CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Process Maker PM4Core-Docker Arbitrary File Upload Vulnerability Allowing Code Execution
A vulnerability allowing arbitrary file uploads has been identified in the Process Maker PM4Core-Docker application, specifically in version 4.1.21-RC7. This issue arises in the UI login page's logo upload feature, where attackers can upload crafted PHP or HTML files that execute arbitrary code.
Process Maker pm4core-docker Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability exists in Process Maker pm4core-docker version 4.1.21-RC7. This vulnerability allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the Name parameter. The issue arises from inadequate input sanitization in the import function, enabling the execution of malicious JavaScript when a processed file is archived.
Aginode GigaSwitch Insecure Permissions Vulnerability Allowing Sensitive Information Disclosure
A vulnerability in Aginode GigaSwitch version 5 exists due to insecure permissions, allowing low-privileged users to access sensitive information, such as the administrator's password hash or, under certain conditions, the password in plaintext, using the SCP command. This issue arises from a design flaw that permits unauthorized access to confidential data through the device's configuration files.
D-Link DIR-823X Null Pointer Dereference Vulnerability
A critical null pointer dereference vulnerability has been identified in the D-Link DIR-823X router, specifically in the firmware versions 240126 and 240802. This vulnerability resides in the function FUN_00412244 and can be exploited remotely.
Fanli2012 Native-PHP-CMS SQL Injection Vulnerability in fladmin/cat_dodel.php
A critical SQL injection vulnerability has been identified in Fanli2012 native-php-cms version 1.0. The issue arises in the file fladmin/cat_dodel.php, where the input parameter 'id' is not properly sanitized. This lack of input validation allows attackers to inject malicious SQL commands, potentially leading to unauthorized data access or manipulation. The vulnerability can be exploited remotely.
Fanli2012 Native-PHP-CMS SQL Injection Vulnerability in Article Management
A critical SQL injection vulnerability has been identified in Fanli2012 native-php-cms version 1.0. The issue arises in the file '/fladmin/article_dodel.php', where the 'id' parameter is not properly sanitized. This lack of input validation allows attackers to inject malicious SQL commands, potentially leading to unauthorized data access or manipulation. The vulnerability can be exploited remotely.
Fanli2012 Native-PHP-CMS SQL Injection Vulnerability in Friendlink Dodel.php
A critical SQL injection vulnerability has been identified in Fanli2012 native-php-cms version 1.0. The issue arises in the file '/fladmin/friendlink_dodel.php', where the 'id' parameter is not properly sanitized. This lack of input validation allows attackers to inject malicious SQL commands, potentially leading to unauthorized data access or manipulation. The vulnerability can be exploited remotely.
parse-uri Regular Expression Denial-of-Service Vulnerability
A regular expression denial-of-service (ReDoS) vulnerability has been identified in the parse-uri library, specifically in version 1.0.9. This issue arises when an attacker crafts a URL that exploits the library's regex parsing, leading to a denial-of-service condition by causing excessive processing time.
Fanli2012 Native-PHP-CMS SQL Injection Vulnerability in product_list.php
A critical SQL injection vulnerability has been identified in Fanli2012 native-php-cms version 1.0. The issue resides in the product_list.php file, where the 'cat' parameter is not properly sanitized, allowing attackers to inject malicious SQL commands. This vulnerability can be exploited remotely.
Fanli2012 Native-PHP-CMS SQL Injection Vulnerability in fladmin/cat_edit.php
A critical SQL injection vulnerability has been identified in Fanli2012 native-php-cms version 1.0. The issue arises in the file fladmin/cat_edit.php, where the id parameter is not properly sanitized, allowing attackers to inject malicious SQL commands. This vulnerability can be exploited remotely.
