CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
OpenObserve Improper Authorization Vulnerability in User Management Endpoint Allows Admin to Remove Root User
A vulnerability exists in OpenObserve versions prior to 0.14.1, specifically in the user management endpoint '/api/{org_id}/users/{email_id}'. This vulnerability allows an 'Admin' role user to remove a 'Root' user from the organization, violating the intended privilege hierarchy. The issue arises from insufficient role checks in the 'remove_user_from_org' function, which fails to prevent an 'Admin' user from targeting a 'Root' user for removal. Consequently, an 'Admin' user can eliminate critical 'Root' accounts, potentially gaining full control by removing the highest-privileged users.
Matrix Media Repo Denial-of-Service Vulnerability via Memory Exhaustion
A denial-of-service vulnerability has been identified in Matrix Media Repo (MMR) versions prior to 1.3.8. This issue arises because MMR can parse large amounts of JSON data returned from other servers, leading to excessive memory consumption and exhaustion of available resources. The vulnerability can be exploited during normal operation when MMR processes requests to resource owners that return substantial JSON payloads.
Matrix Media Repo Server-Side Request Forgery Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in Matrix Media Repo (MMR) versions prior to 1.3.8. This vulnerability allows MMR to access and serve content from internal networks under certain conditions. The issue arises when MMR is manipulated to make requests to internal resources, potentially exposing sensitive data or services.
Matrix Media Repo Unbounded Disk Consumption Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in Matrix Media Repo (MMR) versions prior to 1.3.5. This issue allows an unauthenticated attacker to cause excessive disk usage by inducing the application to download and store large quantities of remote media files. The vulnerability primarily affects instances using a file-backed storage option or those that self-host an S3 storage system, leading to a disk fill attack. When the disk becomes full, authenticated users are unable to upload new media, causing a denial-of-service condition. In cases where cloud-based S3 storage is used, the vulnerability could result in significant service charges instead of a denial-of-service impact.
Matrix Media Repo Unauthenticated Content Injection Vulnerability
A vulnerability in Matrix Media Repo (MMR) versions prior to 1.3.5 allows unauthenticated remote participants to download and cache media from a remote homeserver to the local media repository. This content can then be accessed from the local homeserver without authentication. As a result, unauthenticated remote adversaries can exploit this feature to introduce undesirable content into the media repository.
Mattermost Mobile Attachment Processing Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in Mattermost Mobile versions through 2.22.0. The issue arises because the application fails to properly manage posts with attachments that include fields not convertible to a string. This flaw allows an attacker to create and send such a post to a channel, causing the mobile application to crash.
Mattermost Denial-of-Service Vulnerability in Post Attachments
A denial-of-service vulnerability has been identified in Mattermost versions 10.2.x through 10.2.0, 9.11.x through 9.11.5, 10.0.x through 10.0.3, and 10.1.x through 10.1.3. The issue arises because the application fails to properly process posts with attachments that include fields unable to be converted to a string. This flaw allows an attacker to crash the web application by creating and sending such a post to a channel.
D-Link DIR-816 Access Control Vulnerability in formDMZ.cgi Allowing Unauthenticated DMZ Configuration
An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability allows unauthenticated attackers to manipulate the DMZ service settings of the device by sending a crafted POST request. The issue arises in the component formDMZ.cgi, where inadequate access controls permit unauthorized modifications to the DMZ configuration.
D-Link DIR-816 Access Control Vulnerability in URL Filter Component
An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability allows unauthenticated attackers to manipulate the device's URL filter settings by sending a crafted POST request.
D-Link DIR-816 Information Disclosure Vulnerability in d_status.asp Component
A vulnerability allowing information disclosure has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability arises in the d_status.asp component, where unauthenticated attackers can access sensitive information by sending a crafted POST request.
D-Link DIR-816 Access Control Vulnerability in AGL Service
An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the component form2alg.cgi. This vulnerability allows unauthenticated attackers to manipulate the AGL service of the device by sending a crafted POST request.
