens a malicious file. The execution of arbitrary code would occur in the context of the current user.
Adobe Substance 3D Stager Out-of-Bounds Write Vulnerability Leading to Arbitrary Code Execution
An out-of-bounds write vulnerability has been identified in Adobe Substance 3D Stager versions through 3.0.4. This vulnerability could allow arbitrary code execution in the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe Substance 3D Stager Out-of-Bounds Write Vulnerability Leading to Arbitrary Code Execution
An out-of-bounds write vulnerability has been identified in Adobe Substance 3D Stager versions 3.0.4 and earlier. This vulnerability could allow for arbitrary code execution in the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe Substance 3D Stager Out-of-Bounds Write Vulnerability Leading to Arbitrary Code Execution
An out-of-bounds write vulnerability has been identified in Adobe Substance 3D Stager versions 3.0.4 and earlier. This vulnerability could allow arbitrary code execution in the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe Substance 3D Stager Heap-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution
A heap-based buffer overflow vulnerability has been identified in Adobe Substance 3D Stager versions through 3.0.4. This vulnerability could lead to arbitrary code execution in the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe Substance 3D Stager Stack-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution
A stack-based buffer overflow vulnerability has been identified in Adobe Substance 3D Stager versions through 3.0.4. This vulnerability could lead to arbitrary code execution in the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe Photoshop Desktop Uncontrolled Search Path Element Vulnerability Leading to Arbitrary Code Execution
A vulnerability allowing arbitrary code execution has been identified in Adobe Photoshop Desktop versions 25.12, 26.1 and earlier. This issue arises from an Uncontrolled Search Path Element vulnerability, where an attacker can manipulate the search path environment variable to direct the application to a malicious library. When the application loads this library, it can execute arbitrary code. Exploitation of this vulnerability requires user interaction, as the victim must manually run the affected application.
Adobe Photoshop Desktop Integer Underflow Vulnerability Leading to Arbitrary Code Execution
A vulnerability allowing integer underflow has been identified in Adobe Photoshop Desktop versions 25.12, 26.1 and earlier. This vulnerability could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Invoice Ninja Authenticated Server-Side Request Forgery Vulnerability Allowing Arbitrary File Read and Network Resource Requests
A server-side request forgery (SSRF) vulnerability has been identified in Invoice Ninja versions 5.8.56 prior to 5.11.23. This vulnerability allows authenticated users to make arbitrary file read requests and access network resources on behalf of the application user.
Django Denial-of-Service Vulnerability in IPv6 Validation
A denial-of-service vulnerability has been identified in Django versions 5.1 prior to 5.1.5, 5.0 prior to 5.0.11, and 4.2 prior to 4.2.18. The issue arises from a lack of upper-bound limit enforcement in strings used for IPv6 validation, potentially leading to a denial-of-service attack. This vulnerability affects the private functions 'clean_ipv6_address' and 'is_valid_ipv6_address', as well as the 'django.forms.GenericIPAddressField' form field. However, the 'django.db.models.GenericIPAddressField' model field is not affected.
Git Credential Manager Carriage Return Handling Vulnerability Allows Credential Injection
A vulnerability exists in Git Credential Manager (GCM) due to improper handling of Carriage Return characters in URLs. This issue arises because Git and GCM interpret newlines differently, leading to a scenario where credentials for one server can be mistakenly sent to another. The vulnerability affects GCM versions through 2.6.0 and has been patched in 2.6.1. Users are advised to upgrade or, if unable to do so, to avoid cloning from untrusted URLs, especially with the recursive option.
Git Credential Handling Vulnerability Allows Credential Misleading via Control Sequences
A vulnerability in Git's credential handling can mislead users into providing sensitive information, such as passwords, for trusted Git hosting sites. This occurs when Git prompts for credentials in the terminal without using a credential helper. The vulnerability is present in Git versions 2.48.0 through 2.47.1, 2.46.2 through 2.45.2, 2.44.2, 2.43.5, 2.42.3, 2.41.2, and 2.40.3. During the credential prompt, Git prints the host name with any URL-encoded parts decoded, allowing attackers to craft URLs with ANSI escape sequences. These sequences can confuse users into sending passwords to untrusted sites under the attacker's control.