Fanli2012 Native-PHP-CMS SQL Injection Vulnerability in Login Functionality
A critical SQL injection vulnerability has been identified in Fanli2012 native-php-cms version 1.0. The issue arises in the login administration file, specifically '/fladmin/login.php', where the 'username' parameter can be manipulated to execute malicious SQL commands. This vulnerability can be exploited remotely, without any authentication requirements.
HI-SCAN 6040i Hardcoded Credentials Vulnerability
A vulnerability exists in the HI-SCAN 6040i Hitrax model HX-03-19-I due to hardcoded credentials that allow unauthorized access to vendor support and service functions.
Smiths Detection HI-SCAN 6040i Hitrax User Credential Enumeration Vulnerability via GIOP Protocol
A vulnerability exists in the AsDB service of the Smiths Detection HI-SCAN 6040i Hitrax model HX-03-19-I. This issue allows attackers to enumerate user credentials by sending crafted requests over the GIOP protocol.
Smiths Detection HI-SCAN 6040i Hitrax USB Autorun Arbitrary Code Execution Vulnerability
A vulnerability exists in the USB Autorun feature of Smiths Detection HI-SCAN 6040i Hitrax models through HX-03-19-I. This issue allows attackers to execute arbitrary code by uploading a malicious script from a USB device.
HI-SCAN 6040i Privilege Escalation Vulnerability
A vulnerability exists in HI-SCAN 6040i Hitrax HX-03-19-I due to insecure default configurations, allowing authenticated attackers with low-level privileges to escalate their privileges to root level.
HI-SCAN 6040i Hitrax Cleartext Credential Transmission Vulnerability Over GIOP Protocol
A vulnerability exists in the HI-SCAN 6040i Hitrax model HX-03-19-I, where user credentials are transmitted in cleartext via the GIOP protocol. This exposure could allow attackers to intercept and access sensitive information through a man-in-the-middle attack.
Sentry SAML SSO User Account Takeover Vulnerability
A critical vulnerability exists in the SAML Single Sign-On (SSO) implementation of Sentry, versions 21.12.0 through 24.12.1. This vulnerability allows an attacker to take over any user account by exploiting a malicious SAML Identity Provider and targeting another organization on the same Sentry instance. The attack requires knowledge of the victim's email address.
Fanli2012 Native-PHP-CMS Cross-Site Scripting Vulnerability in sysconfig_doedit.php
A cross-site scripting (XSS) vulnerability has been identified in Fanli2012 native-php-cms version 1.0. The issue arises in the file /fladmin/sysconfig_doedit.php, where user input is not properly sanitized before being output, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely and requires user interaction.
Fanli2012 Native-PHP-CMS Improper Authorization Vulnerability in Backend Component
A critical vulnerability has been identified in Fanli2012 native-php-cms version 1.0. The issue arises from improper authorization handling in the backend file '/fladmin/sysconfig_doedit.php', allowing attackers to modify backend data without authorization. This vulnerability can be exploited remotely.
Fanli2012 Native-PHP-CMS Cross-Site Scripting Vulnerability in fladmin/jump.php
A cross-site scripting (XSS) vulnerability has been identified in Fanli2012 native-php-cms version 1.0. The issue arises in the file fladmin/jump.php, where the message and error parameters are not properly sanitized. This lack of input validation allows attackers to inject malicious scripts that could be executed in the context of the user's browser, potentially leading to cookie theft or other malicious actions.
Fanli2012 Native-PHP-CMS Default Credentials Vulnerability in User Password Recovery Script
A critical vulnerability exists in Fanli2012 native-php-cms version 1.0, specifically within the file '/fladmin/user_recoverpwd.php'. This vulnerability allows for the use of default credentials, enabling remote password resets for the administrator account. The issue arises from a logic flaw that permits the manipulation of password recovery processes, effectively bypassing authentication requirements.
Apple Music Input Sanitization Vulnerability Leading to Internal State Disclosure
A vulnerability in Apple Music for Windows was addressed by improving input sanitization. This issue, present in version 1.5.0.152, could allow processing of maliciously crafted web content to disclose internal states of the application.
