CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
MonetDB Server Denial-of-Service Vulnerability in Tail Type Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.49.1. The issue arises in the tail_type component, where attackers can cause the server to crash by sending crafted SQL statements. This vulnerability can be reproduced by executing a specific SQL query that exploits the group's handling within the query processing engine.
MonetDB Server Denial-of-Service Vulnerability in exp_values_set_supertype Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.49.1. The issue arises in the exp_values_set_supertype component, where attackers can cause the server to crash by sending crafted SQL statements. This vulnerability can be reproduced by creating a merge table, adding a partition with specific values, and then executing the SQL commands, which triggers a server crash.
MonetDB Server Denial-of-Service Vulnerability in gc_col Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.49.1. The issue arises in the gc_col component, where attackers can cause the server to crash by sending crafted SQL statements. This vulnerability can be reproduced by creating a merge table, starting a transaction, and then dropping specific columns, which triggers a server crash.
MonetDB Server Denial-of-Service Vulnerability in mat_join2 Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.49.1. The issue arises in the mat_join2 component, where attackers can cause the server to crash by using specially crafted SQL statements. This vulnerability can be reproduced in a Docker environment using the official MonetDB image for December 2023.
MonetDB Server Denial-of-Service Vulnerability in Merge Table Prune and Unionize Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.49.1. The issue arises in the 'merge_table_prune_and_unionize' component, where attackers can cause the server to crash by using specially crafted SQL statements. This vulnerability can be reproduced in a Docker environment using the 'monetdb/monetdb:Dec2023' image.
MonetDB Server Denial-of-Service Vulnerability in exp_atom Component
A denial-of-service vulnerability has been identified in the exp_atom component of MonetDB Server version 11.49.1. This issue allows attackers to cause the server to crash by sending specially crafted SQL statements. The vulnerability can be reproduced in a Docker environment using the official MonetDB Docker image for the December 2023 release.
MonetDB Server Denial-of-Service Vulnerability in HEAP_malloc Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.49.1. The issue arises in the HEAP_malloc component, where attackers can cause the server to crash by sending crafted SQL statements. This vulnerability can be reproduced by creating a table with a specific SQL query, inserting data, and then executing a series of SQL commands that trigger the crash. The problem has been acknowledged as a bug in the Dec2023-SP1 release.
MonetDB Server Denial-of-Service Vulnerability in exp_bin Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.49.1, specifically within the exp_bin component. This issue allows attackers to cause the server to crash by sending crafted SQL statements. The vulnerability can be reproduced by creating a table and executing a SELECT statement that includes certain SQL functions and operations, such as median calculation and window functions, which trigger the crash.
MonetDB Server Denial-of-Service Vulnerability in GDKanalytical_correlation Component
A denial-of-service vulnerability has been identified in the GDKanalytical_correlation component of MonetDB Server version 11.47.11. This issue allows attackers to crash the server by using specially crafted SQL statements. The vulnerability can be reproduced in a Docker container running Ubuntu 20.04.
MonetDB Server Denial-of-Service Vulnerability in Trimchars Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.47.11. The issue arises in the trimchars component, where crafted SQL statements can cause the server to crash. This vulnerability is related to the handling of NULL values by the newurl function, which can lead to fatal errors in the trimchars function, causing the server to become unresponsive.
MonetDB Server Denial-of-Service Vulnerability in atom_get_int Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.47.11. The issue arises in the atom_get_int component, where attackers can cause the server to crash by sending specially crafted SQL statements. This vulnerability can be reproduced by executing a SQL query that orders the results by a debug variable, which triggers a backtrace indicating the crash sequence.
MonetDB Server Denial-of-Service Vulnerability in SQL Statement Processing
A denial-of-service vulnerability has been identified in MonetDB Server version 11.47.11. The issue arises in the 'bind_col_exp' component, where attackers can cause the server to crash by using specially crafted SQL statements. This vulnerability can be reproduced by creating a table and then executing a SELECT query that includes complex ordering and aggregation functions, which leads to a server crash.
MonetDB Server Damerau-Levenshtein Component Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the Damerau-Levenshtein component of MonetDB Server version 11.49.1. This issue allows attackers to cause the server to crash by using specially crafted SQL statements. The vulnerability can be reproduced in a Docker container running Ubuntu 20.04.
