CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Iocharger Command Injection Vulnerability in AC Model Chargers
A command injection vulnerability has been identified in Iocharger firmware for AC model chargers, affecting versions prior to 24120701. This vulnerability allows authenticated users to execute operating system commands as the root user on the charging station. The issue arises from improper neutralization of special elements used in commands, enabling OS command injection. The vulnerability can be exploited by finding the name of a specific CGI script and using a low-privilege account to access it, or by convincing a user with the necessary access to execute a request.
Iocharger AC Models Command Injection Vulnerability Leading to Root Access
A command injection vulnerability has been identified in Iocharger firmware for AC models, all versions prior to 25010801. This vulnerability allows authenticated users to execute OS commands as root on the charging station. The issue arises from improper neutralization of special elements used in commands, enabling OS command injection. While the vulnerability is present in the web interface, it may be more challenging to exploit as it requires access to a specific binary, similar to one used in the Iocharger Pedestal charging station. An attacker would need a low-privilege account or to persuade a user with such access to send a crafted HTTP request.
Iocharger AC Model Chargers Command Injection Vulnerability Leading to Root Access
A command injection vulnerability has been identified in Iocharger firmware for AC model chargers, affecting versions prior to 24120701. This vulnerability allows authenticated users to execute operating system commands as the root user on the charging station. The issue arises from improper neutralization of special elements used in commands, enabling command injection via a specific binary. While the vulnerability is not directly exposed through the web interface, it can be exploited by convincing a user with low privileges to send a crafted HTTP request. The impact of this vulnerability is critical, as it allows full control over the charging station, including the ability to add, modify, and delete files and services. Additionally, compromised devices could potentially be used to access restricted networks. Given that this vulnerability involves an electric vehicle charger handling significant power, there are potential safety implications.
Iocharger AC Model Chargers Command Injection Vulnerability Leading to Root Access
A command injection vulnerability has been identified in Iocharger firmware for AC model chargers, affecting versions prior to 24120701. This vulnerability allows authenticated users to execute operating system commands as the root user on the charging station. The issue arises from improper neutralization of special elements used in commands, enabling unauthorized command execution. While the vulnerability is not directly exposed through the web interface, it can be exploited by users with low-privilege accounts who can send crafted HTTP requests or by manipulating the Iocharger Pedestal charging station binary.
Iocharger Command Injection Vulnerability in AC Models Allowing Root Access
A command injection vulnerability has been identified in Iocharger firmware for AC models prior to version 241207101. This vulnerability allows authenticated users to execute operating system commands as the root user on the affected charging station. The issue arises from improper handling of special elements in commands, which could be exploited by convincing a user with low privileges to send a crafted HTTP request. Once exploited, the attacker could gain full control over the charging station, including the ability to add, modify, or delete files and services. Additionally, because this is an electric vehicle charger managing significant power, there are potential safety implications.
Iocharger Command Injection Vulnerability in AC Models Allows Root OS Command Execution
A command injection vulnerability has been identified in Iocharger firmware for AC models, affecting versions prior to 24120701. This vulnerability allows authenticated users to execute operating system commands as root on the charging station. The issue arises from improper neutralization of special elements used in commands, enabling command injection via a specific binary. While the vulnerability requires a low-privilege account to access the binary, it can potentially be exploited by convincing a user with the necessary access to send a crafted HTTP request.
Iocharger Command Injection Vulnerability in AC Models Allowing Remote Code Execution
A command injection vulnerability has been identified in Iocharger firmware for AC models prior to version 24120701. This vulnerability allows authenticated users to inject commands through a specific parameter in a <redacted>.exe request, leading to remote code execution as the root user. The issue arises because the injection point is not a typical location for such vulnerabilities, making it likely that an attacker would need to reverse-engineer the firmware or experiment with various <redacted> fields to discover it. Additionally, the attacker must have a low-privilege account to access the <redacted> binary or persuade a user with the necessary privileges to execute a malicious payload.
Iocharger Command Injection Vulnerability in AC Models Prior to Version 24120701 Allowing Remote Code Execution
A command injection vulnerability has been identified in the Iocharger firmware for AC models prior to version 24120701. This vulnerability allows authenticated users to execute arbitrary commands via a specific parameter in a <redacted>.exe request, leading to remote code execution as the root user. The vulnerability is not commonly found in this context, making it likely that an attacker would need to reverse-engineer the firmware or test various <redacted> fields to discover it. Access to the <redacted> binary is required, either by having a low-privilege account or by persuading a user with such access to execute a malicious payload.