D-Link DIR-816 Access Control Vulnerability in form2PortriggerRule.cgi Allowing Unauthenticated Port Triggering
An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. The issue allows unauthenticated attackers to manipulate the port triggering settings of the device by sending a crafted POST request. This vulnerability arises from inadequate access controls in the affected CGI component, form2PortriggerRule.cgi.
D-Link DIR-816 Access Control Vulnerability in Repeater Service Configuration
An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability allows unauthenticated attackers to manipulate the 2.4G and 5G repeater services of the device by sending a crafted POST request.
D-Link DIR-816 Access Control Vulnerability in form2WlAc.cgi Allowing Unauthenticated MAC ACL Modification
An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability allows unauthenticated attackers to manipulate the MAC access control list for both the 2.4GHz and 5GHz bands. Exploitation is achieved by sending a crafted POST request to the device.
D-Link DIR-816 Access Control Vulnerability in form2Wan.cgi Allowing Unauthenticated WAN Service Modification
An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability allows unauthenticated attackers to manipulate the WAN service settings of the device by sending a crafted POST request. The issue arises in the form2Wan.cgi component, where inadequate access controls permit unauthorized modifications to critical network configurations.
D-Link DIR-816 Access Control Vulnerability in form2WlanBasicSetup.cgi Allowing Unauthenticated WLAN Service Modification
An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. The issue allows unauthenticated attackers to manipulate the 2.4G and 5G WLAN services of the device by sending a crafted POST request to the form2WlanBasicSetup.cgi component.
Gomatrixserverlib Server-Side Request Forgery Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in Gomatrixserverlib, a Go library for Matrix federation. This vulnerability allows the library to access and serve content from a private network, under certain conditions. The issue is present in versions of Gomatrixserverlib through dbd5f31fefc031633c3418165e4ef6d343e03999.
Mattermost Mobile Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Mattermost Mobile versions through 2.22.0. The issue arises because the application fails to properly validate the style of proto provided to an action's style in post.props.attachments. This lack of validation allows an attacker to crash the mobile application by sending crafted malicious input.
JFinalOA Cross-Site Scripting Vulnerability in Edit Page Interface
A cross-site scripting (XSS) vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the apply/getEditPage?view interface, where attackers can execute arbitrary web scripts or HTML by injecting a crafted payload.
JFinalOA SQL Injection Vulnerability in Workflow History Component
A SQL injection vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the workflow history component, specifically through the 'getWorkFlowHis?insid' parameter.
JFinalOA Cross-Site Scripting Vulnerability in Business Upload List Interface
A cross-site scripting (XSS) vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the getBusinessUploadListPage?busid interface, where attackers can execute arbitrary web scripts or HTML by injecting a crafted payload.
JFinalOA Cross-Site Scripting Vulnerability in openSelectManyUserPage?orgid Interface
A cross-site scripting (XSS) vulnerability has been identified in JFinalOA versions prior to v2025.01.01. The issue arises in the openSelectManyUserPage?orgid interface, where attackers can execute arbitrary web scripts or HTML by injecting a crafted payload.
JFinalOA Cross-Site Scripting Vulnerability in Draft List Interface
A cross-site scripting (XSS) vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the '/bumph/getDraftListPage?type' interface, where attackers can execute arbitrary web scripts or HTML by injecting a crafted payload.
JFinalOA Cross-Site Scripting Vulnerability in Edit Page Interface
A cross-site scripting (XSS) vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the common/getEditPage?view interface, where attackers can execute arbitrary web scripts or HTML by injecting a crafted payload.
JFinalOA SQL Injection Vulnerability
A SQL injection vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the apply/save#oaContractApply.id component, allowing attackers to manipulate SQL queries and potentially access or modify database information.
JFinalOA SQL Injection Vulnerability in borrowmoney Component
A SQL injection vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the borrowmoney component, specifically within the listData?applyUser endpoint.
JFinalOA SQL Injection Vulnerability in validRoleKey Component
A SQL injection vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the validRoleKey component, specifically through the sysRole.key parameter.
