CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 14, 2025

Microsoft Windows MapUrlToZone Security Feature Bypass Vulnerability

A security feature bypass vulnerability has been identified in Microsoft Windows. This vulnerability allows an attacker to bypass the MapURLToZone method, which could lead to improper handling of security zones. The issue affects all supported versions of Microsoft Windows.

4.7
Jan 14, 2025

Microsoft Power Automate Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in Microsoft Power Automate for Desktop, specifically in version 2.51 and prior to 2.52. This vulnerability allows for arbitrary code execution, with exploitation requiring user interaction.

4.2
Jan 14, 2025

Microsoft Access Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in Microsoft Access. This issue affects multiple versions of Microsoft Access, including the 2019 and 2021 LTSC releases, as well as Microsoft 365 Apps for Enterprise. The vulnerability arises from a heap-based buffer overflow, which could be exploited by sending a specially crafted email attachment that bypasses security measures and executes malicious code when opened. Notably, the Preview Pane does not pose an attack vector for this vulnerability.

4.2
Jan 14, 2025

Microsoft Visual Studio Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in multiple versions of Microsoft Visual Studio, including Visual Studio 2015 Update 3, Visual Studio 2019 version 16.11, Visual Studio 2022 versions 17.6, 17.8, 17.10, and 17.12. This vulnerability arises from a heap-based buffer overflow and an out-of-bounds read, allowing attackers to execute arbitrary code by convincing users to open a maliciously crafted package file in Visual Studio.

4.6
Jan 14, 2025

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in .NET, .NET Framework, and Microsoft Visual Studio. This issue arises from a buffer over-read in the .NET runtime, specifically in the 'DiaSymReader.dll' file. The vulnerability allows an attacker to execute arbitrary code by convincing a user to open a maliciously crafted package file in Visual Studio. The affected .NET Framework versions include 4.6/4.6.2, 4.7, 4.7.1, 4.7.2, and 4.8.1, as well as .NET 6.0.0 prior to 6.0.36, .NET 8.0.0 prior to 8.0.11, and .NET 9.0.0.

5.4
Jan 14, 2025

.NET Elevation of Privilege Vulnerability

A vulnerability allowing elevation of privilege has been identified in the .NET Runtime, specifically in versions 6.0.0 prior to 6.0.36, 8.0.0 through 8.0.11, and 9.0.0 prior to 9.0.1, when installed on Linux. This vulnerability arises from the creation of temporary files in directories with insecure permissions, which can be exploited by attackers to overwrite arbitrary file content in the security context of the local system.

4.7
Jan 14, 2025

.NET and Visual Studio Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in .NET and Microsoft Visual Studio. This issue arises from a heap-based buffer overflow, which is triggered by an integer overflow in the 'msdia140.dll' file. The vulnerability affects multiple versions of the .NET runtime and several releases of Visual Studio. Exploitation requires convincing a user to open a maliciously crafted package file in Visual Studio.

5.1
Jan 14, 2025

.NET, PowerShell, and Visual Studio Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in .NET 9.0, PowerShell 7.5, and Microsoft Visual Studio 2022. This vulnerability allows an attacker to execute arbitrary code on the affected system.

5.1
Jan 14, 2025

AquilaCMS Deserialization Vulnerability in Categories API Endpoint

A critical deserialization vulnerability has been identified in AquilaCMS version 1.412.13. The issue arises in the file '/api/v2/categories', where the 'PostBody.populate' argument can be manipulated, leading to unauthorized data deserialization. This vulnerability can be exploited remotely.

4.0
Jan 14, 2025

Ivanti Endpoint Manager Improper Signature Verification Vulnerability Allowing Remote Code Execution

A vulnerability in Ivanti Endpoint Manager (EPM) has been identified, specifically in versions prior to the January 2025 Security Update for both EPM 2024 and EPM 2022 SU6. This vulnerability arises from improper signature verification, which allows a remote, unauthenticated attacker to execute code. However, exploitation requires local user interaction.