SonicWall SonicOS Integer-Based Buffer Overflow Vulnerability via IPSec Allowing Denial-of-Service and Potential Arbitrary Code Execution
A buffer overflow vulnerability has been identified in SonicWall SonicOS through IPSec, specifically in versions 6.5.4.4-44v-21-2395 and earlier, as well as in several Gen7 models. This vulnerability allows remote attackers, under certain conditions, to cause a denial-of-service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload. The issue arises from an integer-based buffer overflow, which can be exploited to manipulate memory and execute unauthorized code.
SonicWall SonicOS Post-authentication Absolute Path Traversal Vulnerability Allowing Arbitrary File Read
A post-authentication absolute path traversal vulnerability has been identified in SonicWall SonicOS management. This vulnerability allows remote attackers to read arbitrary files on the system. It affects multiple generations of SonicWall firewalls and certain versions of the SonicWall NSv product.
SonicWall SonicOS Post-authentication Format String Vulnerability Allowing Firewall Crash and Potential Code Execution
A post-authentication format string vulnerability has been identified in the management interface of SonicWall SonicOS. This vulnerability allows remote attackers to cause a crash of the firewall and potentially execute arbitrary code. It affects multiple generations of SonicWall firewalls and certain versions of the SonicWall NSv product.
SonicWall SonicOS Post-authentication Stack-based Buffer Overflow Vulnerability
A post-authentication stack-based buffer overflow vulnerability has been identified in SonicWall SonicOS management. This vulnerability allows remote attackers to crash the firewall and potentially execute arbitrary code. It affects multiple generations of SonicWall firewalls and management services, with the vulnerable versions being 6.5.4.15-117n and older, 7.0.1-5161 and older, 7.1.2-7019 and older, and 8.0.0-8035.
pgAdmin LDAP Authentication Session Fixation Vulnerability
A vulnerability exists in pgAdmin when it is running in server mode with LDAP authentication. If multiple users log in simultaneously, there is a risk that one user may be inadvertently attached to another user's session.
Mattermost Invite Permission Vulnerability in Team Privacy Settings
A vulnerability exists in Mattermost versions 9.11.x prior to 9.11.5, allowing team admins without invitation permissions to invite users. This is achieved by changing the 'allow_open_invite' field after making their team public, thereby bypassing permission restrictions.
Mattermost Calls Configuration Reporting Vulnerability in Versions 10.x through 10.2
A vulnerability exists in Mattermost versions 10.x through 10.2, where the application fails to accurately represent missing settings. This discrepancy can lead to confusion for administrators regarding the security-sensitive configuration of Calls, due to misleading information in the user interface.
Mattermost Denial-of-Service Vulnerability via Improper Post Type Validation
A denial-of-service vulnerability has been identified in Mattermost versions 10.2.0, 9.11.x through 9.11.5, 10.0.x through 10.0.3, and 10.1.x through 10.1.3. The issue arises from the application's failure to properly validate post types, allowing attackers to disrupt service for users with the 'sysconsole_read_plugins' permission. This is achieved by creating a post with the 'custom_pl_notification' type and specific properties.
Cinema Seat Reservation System SQL Injection Vulnerability in deleteBooking.php
A critical SQL injection vulnerability has been identified in the Cinema Seat Reservation System version 1.0. The issue arises in the file deleteBooking.php, where improper handling of the 'id' argument allows for SQL injection. This vulnerability can be exploited remotely.
Online Bike Rental Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been identified in the Online Bike Rental application, version 1.0. The issue arises in an unknown function within the file 'vehical-details.php', specifically related to the HTTP GET request handling. This vulnerability can be exploited remotely.
Codezips Project Management System SQL Injection Vulnerability
A critical SQL injection vulnerability exists in Codezips Project Management System version 1.0, specifically within the file '/pages/forms/teacher.php'. This vulnerability allows remote attackers to manipulate the 'name' parameter, injecting malicious SQL queries that could be executed by the database. The lack of proper input validation and sanitization in the application is the root cause, enabling exploitation of the vulnerability.
SonicWall Gen7 SonicOS Cloud NSv Privilege Escalation Vulnerability
A vulnerability exists in the Gen7 SonicOS Cloud platform NSv, specifically in the AWS and Azure editions. It allows a remote authenticated local low-privileged attacker to elevate privileges to root, potentially leading to code execution.
SonicWall SonicOS SSH Management Server-Side Request Forgery Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in the SonicOS SSH management interface. This vulnerability allows remote attackers to establish TCP connections to any IP address and port while the user is logged into the firewall. The issue affects multiple SonicWall firewall products across different generations and versions.
SonicWall SSLVPN Authentication Bypass Vulnerability
A vulnerability allowing authentication bypass in the SSLVPN authentication mechanism has been identified in SonicWall products. This improper authentication issue allows remote attackers to bypass authentication requirements. The vulnerability is present in several SonicWall firewall products, specifically in certain versions of SonicOS. The issue arises from the SSLVPN authentication mechanism, which can be exploited to gain unauthorized access.