Apple Calendar Reminders Access Vulnerability
A path handling vulnerability has been identified in the Calendar app on watchOS 11.1, visionOS 2.1, iOS 18.1, and iPadOS 18.1. This vulnerability allows an attacker with access to calendar data to also read reminders. The issue was addressed with improved logic.
Apple iOS and iPadOS Siri Logic Issue Allowing Contact Access from Lock Screen
A logic issue in the Siri component of Apple iOS and iPadOS has been identified, which could allow an attacker with physical access to a locked device to access contacts from the lock screen. This vulnerability affects iOS 17.7.1, iPadOS 17.7.1, and prior to iOS 18.1 and iPadOS 18.1. The issue has been addressed with improved checks.
Apple iOS and iPadOS Face ID Stolen Device Protection Bypass Vulnerability
A vulnerability exists in iOS and iPadOS that allows an attacker with physical access to the device to disable Stolen Device Protection. This issue is related to the Face ID feature and was addressed in the latest version of both operating systems.
Apple GPU Drivers Memory Initialization Vulnerability Leading to System Termination
A memory initialization vulnerability in the GPU drivers of Apple products can cause unexpected system termination. This issue affects several different versions and was addressed with improved memory handling. The vulnerability is present in iOS 18.1, iPadOS 18.1, iOS 17.7.1, iPadOS 17.7.1, macOS Sonoma 14.7.1, and macOS Ventura 13.7.1.
Apple iOS and iPadOS Lock Screen Notification Access Vulnerability
A vulnerability exists in iOS devices that allows an attacker with physical access to view notification contents from the Lock Screen. This issue is present in iOS 17.5 and iPadOS 17.5.
Apple AVEVideoEncoder Arbitrary Code Execution Vulnerability with Kernel Privileges
A vulnerability in the AVEVideoEncoder component of various Apple operating systems, including macOS Sonoma 14.5, macOS Monterey 12.7.5, macOS Ventura 13.6.7, watchOS 10.5, tvOS 17.5, and visionOS 1.2, allows an application to execute arbitrary code with kernel privileges. This issue stems from inadequate memory handling, which could be exploited to gain elevated privileges.
Apple WebKit Processing Files Vulnerability Leading to App Termination or Arbitrary Code Execution
A vulnerability in WebKit, the engine powering Safari and other applications, allows for processing maliciously crafted files, which can lead to unexpected app termination or arbitrary code execution. This issue affects multiple Apple platforms, including macOS Sonoma 14.5, iOS 17.5, iPadOS 17.5, watchOS 10.5, tvOS 17.5, and visionOS 1.2. The vulnerability arises from an out-of-bounds write issue that was addressed with improved input validation and memory handling.
Amazon WorkSpaces Native Client Man-in-the-Middle Vulnerability
A man-in-the-middle vulnerability has been identified in the native clients for Amazon WorkSpaces, specifically when using the PCoIP protocol. This issue allows an attacker to intercept and access remote WorkSpaces sessions. The vulnerability affects the Windows, macOS, Linux, and Android clients of Amazon WorkSpaces.
Amazon WorkSpaces, AppStream 2.0, and DCV Clients Man-in-the-Middle Vulnerability
A man-in-the-middle vulnerability has been identified in the native clients for Amazon WorkSpaces (when using the Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV. This vulnerability allows an attacker to access remote sessions by intercepting the communication between the client and the server. The issue affects specific versions of these clients, as detailed below.
D-Link DIR-878 Information Disclosure Vulnerability in HTTP POST Request Handler
An information disclosure vulnerability has been identified in the D-Link DIR-878 router, specifically in version 1.03. The issue arises from an unknown function in the file '/dllog.cgi', within the HTTP POST request handler component. This vulnerability allows sensitive information to be exposed to unauthorized actors, potentially impacting confidentiality. The vulnerability can be exploited remotely, without any authentication requirements.
