CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Dec 8, 2020

Apple Products Memory Initialization Vulnerability Allowing Kernel Memory Disclosure

A memory initialization vulnerability has been identified in the XNU kernel, affecting multiple Apple operating systems, including macOS Big Sur, High Sierra, Mojave, iOS 12.4.9, iOS 14.2, iPadOS 14.2, and watchOS 6.2.9. This vulnerability may allow a malicious application to disclose kernel memory, with reports of an active exploit.

6.0
Dec 8, 2020

Apple XNU Kernel Type Confusion Vulnerability Allowing Arbitrary Code Execution

A type confusion vulnerability has been identified in the XNU kernel's turnstile management, which could allow a malicious application to execute arbitrary code with kernel privileges. This vulnerability affects multiple Apple operating systems, including macOS Big Sur, High Sierra, Mojave, iOS 12, iOS 14, iPadOS 14, and various versions of watchOS. The issue arises from improper state handling, which has been addressed in the latest updates for each affected platform.

6.3
Dec 8, 2020

Apple Products Memory Corruption Vulnerability in FontParser Allowing Arbitrary Code Execution

A memory corruption vulnerability has been identified in the FontParser component of multiple Apple products, including macOS, iOS, iPadOS, and watchOS. This vulnerability allows for arbitrary code execution when processing maliciously crafted font files. It affects several different versions and ranges across these operating systems.

6.3
Nov 23, 2020

October CMS Twig Sandbox Bypass Vulnerability Allowing Arbitrary PHP Execution

A vulnerability exists in October CMS versions 1.0.319 prior to 1.0.469, allowing authenticated backend users with certain permissions to bypass the Twig sandbox and execute arbitrary PHP code. This issue arises when 'cms.enableSafeMode' is enabled, as it should prevent such actions. The vulnerability can be exploited by users with 'cms.manage_pages', 'cms.manage_layouts', or 'cms.manage_partials' permissions who are not trusted to write and execute PHP code. The problem has been addressed in version 1.0.469 and 1.1.0.

2.2
Nov 23, 2020

October CMS Local File Inclusion Vulnerability

A local file inclusion vulnerability has been identified in October CMS versions 1.0.421 prior to 1.0.469. This vulnerability allows unauthenticated users to read local files on the server by sending a specially crafted request. The issue arises from inadequate validation of file paths in the Halcyon Builder component, which manages file queries and template rendering.

3.5
Nov 20, 2020

Drupal Core Improper Filename Sanitization Vulnerability Leading to Remote Code Execution

A remote code execution vulnerability exists in Drupal Core due to improper sanitization of certain filenames in uploaded files. This flaw allows files to be misinterpreted as different extensions, potentially leading to incorrect MIME types being served or files being executed as PHP, depending on the hosting configuration. The vulnerability affects multiple Drupal versions: 9.0 (prior to 9.0.8), 8.9 (prior to 8.9.9), 8.8 (prior to 8.8.11), and 7 (prior to 7.74).

6.4
Nov 16, 2020

WPBakery Plugin Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WPBakery plugin for WordPress, affecting versions prior to 6.4.1. This vulnerability allows authenticated users with contributor or author roles to inject malicious JavaScript into posts. The issue arises because the plugin disables WordPress's standard XSS protection for these user roles, enabling the injection of unfiltered HTML and JavaScript.

5.4
Nov 10, 2020

Apache Airflow Experimental API Authentication Bypass Vulnerability

A vulnerability exists in Apache Airflow versions prior to 1.10.11, where the Experimental API allowed unauthenticated access by default. This default setting posed security risks, as users could inadvertently make unprotected API requests. Although the default has been changed to deny all requests in version 1.10.11, existing users must manually update their configuration to reflect this change. The vulnerability can be exploited by creating a malicious DAG that executes arbitrary commands, leveraging the authentication bypass to gain unauthorized access.

6.6
Nov 2, 2020

SonarQube Authentication Bypass Vulnerability Allowing Unauthorized Project Manipulation

An authentication bypass vulnerability has been identified in SonarQube version 8.4.2.36762. This issue allows external attackers to exploit SonarScanner by leaving the -D sonar.login option empty, which forces anonymous authentication. As a result, attackers can create and overwrite both public and private projects using the /api/ce/submit endpoint. This vulnerability arises from a default configuration that unintentionally exposes project management capabilities to unauthenticated users.