Git Credential Manager Carriage-Return Character Handling Vulnerability Allows Credential Leakage
A vulnerability in Git Credential Manager (GCM) exists due to improper handling of carriage-return characters in the Git credential protocol. GCM, a secure credential helper built on .NET, reads credentials from standard input as key-value pairs. While Git treats carriage-return characters as invalid, GCM's underlying .NET implementation considers them as newlines. This discrepancy allows attackers to craft malicious URLs that, when accessed, can leak credentials for other Git remotes. The issue is exacerbated when cloning repositories with submodules using the '--recursive' option, as submodule URLs cannot be inspected beforehand.
Rasa Remote Code Execution Vulnerability via Malicious Model Loading
A critical remote code execution vulnerability has been identified in Rasa Open Source versions prior to 3.6.21 and Rasa Pro versions prior to 3.10.12, 3.9.16, and 3.8.18. The vulnerability allows an attacker to execute arbitrary code by loading a maliciously crafted model into a Rasa instance. This issue arises when the HTTP API is enabled without proper authentication or security controls, creating an opportunity for exploitation.
QNX SDP PCX Image Codec NULL Pointer Dereference Vulnerability Allowing Denial-of-Service
A NULL pointer dereference vulnerability has been identified in the PCX image codec of QNX Software Development Platform (SDP) versions 8.0, 7.1, and 7.0. This vulnerability could allow an unauthenticated attacker to induce a denial-of-service condition in the process utilizing the image codec by forcing the system to parse a maliciously crafted PCX format image file.
QNX SDP PCX Image Codec Out-of-Bounds Write Vulnerability Allowing Code Execution or Denial-of-Service
An out-of-bounds write vulnerability has been identified in the PCX image codec of QNX Software Development Platform (SDP) versions 8.0, 7.1, and 7.0. This vulnerability could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec. The vulnerability arises when the image codec is induced to parse a maliciously crafted PCX format image file.
QNX SDP TIFF Image Codec Out-of-Bounds Read Vulnerability Allowing Information Disclosure
An out-of-bounds read vulnerability has been identified in the TIFF image codec of QNX Software Development Platform (SDP) versions 8.0, 7.1, and 7.0. This vulnerability could allow an unauthenticated attacker to cause information disclosure in the context of the process using the image codec, by inducing the system to parse a maliciously crafted TIFF image file.
QNX SDP TIFF Image Codec Off-by-One Error Vulnerability Allowing Information Disclosure
An off-by-one error vulnerability has been identified in the TIFF image codec of QNX Software Development Platform (SDP) versions 8.0, 7.1, and 7.0. This vulnerability could allow an unauthenticated attacker to cause information disclosure within the context of the process using the image codec. The issue arises when the system is induced to parse a maliciously crafted TIFF image file.
Wildfly HAL Console Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been identified in the HAL Console component of Wildfly. This issue arises because the application fails to properly sanitize user input before it is displayed on web pages served to other users. To exploit this vulnerability, an attacker must be authenticated and belong to one of the following management groups: 'SuperUser', 'Admin', or 'Maintainer'.
HPE Aruba Networking AOS-8 and AOS-10 Command Injection Vulnerability Allowing Arbitrary Code Execution
An authenticated command injection vulnerability has been identified in the command line interface of HPE Aruba Networking AOS-8 and AOS-10 operating systems. This vulnerability allows attackers to execute arbitrary commands as a privileged user on the underlying operating system. The issue affects HPE Aruba Networking Mobility Conductors, Controllers, and WLAN and SD-WAN Gateways managed by HPE Aruba Networking Central, specifically in AOS-10.4.x.x versions through 10.4.1.4, and AOS-8.12.x.x versions through 8.12.0.2, as well as AOS-8.10.x.x versions through 8.10.0.14.
HPE Aruba Networking AOS-8 and AOS-10 Authenticated Parameter Injection Vulnerability Allowing Arbitrary File Overwrite
A vulnerability allowing authenticated parameter injection has been identified in the web-based management interface of HPE Aruba Networking AOS-8 and AOS-10 operating systems. This vulnerability could be exploited by an authenticated user to overwrite arbitrary system files.