MonetDB Server Denial-of-Service Vulnerability in vscanf Component
A denial-of-service vulnerability has been identified in the vscanf component of MonetDB Server version 11.47.11. This issue allows attackers to cause the server to crash by sending specially crafted SQL statements. The vulnerability can be reproduced by executing a SQL query that improperly parses interval data, leading to a server crash.
MonetDB Server Denial-of-Service Vulnerability in BATcalcbetween_intern Component
A denial-of-service vulnerability has been identified in the BATcalcbetween_intern component of MonetDB Server version 11.47.11. This issue allows attackers to cause the server to crash by sending specially crafted SQL statements. The vulnerability can be reproduced in a Docker container running Ubuntu 20.04.
Omron NB-Series XML External Entity Reference Vulnerability in NX-Designer
A vulnerability allowing improper restriction of XML external entity references has been identified in Omron NB-Series NX-Designer. This issue could enable attackers to disclose confidential data on a computer.
Omron NJ/NX-Series Machine Automation Controllers Path Traversal Vulnerability Allowing Remote Code Execution
A path traversal vulnerability has been identified in Omron NJ/NX-series Machine Automation Controllers. This vulnerability allows an attacker to gain unauthorized access and execute unauthorized code remotely on the affected controller products.
Event Monster WordPress Plugin Information Exposure Vulnerability
A vulnerability allowing information exposure has been identified in the Event Monster WordPress plugin, specifically in versions through 1.4.3. The issue arises during the export of the Visitors List, where a CSV file is generated in the wp-content directory with a hardcoded filename that is publicly accessible. This flaw enables unauthenticated attackers to retrieve personal data of event attendees, including their first and last names, email addresses, and phone numbers.
Eaton XC-303 Hardcoded SSH Root Password Vulnerability
A vulnerability exists in Eaton XC-303 PLCs running firmware versions prior to 3.5.16 and 3.5.17 Build 712, allowing an attacker with network access to log in as root via SSH. The root password, hardcoded in the firmware, is 'Etn602'. This issue arises because versions 3.5.16 and below use the insecure 'crypt' algorithm to hash the root password, leaving it susceptible to brute-force attacks. Exploiting this vulnerability enables persistent access to the device, as it lacks secure boot functionality.
OpenFGA Authorization Bypass Vulnerability
A vulnerability allowing authorization bypass has been identified in OpenFGA versions 1.3.8 prior to 1.8.3, including the Helm chart versions openfga-0.1.38 prior to openfga-0.2.19 and Docker versions 1.3.8 prior to 1.8.2. This vulnerability arises when the Check API or ListObjects API is called with a model that includes conditions, and OpenFGA is configured with caching enabled. Under these circumstances, it is possible to bypass authorization by manipulating contextual tuples that include conditions.
Notary Project notation-go Certificate Revocation Check Vulnerability in Timestamping
A vulnerability exists in the Notary Project's notation-go library, specifically in versions 1.2.0-beta.1 through 1.3.0-rc.1. During the generation of timestamp signatures, the library failed to verify the revocation status of the certificates used. This oversight could allow an attacker to exploit the vulnerability through a Man-in-the-Middle attack, using a compromised or revoked certificate to create a malicious countersignature. Such a countersignature would be accepted and stored by the notation-go library, potentially leading to denial-of-service scenarios in CI/CD environments where signature verification is disrupted by the presence of revoked certificates.
Notary Project Notation-Go CRL-Based Revocation Check Process Crash Vulnerability
A denial-of-service vulnerability has been identified in the Notary Project's notation-go library, specifically in version 1.3.0-rc.1. The issue arises during the Certificate Revocation List (CRL) based revocation check, where the CRL cache update process can fail and cause an unexpected program crash. This failure occurs because the os.Rename method, used to move a temporary file from the operating system's temporary directory to the notation cache directory, is not compatible with certain operating system limitations, particularly on Linux distributions like RedHat that use a specific mount point for temporary files. As a result, the revocation check process repeatedly crashes, aborting the signature verification process.
Bitdefender Virus Scanner for macOS DYLD Injection Vulnerability
A vulnerability exists in the Bitdefender Virus Scanner binary for macOS, allowing dynamic library injection (DYLD injection) that bypasses Apple Mobile File Integrity (AMFI). This issue arises from the lack of Hardened Runtime or Library Validation signing and affects Bitdefender Virus Scanner versions prior to 3.18.
