CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability in URL Filtering
A vulnerability exists in Palo Alto Networks PAN-OS URL filtering policy that could enable a network-based attacker to perform reflected and amplified TCP denial-of-service (RDoS) attacks. This issue affects PA-Series hardware firewalls, VM-Series virtual firewalls, and CN-Series container firewalls. The vulnerability arises from a misconfiguration where a URL filtering profile with blocked categories is assigned to a source zone with an external facing interface. Such a configuration is atypical for URL filtering and is likely unintended. When exploited, the denial-of-service attack can obscure the attacker's identity, making it appear as though the Palo Alto firewall is the source of the attack.
F5 BIG-IP HTTP2 Profile Memory Resource Consumption Vulnerability Leading to Denial-of-Service
A vulnerability exists in F5 BIG-IP versions 16.1.x prior to 16.1.2.2, 15.1.x prior to 15.1.6.1, and 14.1.x prior to 14.1.5. When an HTTP2 profile is active on a virtual server, certain undisclosed traffic can unintentionally increase memory usage. This rise in memory consumption can degrade system performance, potentially causing the Traffic Management Microkernel (TMM) process to crash or require a manual restart. This issue represents a data plane problem, with no exposure to the control plane.
NextAuth.js Email Provider Vulnerability in Sign-In Process
A vulnerability exists in NextAuth.js versions prior to 4.10.3 and 3.29.10, specifically within the EmailProvider. When an attacker sends a comma-separated list of emails to the sign-in endpoint, both the attacker's and the victim's email addresses receive verification emails. This allows the attacker to log in as a new user with an email address combining both addresses, bypassing authorization checks that rely on email domains.
NextAuth.js Information Disclosure Vulnerability in OAuth Error Handling
A vulnerability allowing information disclosure has been identified in NextAuth.js versions prior to 4.10.2 and 3.29.9. This issue arises during OAuth error handling, where an attacker with log access can retrieve sensitive information, such as an identity provider's secret, from the logs. This leaked information could be exploited to impersonate the client and request additional permissions. The vulnerability has been addressed in versions 4.10.2 and 3.29.9 by changing the log level for provider information and adding a warning about the debug option in production.
BxSlider WP Plugin Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in the BxSlider WP plugin for WordPress, affecting versions through 2.0.0. This vulnerability allows authenticated users with contributor roles or higher to inject malicious scripts into the website, which could be executed when visitors view the site.
WP Video Lightbox WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WP Video Lightbox WordPress plugin, affecting versions prior to 1.9.5. The issue arises because the plugin does not properly escape the $_SERVER['REQUEST_URI'] parameter before including it in an attribute. This flaw could be exploited in older web browsers.
Caddy Out-of-Bounds Read Vulnerability in HTTP Rewrite Module Allowing Denial-of-Service
A vulnerability in Caddy version 2.5.1's HTTP rewrite module allows for an out-of-bounds read, which can lead to a denial-of-service condition. This issue arises from a flawed URI parsing implementation in the rewrite function, where certain URI fragments can cause a runtime panic by creating invalid slice bounds. Although this vulnerability was reported as a security issue, it has been disputed, with claims that it merely reflects a bug in handling malformed URIs, particularly under 'bad' configuration scenarios. The reported issue does not affect server availability, as Caddy continues to process requests normally after logging the error.
jQuery UI Checkboxradio Widget Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been identified in the jQuery UI Checkboxradio widget, affecting versions prior to 1.13.2. When a checkboxradio widget is initialized on an input within a label, the label's contents are treated as the input label. If the initial HTML includes encoded entities, calling '.checkboxradio("refresh")' will decode them, potentially leading to the execution of JavaScript. This vulnerability is particularly concerning if the label content is based on user input, as it could allow for the injection and execution of malicious scripts.
Atlassian Questions for Confluence Hard-Coded Credentials Vulnerability
A vulnerability exists in the Atlassian Questions for Confluence app, specifically for Confluence Server and Data Center. The app creates a user account named 'disabledsystemuser' in the 'confluence-users' group, using a hard-coded password. This allows remote, unauthenticated attackers who know the password to access Confluence content available to 'confluence-users' group members. The vulnerable versions are 2.7.34, 2.7.35, and 3.0.2.