6.2
Oct 28, 2020

SonarQube Cleartext Credential Exposure Vulnerability

A vulnerability in SonarQube version 8.4.2.36762 allows remote attackers to access cleartext credentials for SMTP, SVN, and GitLab through the api/settings/values endpoint. This issue arises because these credentials are stored in plaintext and can be retrieved without authentication, exposing sensitive information from integrations with other tools in the agile process.

6.2
Oct 27, 2020

Apple CFNetwork HSTS Bypass Vulnerability

A vulnerability exists in the CFNetwork component of multiple Apple products, including iOS, iPadOS, macOS, watchOS, and iTunes for Windows. This vulnerability allows an attacker in a privileged network position to bypass HTTP Strict Transport Security (HSTS) for certain top-level domains that are not included in the HSTS preload list. The issue arises from a configuration flaw that has now been addressed with additional restrictions.

4.6
Oct 19, 2020

webpack-subresource-integrity Integrity Validation Vulnerability in Dynamically Loaded Chunks

A vulnerability exists in the webpack-subresource-integrity plugin, specifically in version 1.5.0, where dynamically loaded chunks are assigned an incorrect integrity hash. This flaw prevents browsers from properly validating the integrity of these chunks, thereby undermining the additional protection that Subresource Integrity (SRI) is meant to provide. In contrast, top-level chunks remain unaffected. The issue arises from a bug introduced in version 1.5.0, which was later corrected in version 1.5.1.

3.3
Oct 16, 2020

Apple iOS, iPadOS, and macOS CoreFoundation Environment Variable Handling Vulnerability Allowing Information Disclosure

A vulnerability exists in the CoreFoundation component of Apple iOS 13.6, iPadOS 13.6, and macOS Catalina 10.15.6. The issue arises from improper handling of environment variables, which could allow a local user to access sensitive information. This vulnerability has been addressed with improved validation of environment variables.

6.0
Oct 16, 2020

Apple iOS, iPadOS, and tvOS Memory Corruption Vulnerability Allowing Arbitrary Code Execution with Kernel Privileges

A memory corruption vulnerability has been identified in Apple iOS 13.6, iPadOS 13.6, and tvOS 13.4.8. This vulnerability allows an application to execute arbitrary code with kernel privileges. The issue was addressed by removing the vulnerable code.

6.2
Oct 8, 2020

Next.js Open Redirect Vulnerability

A vulnerability allowing open redirects has been identified in Next.js versions 9.5.0 prior to 9.5.4. This issue arises from the handling of specially encoded paths with the trailing slash redirect, allowing redirection to external sites. While this redirect does not directly harm users, it could facilitate phishing attacks by directing users from a trusted domain to an attacker's domain.

4.5
Oct 5, 2020

Wiki.js Directory Traversal Vulnerability in Local Asset Caching Modules

A directory traversal vulnerability has been identified in Wiki.js versions prior to 2.5.151. This issue arises when a storage module with local asset cache fetching is enabled, such as the Local File System or Git modules. Under these conditions, a malicious user could craft a URL that exploits directory traversal, potentially allowing access to any file on the server's file system. This vulnerability could be exacerbated if no web application firewall, like Cloudflare, is in place to strip harmful URLs.

3.8
Sep 9, 2020

WordPress File Manager Plugin Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the WordPress File Manager plugin, specifically in versions 6.0 through 6.8. The issue arises because the plugin renames an example elFinder connector file to have a .php extension, allowing remote attackers to upload and execute arbitrary PHP code. Exploitation involves using the elFinder upload command to write PHP scripts into a directory where they can be executed.

4.5
Sep 4, 2020

Laravel Mass Assignment Vulnerability via JSON Column Nesting

A vulnerability exists in Laravel versions prior to 6.18.35 and in the 7.x branch prior to 7.24.0. The issue arises from improper handling of the $guarded property in certain situations involving requests with JSON column nesting expressions. This can lead to unexpected mass assignment of model attributes.

5.4
Sep 4, 2020

Laravel Mass Assignment Vulnerability Leading to Unvalidated Database Entries

A vulnerability exists in Laravel versions prior to 6.18.34 and in the 7.x branch prior to 7.23.2, allowing unvalidated data to be saved to the database under certain conditions. This issue arises during mass assignment when table names are automatically removed, creating a potential for unexpected values to be recorded without proper validation.

5.8
Aug 31, 2020

Lara Google Analytics WordPress Plugin Authenticated Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Lara Google Analytics WordPress plugin, versions through 2.0.4. This vulnerability allows authenticated users to inject malicious scripts that are stored and executed later.