Selesta Visual Access Manager Cross Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability exists in Selesta Visual Access Manager versions prior to 4.42.2. The issue can be exploited through the '/common/autocomplete.php' endpoint.
Selesta Visual Access Manager Cross Site Scripting Vulnerability
A cross site scripting (XSS) vulnerability exists in Selesta Visual Access Manager (VAM) versions prior to 4.42.2. The issue can be exploited through the 'vam/vam_visits.php' page.
Selesta Visual Access Manager Arbitrary File Write Vulnerability
A vulnerability allowing authenticated attackers to write arbitrary files has been identified in Selesta Visual Access Manager (VAM) versions prior to 4.42.2. This issue arises from the ability to manipulate POST parameters on the 'common/vam_Sql.php' page.
Selesta Visual Access Manager Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Selesta Visual Access Manager versions prior to 4.42.2. The issue arises in the 'monitor/s_monitor_map.php' file, where user input is not properly sanitized, allowing for the injection of malicious scripts that could be executed in the context of the user's browser.
Selesta Visual Access Manager Cross Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability exists in Selesta Visual Access Manager (VAM) versions prior to 4.42.2. The issue can be exploited through the 'vam/vam_ep.php' page.
Selesta Visual Access Manager Cross Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability exists in Selesta Visual Access Manager (VAM) versions prior to 4.42.2. The issue can be exploited through the 'monitor/s_scheduledfile.php' page.
Selesta Visual Access Manager SQL Injection Vulnerability in VAM Visits PHP
A SQL injection vulnerability has been identified in Selesta Visual Access Manager (VAM) versions prior to 4.42.2. This issue allows authenticated attackers to exploit multiple POST parameters in the /vam/vam_visits.php file.
Selesta Visual Access Manager Incorrect Access Control Vulnerability Allowing Arbitrary SQL Query Execution
A vulnerability exists in Selesta Visual Access Manager (VAM) versions prior to 4.42.2, where an authenticated user can access the administrative page '/common/vam_Sql.php'. This page permits the execution of arbitrary SQL queries, potentially leading to unauthorized data manipulation or disclosure.
Selesta Visual Access Manager SQL Injection Vulnerability
A SQL injection vulnerability has been identified in Selesta Visual Access Manager (VAM) versions prior to 4.42.2. This vulnerability allows authenticated attackers to manipulate a GET parameter in the '/monitor/s_terminal.php' page, potentially leading to unauthorized data access or modification.
Selesta Visual Access Manager SQL Injection Vulnerability
A SQL injection vulnerability has been identified in Selesta Visual Access Manager (VAM) versions prior to 4.42.2. This vulnerability allows authenticated attackers to inject malicious SQL queries through multiple POST parameters of the 'vam_anagraphic.php' page.
Selesta Visual Access Manager SQL Injection Vulnerability in Scheduled File Monitoring
A SQL injection vulnerability has been identified in Selesta Visual Access Manager (VAM) versions prior to 4.42.2. This issue allows authenticated attackers to exploit multiple POST parameters in the '/monitor/s_scheduledfile.php' endpoint.
Selesta Visual Access Manager SQL Injection Vulnerability
A SQL injection vulnerability has been identified in Selesta Visual Access Manager (VAM) versions prior to 4.42.2. This vulnerability allows authenticated attackers to manipulate SQL queries through multiple POST parameters of the 'vam_ep.php' page.
Selesta Visual Access Manager SQL Injection Vulnerability
A SQL injection vulnerability has been identified in Selesta Visual Access Manager (VAM) versions prior to 4.42.2. This vulnerability allows authenticated attackers to manipulate SQL queries through multiple POST parameters of the 'vam_eps.php' page.
Selesta Visual Access Manager SQL Injection Vulnerability
A SQL injection vulnerability has been identified in Selesta Visual Access Manager (VAM) versions prior to 4.42.2. This vulnerability allows authenticated attackers to inject malicious SQL queries through multiple GET parameters in the 'vam_i_command.php' file.
Selesta Visual Access Manager SQL Injection Vulnerability
A SQL injection vulnerability has been identified in Selesta Visual Access Manager (VAM) versions prior to 4.42.2. This issue allows authenticated attackers to exploit a GET parameter in '/common/ajaxfunction.php' to manipulate SQL queries and potentially access or modify database information.