XWiki Platform Realtime WYSIWYG Editor Privilege Escalation Vulnerability
A privilege escalation vulnerability has been identified in the XWiki Platform Realtime WYSIWYG Editor extension, affecting versions 13.9-rc-1 prior to 15.10.12, 13.9-rc-1 prior to 16.4.1, and 13.9-rc-1 prior to 16.6.0-rc-1. In the vulnerable versions, a user with edit rights can join a realtime editing session where other participants have script or programming access. This user can insert script rendering macros that are executed for those with script rights in the session, potentially leading to unauthorized access rights. The vulnerability arises because the realtime editing feature, which was experimental and not recommended in the affected versions, has become enabled by default in XWiki 16.9.0.
Vyper EcRecover and Identity Precompile Success Flag Bypass Vulnerability
A vulnerability exists in the Vyper compiler versions through 0.4.0, where calls to the Ethereum precompiles EcRecover (0x1) and Identity (0x4) do not properly check for successful execution. This oversight allows an attacker to manipulate the gas provided to these calls, potentially causing incorrect execution results while exploiting the EVM's gas handling rules. After a failed precompile call, only a fraction of the original gas remains, limiting the complexity of subsequent operations. Although this issue has been addressed in Vyper version 0.4.1, it could lead to unintended consequences in smart contracts that rely on the affected precompiles.
Microsoft Windows Telephony Service Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in the Windows Telephony Service. This issue allows an attacker to execute arbitrary code on the affected system. The vulnerability arises from a heap-based buffer overflow.
Microsoft Windows Telephony Service Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in the Windows Telephony Service. This vulnerability allows an attacker to execute arbitrary code on the affected system. It is present in multiple versions of Windows Server, including 2012 R2, 2008 R2, and 2008, as well as in Windows Server 2012 (Server Core installation). The vulnerability arises from a heap-based buffer overflow, which can be exploited by tricking a user into sending a request to a malicious server that returns harmful data.
Microsoft Windows Telephony Service Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in the Windows Telephony Service. This vulnerability allows an attacker to execute arbitrary code on the affected system. It is present in several versions of Windows Server and Windows 10, as well as in Windows 11. The vulnerability arises from a heap-based buffer overflow, which can be exploited by tricking a user into sending a request to a malicious server that returns harmful data.
Microsoft Windows Telephony Service Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in the Windows Telephony Service. This issue allows an attacker to execute arbitrary code on the affected system.
Visual Studio Elevation of Privilege Vulnerability
An elevation of privilege vulnerability has been identified in Visual Studio. This issue allows an attacker to gain higher privileges than intended, potentially leading to unauthorized actions or access within the application.
Microsoft On-Premises Data Gateway Information Disclosure Vulnerability
A vulnerability allowing information disclosure has been identified in the Microsoft On-Premises Data Gateway. This issue arises when a SAP HANA data source is configured to use single sign-on (SSO). Successful exploitation could allow an attacker to access data from the targeted Power BI dashboard, depending on the privileges of the compromised user.
Microsoft OneNote Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in Microsoft Office OneNote. This issue affects multiple versions of OneNote for Mac, as well as Office LTSC for Mac 2024 and 2021. The vulnerability arises from improper restrictions on file names and resources, allowing for unauthorized code execution.
Microsoft Access Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in Microsoft Access. This issue allows an attacker to execute arbitrary code on the affected system.
Microsoft SharePoint Server Spoofing Vulnerability
A spoofing vulnerability has been identified in Microsoft SharePoint Server. This vulnerability allows an attacker to impersonate another user, potentially leading to unauthorized access or actions within the SharePoint environment.
Microsoft Windows upnphost.dll Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the Windows upnphost.dll component. This issue can lead to a disruption of service, causing applications or services to become unresponsive or unavailable.
Microsoft Windows Graphics Component Elevation of Privilege Vulnerability
An elevation of privilege vulnerability has been identified in the Windows Graphics Component. This vulnerability allows an attacker to gain higher privileges on the system.