3.4
Jan 14, 2025

Ivanti Endpoint Manager Remote Code Execution Vulnerability Due to Insufficient Filename Validation

A remote code execution vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 Security Update for both the 2024 and 2022 SU6 releases. This vulnerability arises from inadequate validation of filenames, allowing an unauthenticated attacker to execute arbitrary code remotely. Exploitation of this issue requires local user interaction.

3.8
Jan 14, 2025

Ivanti Endpoint Manager Out-of-Bounds Write Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 Security Update for both the 2024 release and the 2022 SU6 release. The vulnerability arises from an out-of-bounds write, allowing a remote unauthenticated attacker to disrupt service.

4.2
Jan 14, 2025

Ivanti Endpoint Manager Privilege Escalation Vulnerability

A privilege escalation vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 Security Update for both the 2024 and 2022 SU6 releases. This vulnerability allows a local authenticated attacker to escalate privileges by exploiting an out-of-bounds read condition.

3.0
Jan 14, 2025

Ivanti Endpoint Manager Out-of-Bounds Write Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 Security Update for both the 2024 release and the 2022 SU6 release. The vulnerability arises from an out-of-bounds write, which allows a remote unauthenticated attacker to disrupt service.

4.2
Jan 14, 2025

Ivanti Endpoint Manager Out-of-Bounds Write Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 security update for both the 2024 and 2022 SU6 releases. The vulnerability arises from an out-of-bounds write, allowing remote unauthenticated attackers to disrupt service.

4.2
Jan 14, 2025

Ivanti Endpoint Manager Out-of-Bounds Write Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 security update for both the 2024 and 2022 SU6 releases. The vulnerability arises from an out-of-bounds write, allowing remote unauthenticated attackers to disrupt service.

4.2
Jan 14, 2025

Ivanti Endpoint Manager Out-of-Bounds Write Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 Security Update for both the 2024 and 2022 SU6 releases. The vulnerability arises from an out-of-bounds write, which allows a remote unauthenticated attacker to disrupt service.

4.2
Jan 14, 2025

Ivanti Endpoint Manager Privilege Escalation Vulnerability

A privilege escalation vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 Security Update for both the 2024 and 2022 SU6 releases. This vulnerability allows a local authenticated attacker to escalate privileges by exploiting an uninitialized resource.

3.0
Jan 14, 2025

Ivanti Endpoint Manager Deserialization Vulnerability Leading to Remote Code Execution

A deserialization vulnerability allowing remote code execution has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2024-2025 Security Update and the 2022 SU6 January-2025 Security Update. This vulnerability arises from the deserialization of untrusted data, which a remote unauthenticated attacker can exploit, although it requires local user interaction.

3.8
Jan 14, 2025

Ivanti Endpoint Manager SQL Injection Vulnerability Allowing Remote Code Execution

A SQL injection vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2024-2025 Security Update and the 2022 SU6 January-2025 Security Update. This vulnerability allows remote authenticated attackers with admin privileges to execute code remotely. The issue arises from incomplete fixes related to a previous vulnerability, CVE-2024-32848.

3.5
Jan 14, 2025

Ivanti Endpoint Manager Absolute Path Traversal Vulnerability Allowing Information Disclosure

A path traversal vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 Security Update for both the 2024 release and the 2022 SU6 release. This vulnerability allows remote, unauthenticated attackers to access and leak sensitive information by exploiting the application's failure to properly validate file paths. The issue arises in the WSVulnerabilityCore.dll component, where certain web API endpoints can be manipulated to read files from the server's file system.

6.5
Jan 14, 2025

Ivanti Endpoint Manager Absolute Path Traversal Vulnerability Allowing Information Disclosure

A path traversal vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions 2024 November security update and prior, as well as 2022 SU6 November security update and prior. This vulnerability allows remote unauthenticated attackers to leak sensitive information by exploiting the application's web API endpoints related to vulnerability management.

6.5
Jan 14, 2025

Ivanti Endpoint Manager Absolute Path Traversal Vulnerability Allowing Information Disclosure

A path traversal vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions 2024 November security update and prior, as well as 2022 SU6 November security update and prior. This vulnerability allows remote, unauthenticated attackers to exploit absolute path traversal, leading to the leakage of sensitive information. The issue arises because the affected application does not properly validate user input in certain API endpoints, allowing attackers to manipulate file paths and access restricted data.

