CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 8, 2025

TXOne Networks Portable Inspector Management Program Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in the management program of TXOne Networks Portable Inspector and Portable Inspector Pro Edition, both through version 1.0.0. This vulnerability arises from improper input validation, allowing remote attackers to crash the management service. While this creates a denial-of-service situation, it can be resolved by restarting the management service.

2.5
Jan 8, 2025

Dell PowerScale OneFS Uncontrolled Resource Consumption Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability due to uncontrolled resource consumption has been identified in Dell PowerScale OneFS versions 8.2.2.x through 9.9.0.0. This vulnerability allows a remote attacker with low privileges to disrupt service, potentially causing system downtime or unresponsiveness.

3.3
Jan 8, 2025

Huawei HarmonyOS Improper Authentication Vulnerability in ANS System Service Module

A vulnerability has been identified in the ANS system service module of Huawei's HarmonyOS. This vulnerability arises from improper authentication, which could lead to abnormal feature performance. Affected versions include HarmonyOS 3.0.0, 3.1.0, 2.0.0, 2.1.0, EMUI 13.0.0, and EMUI 12.0.0.

4.4
Jan 8, 2025

Huawei HarmonyOS Improper Permission Control Vulnerability in Gallery Module

A vulnerability has been identified in the Gallery module of Huawei's HarmonyOS, specifically in versions 3.0.0, 3.1.0, 2.0.0, 2.1.0, EMUI 13.0.0, and EMUI 12.0.0. This vulnerability arises from improper permission control, which could be exploited to affect the availability of the service.

4.3
Jan 8, 2025

Huawei HarmonyOS Medialibrary Module Path Traversal Vulnerability

A path traversal vulnerability has been identified in the Medialibrary module of Huawei's HarmonyOS. This vulnerability affects several versions, including HarmonyOS 3.0.0, 2.0.0, 2.1.0, EMUI 13.0.0, and EMUI 12.0.0. Successful exploitation of this vulnerability could lead to unauthorized access to files, allowing attackers to read or modify data outside of the intended directory structure, thereby impacting the integrity and confidentiality of the system.

4.6
Jan 8, 2025

Huawei HarmonyOS 5.0.0 UIExtension Module Cross-Process Screen Stack Vulnerability

A cross-process screen stack vulnerability has been identified in the UIExtension module of Huawei's HarmonyOS 5.0.0. This vulnerability may lead to unauthorized access to service confidentiality.

4.4
Jan 8, 2025

Huawei HarmonyOS 5.0.0 UIExtension Module Cross-Process Screen Stack Vulnerability

A cross-process screen stack vulnerability has been identified in the UIExtension module of Huawei HarmonyOS 5.0.0. This vulnerability may lead to unauthorized access to service confidentiality.

4.5
Jan 8, 2025

Huawei HarmonyOS UAF Vulnerability in Device Node Access Module

A use-after-free vulnerability has been identified in the device node access module of Huawei's HarmonyOS. This vulnerability can lead to service exceptions, causing disruptions in device functionality. It affects multiple versions of HarmonyOS, including 4.2.0, 4.0.0, and EMUI 14.0.0.

4.0
Jan 8, 2025

Aviatrix Controller Command Injection Vulnerability Allowing Remote Code Execution

A command injection vulnerability has been identified in Aviatrix Controller versions prior to 7.1.4191 and 7.2.4996. The issue arises from improper sanitization of user-controlled input, which allows an unauthenticated attacker to execute arbitrary commands on the server. Exploitation can be achieved by sending shell metacharacters through specific API parameters, bypassing command validation and appending malicious payloads to the executed commands.

5.0
Jan 8, 2025

IBM Db2 Information Disclosure Vulnerability in Log Files

An information disclosure vulnerability has been identified in IBM Db2 for Linux, UNIX, and Windows, specifically in version 11.5. This vulnerability allows sensitive information to be inadvertently included in a log file under certain conditions. The issue also affects Db2 Connect Server.

3.8
Jan 8, 2025

Apple Smart Card Services Stack-Based Buffer Overflow Vulnerability in Gemalto Key Handle

A stack-based buffer overflow vulnerability has been identified in the GemaltoKeyHandle.cpp file of Apple Smart Card Services. This issue affects several macOS versions and has been addressed in the SCSSU-201801 security update.

1.5
Jan 7, 2025

WeGIA Arbitrary File Upload Vulnerability Leading to Remote Code Execution

A critical vulnerability exists in WeGIA versions prior to 3.2.8, specifically in the file upload endpoint '/WeGIA/html/socio/sistema/controller/controla_xlsx.php'. This vulnerability allows for the upload of malicious files, such as .phar files, without proper validation. Once uploaded, these files can be executed on the server, leading to remote code execution.