Apache Spark Command Injection Vulnerability Allowing Arbitrary Command Execution
A command injection vulnerability has been identified in the Apache Spark UI, specifically in versions 3.0.3 and earlier, 3.1.1 to 3.1.2, and 3.2.0 to 3.2.1. This vulnerability arises when Access Control Lists (ACLs) are enabled through the configuration option 'spark.acls.enable'. In such cases, the 'HttpSecurityFilter' can be exploited by impersonating a user and injecting commands that are executed in the context of the user under which Spark is running. This issue was disclosed as CVE-2022-33891 and is being tracked as SPARK-38992.
Angular and AngularJS Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in all versions of Angular and AngularJS packages. This issue arises from insecure page caching in Internet Explorer, which permits the interpolation of <textarea> elements. As a result, an attacker could inject malicious scripts that are executed in the context of the user's browser.
AWS SDK for Java S3 Component Partial Path Traversal Vulnerability
A partial path traversal vulnerability has been identified in the AWS SDK for Java S3 component, specifically in version 1.12.260 and prior. The issue arises in the TransferManager's downloadDirectory method, where the validation of S3 object keys can be bypassed. This allows a knowledgeable actor to include a UNIX double-dot in the key, potentially retrieving a directory from their S3 bucket that is one level up in the filesystem from their current working directory. The vulnerability is limited to directories that match the specified destinationDirectory prefix. If this method is used to download contents from an untrusted bucket, files can be written outside the intended destination directory.
NextAuth.js Email Provider HTML Injection Vulnerability
A vulnerability in the NextAuth.js email provider allows for HTML injection via the email signin endpoint. This issue affects NextAuth.js versions 3.x prior to 3.29.8 and 4.x prior to 4.9.0. An attacker can exploit this vulnerability by sending a crafted email address that includes malicious HTML. The email server then sends this HTML to the user, potentially leading to a phishing attack. For example, an attacker could send an email address formatted with a link to their site, and the email client would render it as a clickable link. This vulnerability has been addressed by updating the email handling to prevent such HTML from being rendered.
quic-go Denial-of-Service Vulnerability via Slowloris Variant in MTU Discovery
A denial-of-service vulnerability has been identified in quic-go versions through 0.27.0. This issue allows remote attackers to cause excessive CPU consumption by sending incomplete QUIC or HTTP/3 requests, exploiting a Slowloris-like technique. The vulnerability arises from a misinterpretation of the MTU Discovery service in the file mtu_discoverer.go, leading to an overflow of the probe timer.
Cloudflare WARP Client for Windows Privilege Escalation Vulnerability Allowing Arbitrary File Overwrite
A vulnerability in the Cloudflare WARP client for Windows, in versions prior to 2022.5.309.0, allowed the creation of mount points from the ProgramData folder. This issue could be exploited during the installation of the WARP client to escalate privileges and overwrite files protected by the SYSTEM.
NextAuth.js Improper Callback URL Handling Vulnerability
A vulnerability exists in NextAuth.js, an authentication solution for Next.js applications, in versions prior to 3.29.5 and 4.5.0. The issue arises when an attacker sends a request with an invalid 'callbackUrl' query parameter. This malformed URL fails during the URL object creation, leading to an unhandled error. Consequently, the API route handler times out, causing the login process to fail. This vulnerability has been patched in NextAuth.js versions 3.29.5 and 4.5.0.
Google Analytics Dashboard WordPress Plugin Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been identified in the Google Analytics Dashboard WordPress Plugin, specifically in version 2.1.1. This vulnerability allows remote attackers to inject malicious scripts, which could be executed in the context of the user's browser. Exploitation requires tricking a logged-in WordPress Administrator into visiting a malicious website.
Cloudflare WARP for Windows Privilege Escalation Vulnerability via Unquoted Service Path
A vulnerability in Cloudflare WARP for Windows, starting from version 2022.2.95.0, allows arbitrary code execution that could lead to privilege escalation. This issue arises from an unquoted service path in the application. The vulnerability has been addressed in version 2022.3.186.0.
Google Tag Manager for WordPress Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Google Tag Manager for WordPress (GTM4WP) plugin, affecting versions through 1.15.1. The issue arises from insufficient escaping of the 'gtm4wp-options[scroller-contentid]' parameter in the 'frontend.php' file. This vulnerability allows attackers with administrative access to inject arbitrary web scripts. It is particularly concerning for multi-site installations where 'unfiltered_html' is disabled for administrators, as well as for sites with 'unfiltered_html' restrictions.