6.5
Jan 14, 2025

Ivanti Endpoint Manager Unbounded Resource Search Path Vulnerability Allowing Remote Code Execution

A vulnerability exists in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 Security Update for both the 2024 and 2022 SU6 releases. This vulnerability allows remote authenticated attackers with admin privileges to execute code by exploiting an unbounded resource search path.

3.3
Jan 14, 2025

Rsync Race Condition Vulnerability in Symbolic Link Handling Can Lead to Privilege Escalation

A race condition vulnerability has been identified in Rsync, specifically in versions through 3.2.4. This flaw occurs during the application's handling of symbolic links, where Rsync typically skips them by default. An attacker could exploit this behavior by replacing a regular file with a symbolic link at a strategic moment, allowing them to traverse symbolic links and bypass the default handling. Depending on the privileges of the Rsync process, this could result in leaking sensitive information or even escalating privileges.

4.2
Jan 14, 2025

Rsync --safe-links Option Bypass Leading to Path Traversal Vulnerability

A path traversal vulnerability has been identified in the rsync utility, specifically when the '--safe-links' option is used. The rsync client does not properly verify if a symbolic link destination from the server contains another symbolic link, allowing for traversal outside the intended directory. This flaw could lead to arbitrary file writes in unintended locations.

6.4
Jan 14, 2025

Rsync Path Traversal Vulnerability via Symbolic Links

A path traversal vulnerability has been identified in the rsync utility, specifically in versions through 3.2.7. This vulnerability arises when the '--inc-recursive' option is enabled, either by default for many client options or by the server without client acknowledgment. The issue stems from inadequate verification of symbolic links, allowing a malicious server to manipulate file writing locations on the client, potentially overwriting critical files. This vulnerability is particularly concerning as it can be exploited to exfiltrate sensitive data or execute arbitrary code by overwriting files that are executed as scripts.

6.4
Jan 14, 2025

Rsync Arbitrary File Enumeration Vulnerability

A vulnerability in Rsync versions through 3.2.7 allows a server to enumerate the contents of arbitrary files on a client's machine. This issue arises when files are transferred from the client to the server. During the transfer, the Rsync server sends checksums of local data to the client for comparison, determining what data needs to be sent. An attacker can exploit this by sending specially crafted checksum values for specific files, enabling them to reconstruct the files' contents byte by byte based on the client's responses. This vulnerability is particularly concerning as it can lead to the unauthorized disclosure of sensitive information, such as SSH keys, which could be exploited to execute malicious code on the client's machine by overwriting files like ~/.bashrc or ~/.popt.

7.3
Jan 14, 2025

Rsync Uninitialized Memory Vulnerability Leading to Information Disclosure

A vulnerability in Rsync versions through 3.2.7 allows for information leakage via uninitialized stack memory. This issue arises when Rsync's daemon compares file checksums. An attacker can manipulate the checksum length to force a comparison with uninitialized memory, leaking one byte of sensitive data at a time. Over multiple requests, up to MAX_DIGEST_LEN - 8 bytes can be extracted, potentially bypassing Address Space Layout Randomization (ASLR).

6.4
Jan 14, 2025

Wikimedia Foundation MediaWiki DataTransfer Extension Cross-Site Request Forgery and Cross-Site Scripting Vulnerability

A vulnerability in the Wikimedia Foundation MediaWiki DataTransfer Extension allows for Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) attacks. This issue affects MediaWiki DataTransfer Extension versions 1.39.X prior to 1.39.11, 1.41.X prior to 1.41.3, and 1.42.X prior to 1.42.2.

3.3
Jan 14, 2025

Wikimedia MediaWiki OpenBadges Extension Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the Wikimedia Foundation MediaWiki OpenBadges Extension. This issue arises from improper input sanitization during web page generation, allowing malicious users to inject harmful scripts. The vulnerability affects OpenBadges Extension versions 1.39.X prior to 1.39.11, 1.41.X prior to 1.41.3, and 1.42.X prior to 1.42.2.