3.3
Aug 28, 2020

Hoosk Codeigniter CMS Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in Hoosk Codeigniter CMS versions prior to 1.7.2. This issue allows an attacker to trick an authenticated admin user into visiting a malicious webpage, where any user accounts could be deleted without the admin's consent.

2.7
Aug 12, 2020

vBulletin Remote Code Execution Vulnerability via Crafted subWidgets Data

A remote code execution vulnerability exists in vBulletin versions 5.5.4 prior to 5.6.2. This issue arises from an incomplete fix for a previous vulnerability (CVE-2019-16759) and allows execution of arbitrary PHP code through manipulated subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.

7.4
Jul 29, 2020

Auth0 Node.js Client Library Authorization Header Sanitization Vulnerability

A vulnerability exists in the Auth0 Node.js client library (npm package) in versions prior to 2.27.1. The issue arises in Machine to Machine applications authorized to use Auth0's management API. When an error occurs, the Authorization header is not properly sanitized before being logged, potentially exposing bearer tokens. This vulnerability could be exploited if the logged token is intercepted or accessed by an unauthorized party.

2.5
Jul 27, 2020

Uvicorn HTTP Response Splitting Vulnerability

A vulnerability allowing HTTP response splitting has been identified in Uvicorn versions prior to 0.11.7. This issue arises because CRLF sequences are not properly escaped in HTTP header values. As a result, attackers can exploit this flaw to inject arbitrary headers into HTTP responses or even return custom response bodies, whenever crafted input is used to create HTTP headers.

3.8
Jul 27, 2020

Uvicorn Log Injection Vulnerability Allowing ANSI Escape Sequence Injection

A log injection vulnerability has been identified in all versions of the Uvicorn package. This issue arises from the request logger, which is susceptible to ANSI escape sequence injection. By sending crafted URLs with percent-encoded escape sequences, attackers can manipulate the logged output. Uvicorn logs HTTP request details to the console or a log file, processing the URLs with urllib.parse.unquote. This conversion can unintentionally introduce special characters that terminals interpret in specific ways. Exploitation of this vulnerability can lead to two main consequences: corrupting Uvicorn's access logs and using ANSI codes to interact with the terminal emulator displaying the logs, either live or from a file.

3.7
Jul 17, 2020

Kramdown Template Option Processing Vulnerability Allowing File Read and Code Execution

A vulnerability exists in the kramdown gem, specifically in versions prior to 2.3.0, within the default processing of the 'template' option in Kramdown documents. This behavior can lead to unintended read access to sensitive files, such as '/etc/passwd', or unauthorized execution of embedded Ruby code. The vulnerability is triggered when the '{::options}' extension is used with the 'template' option, allowing crafted input to be processed in a way that could execute arbitrary code or access restricted files. Kramdown is a Markdown parser and converter written in Ruby, and this vulnerability affects multiple NetApp products that incorporate Ruby.

2.7
Jul 17, 2020

Apache Airflow Remote Code Execution Vulnerability in Example DAG

A remote code execution vulnerability has been identified in Apache Airflow versions 1.10.10 and prior. This issue arises from a command injection vulnerability in the 'example_trigger_target_dag' that is included with Airflow. It allows authenticated users to execute arbitrary commands as the user running the Airflow worker or scheduler, depending on the executor in use. However, if the 'load_examples' option is set to 'False' in the configuration, the vulnerability does not exist.

6.7
Jul 15, 2020

Lodash Prototype Pollution Vulnerability

A prototype pollution vulnerability exists in Lodash versions prior to 4.17.20. The issue arises in the 'zipObjectDeep' function, where an attacker can inject properties into the Object prototype. This manipulation affects all objects, potentially leading to unauthorized data modification or disclosure. Additionally, such exploitation can cause a denial-of-service condition by crashing the server or overwhelming it with requests.

5.9
Jul 10, 2020

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

A vulnerability allowing limited information disclosure to low-privileged users exists in Citrix ADC and Citrix Gateway versions prior to 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, and 10.5-70.18. Additionally, several Citrix SD-WAN WANOP appliance models prior to 11.1.1a, 11.0.3d, and 10.2.7 are affected. The vulnerability arises from improper access control, which could be exploited to bypass authorization and access sensitive information.