Selesta Visual Access Manager SQL Injection Vulnerability
A SQL injection vulnerability has been identified in Selesta Visual Access Manager (VAM) versions prior to 4.42.2. This vulnerability allows authenticated attackers to inject malicious SQL queries through multiple parameters in the '/monitor/s_normalizedtrans.php' page.
Pat Infinite Solutions HelpdeskAdvanced Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Pat Infinite Solutions HelpdeskAdvanced versions through 11.0.33. The issue arises in the WSCView function, where an attacker can exploit the vulnerability by sending a crafted request that the user inadvertently approves.
Pat Infinite Solutions HelpdeskAdvanced Cross Site Scripting Vulnerability
A cross site scripting (XSS) vulnerability has been identified in Pat Infinite Solutions HelpdeskAdvanced versions through 11.0.33. The issue arises in the Filter/FilterEditor function, where user input is not properly sanitized, allowing for the injection of malicious scripts that could be executed in the context of the user's browser.
Pat Infinite Solutions HelpdeskAdvanced Directory Traversal Vulnerability
A directory traversal vulnerability has been identified in Pat Infinite Solutions HelpdeskAdvanced versions through 11.0.33. The issue arises in the Navigator/Index function, allowing attackers to traverse directories and potentially access restricted files.
Pat Infinite Solutions HelpdeskAdvanced Incorrect Access Control Vulnerability Allowing Deletion of Admin Users
A vulnerability in Pat Infinite Solutions HelpdeskAdvanced versions through 11.0.33 allows low privileged users to delete admin users. This is achieved by sending a request to the 'WSCView/Delete' function, indicating a flaw in access control mechanisms that could be exploited to undermine administrative user roles.
Pat Infinite Solutions HelpdeskAdvanced Cross Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Pat Infinite Solutions HelpdeskAdvanced versions through 11.0.33. The issue arises in the WSCView/Save function, where user input is not properly sanitized, allowing for the injection of malicious scripts.
Pat Infinite Solutions HelpdeskAdvanced Directory Traversal Vulnerability Allowing Arbitrary File Creation
A directory traversal vulnerability has been identified in Pat Infinite Solutions HelpdeskAdvanced versions through 11.0.33. This vulnerability allows authenticated users to send SOAP requests to the WSConnector service, creating arbitrary files on the system.
Pat Infinite Solutions HelpdeskAdvanced Incorrect Access Control Vulnerability
A vulnerability allowing low privileged users to edit their own Access Control List (ACL) rules has been identified in Pat Infinite Solutions HelpdeskAdvanced versions 11.0.33 and prior. This issue arises from incorrect access control, which enables users to send requests to the 'AclList/SaveAclRules' administrative function and modify their ACL rules.
Pat Infinite Solutions HelpdeskAdvanced Directory Traversal Vulnerability via WSCView/Save Function
A directory traversal vulnerability has been identified in Pat Infinite Solutions HelpdeskAdvanced versions through 11.0.33. This vulnerability can be exploited via the WSCView/Save function, allowing attackers to traverse directories and potentially access restricted files.
Pat Infinite Solutions HelpdeskAdvanced Directory Traversal Vulnerability via Email/SaveAttachment Function
A directory traversal vulnerability has been identified in Pat Infinite Solutions HelpdeskAdvanced versions through 11.0.33. This vulnerability arises in the Email/SaveAttachment function, allowing attackers to traverse directories and potentially access unauthorized files.
Pat Infinite Solutions HelpdeskAdvanced Directory Traversal Vulnerability
A directory traversal vulnerability has been identified in Pat Infinite Solutions HelpdeskAdvanced versions through 11.0.33. The issue arises in the Attachment/DownloadTempFile function, allowing unauthorized access to files outside the intended directory.
WeGIA Reflected Cross-Site Scripting Vulnerability in editar_permissoes.php
A reflected cross-site scripting vulnerability has been identified in the WeGIA application, specifically within the 'editar_permissoes.php' endpoint. This issue arises because the application does not properly validate and sanitize user inputs in the 'msg_c' parameter, allowing attackers to inject malicious scripts. These scripts are then executed in the context of the user's browser. The vulnerability affects WeGIA versions prior to 3.2.6.