GitHub Desktop Credential Leak Vulnerability via Malicious Remote URLs
A vulnerability in GitHub Desktop versions 3.3.15 and through 3.4.12 allows for unauthorized access to user credentials. This issue arises when an attacker convinces a user to clone a repository, either directly or through a submodule, using a maliciously crafted remote URL. GitHub Desktop relies on Git for network operations like cloning and fetching. When Git encounters a remote that requires authentication, it requests credentials from GitHub Desktop using the git-credential protocol. The vulnerability lies in the misinterpretation of the credential request, causing GitHub Desktop to send credentials for a different host than the one currently being accessed by Git. As a result, sensitive information such as GitHub usernames, OAuth tokens, or credentials for other Git remote hosts stored in GitHub Desktop could be improperly transmitted to an unrelated host.
CrafterCMS Engine Resource Leak Vulnerability Allowing Directory Indexing
A 'Resource Leak' vulnerability has been identified in CrafterCMS Engine versions 4.0.0 prior to 4.0.8 and 4.1.0 prior to 4.1.6, running on Linux, MacOS, Windows (64-bit), and ARM. This vulnerability allows directory indexing and the exposure of leaked resources.
Wuzhicms Server-Side Request Forgery Vulnerability in Config.php
A server-side request forgery (SSRF) vulnerability has been identified in Wuzhicms version 4.1.0. The issue arises in the 'test' function of 'coreframe/app/search/admin/config.php', where the 'sphinxhost' and 'sphinxport' parameters are not properly validated. This lack of input filtering allows attackers to probe internal network ports, potentially leading to unauthorized access or information disclosure.
Git Sideband Channel Vulnerability Allowing Misrepresentation of Information
A vulnerability exists in Git versions through 2.48.1 that involves the sideband channel used for transporting messages from remote processes to the client. This channel can be exploited because Git does not sanitize messages before they are sent to the standard error output, which is typically connected to a terminal that interprets ANSI escape sequences. Malicious actors could use this oversight to obscure information, mislead users, or trick them into running untrusted scripts. The vulnerability is particularly concerning during recursive clones from untrusted repositories.
Mattermost Mobile Apps Post Prop Validation Vulnerability Leading to Crashes
A vulnerability exists in Mattermost Mobile Apps in versions through 2.22.0, where the application fails to properly validate post properties. This flaw allows a malicious authenticated user to send a harmful post that can cause the app to crash.
Mattermost Denial-of-Service Vulnerability via Malicious Post in Multiple Versions
A denial-of-service vulnerability has been identified in Mattermost versions 10.2.0, 9.11.5, 10.0.3, and 10.1.3. This issue arises because the application fails to properly validate post properties, allowing a malicious authenticated user to cause a crash by sending a harmful post.
Mattermost Denial-of-Service Vulnerability via Malicious Post in Multiple Versions
A denial-of-service vulnerability has been identified in Mattermost versions 10.2.0, 9.11.5, 10.0.3, and 10.1.3. This issue arises because the application fails to properly validate post properties, allowing a malicious authenticated user to cause a crash by sending a harmful post.
Mattermost Mobile Apps Post Prop Validation Vulnerability Leading to Crashes
A vulnerability exists in Mattermost Mobile Apps in versions 2.22.0 and earlier, where the application fails to properly validate post properties. This flaw allows a malicious authenticated user to send a harmful post that can cause the app to crash.
OpenText Solutions Business Manager Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in OpenText Solutions Business Manager (SBM) versions through 12.2.1. This vulnerability allows for improper neutralization of input during web page generation, potentially leading to the exposure of private information to unauthorized individuals.
TOTOLINK X5000R OS Command Injection Vulnerability in WiFi Schedule Configuration
An OS command injection vulnerability has been identified in the TOTOLINK X5000R router, specifically in firmware version 9.1.0cu.2350_B20230313. The vulnerability arises in the 'setWiFiScheduleCfg' function within the '/web/cgi-bin/cstecgi.cgi' file. Authenticated attackers can exploit this issue by sending crafted requests that include malicious commands in the 'desc' parameter, which are then executed on the operating system.
