CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Ivanti Avalanche Path Traversal Vulnerability Allowing Sensitive Information Disclosure
A path traversal vulnerability has been identified in Ivanti Avalanche versions prior to 6.4.7. This vulnerability allows remote unauthenticated attackers to leak sensitive information. It is important to note that this CVE addresses incomplete fixes from a previous vulnerability, CVE-2024-47011.
Ivanti Avalanche Path Traversal Vulnerability Allowing Authentication Bypass
A path traversal vulnerability has been identified in Ivanti Avalanche versions prior to 6.4.7. This vulnerability allows remote unauthenticated attackers to bypass authentication. The issue arises from incomplete fixes in a previous vulnerability (CVE-2024-47010).
Ivanti Endpoint Manager Absolute Path Traversal Vulnerability Allowing Information Disclosure
A path traversal vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 Security Update for both the 2024 and 2022 SU6 releases. This vulnerability allows remote, unauthenticated attackers to exploit absolute path traversal, leading to the unauthorized disclosure of sensitive information. The issue arises from the application's failure to properly validate user input, enabling attackers to manipulate file paths and access restricted data.
Ivanti Application Control Engine Race Condition Vulnerability Allowing Application Blocking Bypass
A race condition vulnerability has been identified in Ivanti Application Control Engine versions prior to 10.14.4.0. This vulnerability allows a local authenticated attacker to bypass the application's blocking functionality, potentially leading to unauthorized actions or access within the application.
iceCMS Access Control Vulnerability in Square Comment API
An access control vulnerability has been identified in iceCMS version 2.2.0, specifically within the Square Comment API endpoint 'DelectSquareById'. This vulnerability allows unauthenticated attackers to access sensitive information by exploiting improper access controls, particularly in the content management features of the admin interface.
iceCMS Access Control Vulnerability in Sensitive Information Disclosure
An access control vulnerability has been identified in iceCMS version 2.2.0, specifically within the component '/square/getAllSquare/circle'. This vulnerability allows unauthenticated attackers to access sensitive information.
Shanghai Lingdang Information Technology Lingdang CRM Path Traversal Vulnerability
A path traversal vulnerability has been identified in Shanghai Lingdang Information Technology's Lingdang CRM, affecting versions through 8.6.0.0. The issue arises in the file '/crm/weixinmp/index.php' when specific query parameters are manipulated. This vulnerability allows for remote exploitation by traversing directories and potentially accessing unauthorized files on the server.
Blog Botz OpenCart Module Unrestricted File Upload Vulnerability
A critical vulnerability allowing unrestricted file uploads has been identified in the Blog Botz module for OpenCart, version 1.0. The issue arises in the file '/index.php?route=extension/module/blog_add', where the 'image' parameter can be manipulated to upload files of arbitrary types. This vulnerability can be exploited remotely, potentially leading to unauthorized access to the site's hosting environment. An attacker could upload a malicious PHP file, such as a web shell, and execute it on the server. This exploitation could result in a complete compromise of the site, including access to admin credentials and sensitive database information, such as payment details or Personally Identifiable Information.
libretro RetroArch Untrusted Search Path Vulnerability in profapi.dll Component
A vulnerability allowing for code injection via an untrusted search path has been identified in libretro RetroArch versions through 1.19.1 on Windows. The issue arises in the Startup component, specifically within the profapi.dll library. During startup, the application loads DLL files from the local installation folder, creating an opportunity to inject code into a manipulated profapi.dll file. This could potentially lead to remote code execution through DLL injection.
Virtual Computer Vysual RH Solution Cross-Site Scripting Vulnerability in Login Panel
A reflected cross-site scripting vulnerability has been identified in Virtual Computer Vysual RH Solution version 2024.12.1. The issue arises in the Login Panel component, specifically within the index.php file. The vulnerability is triggered by manipulating the 'page' parameter, which allows for the injection of malicious scripts. This cross-site scripting flaw can be exploited remotely, with the victim required to interact with the malicious link.
Phoenix SecureCore UEFI Variable Handling Vulnerability Leading to Input Data Manipulation
A vulnerability exists in Phoenix SecureCore firmware for various Intel processor families, including Kaby Lake, Coffee Lake, Comet Lake, and Ice Lake. This vulnerability arises from improper handling of UEFI variables, allowing for unsafe memory access that could result in temporary denial of service. The issue affects SecureCore for Intel Kaby Lake versions prior to 4.0.1.1012, Coffee Lake versions prior to 4.1.0.568, Comet Lake versions prior to 4.2.1.292, and Ice Lake versions prior to 4.2.0.334.