Indico Broken Object Level Authorization Vulnerability
A Broken Object Level Authorization (BOLA) vulnerability exists in Indico versions through 3.3.5. This vulnerability allows attackers to read information by sending a crafted POST request to the /api/principals endpoint. The issue arises because the application design intentionally permits all users to access certain information about other user accounts, without restricting this functionality to privileged roles such as event organizers.
IBM CICS TX Stored Cross-Site Scripting Vulnerability Allowing JavaScript Injection
A stored cross-site scripting vulnerability has been identified in IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1. This issue allows users to inject arbitrary JavaScript into the Web UI, potentially altering functionality and leading to credential disclosure within a trusted session.
Intel Neural Compressor Time-of-Check Time-of-Use Race Condition Vulnerability Allowing Information Disclosure
A time-of-check time-of-use race condition vulnerability has been identified in Intel Neural Compressor software versions prior to 3.0. This vulnerability may allow an authenticated user to disclose information through adjacent access.
FFmpeg Unchecked Return Value, Out-of-bounds Read Vulnerability in libavfilter af_pan Allowing Read of Sensitive Constants
A vulnerability in FFmpeg's libavfilter component, specifically in the af_pan audio filter, has been identified. This issue involves an unchecked return value leading to an out-of-bounds read, which allows the reading of sensitive constants within an executable. The vulnerability was present in FFmpeg version 7.1 and has been fixed in a subsequent update.
07FLYCMS Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in 07FLYCMS version 1.3.9. The issue arises in the admin/doAdminAction.php file, specifically when the 'act' parameter is set to 'editShop' and the 'shopId' parameter is included.
Campcodes Cybercafe Management System SQL Injection Vulnerability
A SQL injection vulnerability has been identified in Campcodes Cybercafe Management System version 1.0. The issue resides in the 'view-user-detail.php' file, where user input is not properly sanitized, allowing attackers to manipulate SQL queries and potentially access or modify database information.
07FLYCMS Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in 07FLYCMS version 1.3.9. The issue arises in the OaWorkReport edit page, allowing attackers to perform actions on behalf of users without their consent.
07FLYCMS Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in 07FLYCMS version 1.3.9. The issue resides in the OaTask editing component, accessible through the erp.07fly.net domain.
07FLYCMS Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in 07FLYCMS version 1.3.9. The issue resides in the OaWorkReport component, specifically within the add.html page. This vulnerability allows an attacker to trick a user into submitting a request that could potentially manipulate data or perform actions on their behalf.
PMB Platform Temporary File Persistence Vulnerability
A vulnerability exists in the PMB platform in versions 4.0.10 and above, allowing attackers to persist temporary files on the server. This issue arises in the file upload functionality at the '/pmb/authorities/import/iimport_authorities' endpoint. When a file is uploaded, the server creates a temporary file that is normally deleted after a POST request is sent to the same endpoint. However, an attacker can intercept and delay this POST request, preventing the temporary file from being removed.
PMB Platform Information Exposure Vulnerability
A vulnerability allowing information exposure has been identified in the PMB platform, affecting versions 4.2.13 and earlier. This issue enables an attacker to upload a file to the environment and enumerate internal files on a machine by analyzing the response to the upload request.
PMB Platform Unrestricted File Upload Vulnerability Allowing Remote Access
A vulnerability allowing unrestricted file uploads has been identified in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could enable an attacker to upload a file that facilitates remote access to the machine, allowing unrestricted access to modify files and execute commands.
WAGO 750-8xx Controller Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in WAGO 750-8xx controllers, including the 750-8100, 750-831, 750-880, and 750-889 models, all running versions through their respective maximums. The vulnerability allows an unauthenticated remote attacker to disrupt normal device operation by causing uncontrolled resource consumption, particularly high network load, which can interfere with the device's CPU performance and cycle timing. This network packet flood can be especially problematic, as it may temporarily degrade the device's functionality, although it typically resumes normal operation once the network load decreases.
Fortinet FortiManager and FortiAnalyzer Weak Authentication Vulnerability Allowing Unauthorized Code Execution
A weak authentication vulnerability has been identified in Fortinet FortiManager Cloud, FortiAnalyzer, FortiManager, and FortiManager Cloud. This vulnerability affects several different versions and ranges, specifically FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, and FortiAnalyzer Cloud versions 7.4.1 through 7.4.3. The vulnerability allows attackers to execute unauthorized code or commands by leveraging a brute-force attack.
