CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Microsoft Windows App Installer Spoofing Vulnerability Allowing Malware Distribution
A spoofing vulnerability has been identified in the AppX installer for Microsoft Windows. This vulnerability allows attackers to craft malicious packages that can bypass standard security measures and deliver malware, including families like Emotet, TrickBot, and BazarLoader. The vulnerability is particularly concerning because it can be exploited through social engineering tactics, convincing users to open harmful attachments. While users with lower privileges may face reduced risk, those with administrative rights are more vulnerable.
Apache Log4j Remote Code Execution and Denial-of-Service Vulnerability via Thread Context Map Patterns
A vulnerability in Apache Log4j 2.15.0 has been identified, where the fix for a previous remote code execution vulnerability (CVE-2021-44228) was incomplete in certain non-default configurations. This new vulnerability allows attackers to exploit Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup or a Thread Context Map pattern. Exploitation can lead to an information leak and remote code execution in some environments, while all environments are susceptible to local code execution. Log4j versions 2.16.0 (Java 8) and 2.12.2 (Java 7) address this vulnerability by removing support for message lookup patterns and disabling JNDI functionality by default.
Apache Log4j2 Remote Code Execution Vulnerability
A remote code execution vulnerability exists in Apache Log4j2 versions 2.0-beta9 through 2.15.0, excluding security releases 2.12.2, 2.12.3, and 2.3.1. The vulnerability arises because JNDI features used in configuration, log messages, and parameters do not adequately protect against attacker-controlled LDAP and other JNDI-related endpoints. An attacker who can manipulate log messages or their parameters can execute arbitrary code loaded from LDAP servers, provided that message lookup substitution is enabled. This issue is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Next.js Denial-of-Service Vulnerability via Invalid URL Processing
A denial-of-service vulnerability has been identified in Next.js, a React framework, affecting versions prior to 12.0.5 and 11.1.3. When deployments using Node.js versions above 15.0.0 receive invalid or malformed URLs, it can lead to a server crash. This issue arises because the server fails to properly handle the invalid URLs, causing an unhandled promise rejection that terminates the server process. The vulnerability is not present in environments like Vercel, where such invalid requests are filtered out before reaching the Next.js application.
Ivanti Endpoint Manager Cloud Service Appliance Code Injection Vulnerability Leading to Remote Code Execution
A code injection vulnerability has been identified in Ivanti Endpoint Manager Cloud Service Appliance (CSA) versions 4.5 and 4.6. This vulnerability allows an unauthenticated user to execute arbitrary code with limited permissions, specifically as the 'nobody' user. The issue arises from a cookie-based command injection that can be exploited by manipulating cookie values in HTTP requests.
Mozilla Firefox, Thunderbird, and Firefox ESR Use-After-Free Vulnerability in HTTP/2 Session Object
A use-after-free vulnerability has been identified in Mozilla Firefox, Thunderbird, and Firefox ESR. This issue arises when an HTTP/2 session object is released on a different thread, leading to memory corruption and a potentially exploitable crash. The vulnerability affects Firefox versions prior to 93, Thunderbird versions prior to 91.3, and Firefox ESR versions prior to 91.3.
Mozilla Firefox and Thunderbird Same-Origin Policy Bypass Vulnerability via HTTP/2 Opportunistic Encryption
A vulnerability exists in Mozilla Firefox and Thunderbird that allows a network attacker to bypass the Same-Origin Policy on services hosted on encrypted ports that did not opt-in to HTTP/2 Opportunistic Encryption. This issue affects Firefox versions prior to 94, Thunderbird versions prior to 91.3, and Firefox ESR versions prior to 91.3. The vulnerability arises because the browser can be coaxed into treating content from a non-opted-in encrypted port as same-origin with unencrypted HTTP, potentially leading to unauthorized access to sensitive information or resources.
SonicWall SMA 100 Series Stack-Based Buffer Overflow Vulnerability in Apache httpd mod_cgi Module Allowing Unauthenticated Remote Code Execution
A stack-based buffer overflow vulnerability has been identified in the SonicWall SMA 100 series appliances, specifically in the Apache httpd server's mod_cgi module. This vulnerability allows a remote, unauthenticated attacker to execute code as the 'nobody' user on the affected appliance. The issue arises from the mod_cgi module improperly handling environment variables, leading to a buffer overflow on the stack. The vulnerability affects several firmware versions across the SMA 100 series, including SMA 200, 210, 400, 410, and 500v.