Phoenix SecureCore UEFI Variable Handling Vulnerability on Intel Processors
A vulnerability exists in Phoenix SecureCore firmware for Intel Kaby Lake, Coffee Lake, Comet Lake, and Ice Lake processors. This vulnerability involves improper handling of UEFI variables, allowing for input data manipulation that could lead to unsafe memory access and a temporary denial-of-service condition.
Sourcecodester House Rental Management System Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Sourcecodester House Rental Management System version 1.0. The issue is located in the 'rental/manage_categories.php' file, where user input is not properly sanitized, allowing for the injection of malicious scripts.
AMI AptioV BIOS TOCTOU Race Condition Vulnerability Allowing Arbitrary Code Execution
A TOCTOU (Time-of-Check to Time-of-Use) race condition vulnerability has been identified in the AMI AptioV BIOS. This vulnerability allows an attacker to exploit the race condition through local means, potentially leading to the execution of arbitrary code on the affected device. The issue arises in products using the Computrace module.
Wavlink AC3000 Buffer Overflow Vulnerabilities in QoS CGI Settings
Multiple stack-based buffer overflow vulnerabilities have been identified in the QoS CGI 'qos_settings' function of the Wavlink AC3000 router, specifically in the M33A8.V5030.210505 version. These vulnerabilities allow for authenticated attackers to send specially crafted HTTP requests that trigger the buffer overflows, potentially leading to arbitrary code execution.
Wavlink AC3000 Buffer Overflow Vulnerability in QoS CGI Settings
Multiple stack-based buffer overflow vulnerabilities have been identified in the QoS CGI 'qos_settings' function of the Wavlink AC3000 router, specifically in the firmware version M33A8.V5030.210505. These vulnerabilities can be triggered by authenticated users sending specially crafted HTTP requests. The 'qos_dat' POST parameter is one of the fields that can be exploited, leading to arbitrary code execution.
Wavlink AC3000 Buffer Overflow Vulnerability in Qos.cgi Qos_Settings Function
Multiple buffer overflow vulnerabilities have been identified in the Wavlink AC3000 router, specifically in the qos.cgi file within the qos_settings() function. These vulnerabilities arise from stack-based buffer overflows caused by improperly validated HTTP POST request parameters. The affected version is Wavlink AC3000 M33A8.V5030.210505. An authenticated attacker can exploit these vulnerabilities, leading to arbitrary code execution.
Wavlink AC3000 OpenVPN CGI Configuration Control Vulnerability Allowing Arbitrary Command Execution
A vulnerability allowing arbitrary command execution has been identified in the Wavlink AC3000 router, specifically in the OpenVPN CGI interface's server setup functionality. This issue arises from multiple external configuration control vulnerabilities that can be exploited by sending a specially crafted HTTP request. The vulnerability affects Wavlink AC3000 routers running firmware version M33A8.V5030.210505.
Wavlink AC3000 OpenVPN Configuration Injection Vulnerability Allowing Arbitrary Command Execution
A vulnerability allowing arbitrary command execution through configuration injection has been identified in the Wavlink AC3000 router, specifically in the OpenVPN CGI interface version M33A8.V5030.210505. The issue arises because the OpenVPN server setup function does not properly validate input from several POST parameters, allowing authenticated users to inject malicious commands that are executed by the router's OpenVPN service.
Wavlink AC3000 OpenVPN Configuration Injection Vulnerability Allowing Arbitrary Command Execution
A vulnerability allowing arbitrary command execution through configuration injection has been identified in the Wavlink AC3000 router, specifically in the OpenVPN CGI interface version M33A8.V5030.210505. The issue arises within the 'openvpn_server_setup' function, where certain POST parameters can be exploited by authenticated users to inject malicious commands into the system.
Wavlink AC3000 Multiple ProFTPD Configuration Control Vulnerabilities
Multiple external configuration control vulnerabilities have been identified in the Wavlink AC3000 router, specifically in the nas.cgi set_nas() ProFTPD functionality, within the firmware version M33A8.V5030.210505. These vulnerabilities allow for permission bypass through specially crafted HTTP requests. An authenticated user can exploit these issues, leading to unauthorized configuration changes that could be leveraged for further exploitation.