WP Responsive Tabs Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WP Responsive Tabs plugin for WordPress, affecting all versions through 1.2.9. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'wprtabs' shortcode. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary scripts into pages, which are executed when users access the affected pages.
Admin and Customer Messages After Order for WooCommerce Limited File Upload Vulnerability
A vulnerability exists in the Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress, in all versions through 13.2. The issue arises from inadequate validation of file types in the upload_file() function, allowing authenticated attackers with Subscriber-level access and above to upload files to the server. This vulnerability could potentially lead to remote code execution and has been confirmed to allow Cross-Site Scripting.
Passwords Manager WordPress Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the Passwords Manager plugin for WordPress, affecting all versions through 1.4.8. The vulnerability arises from inadequate escaping of user-supplied data in several AJAX actions, allowing authenticated attackers with Subscriber-level access or higher to inject additional SQL queries. This could be exploited to extract sensitive information from the database.
Passwords Manager WordPress Plugin Missing Capability Check Vulnerability
A vulnerability exists in the Passwords Manager plugin for WordPress, in all versions through 1.4.8. The issue stems from a lack of proper capability checks on the 'pms_save_setting' and 'post_new_pass' AJAX actions. This flaw allows authenticated attackers with Subscriber-level access and above to unauthorizedly modify plugin settings, add passwords, and update the encryption key used for password management.
Passwords Manager WordPress Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the Passwords Manager plugin for WordPress, affecting all versions through 1.4.8. The vulnerability arises from inadequate escaping of user-supplied parameters in several AJAX functions, allowing unauthenticated attackers to inject additional SQL queries. Exploitation of this vulnerability could lead to the extraction of sensitive information from the database.
WordPress Multi Step Form Plugin Unauthorized File Upload Vulnerability
A vulnerability exists in the Multi Step Form plugin for WordPress, allowing unauthorized file uploads. This issue arises from a lack of proper capability checks on the 'fw_upload_file' AJAX action, affecting all versions up to and including 1.7.23. As a result, unauthenticated attackers can upload certain file types, such as images.
Fortinet FortiRecorder, FortiWeb, and FortiVoice Path Traversal Vulnerability Allowing Privilege Escalation
A path traversal vulnerability has been identified in Fortinet FortiRecorder versions 7.2.0 through 7.2.1 and 7.0.0 through 7.0.4, as well as FortiWeb versions 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.10, and 6.4.0 through 6.4.3. Additionally, FortiVoice versions 7.0.0 through 7.0.4, 6.4.0 through 6.4.9, and 6.0.0 through 6.0.12 are affected. This vulnerability allows attackers to escalate privileges by sending specially crafted packets, taking advantage of improper restrictions on file paths that could lead to accessing unauthorized directories.
Fortinet FortiAnalyzer, FortiManager, and FortiAnalyzer Cloud Privilege Escalation Vulnerability
A vulnerability allowing privilege escalation has been identified in Fortinet FortiAnalyzer, FortiManager, and FortiAnalyzer Cloud. This issue arises from incorrect privilege assignments and affects multiple versions across these products. Specifically, it impacts FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, and 6.4.0 through 6.4.15. FortiManager versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, and 6.4.0 through 6.4.15 are also affected. Additionally, FortiAnalyzer Cloud versions 7.4.1 through 7.4.2, 7.2.1 through 7.2.6, 7.0.1 through 7.0.13, and 6.4.1 through 6.4.7 are vulnerable. The vulnerability allows attackers to escalate privileges by using specific shell commands.
Octopus Deploy Kubernetes Worker and Agent Sensitive Variable Logging Vulnerability
A vulnerability exists in Octopus Deploy Kubernetes worker and agent versions 1.x prior to 1.19.0 and 2.x prior to 2.8.0, allowing sensitive variables to be logged in clear text in the Kubernetes script pod logs. This issue was initially identified in version 2 but was later found to affect version 1 as well.