Microsoft Windows CSC Service Elevation of Privilege Vulnerability
A vulnerability has been identified in the Windows CSC Service that allows for elevation of privilege. This issue could be exploited to gain higher-level permissions on the system.
Microsoft Windows CSC Service Information Disclosure Vulnerability
A vulnerability allowing information disclosure has been identified in the Windows CSC (Client Side Caching) service. This issue could potentially be exploited to access sensitive information.
Microsoft Brokering File System Elevation of Privilege Vulnerability
A use-after-free vulnerability has been identified in the Microsoft Brokering File System, which could allow an attacker to elevate privileges. This vulnerability affects several Microsoft products, including Windows Server 2025, Windows 11 Version 24H2 for x64-based and ARM64-based Systems, and Windows Server 2022, 23H2 Edition (Server Core installation).
Microsoft Windows VBS Enclave Elevation of Privilege Vulnerability
An elevation of privilege vulnerability has been identified in Windows Virtualization-Based Security (VBS) enclaves. This vulnerability allows an attacker to potentially leak data from the target enclave or execute code within the context of the enclave. The issue affects multiple versions of Windows 11, including 24H2, 23H2, and 22H2, for both x64-based and ARM64-based systems.
Microsoft Access Remote Code Execution Vulnerability
A remote code execution vulnerability exists in Microsoft Access. This issue allows an attacker to execute arbitrary code on the affected system.
Microsoft Office Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in multiple Microsoft Office products, including Microsoft Office LTSC 2024 and Microsoft 365 Apps for Enterprise. This vulnerability allows an attacker to execute arbitrary code on the affected system. The issue arises from an untrusted search path, which can be exploited under certain conditions.
Microsoft Excel Security Feature Bypass Vulnerability
A security feature bypass vulnerability has been identified in Microsoft Excel. This vulnerability allows for the circumvention of certain security measures within the application, potentially leading to unauthorized actions or access.
Microsoft Word Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in Microsoft Word. This issue is present in several different versions of the application, including Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024 for both 64-bit and 32-bit editions, Microsoft Office LTSC for Mac 2021, and Microsoft 365 Apps for Enterprise for both 64-bit and 32-bit systems. The vulnerability arises from an untrusted pointer dereference, which could potentially allow an attacker to execute arbitrary code on the affected system.
Microsoft Excel Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in Microsoft Excel. This issue affects several different versions and stems from a use-after-free flaw, which could be exploited to execute arbitrary code.
Microsoft Outlook Remote Code Execution Vulnerability
A remote code execution vulnerability exists in Microsoft Outlook for Mac, specifically in the Legacy version. This issue allows an attacker to bypass Outlook's protections against certain file extensions, potentially leading to the execution of malicious code. The vulnerability is exploited locally, requiring user interaction, such as previewing an attached file in the attachment Preview Pane.
Microsoft AutoUpdate Elevation of Privilege Vulnerability
An elevation of privilege vulnerability has been identified in Microsoft AutoUpdate (MAU) for Mac, specifically in version 4.76. This vulnerability allows an attacker to gain elevated privileges, enabling them to execute commands as Root in the target environment.
Microsoft Outlook Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in multiple editions of Microsoft Outlook, including Outlook 2016, Office LTSC 2024, Office LTSC 2021, Microsoft 365 Apps for Enterprise, and Office 2019. This vulnerability allows an attacker to execute arbitrary code on the affected system. The issue arises from the use of uninitialized resources, and exploitation requires the victim to open a malicious file. While the vulnerability is classified as remote code execution, it is important to note that the attack must be carried out locally, with the attacker needing access to the victim's Outlook account.
Microsoft Office Visio Remote Code Execution Vulnerability
A remote code execution vulnerability exists in Microsoft Office Visio. This issue allows an attacker to execute arbitrary code on the affected system.
Microsoft Excel Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in Microsoft Excel. This issue allows an attacker to execute arbitrary code on the affected system. The vulnerability is present in multiple versions of Microsoft Office, including the 2021 and 2019 LTSC releases, as well as in Microsoft 365 Apps for Enterprise. The root cause of the vulnerability is an untrusted pointer dereference, which can be exploited by manipulating how Excel handles certain types of data.