Wavlink AC3000 Multiple ProFTPD Configuration Injection Vulnerabilities
Multiple external configuration control vulnerabilities have been identified in the Wavlink AC3000 router, specifically in the nas.cgi set_nas() ProFTPD functionality, within the firmware version M33A8.V5030.210505. These vulnerabilities allow for permission bypass through specially crafted HTTP requests. An authenticated user can exploit these issues by injecting malicious data into various POST parameters, leading to unauthorized configuration changes that could be exploited further.
Wavlink AC3000 Multiple ProFTPD Configuration Injection Vulnerabilities
Multiple external configuration control vulnerabilities have been identified in the Wavlink AC3000 router, specifically in the nas.cgi set_nas() ProFTPD functionality, within the firmware version M33A8.V5030.210505. These vulnerabilities allow for permission bypass through specially crafted HTTP requests. An authenticated user can exploit these issues by injecting malicious data into various POST parameters, leading to unauthorized configuration changes that could be exploited for further access or control.
Wavlink AC3000 FTP Configuration Injection Vulnerability
A configuration injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the nas.cgi set_ftp_cfg() function of version M33A8.V5030.210505. This vulnerability allows authenticated users to send specially crafted HTTP requests that bypass permissions and inject malicious configurations into the router's FTP settings. The injected configurations can be exploited to manipulate the FTP server's behavior, potentially leading to unauthorized access or actions on the device.
Wavlink AC3000 Permission Bypass and Configuration Injection Vulnerabilities
Multiple external configuration control vulnerabilities have been identified in the Wavlink AC3000 router, specifically in the nas.cgi set_ftp_cfg() function. These vulnerabilities allow for permission bypass and configuration injection through specially crafted HTTP requests. The issues affect Wavlink AC3000 M33A8.V5030.210505. An authenticated user can exploit these vulnerabilities by sending HTTP POST requests with manipulated parameters.
Wavlink AC3000 External Configuration Control Vulnerabilities in FTP Settings
Multiple external configuration control vulnerabilities have been identified in the Wavlink AC3000 router, specifically in the nas.cgi set_ftp_cfg() function of version M33A8.V5030.210505. These vulnerabilities allow for permission bypass through specially crafted HTTP requests. An authenticated user can exploit these issues, leading to unauthorized configuration changes via the ftp_name, ftp_port, and ftp_max_sessions parameters.
Wavlink AC3000 Directory Traversal Vulnerabilities in nas.cgi add_dir() Function
Multiple directory traversal vulnerabilities have been identified in the Wavlink AC3000 router, specifically in the nas.cgi add_dir() functionality, version M33A8.V5030.210505. These vulnerabilities allow for permission bypass through specially crafted HTTP requests. The issues arise because the add_dir function does not properly validate input parameters, enabling attackers to manipulate directory paths and change file permissions on the device.
Wavlink AC3000 Directory Traversal Vulnerabilities in nas.cgi add_dir() Function
Multiple directory traversal vulnerabilities have been identified in the Wavlink AC3000 router, specifically in the nas.cgi add_dir() functionality, version M33A8.V5030.210505. These vulnerabilities allow for permission bypass by exploiting the adddir_name and disk_part POST parameters. An authenticated user can send a crafted HTTP request that takes advantage of improper input validation, leading to unauthorized modification of file or directory permissions on the device.
Wavlink AC3000 Command Injection Vulnerability in nas.cgi add_dir() Function
A command injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the nas.cgi add_dir() functionality. This vulnerability allows authenticated users to execute arbitrary commands on the device by sending a specially crafted HTTP request. The issue arises in the adddir_name and disk_part POST parameters, where injected commands can be executed with system privileges.
Wavlink AC3000 Command Injection Vulnerability in nas.cgi add_dir() Function
A command injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the nas.cgi add_dir() function. This vulnerability allows authenticated users to execute arbitrary commands on the device by sending a specially crafted HTTP request. The issue arises in the disk_part and adddir_name POST parameters, where injected commands can be executed with system privileges.
Wavlink AC3000 OS Command Injection Vulnerability in adm.cgi sch_reboot() Function
A command injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the adm.cgi file within the sch_reboot() function. This vulnerability allows authenticated users to execute arbitrary commands on the device. The issue arises from improper validation of user input in several POST parameters, which can be exploited by crafting a specific HTTP request. Once exploited, the injected commands are executed with the privileges of the user account under which the web server is running.