SonicWall SonicOS SSLVPN Cryptographically Weak PRNG Vulnerability Allowing Authentication Bypass
A vulnerability exists in the SonicOS SSLVPN authentication token generator due to the use of a cryptographically weak pseudo-random number generator (PRNG). In certain cases, this weakness allows an attacker to predict the generated tokens, potentially leading to authentication bypass. This issue affects multiple versions of SonicWall SonicOS on both Gen6 and Gen7 firewalls, as well as the Gen7 Cloud platform NSv (AWS and Azure editions only)
GitLab CE/EE SAML External Provider Configuration Vulnerability
A vulnerability exists in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 16.4 prior to 17.5.5, 17.6 prior to 17.6.3, and 17.7 prior to 17.7.1. The issue arises when users are created through the SAML provider; the external groups setting can override the external provider configuration. Consequently, users may not be designated as external, granting them access to internal projects or groups.
Online Bike Rental System Change Image Handler Unrestricted File Upload Vulnerability
A critical vulnerability allowing unrestricted file uploads has been identified in the Change Image Handler component of the Online Bike Rental System version 1.0. This issue could be exploited remotely, potentially affecting other endpoints as well.
Leiyuxi Cy-Fast SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Leiyuxi Cy-Fast version 1.0. The issue arises in the 'listData' function within the file '/sys/user/listData', where the manipulation of argument order can be exploited. This vulnerability can be exploited remotely.
GitLab CE/EE Denial-of-Service Vulnerability Due to Cyclic Epic References
A denial-of-service vulnerability has been identified in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 15.7 prior to 17.5.5, 17.6 prior to 17.6.3, and 17.7 prior to 17.7.1. The issue arises from the ability to create cyclic references between epics, leading to resource exhaustion. This can be exploited by authenticated users on the affected GitLab instance.
BU Section Editing WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the BU Section Editing WordPress plugin, affecting versions through 0.9.9. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against high-privilege users, such as administrators.
Aklamator INfeed WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Aklamator INfeed WordPress plugin, affecting versions through 2.0.0. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
Aklamator INfeed WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Aklamator INfeed WordPress plugin, affecting versions through 2.0.0. The issue arises because the plugin fails to properly sanitize and escape certain settings. This flaw enables high-privilege users, such as administrators, to execute stored cross-site scripting attacks, even in environments where the unfiltered_html capability is restricted, such as multisite setups.
Asgard Security Scanner WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Asgard Security Scanner WordPress plugin, affecting versions through 0.7. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against high-privilege users, such as administrators.
Backlink Monitoring Manager WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Backlink Monitoring Manager WordPress plugin, affecting versions through 0.1.3. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
PostLists WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the PostLists WordPress plugin, affecting versions through 2.0.2. The issue arises because the plugin does not properly escape the 'REQUEST_URI' parameter from the server before outputting it in an attribute. This flaw could be exploited in older web browsers.
Leiyuxi Cy-Fast SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Leiyuxi Cy-Fast version 1.0. The issue arises in the 'listData' function within the file '/sys/role/listData', where the manipulation of argument order allows for SQL injection. This vulnerability can be exploited remotely.
YunzMall Password Recovery Vulnerability in ResetpwdController.php
A critical vulnerability exists in YunzMall versions through 2.4.2, specifically in the password recovery function of the ResetpwdController.php file. This issue arises from the HTTP POST request handling, where improper manipulation of the password argument enables weak password recovery. The vulnerability can be exploited remotely.
KaiYuanTong ECT Platform Command Injection Vulnerability in HTTP POST Request Handler
A critical command injection vulnerability has been identified in KaiYuanTong ECT Platform versions through 2.0.0. The issue resides in the file '/public/server/runCode.php', within the HTTP POST Request Handler component. The vulnerability allows remote attackers to inject commands by manipulating the 'code' argument, exploiting improper handling of input that could alter command execution.
Ruby Marvin Attack Vulnerability
A vulnerability exists in the Ruby interpreter, allowing for the Marvin Attack. This attack enables an attacker to decrypt previously encrypted messages or forge signatures by exchanging a large volume of messages with the affected service. The vulnerability is present in all Ruby versions.
OpenJPEG Heap Buffer Overflow Vulnerability in opj_decompress Utility
A heap buffer overflow vulnerability has been identified in the OpenJPEG project, specifically in version 2.5.2 of the opj_decompress utility. This vulnerability can be triggered by using the -t option with an argument of 1, leading to a heap buffer overflow that causes a crash or other undefined behavior.