Google Tag Manager for WordPress Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Google Tag Manager for WordPress plugin, specifically in versions through 1.15.1. The issue arises in the frontend.php file, where the site search is inadequately sanitized before being added to the data layer. This vulnerability allows unauthenticated attackers to inject malicious scripts via the 's' parameter.
Gatsby Plugin MDX Deserialization Vulnerability Allowing JavaScript Execution
A vulnerability allowing deserialization of untrusted data has been identified in the Gatsby plugin MDX, specifically in versions prior to 2.14.1, from 3.0.0, and prior to 3.15.2. This vulnerability arises from the plugin's default configuration, which lacks proper input sanitization, allowing maliciously crafted frontmatter to be executed as JavaScript. The issue can be exploited in both webpack and data modes, such as when MDX files are processed as components in React or queried via GraphQL. A proof-of-concept demonstrating the vulnerability is available.
django-s3file Path Traversal Vulnerability Allowing Arbitrary File Access and Deletion
A path traversal vulnerability has been identified in django-s3file versions prior to 5.5.1. This vulnerability allows for traversal of the entire AWS S3 bucket, with the potential to access or delete files. If the AWS_LOCATION setting is configured, the traversal is restricted to that specific location. The vulnerability was discovered by the maintainer, and there were no prior reports of it being known or exploited by third parties before the patch was released.
Caddy Open Redirect Vulnerability
An open redirect vulnerability has been identified in Caddy version 2.4. A remote, unauthenticated attacker can exploit this issue to redirect users to arbitrary web URLs by crafting deceptive links that trick victims into clicking them.
Undertow Denial-of-Service Vulnerability in Multiple NetApp Products
A denial-of-service vulnerability has been identified in Undertow, a web server component used in various NetApp products. This issue arises because the HTTP2SourceChannel does not properly write the final frame in certain situations, leading to a denial-of-service condition. The vulnerability affects Undertow versions prior to 2.0.35.SP1, 2.2.6.SP1, 2.2.7.SP1, 2.0.36.SP1, 2.2.9.Final, and 2.0.39.Final.
NextAuth.js Open Redirect Vulnerability in OAuth 1 Provider Implementation
A open redirect vulnerability has been identified in NextAuth.js versions prior to 3.29.3 and 4.3.3. This issue arises when developers implement an OAuth 1 provider, such as Twitter, which is the only built-in provider using OAuth 1. The vulnerability allows for URL redirection to untrusted sites.
Shopify Hydrogen Cross-Site Scripting Vulnerability
A Cross-Site Scripting (XSS) vulnerability has been identified in Shopify Hydrogen, a React-based framework for building custom storefronts. This issue allows arbitrary users to execute scripts on pages created with Hydrogen. The vulnerability affects all versions of Hydrogen from 0.10.0 to 0.18.0 and is exploitable in applications where the hydrating data is user-controlled.
Metform WordPress Plugin Sensitive Information Disclosure Vulnerability
A vulnerability allowing sensitive information disclosure has been identified in the Metform WordPress plugin, specifically in versions through 2.1.3. The issue arises from improper access control in the 'action.php' file, located within the 'core/forms' directory. This vulnerability can be exploited by unauthenticated attackers to access and view all API keys and secrets associated with various integrated third-party services, including PayPal, Stripe, Mailchimp, Hubspot, HelpScout, reCAPTCHA, and others.
HubSpot WordPress Plugin Blind Server-Side Request Forgery Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in the HubSpot WordPress plugin, affecting versions prior to 8.8.15. The vulnerability arises because the plugin does not properly validate the proxy URL provided to the proxy REST endpoint. This flaw could enable users with the edit_posts capability, which includes contributors and higher roles, to execute SSRF attacks.
Apache CouchDB Remote Code Execution Vulnerability via Insecure Default Configuration
A remote code execution vulnerability has been identified in Apache CouchDB versions prior to 3.2.2. The issue arises from an insecure default installation that allows an attacker to gain administrative privileges without authentication. This vulnerability exploits the CouchDB's use of Erlang's distribution protocol, taking advantage of a default 'cookie' value that authenticates communication between Erlang nodes. The problem is exacerbated by CouchDB opening a random network port for distributed operations, which can be accessed if not properly secured.