Wavlink AC3000 OS Command Injection Vulnerability in adm.cgi sch_reboot() Function
A command injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the adm.cgi file within the sch_reboot() function. This vulnerability allows authenticated users to execute arbitrary commands on the device. The issue arises from improper handling of the restart_min POST parameter, which can be exploited by sending a specially crafted HTTP request. Once exploited, the injected command is executed with the privileges of the user running the web server.
Wavlink AC3000 OS Command Injection Vulnerability in adm.cgi sch_reboot() Function
Multiple operating system command injection vulnerabilities have been identified in the Wavlink AC3000 router, specifically in the adm.cgi file within the sch_reboot() function. These vulnerabilities allow for arbitrary code execution via specially crafted HTTP requests. The issues arise in the restart_hour, restart_min, and restart_week POST parameters. An authenticated user can exploit these vulnerabilities by sending requests that inject malicious commands, which are then executed with elevated privileges.
Wavlink AC3000 Buffer Overflow Vulnerability in adm.cgi set_sys_adm() Function
A buffer overflow vulnerability has been identified in the Wavlink AC3000 router, specifically in the adm.cgi set_sys_adm() function of version M33A8.V5030.210505. This vulnerability allows for a stack-based buffer overflow through a specially crafted HTTP request. An authenticated user can exploit this issue by sending the crafted request, leading to potential unauthorized code execution.
Wavlink AC3000 Information Disclosure Vulnerability in testsave.sh
A vulnerability allowing information disclosure exists in the Wavlink AC3000 router, specifically in the testsave.sh script. This issue arises in the version M33A8.V5030.210505. The vulnerability can be exploited by sending a specially crafted HTTP request, which the router's lighttpd server will process. The testsave.sh script, located in the '/www/cgi-bin' directory, is executed when the corresponding URL is accessed. The script outputs the contents of the '/var/log/messages' file, thereby disclosing sensitive information.
Wavlink AC3000 Buffer Overflow Vulnerability in QoS Management
A stack-based buffer overflow vulnerability has been identified in the Wavlink AC3000 router, specifically in the internet.cgi file's set_qos() function. This vulnerability affects version M33A8.V5030.210505. The issue arises from the 'en_enable' POST parameter, which can be exploited by sending a specially crafted HTTP request. The vulnerability allows authenticated users to overwrite the return address of the function with arbitrary data, potentially leading to remote code execution.
Wavlink AC3000 Buffer Overflow Vulnerability in QoS Management
A stack-based buffer overflow vulnerability has been identified in the Wavlink AC3000 router, specifically in the internet.cgi file's set_qos() function. This vulnerability affects version M33A8.V5030.210505. The issue arises from the improper handling of POST parameters, particularly 'cli_mac', 'cli_name', and 'en_enable', which are all processed without length validation. An authenticated attacker can exploit this vulnerability by sending a crafted HTTP request that overwrites the stack with malicious data, potentially leading to arbitrary code execution.
Wavlink AC3000 Buffer Overflow Vulnerability in QoS Management
A stack-based buffer overflow vulnerability has been identified in the Wavlink AC3000 router, specifically in the internet.cgi file's set_qos() function. This vulnerability affects version M33A8.V5030.210505. The issue arises from the cli_name POST parameter, which can be exploited by sending a specially crafted HTTP request. The vulnerability allows authenticated attackers to overwrite the return address of the function with arbitrary data, potentially leading to remote code execution.
Wavlink AC3000 Command Injection Vulnerability in Routing Configuration
A command injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the internet.cgi set_add_routing() function. This vulnerability allows authenticated attackers to execute arbitrary commands on the device. The issue arises from improper handling of several POST parameters, including 'dest', 'netmask', 'gateway', 'interface', and 'custom_interface'. Exploitation involves sending a crafted HTTP request that includes malicious input in these parameters, bypassing authentication checks and leading to unauthorized command execution.
Wavlink AC3000 Command Injection Vulnerability in Routing Configuration
A command injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the internet.cgi set_add_routing() function of version M33A8.V5030.210505. This vulnerability allows authenticated users to execute arbitrary commands on the router by sending specially crafted HTTP requests. The issue arises because the application fails to properly sanitize input from several POST parameters, including 'dest', 'netmask', 'gateway', and 'custom_interface', before executing it as a command.