2.6
Jan 7, 2025

WeGIA Cross-Site Scripting Vulnerability in File Upload Functionality

A Cross-Site Scripting (XSS) vulnerability exists in WeGIA versions prior to 3.2.6, specifically within the file upload feature of the 'controla_xlsx.php' endpoint. The vulnerability arises because the endpoint allows the upload of files without adequate validation, enabling the inclusion of malicious JavaScript. This could result in the execution of arbitrary scripts in the context of the user's browser, potentially leading to information theft, session hijacking, and other client-side attacks.

2.8
Jan 7, 2025

pgAgent Temporary Directory Predictability Vulnerability Allowing Job Disruption

A vulnerability in pgAgent versions prior to 4.2.3 allows local attackers to disrupt scheduled tasks by pre-creating directories used for executing batch job scripts. The issue arises from the use of a poorly seeded random number generator for directory name generation, which creates a window of opportunity for interference.

3.8
Jan 7, 2025

IceWarp Server Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in IceWarp Server version 10.2.1. The issue arises in the meta parameter, allowing attackers to inject malicious scripts that are executed immediately when the crafted URL is visited. This could lead to session hijacking, cookie theft, or other attacks.

5.5
Jan 7, 2025

I, Librarian Server-Side Request Forgery Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability has been identified in I, Librarian versions prior to and including 5.11.1. The issue arises from improper input validation in the file classes/security/validation.php, allowing attackers to manipulate server-side requests.

2.9
Jan 7, 2025

Bangkok Medical Software HOSxP XE Hardcoded Encryption Key Vulnerability Allowing Data Decryption

A vulnerability exists in Bangkok Medical Software HOSxP XE version 4.64.11.3 due to a hardcoded encryption key and initialization vector (IV) in the HOSxPXE4.exe and HOS-WIN32.INI components. This flaw allows attackers to decrypt sensitive information, including privileged database credentials, potentially compromising the entire patient health database in affected deployments. The vulnerability arises from the use of a static key-IV pair with a predictable encryption algorithm, enabling unauthorized access to application secrets.

2.9
Jan 7, 2025

Intersec Geosafe XML External Entity Injection Vulnerability Allowing Arbitrary File Read, SSRF, and Denial-of-Service

A vulnerability allowing XML External Entity (XXE) injection has been identified in Intersec Geosafe versions 2022.12, 2022.13, and 2022.14. This vulnerability enables attackers to read arbitrary files under the privileges of the running process, make Server-Side Request Forgery (SSRF) requests, or cause a Denial of Service (DoS) through unspecified vectors.

2.1
Jan 7, 2025

SuiteCRM Authenticated Database Leak Vulnerability

A vulnerability allowing authenticated users to access arbitrary database fields has been identified in SuiteCRM versions through 7.12.7. This issue arises from improper handling of user permissions, enabling unauthorized data access.

3.0
Jan 7, 2025

SuiteCRM Deserialization Vulnerability Leading to Authenticated Remote Code Execution

A deserialization vulnerability allowing authenticated users to execute arbitrary code has been identified in SuiteCRM versions through 7.12.7. This issue arises from the ability to upload malicious files using CRM functions, which can then be exploited through deserialization to achieve code execution.

3.2
Jan 7, 2025

Ovidentia File Upload Vulnerability Leading to Remote Code Execution

A file upload vulnerability has been identified in Ovidentia version 8.3. The issue arises because the application does not properly restrict the types of files that can be uploaded. Users can exploit this by uploading a .png file containing PHP code, renaming it to a .php extension, and then accessing it through a specific URI. This flaw allows for remote code execution on the server.

3.7
Jan 7, 2025

EyesOfNetwork Privilege Escalation Vulnerability via Nmap

A privilege escalation vulnerability has been identified in EyesOfNetwork (EON) versions through 5.3.11. This issue arises because Nmap can be executed with root privileges, allowing an attacker to gain complete control over the server.

3.1
Jan 7, 2025

PX4-Autopilot Stack Buffer Overflow Vulnerability in MAVLink Receiver

A stack buffer overflow vulnerability has been identified in PX4-Autopilot version 1.14.3, specifically within the MAVLink receiver module. This vulnerability arises from improper validation of the size of the 'serial_control_mavlink.count' and 'serial_control_mavlink.data' fields. When a MAVLink message of type 'SERIAL_CONTROL' is received, the vulnerability can be exploited, leading to a program crash and a denial-of-service condition during software simulation.

3.2
Jan 7, 2025

code-projects Online Book Shop Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in code-projects Online Book Shop version 1.0. The issue resides in the file /subcat.php, where the parameter catnm is not properly validated before being output, allowing for injection of malicious scripts. This vulnerability can be exploited remotely and requires user interaction.