Philips Vue PACS Cryptographic Key Expiration Vulnerability
A vulnerability exists in Philips Vue PACS, Vue MyVue, Vue Speech, and Vue Motion versions through 12.2.x.x, allowing the use of cryptographic keys or passwords past their expiration date. This flaw increases the risk of cracking attacks by extending the time window during which keys can be compromised.
Philips Vue PACS Use of a Broken Cryptographic Algorithm Vulnerability
A vulnerability exists in Philips Vue PACS versions 12.2.x.x and prior, due to the use of a broken or risky cryptographic algorithm. This flaw introduces an unnecessary risk that could lead to the exposure of sensitive information.
Philips Vue PACS Improper Input Validation and Coding Standards Vulnerability
A vulnerability exists in Philips Vue PACS versions 12.2.x.x and prior, as well as in Vue MyVue, Vue Speech, and Vue Motion (through 12.2.1.5). The issue arises from the software not adhering to certain coding standards, which can create weaknesses or exacerbate existing vulnerabilities. This lack of proper coding practices has led to several specific vulnerabilities, including improper input validation, cleartext transmission of sensitive information, and cross-site scripting, among others. Successful exploitation could allow unauthorized access, data modification, or code execution, negatively impacting the system's overall integrity and availability.
Philips Vue PACS Protection Mechanism Failure Vulnerability Allowing Directed Attacks
A vulnerability exists in Philips Vue PACS versions 12.2.x.x and prior, as well as in Vue MyVue, Vue Speech, and Vue Motion applications through version 12.2.1.5. The issue arises from an improper implementation or failure of a protection mechanism, leaving the product susceptible to directed attacks. This vulnerability is part of a broader set of security issues within the Vue PACS ecosystem, including cleartext transmission of sensitive information, improper input validation, and cross-site scripting, among others.
Philips Vue PACS Improper Input Validation Vulnerability Allowing Cross-Site Scripting
A vulnerability exists in Philips Vue PACS versions 12.2.x.x and prior, as well as in Vue MyVue, Vue Speech, and Vue Motion (through 12.2.1.5). The issue stems from improper input validation, which allows user-controllable input to be inadequately neutralized before being output as a webpage, potentially leading to cross-site scripting attacks. Additionally, the software fails to properly validate structured messages or data before processing them, creating further security risks.
Apple WebKit Use-After-Free Vulnerability Allowing Arbitrary Code Execution
A use-after-free vulnerability has been identified in the WebKit component of Apple iOS, iPadOS, macOS Monterey, and Safari. This vulnerability arises from improper memory management, which can be exploited by processing maliciously crafted web content, potentially leading to arbitrary code execution. Apple has acknowledged reports of active exploitation of this vulnerability.
Apple iOS, iPadOS, and macOS Memory Corruption Vulnerability Allowing Arbitrary Code Execution with Kernel Privileges
A memory corruption vulnerability has been identified in the IOMobileFrameBuffer component of Apple iOS, iPadOS, and macOS. This vulnerability allows a malicious application to execute arbitrary code with kernel privileges. It affects iOS 15.3, iPadOS 15.3, macOS Big Sur 11.6.3, and macOS Monterey 12.2. The issue has been addressed with improved input validation, but Apple is aware of reports suggesting that this vulnerability may have been actively exploited.
Team Circle Image Slider With Lightbox WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Team Circle Image Slider With Lightbox WordPress plugin, affecting versions prior to 1.0.16. The issue arises because the plugin fails to properly sanitize and escape the order_pos parameter before displaying it on an admin page.
ARI Fancy Lightbox WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the ARI Fancy Lightbox WordPress plugin, affecting versions prior to 1.3.9. The issue arises because the plugin does not properly sanitize and escape the 'msg' parameter before displaying it on an admin page.
Apache HTTP Server mod_sed Out-of-Bounds Write Vulnerability Allowing Heap Memory Overwrite
A vulnerability allowing out-of-bounds write has been identified in the mod_sed module of Apache HTTP Server. This issue allows an attacker to overwrite heap memory with potentially attacker-supplied data. The vulnerability affects Apache HTTP Server versions 2.4.52 and earlier.