Wavlink AC3000 Command Injection Vulnerability in Routing Configuration
A command injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the internet.cgi set_add_routing() function. This vulnerability allows authenticated users to execute arbitrary commands on the router by sending specially crafted HTTP requests. The issue arises because the application fails to properly sanitize input from several POST parameters, including 'dest', 'netmask', 'gateway', 'interface', 'custom_interface', and 'comment'. The vulnerability is present in Wavlink AC3000 M33A8.V5030.210505.
Wavlink AC3000 Command Injection Vulnerability in Routing Configuration
A command injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the internet.cgi set_add_routing() function. This vulnerability allows authenticated attackers to execute arbitrary commands on the device. The issue arises from improper handling of several POST parameters, including 'netmask', 'gateway', 'dest', 'interface', 'custom_interface', and 'comment'. The vulnerability is present in the Wavlink AC3000 M33A8.V5030.210505 version.
Wavlink AC3000 Command Injection Vulnerability in login.cgi Allowing Arbitrary Code Execution
A command injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the login.cgi file's set_sys_init() function. This vulnerability, present in version M33A8.V5030.210505, allows for arbitrary code execution. The issue arises because the login.cgi file does not properly authenticate users before executing commands. An attacker can exploit this vulnerability by sending a specially crafted HTTP request, taking advantage of the command injection flaw in the restart_week_value POST parameter.
Wavlink AC3000 Command Injection Vulnerability in login.cgi Allowing Arbitrary Code Execution
A command injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the login.cgi file's set_sys_init() function. This vulnerability allows for arbitrary code execution via OS command injection. It affects the Wavlink AC3000 model with the firmware version M33A8.V5030.210505. The issue arises because the login.cgi file does not properly validate user authentication, allowing attackers to send crafted HTTP requests that exploit this vulnerability.
Wavlink AC3000 Command Injection Vulnerability in login.cgi Allowing Arbitrary Code Execution
A command injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the login.cgi file's set_sys_init() function. This vulnerability allows for arbitrary code execution via OS command injection. It affects the Wavlink AC3000 model with the firmware version M33A8.V5030.210505. The issue arises because the login.cgi file does not properly validate user authentication, allowing attackers to send crafted HTTP requests that exploit this flaw.
Wavlink AC3000 Wireless Router Stack-Based Buffer Overflow Vulnerability in AddMac Functionality
A stack-based buffer overflow vulnerability has been identified in the Wavlink AC3000 router, specifically in the wireless.cgi AddMac() function of version M33A8.V5030.210505. This vulnerability allows authenticated attackers to execute arbitrary commands by sending specially crafted HTTP requests. The issue arises because the AddMac function does not properly validate the length of the 'addMac' POST parameter, enabling attackers to overwrite the return address and gain command execution capabilities.
Wavlink AC3000 Buffer Overflow Vulnerability in adm.cgi rep_as_router() Function
A buffer overflow vulnerability has been identified in the Wavlink AC3000 router, specifically in the adm.cgi file within the rep_as_router() function. This vulnerability, present in version M33A8.V5030.210505, allows for a stack-based buffer overflow when a specially crafted HTTP request is sent. The issue can be triggered by an authenticated user.
Wavlink AC3000 Static Login Vulnerability in wctrls Functionality Granting Root Access
A static login vulnerability has been identified in the Wavlink AC3000 router, specifically in the wctrls functionality of version M33A8.V5030.210505. This vulnerability allows an attacker to gain root access by sending a specially crafted set of network packets to the device. The wctrls service, running on UDP port 36338, accepts these packets and, after a series of encrypted communications, can be exploited to enable a telnet service with root privileges. This issue is compounded by the existence of a static admin login that persists even after a factory reset, allowing for remote access over WAN.
Wavlink AC3000 Unauthenticated Firmware Update Vulnerability in login.cgi
A vulnerability allowing unauthorized firmware updates has been identified in the Wavlink AC3000 router, specifically in the login.cgi component of version M33A8.V5030.210505. This issue arises from the absence of authentication checks, allowing attackers to send crafted HTTP requests that trigger arbitrary firmware uploads.
Wavlink AC3000 Command Execution Vulnerability via HTTP Request
A command execution vulnerability has been identified in the Wavlink AC3000 router, specifically in the update_filter_url.sh script of version M33A8.V5030.210505. This vulnerability allows arbitrary command execution by injecting crafted HTTP requests. The issue can be exploited through a man-in-the-middle attack, taking advantage of the script's lack of HTTPS validation.