5.9
Jul 10, 2020

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

A vulnerability allowing improper input validation has been identified in Citrix ADC, Citrix Gateway, and certain Citrix SD-WAN WANOP appliance models. This vulnerability affects multiple versions of Citrix ADC and Citrix Gateway, as well as Citrix SD-WAN WANOP versions prior to 11.1.1a, 11.0.3d, and 10.2.7. The issue allows limited information disclosure to users with low privileges.

5.5
Jul 10, 2020

Citrix ADC, Gateway, and SD-WAN WAN-OP Authorization Bypass Vulnerability

A vulnerability allowing authorization bypass has been identified in Citrix ADC, Citrix Gateway, and certain Citrix SD-WAN WAN-OP appliance models. This vulnerability affects versions prior to Citrix ADC and Citrix Gateway 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, 10.5-70.18, as well as Citrix SD-WAN WAN-OP versions prior to 11.1.1a, 11.0.3d and 10.2.7. The issue allows unauthenticated access to specific URL endpoints, but exploitation requires access to the NetScaler IP (NSIP) management interface.

7.4
Jun 15, 2020

Caddy TLS Client Authentication Bypass Vulnerability

A vulnerability in Caddy web server versions prior to 0.10.13 allows for an authentication bypass in TLS client authentication. This issue arises from the absence of the StrictHostMatching mode, which is necessary to ensure proper client authentication handling. As a result, the vulnerability could be exploited to bypass authentication requirements under certain conditions.

2.5
Jun 9, 2020

Apple iOS, iPadOS, and watchOS Mail Memory Corruption Vulnerability

A memory corruption vulnerability has been identified in the Mail application on Apple iOS, iPadOS, and watchOS. This vulnerability allows heap corruption when processing maliciously crafted mail messages. It affects multiple versions of iOS and iPadOS, as well as watchOS 6.2.5 and 5.3.7.

6.6
Jun 9, 2020

Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability in Mail Processing

A vulnerability allowing out-of-bounds write operations has been identified in the Mail application across multiple Apple operating systems, including iOS 13.5, iPadOS 13.5, iOS 12.4.7, and watchOS 6.2.5. This vulnerability arises from insufficient bounds checking, which can be exploited by processing maliciously crafted mail messages. The exploitation of this vulnerability may lead to unexpected modifications in memory, application crashes, or heap corruption.

6.6
Jun 8, 2020

Angular.js Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Angular.js versions prior to 1.8.0. The issue arises from a regex-based HTML input replacement that can inadvertently convert sanitized code into an unsanitized form. This vulnerability can be exploited by wrapping '<option>' elements within '<select>' elements, which alters the way the code is parsed and potentially reintroduces harmful scripts.

4.0
Jun 7, 2020

Facade Ignition Laravel Global Variable Handling Vulnerability

A vulnerability exists in the Ignition component for Laravel, specifically in versions prior to 2.0.5 and in the 1.x series versions 1.16.15 and earlier. The issue arises from improper handling of global variables, including globals, _get, _post, _cookie, and _env. This mismanagement can lead to unintended consequences, although the specific impacts are not detailed.

6.0
Jun 5, 2020

Apple Multiple Products Code Execution Vulnerability

A memory consumption vulnerability allowing arbitrary code execution with kernel privileges has been identified in multiple Apple products, including iOS, iPadOS, macOS, watchOS, and tvOS. This issue arises from inadequate memory management, leading to excessive memory usage. The vulnerability has been addressed in iOS 13.5.1, iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, and watchOS 6.2.6.

5.9
May 22, 2020

Apache Kylin OS Command Injection Vulnerability

A command injection vulnerability has been identified in Apache Kylin versions 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, and 3.0.1. This vulnerability arises from certain RESTful APIs that concatenate user input with operating system commands, executing them on the server without proper validation. As a result, users may be able to execute arbitrary OS commands remotely.

5.8
Apr 29, 2020

jQuery Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in jQuery. This issue affects versions greater than or equal to 1.0.3 and prior to 3.5.0. The vulnerability arises when HTML containing <option> elements from untrusted sources is passed to jQuery's DOM manipulation methods, such as .html() or .append(). Even if the HTML is sanitized, it may still execute untrusted code. This vulnerability is particularly concerning because it can be exploited through common jQuery methods that manipulate the DOM.