3.8
Jan 7, 2025

Motorola SM56 Modem WDM Driver Privilege Escalation Vulnerability

A vulnerability in the Motorola SM56 Modem WDM Driver, specifically in the SmSerl64.sys file, version 6.12.23.0, allows low-privileged users to map physical memory through specially crafted IOCTL requests. This vulnerability can be exploited for privilege escalation, leading to code execution with elevated rights and unauthorized information disclosure. Additionally, these signed drivers could potentially bypass the Microsoft driver-signing policy to execute malicious code.

2.6
Jan 7, 2025

SUNIX Parallel Driver Privilege Escalation Vulnerability Allowing Arbitrary I/O Port Access

A vulnerability in the SUNIX Parallel Driver x64 version 10.1.0.0 has been identified in the driver file snxppamd.sys. This vulnerability allows low-privileged users to read and write arbitrary I/O ports by sending specially crafted IOCTL requests. Exploitation of this vulnerability could lead to privilege escalation, execution of code with elevated rights, and unauthorized information disclosure. Additionally, these signed drivers could be misused to circumvent the Microsoft driver-signing policy, enabling the deployment of malicious software.

2.6
Jan 7, 2025

SUNIX Serial Driver Privilege Escalation Vulnerability Allowing Arbitrary I/O Port Access

A vulnerability in the SUNIX Serial Driver x64 version 10.1.0.0 has been identified in the driver file snxpsamd.sys. This vulnerability allows low-privileged users to read and write to arbitrary I/O ports by sending specially crafted IOCTL requests. The issue can be exploited for privilege escalation, enabling code execution with elevated rights, and unauthorized information disclosure. Additionally, these signed drivers could potentially circumvent the Microsoft driver-signing policy to execute malicious code.

2.5
Jan 7, 2025

SUNIX Multi I/O Card Arbitrary I/O Port Access Vulnerability

A vulnerability in the snxpcamd.sys driver of the SUNIX Multi I/O Card, version 10.1.0.0, allows low-privileged users to perform arbitrary read and write operations on I/O ports. This is achieved by sending specially crafted IOCTL requests. The vulnerability could be exploited for privilege escalation, executing code with elevated rights, and unauthorized information access. Additionally, since these drivers are signed, they could potentially circumvent the Microsoft driver-signing policy to introduce malicious software.

2.4
Jan 7, 2025

HPE Aruba Networking 501 Wireless Client Bridge Authenticated Remote Command Injection Vulnerability

Multiple command injection vulnerabilities have been identified in the web interface of the HPE Aruba Networking 501 Wireless Client Bridge, specifically in versions through V2.1.1.0-B0030. These vulnerabilities allow authenticated users to execute arbitrary commands as a privileged user on the underlying operating system. Exploitation requires administrative authentication credentials on the host system.

1.7
Jan 7, 2025

HPE Aruba Networking 501 Wireless Client Bridge Authenticated Remote Command Injection Vulnerability

Multiple command injection vulnerabilities have been identified in the web interface of the HPE Aruba Networking 501 Wireless Client Bridge, specifically in version 2.1.1.0-B0030 and below. These vulnerabilities allow authenticated users to execute arbitrary commands as a privileged user on the underlying operating system. Exploitation requires administrative authentication credentials on the host system.

1.7
Jan 7, 2025

AdPortal File Upload Bypass Vulnerability Allowing Arbitrary Code Execution

A file upload bypass vulnerability has been identified in AdPortal version 3.0.39. This vulnerability allows remote attackers to execute arbitrary code by exploiting the file upload functionality.

2.7
Jan 7, 2025

iPublish Media Solutions AdPortal Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in iPublish Media Solutions AdPortal version 3.0.39. This vulnerability allows remote attackers to inject malicious scripts that could be executed in the context of the user's browser. The issue arises from the shippingAsBilling parameter in the updateuserinfo.html file, which can be exploited to escalate privileges.

1.7
Jan 7, 2025

AdPortal Server-Side Template Injection Vulnerability Allowing Arbitrary Code Execution

A server-side template injection vulnerability has been identified in AdPortal version 3.0.39. This vulnerability allows remote attackers to execute arbitrary code by manipulating the shippingAsBilling and firstname parameters in the updateuserinfo.html file.

2.7
Jan 7, 2025

AIMS eCrew Authorization Bypass Vulnerability

An authorization bypass vulnerability has been identified in AIMS eCrew, affecting multiple functions. This issue allows for unauthorized actions or access by bypassing authentication mechanisms. The vulnerability has been addressed in version JUN23 #190.

1.7
Jan 7, 2025

Splunk App for SOAR Privilege Escalation Vulnerability

A privilege escalation vulnerability exists in the Splunk App for SOAR, specifically in versions 1.0.67 and earlier. The issue arises because the Splunk documentation for these versions recommended granting the 'admin_all_objects' capability to the 'splunk_app_soar' role. This could result in improper access control, allowing low-privileged users without 'admin' roles to gain elevated permissions.