Apache HTTP Server Integer Overflow Vulnerability Leading to Buffer Overflow
An integer overflow vulnerability has been identified in Apache HTTP Server in versions prior to 2.4.53. This vulnerability occurs when the 'LimitXMLRequestBody' directive is set to allow request bodies larger than 350MB, which is above the default limit of 1MB, on 32-bit systems. The integer overflow can be exploited to write data outside the bounds of allocated memory, potentially leading to arbitrary code execution.
Apache HTTP Server HTTP Request Smuggling Vulnerability
A vulnerability allowing HTTP request smuggling has been identified in Apache HTTP Server versions through 2.4.52. The issue arises because the server fails to properly close inbound connections when errors occur while discarding the request body. This oversight can be exploited to manipulate how requests are processed, potentially leading to cache poisoning or bypassing access controls on proxied servers.
Apache HTTP Server Buffer Overflow Vulnerability in mod_lua
A buffer overflow vulnerability has been identified in the Apache HTTP Server mod_lua module, specifically in versions through 2.4.52. This vulnerability allows a carefully crafted request body to be parsed by the Lua script engine, leading to a memory overwrite. The issue was discovered by Chamal De Silva and is classified as moderate severity.
Mitel MiCollab and MiVoice Business Express TP-240 Reflection/Amplification DDoS Vulnerability
A vulnerability in Mitel MiCollab versions prior to 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to abuse an exposed system test facility for reflection and amplification, leading to a distributed denial-of-service (DDoS) attack. This vulnerability has been exploited in the wild, causing performance degradation and excessive outbound traffic. The TP-240 driver interface, exposed to the public internet on approximately 2,600 misconfigured systems, can be used to launch sustained DDoS attacks of up to 14 hours by amplifying traffic by a factor of 4 billion.
Shopware Improper API Route Checking Allows Unauthorized Customer Modification and Order Creation Vulnerability
A vulnerability exists in Shopware versions through 6.3.1.0, allowing users to modify customer data and create orders without the necessary application permissions. This issue stems from inadequate validation of API routes, enabling unauthorized actions. Users are encouraged to update to version 6.4.8.2, which addresses this vulnerability. For those on older versions 6.1, 6.2, and 6.3, a plugin is available to implement the required security measures.
Shopware HTTP Header Caching Vulnerability
A vulnerability exists in Shopware versions through 6.1.0 that improperly handles sensitive HTTP headers, allowing them to be cached and potentially exposed to clients. This issue can lead to private headers being marked as public in HTTP caches, creating a risk of sensitive information disclosure. The vulnerability has been addressed in version 6.4.8.2.
Shopware HTML Injection Vulnerability in Voucher Code Form
A vulnerability allowing HTML injection has been identified in Shopware versions through 6.2.3. This issue arises in the voucher code form, where it is possible to inject code that could be executed or displayed. The vulnerability has been patched in version 6.4.8.1.
Shopware HTTP Cache Vulnerability Leading to Shared Guest Sessions
A vulnerability in Shopware versions through 6.4.8.0 allows guest sessions to be shared between customers when the HTTP cache is enabled. This issue can create inconsistent experiences for guest users. However, setups using Varnish are not affected.
Shopware Password Reset Vulnerability Leading to Session Retention
A vulnerability exists in Shopware versions through 6.1.0, where user sessions remain active after a password is reset via the password recovery process. This issue has been addressed in version 6.4.8.1. For users on older versions 6.1, 6.2, and 6.3, a plugin is available to implement the necessary security measures.
Spring Cloud Gateway HTTP2 Insecure TrustManager Vulnerability
A vulnerability exists in Spring Cloud Gateway versions prior to 3.1.1+ that allows applications enabled for HTTP2, without a key store or trusted certificates, to use an insecure TrustManager. This misconfiguration enables the gateway to connect to remote services using invalid or custom certificates.
CodeIgniter4 Remote CLI Command Execution Vulnerability
A vulnerability in CodeIgniter4 versions prior to 4.1.9 allows for improper input validation, which can lead to the execution of Command Line Interface (CLI) routes through HTTP requests. This issue has been addressed in version 4.1.9, but no workarounds are available.