3.4
Jan 14, 2025

SourceCodester Task Reminder System Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in SourceCodester Task Reminder System version 1.0. The issue arises in the Maintenance Section, where user input in the 'System Name' argument is not properly sanitized before being output, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely, but requires authentication and user interaction.

2.4
Jan 14, 2025

Shanghai Lingdang Information Technology Lingdang CRM Unrestricted File Upload Vulnerability

A critical vulnerability allowing unrestricted file upload has been identified in Shanghai Lingdang Information Technology Lingdang CRM versions through 8.6.0.0. The issue arises from an unknown function in the file '/crm/weixinmp/index.php', where the 'name' argument can be manipulated to upload files without restriction. This vulnerability can be exploited remotely.

3.0
Jan 14, 2025

Shanghai Lingdang Information Technology Lingdang CRM SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Shanghai Lingdang Information Technology's Lingdang CRM, affecting versions through 8.6.0.0. The issue arises from the file '/crm/weixinmp/index.php' where the 'searchcontent' argument can be manipulated, allowing for SQL injection attacks to be executed remotely.

3.1
Jan 14, 2025

Arcadyan Meteor 2 CPE FG360 Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Arcadyan Meteor 2 CPE FG360 firmware version ETV2.10. This vulnerability allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload, taking advantage of the firmware's inadequate input validation on WiFi SSID fields. The injected scripts are executed in the context of users' web browsers when they access the router's homepage.

2.9
Jan 14, 2025

Arcadyan Meteor 2 CPE FG360 Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in the Arcadyan Meteor 2 CPE FG360 firmware version ETV2.10. This vulnerability allows attackers to execute arbitrary code by sending a crafted request. The issue arises from the iPerf3 utility on the device, which is susceptible to command injection. Exploitation of this vulnerability enables the execution of limited operating system commands, such as initiating a system reboot or establishing a reverse shell connection to the attacker's server, thereby allowing remote control of the device.

3.9
Jan 14, 2025

IBM MQ Password Disclosure Vulnerability in Web Console

A vulnerability in the IBM MQ web console in versions 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to access sensitive information. This occurs when a detailed technical error message is generated, potentially disclosing passwords or other confidential data.

2.2
Jan 14, 2025

Apache Linkis Metadata Query Service JDBC File Read Vulnerability in DataSource Manager Module

A file read vulnerability has been identified in the Apache Linkis Metadata Query Service JDBC, specifically in versions prior to 1.7.0. This issue arises from inadequate parameter filtering, which allows an attacker with an authorized Linkis account to inject malicious MySQL JDBC parameters in the DataSource Manager Module. Exploiting this vulnerability could enable the attacker to read arbitrary files from the Linkis server. It is recommended that users upgrade to Apache Linkis version 1.7.0.

2.0
Jan 14, 2025

Ivanti Avalanche Path Traversal Vulnerability Allowing Authentication Bypass

A path traversal vulnerability has been identified in Ivanti Avalanche versions prior to 6.4.7. This vulnerability allows remote unauthenticated attackers to bypass authentication, addressing incomplete fixes from a previous vulnerability (CVE-2024-47010).

3.1
Jan 14, 2025

Ivanti Avalanche Path Traversal Vulnerability Allowing Sensitive Information Disclosure

A path traversal vulnerability has been identified in Ivanti Avalanche versions prior to 6.4.7. This vulnerability allows remote unauthenticated attackers to leak sensitive information. It is important to note that this CVE addresses incomplete fixes from a previous vulnerability, CVE-2024-47011.

3.1
Jan 14, 2025

Ivanti Avalanche Path Traversal Vulnerability Allowing Authentication Bypass

A path traversal vulnerability has been identified in Ivanti Avalanche versions prior to 6.4.7. This vulnerability allows remote unauthenticated attackers to bypass authentication. The issue arises from incomplete fixes in a previous vulnerability (CVE-2024-47010).