5.9
Apr 23, 2020

Ceph Object Gateway Header-Splitting Vulnerability Leading to Cross-Site Scripting

A cross-site scripting (XSS) vulnerability has been identified in the Ceph Object Gateway (RADOS Gateway) within the Amazon S3 interface. This issue arises from the improper handling of untrusted input, allowing anonymous users to send requests that could be exploited to inject malicious scripts into objects. The vulnerability affects all versions of Ceph Object Gateway up to the latest release.

3.5
Apr 17, 2020

Divante Vue Storefront API and Storefront API Stack Trace Disclosure Vulnerability

A vulnerability exists in Divante vue-storefront-api versions through 1.11.1 and in storefront-api versions through 1.0-rc.1. When unexpected HTTP requests are received, the applications respond with an exception that reveals the error stack trace, including absolute file paths and Node.js module names. This issue was merged into the develop branch of both repositories.

4.7
Apr 15, 2020

Istio and Envoy Wildcard Certificate Misrouting Vulnerability

A vulnerability exists in Istio versions through 1.5.1 and Envoy versions through 1.14.1, related to improper handling of HTTP/2 connection reuse when wildcard certificates are involved. This issue can lead to misrouted requests and unintended data exposure between applications hosted on different subdomains but the same IP address. The problem arises when a connection established for a wildcard domain is reused for a specific subdomain, causing requests to be sent to the wrong application.

6.2
Apr 13, 2020

Snap Creek Duplicator WordPress Plugin Directory Traversal Vulnerability Allowing Arbitrary File Read

A directory traversal vulnerability has been identified in the Snap Creek Duplicator WordPress plugin, affecting versions prior to 1.3.28, as well as Duplicator Pro versions prior to 3.8.7.1. The vulnerability allows unauthenticated users to traverse directories using '../' sequences in the 'file' parameter of the 'duplicator_download' or 'duplicator_init' actions, leading to arbitrary file read with the privileges of the web server.

7.8
Apr 9, 2020

Auth0.js Information Disclosure Vulnerability in Error Object

A vulnerability exists in the Auth0.js library (NPM package auth0-js) in versions greater than 8.0.0 and prior to 9.12.3. When an authentication error occurs, the error object returned by the library includes the original user request, which may contain plaintext passwords. If this error object is exposed or logged without modification, there is a risk of password exposure.

4.0
Apr 8, 2020

Varnish Cache PROXY v2 Protocol Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in Varnish Cache versions prior to 6.0.6 LTS, 6.1.x, 6.2.x prior to 6.2.3, and 6.3.x prior to 6.3.2. The issue arises when Varnish communicates with a TLS termination proxy using PROXY version 2, leading to an assertion failure that causes the Varnish daemon to restart. This restart empties the cache, resulting in performance degradation and increased load on backend servers.

5.3
Apr 8, 2020

Varnish Cache Workspace Information Leak Vulnerability

A vulnerability in Varnish Cache versions prior to 6.0.5 LTS, 6.1.x, 6.2.x prior to 6.2.2, and 6.3.x prior to 6.3.1, allows for an information leak from the connection workspace. The issue arises because a pointer is not cleared between handling client requests on the same connection, which can inadvertently disclose data structures and temporary VCL-related headers from previous requests. The vulnerability is triggered when Varnish switches to synthetic response handling due to an internal error, such as reaching the maximum number of allowed VCL restarts or receiving invalid HTTP headers from a backend response.

4.9
Apr 1, 2020

Auth0 WordPress Plugin Insecure Direct Object Reference Vulnerability

A vulnerability allowing insecure direct object references has been identified in the Login by Auth0 WordPress plugin, affecting versions through 3.11.3. This issue could allow users to access or manipulate objects they should not have permission to.

3.7
Apr 1, 2020

Auth0 WordPress Plugin CSV Injection Vulnerability

A CSV injection vulnerability has been identified in the Login by Auth0 WordPress plugin, affecting versions through 3.11.3. The issue arises because the plugin's data fields, which source information from various origins, lack proper input validation and sanitization before user data is exported. This oversight can be exploited by uploading a crafted Excel document that injects malicious CSV data.

3.6
Apr 1, 2020

Auth0 WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Login by Auth0 WordPress plugin, affecting versions prior to 4.0.0. This vulnerability allows for the injection of malicious scripts that are executed on multiple pages within the WordPress site.

4.0
Apr 1, 2020

Auth0 WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Auth0 WordPress plugin, affecting versions prior to 4.0.0. The vulnerability resides within the settings page of the plugin, allowing attackers to inject malicious scripts that are executed when the page is viewed.

3.6