OpenJPEG Heap Buffer Overflow Vulnerability in opj_decompress Utility
A heap buffer overflow vulnerability has been identified in the OpenJPEG project, specifically in version 2.5.2 of the opj_decompress utility. This vulnerability can be triggered by certain options, leading to an application crash or other undefined behavior. The issue arises in the 'bin/common/color.c' file, within the 'sycc422_to_rgb' function, when the '-r' option is used with an argument of '2'.
SingMR HouseRent Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in SingMR HouseRent version 1.0. The issue arises in the file '/toAdminUpdateHousePage?hID=30', where unknown code can be manipulated to inject malicious scripts. This vulnerability can be exploited remotely and has been publicly disclosed.
SingMR HouseRent Unrestricted File Upload Vulnerability in AddHouseController
A critical vulnerability allowing arbitrary file uploads has been identified in SingMR HouseRent version 1.0. The issue arises in the 'singleUpload' function of the 'AddHouseController.java' file, where uploaded files are not properly restricted. This vulnerability can be exploited remotely, and the details of the exploit have been made public.
SingMR HouseRent Improper Access Control Vulnerability in AdminController
A critical vulnerability exists in SingMR HouseRent version 1.0, specifically within the AdminController.java file. This issue arises from improper access controls, allowing unauthorized access to certain functionalities. The vulnerability can be exploited remotely.
Donglight Bookstore Unrestricted File Upload Vulnerability Leading to Remote Code Execution
A critical vulnerability allowing unrestricted file uploads has been identified in Donglight Bookstore version 1.0. The issue resides in the 'uploadPicture' function of the 'AdminBookController' file. This vulnerability can be exploited remotely, and the uploaded files can be executed within the application's environment.
Redaxo CMS Cross-Site Scripting Vulnerability in Structure Management Page
A cross-site scripting (XSS) vulnerability has been identified in Redaxo CMS version 5.18.1. The issue arises in the Structure Management Page, specifically within an unknown function of the file 'index.php'. The vulnerability is triggered by manipulating the 'Article Name' argument, allowing remote attackers to execute the XSS exploit. This vulnerability has been publicly disclosed, and the vendor was notified but did not respond.
REVE Antivirus for Linux Incorrect Default Permissions Vulnerability
A critical vulnerability exists in REVE Antivirus version 1.0.0.0 for Linux, specifically within the file '/usr/local/reveantivirus/tmp/reveinstall'. The issue arises from insecure default file permissions that allow unprivileged users to modify system service units in '/etc/init.d/'. This manipulation can lead to privilege escalation, as overwritten files can execute malicious code as root after a system reboot.
Kurniaramadhan E-Commerce-PHP Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Kurniaramadhan E-Commerce-PHP version 1.0. The issue arises in the Create Product Page, specifically within the file '/admin/create_product.php'. The vulnerability allows for the injection of malicious JavaScript into the application, which could be executed in the context of the user's browser. This XSS vulnerability can be exploited remotely.
Kurniaramadhan E-Commerce-PHP SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Kurniaramadhan E-Commerce-PHP version 1.0, specifically within the file 'blog-details.php'. The vulnerability arises from the 'blog_id' parameter, allowing remote attackers to manipulate the argument and execute malicious SQL queries. This exploitation can lead to unauthorized access to sensitive data, including admin panel credentials, and potentially allow for the injection of malicious JavaScript into the application.
kurniaramadhan E-Commerce-PHP Cross-Site Request Forgery Vulnerability
A cross-site request forgery (CSRF) vulnerability has been identified in kurniaramadhan E-Commerce-PHP version 1.0. This vulnerability allows remote attackers to manipulate users into performing actions without their consent, as the application lacks proper CSRF protection.
Wander-Chu SpringBoot-Blog Cross-Site Scripting Vulnerability in Article Modification Function
A cross-site scripting (XSS) vulnerability has been identified in Wander-Chu SpringBoot-Blog version 1.0. The issue arises in the 'modifyArticle' function within the 'PageController.java' file, part of the Blog Article Handler component. The vulnerability allows for the injection of malicious scripts through the 'content' and 'slug' arguments, which are not properly sanitized before being stored. This flaw can be exploited remotely, leading to stored XSS, where injected scripts are executed in the context of the user.
Wander-Chu SpringBoot-Blog Unrestricted File Upload Vulnerability in Admin Attachment Handler
A critical vulnerability allowing unrestricted file uploads has been identified in Wander-Chu SpringBoot-Blog version 1.0. The issue resides in the Admin Attachment Handler, specifically within the upload function of the AttachController. The vulnerability can be exploited remotely by manipulating the file upload argument, allowing the direct upload of JSP and HTML files that could contain malicious payloads.