3.2
Jan 14, 2025

Ivanti Endpoint Manager Absolute Path Traversal Vulnerability Allowing Information Disclosure

A path traversal vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 Security Update for both the 2024 and 2022 SU6 releases. This vulnerability allows remote, unauthenticated attackers to exploit absolute path traversal, leading to the unauthorized disclosure of sensitive information. The issue arises from the application's failure to properly validate user input, enabling attackers to manipulate file paths and access restricted data.

5.9
Jan 14, 2025

Ivanti Application Control Engine Race Condition Vulnerability Allowing Application Blocking Bypass

A race condition vulnerability has been identified in Ivanti Application Control Engine versions prior to 10.14.4.0. This vulnerability allows a local authenticated attacker to bypass the application's blocking functionality, potentially leading to unauthorized actions or access within the application.

1.1
Jan 14, 2025

iceCMS Access Control Vulnerability in Square Comment API

An access control vulnerability has been identified in iceCMS version 2.2.0, specifically within the Square Comment API endpoint 'DelectSquareById'. This vulnerability allows unauthenticated attackers to access sensitive information by exploiting improper access controls, particularly in the content management features of the admin interface.

3.8
Jan 14, 2025

iceCMS Access Control Vulnerability in Sensitive Information Disclosure

An access control vulnerability has been identified in iceCMS version 2.2.0, specifically within the component '/square/getAllSquare/circle'. This vulnerability allows unauthenticated attackers to access sensitive information.

4.7
Jan 14, 2025

Shanghai Lingdang Information Technology Lingdang CRM Path Traversal Vulnerability

A path traversal vulnerability has been identified in Shanghai Lingdang Information Technology's Lingdang CRM, affecting versions through 8.6.0.0. The issue arises in the file '/crm/weixinmp/index.php' when specific query parameters are manipulated. This vulnerability allows for remote exploitation by traversing directories and potentially accessing unauthorized files on the server.

2.0
Jan 14, 2025

Blog Botz OpenCart Module Unrestricted File Upload Vulnerability

A critical vulnerability allowing unrestricted file uploads has been identified in the Blog Botz module for OpenCart, version 1.0. The issue arises in the file '/index.php?route=extension/module/blog_add', where the 'image' parameter can be manipulated to upload files of arbitrary types. This vulnerability can be exploited remotely, potentially leading to unauthorized access to the site's hosting environment. An attacker could upload a malicious PHP file, such as a web shell, and execute it on the server. This exploitation could result in a complete compromise of the site, including access to admin credentials and sensitive database information, such as payment details or Personally Identifiable Information.

3.9
Jan 14, 2025

libretro RetroArch Untrusted Search Path Vulnerability in profapi.dll Component

A vulnerability allowing for code injection via an untrusted search path has been identified in libretro RetroArch versions through 1.19.1 on Windows. The issue arises in the Startup component, specifically within the profapi.dll library. During startup, the application loads DLL files from the local installation folder, creating an opportunity to inject code into a manipulated profapi.dll file. This could potentially lead to remote code execution through DLL injection.

5.6
Jan 14, 2025

Virtual Computer Vysual RH Solution Cross-Site Scripting Vulnerability in Login Panel

A reflected cross-site scripting vulnerability has been identified in Virtual Computer Vysual RH Solution version 2024.12.1. The issue arises in the Login Panel component, specifically within the index.php file. The vulnerability is triggered by manipulating the 'page' parameter, which allows for the injection of malicious scripts. This cross-site scripting flaw can be exploited remotely, with the victim required to interact with the malicious link.

3.4
Jan 14, 2025

Phoenix SecureCore UEFI Variable Handling Vulnerability Leading to Input Data Manipulation

A vulnerability exists in Phoenix SecureCore firmware for various Intel processor families, including Kaby Lake, Coffee Lake, Comet Lake, and Ice Lake. This vulnerability arises from improper handling of UEFI variables, allowing for unsafe memory access that could result in temporary denial of service. The issue affects SecureCore for Intel Kaby Lake versions prior to 4.0.1.1012, Coffee Lake versions prior to 4.1.0.568, Comet Lake versions prior to 4.2.1.292, and Ice Lake versions prior to 4.2.0.334.

0.9