1.8
Jan 7, 2025

Ali Alpha Price Table For Elementor DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the Ali Alpha Price Table For Elementor plugin, affecting versions through 1.0.8. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

1.6
Jan 7, 2025

WordPress EMC2 Alert Boxes Plugin Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress EMC2 Alert Boxes plugin, affecting versions through 1.3. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.6
Jan 7, 2025

ORION Allada T-Shirt Designer for WooCommerce Missing Authorization Vulnerability

A broken access control vulnerability has been identified in the ORION Allada T-Shirt Designer for WooCommerce plugin, affecting versions through 1.1. This vulnerability allows unauthenticated users to perform actions that require higher privileges, due to a lack of proper authorization checks.

2.6
Jan 7, 2025

Code Themes Digi Store DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the Code Themes Digi Store WordPress theme, affecting versions through 1.1.4. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

1.6
Jan 7, 2025

WpIndeed Ultimate Learning Pro SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the WpIndeed Ultimate Learning Pro plugin, affecting versions through 3.9. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially enabling malicious actors to interact with the database and steal information.

1.6
Jan 7, 2025

FilaThemes Education LMS Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the FilaThemes Education LMS WordPress theme, affecting versions through 0.0.7. This vulnerability allows malicious users to inject harmful scripts that are executed when other users visit the affected page.

1.6
Jan 7, 2025

WordPress Social Media Share Buttons | MashShare Missing Authorization Vulnerability

A broken access control vulnerability has been identified in the WordPress Social Media Share Buttons | MashShare plugin, affecting versions through 4.0.47. This vulnerability arises from a missing authorization check, which could allow an unprivileged user to perform actions reserved for higher privileges.

3.8
Jan 7, 2025

Link Whisper WordPress Plugin Sensitive Data Exposure Vulnerability

A vulnerability allowing the exposure of sensitive information has been identified in the Link Whisper Free WordPress plugin, affecting versions through 0.7.7. This issue could enable unauthorized users to access confidential data that is typically restricted.

2.5
Jan 7, 2025

HashThemes Hash Elements Plugin Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the HashThemes Hash Elements WordPress plugin, affecting versions through 1.4.9. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when visitors access the site.

3.0
Jan 7, 2025

Code-Projects Online Book Shop SQL Injection Vulnerability in subcat.php

A critical SQL injection vulnerability has been identified in Code-Projects Online Book Shop version 1.0. The issue arises in the file subcat.php, where the cat parameter is manipulated to execute unauthorized SQL queries. This vulnerability can be exploited remotely, potentially leading to unauthorized access to the application's database or even remote code execution.

3.6
Jan 7, 2025

Code-Projects Online Book Shop SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Code-Projects Online Book Shop version 1.0. The issue arises in the file '/search_result.php', where the 's' parameter is manipulated, allowing for unauthorized SQL query execution. This vulnerability can be exploited remotely, potentially leading to unauthorized database access or even remote code execution.

3.6
Jan 7, 2025

Silicon Labs SiWx91x Devices SHA2/224 Hash Length Vulnerability Leading to Denial-of-Service

A vulnerability in SiWx91x devices causes the SHA2/224 algorithm to produce a 256-bit hash instead of the correct 224-bit length. This discrepancy triggers a software assertion, resulting in a Denial-of-Service (DoS) condition. Devices with an implemented watchdog will restart after the watchdog expires, while those without will require a hard reset for recovery.

1.5
Jan 7, 2025

WordPress Hide Category by User Role for WooCommerce Missing Authorization Vulnerability

A missing authorization vulnerability has been identified in the WordPress plugin 'Hide Category by User Role for WooCommerce', affecting versions through 2.1.1. This vulnerability allows for arbitrary content deletion, enabling a malicious actor to remove posts, pages, or media from a website.

1.7
Jan 7, 2025

WordPress WP SecureSubmit Plugin Missing Authorization Vulnerability Allowing Sensitive Data Exposure

A missing authorization vulnerability has been identified in the WP SecureSubmit WordPress plugin, specifically in versions through 1.5.16. This vulnerability allows unauthorized users to access sensitive information that is typically restricted, potentially leading to the exploitation of other system weaknesses.

2.5
Jan 7, 2025

Invoice Ninja Remote Code Execution Vulnerability via Unauthenticated Route

A remote code execution vulnerability has been identified in Invoice Ninja versions 5.8.22 through 5.10.10. The issue arises from an unauthenticated route that allows attackers to execute arbitrary code if they know the APP_KEY. This vulnerability is compounded by default APP_KEY values in several .env files available in the product's repository. The vulnerable route, defined in 'invoiceninja/routes/client.php', accepts a parameter that is decrypted and unserialized, allowing for exploitation through Laravel's serialization mechanisms.

6.5