TOTOLINK X5000R OS Command Injection Vulnerability in WiFi Schedule Configuration
An OS command injection vulnerability has been identified in the TOTOLINK X5000R router, specifically in firmware version 9.1.0cu.2350_B20230313. The vulnerability arises in the 'setWiFiScheduleCfg' function within the '/web/cgi-bin/cstecgi.cgi' file. Authenticated attackers can exploit this issue by sending crafted requests that include malicious commands, which are then executed on the operating system.
TOTOLINK X5000R OS Command Injection Vulnerability in WiFi Scheduling Configuration
An OS command injection vulnerability has been identified in the TOTOLINK X5000R router, specifically in version V9.1.0cu.2350_B20230313. The vulnerability arises in the 'setWiFiScheduleCfg' function, where the 'week' parameter is improperly sanitized, allowing attackers to inject and execute arbitrary OS commands.
TOTOLINK X5000R OS Command Injection Vulnerability in WiFi Schedule Configuration
An OS command injection vulnerability has been identified in the TOTOLINK X5000R router, specifically in version V9.1.0cu.2350_B20230313. The vulnerability arises in the 'setWiFiScheduleCfg' function, where the 'sHour' parameter is improperly sanitized, allowing attackers to inject and execute arbitrary OS commands.
TOTOLINK X5000R OS Command Injection Vulnerability in WiFi Schedule Configuration
An OS command injection vulnerability has been identified in the TOTOLINK X5000R router, specifically in firmware version V9.1.0cu.2350_B20230313. The vulnerability arises in the 'setWiFiScheduleCfg' function within the '/web/cgi-bin/cstecgi.cgi' file. Authenticated attackers can exploit this issue by sending crafted requests that include malicious commands, which are then executed on the operating system.
TOTOLINK X5000R OS Command Injection Vulnerability in WiFi Scheduling Configuration
An OS command injection vulnerability has been identified in the TOTOLINK X5000R router, specifically in firmware version V9.1.0cu.2350_B20230313. The vulnerability arises in the 'setWiFiScheduleCfg' function within the '/web/cgi-bin/cstecgi.cgi' file. Authenticated attackers can exploit this issue by sending crafted requests that include malicious payloads, allowing them to execute arbitrary commands on the device.
TOTOLINK X5000R OS Command Injection Vulnerability in setVpnAccountCfg
An OS command injection vulnerability has been identified in the TOTOLINK X5000R router, specifically in firmware version V9.1.0cu.2350_B20230313. The vulnerability arises in the 'setVpnAccountCfg' function within the '/web/cgi-bin/cstecgi.cgi' file. Authenticated attackers can exploit this issue by sending crafted requests that include malicious commands, which are then executed on the device.
TOTOLINK X5000R OS Command Injection Vulnerability in setVpnAccountCfg
An OS command injection vulnerability has been identified in the TOTOLINK X5000R router, specifically in the firmware version v9.1.0cu.2350_B20230313. The vulnerability arises in the 'setVpnAccountCfg' function within the '/web/cgi-bin/cstecgi.cgi' file. Authenticated attackers can exploit this issue by sending crafted requests that include malicious commands, which are then executed on the device.
TOTOLINK X5000R OS Command Injection Vulnerability in VPN Account Configuration
An OS command injection vulnerability has been identified in the TOTOLINK X5000R router, specifically in firmware version V9.1.0cu.2350_B20230313. The vulnerability arises in the 'setVpnAccountCfg' function within the '/web/cgi-bin/cstecgi.cgi' file. Authenticated attackers can exploit this issue by sending crafted requests that include malicious payloads in the 'pass' parameter, allowing them to execute arbitrary commands on the device.