Wiki.js Directory Traversal Vulnerability on Windows
A directory traversal vulnerability allowing access to files outside of the Wiki.js context has been identified in Wiki.js versions prior to 2.5.254. This issue occurs on Windows hosts when a storage module with local asset cache fetching, such as Local File System or Git, is enabled. The vulnerability can be exploited by crafting a special URL that takes advantage of directory traversal, potentially allowing a malicious user to read any file on the file system. This exploitation is possible only if no web application firewall, like Cloudflare, intercepts and strips harmful URLs.
Logo Showcase with Slick Slider WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Logo Showcase with Slick Slider WordPress plugin, affecting versions prior to 1.2.4. The issue arises because the plugin fails to properly sanitize the Grid Settings, allowing users with at least Author role to inject malicious scripts via post metadata. This vulnerability could be exploited to execute harmful scripts when the affected content is viewed.
Sitecore Experience Platform (XP) Insecure Deserialization Vulnerability Leading to Remote Code Execution
A remote code execution vulnerability has been identified in Sitecore Experience Platform (XP) versions 7.5 Initial Release to 8.2 Update-7. This vulnerability arises from an insecure deserialization issue in the Report.ashx file, which was used for the Executive Insight Dashboard, a feature that has been deprecated. The vulnerability allows unauthorized users to execute arbitrary code on the server where Sitecore is running.
Grafana Cross-Site Scripting Vulnerability Allowing Arbitrary JavaScript Execution
A cross-site scripting (XSS) vulnerability has been identified in Grafana, an open-source monitoring and observability platform. This issue affects Grafana versions 8.0.0-beta1 prior to 8.2.3. The vulnerability allows an attacker to execute arbitrary JavaScript in the context of the victim's browser. Exploitation requires convincing the victim to visit a crafted URL that references a vulnerable page, specifically one that includes the login button in the menu bar. The URL must be designed to exploit AngularJS rendering by incorporating interpolation bindings for AngularJS expressions, which are denoted by double curly braces. When the malicious link is followed, the AngularJS rendering engine executes the embedded JavaScript, potentially leading to unauthorized actions or data exposure.
Mozilla Firefox and Thunderbird Header Splitting Vulnerability in HTTP/3
A header splitting vulnerability has been identified in Mozilla Firefox and Thunderbird. The issue arises because the applications incorrectly processed newlines in HTTP/3 headers, splitting them into two separate headers. This flaw, present in Firefox and Thunderbird versions prior to 91.0.1, allows for header splitting attacks on servers using HTTP/3.
jQuery UI Cross-Site Scripting Vulnerability in the 'of' Option of the .position() Utility
A cross-site scripting (XSS) vulnerability has been identified in jQuery UI versions prior to 1.13.0. This issue arises in the 'of' option of the '.position()' utility, where untrusted input can be accepted and executed as code. The vulnerability is present in an embedded version of jQuery UI within OTRS 7.10.6-rev61 and 8.22, as well as in various NetApp products. The issue has been fixed in jQuery UI 1.13.0, and the relevant components have been updated in OTRS and Tenable.sc.
jQuery UI Datepicker Vulnerability in jQuery UI Versions Prior to 1.13.0 Allows Cross-Site Scripting
A cross-site scripting (XSS) vulnerability has been identified in the jQuery UI Datepicker widget, affecting jQuery UI versions prior to 1.13.0. The vulnerability arises from accepting values for various '*Text' options from untrusted sources, which could execute malicious code. This issue has been addressed in jQuery UI 1.13.0, where such values are now treated as plain text rather than HTML. The vulnerability is present in several applications and frameworks that bundle jQuery UI, including Drupal 7, OTRS 6, and NetApp products.
jQuery UI Datepicker Vulnerability in altField Option Allowing Cross-Site Scripting
A cross-site scripting vulnerability has been identified in the Datepicker widget of jQuery UI, versions prior to 1.13.0. This issue arises from the altField option, which can execute untrusted code if the value is sourced from untrusted inputs. The vulnerability is present in various applications and products that bundle jQuery UI, including Drupal 7, OTRS 6, and several NetApp products. The issue has been acknowledged in the jQuery UI blog and is part of a larger set of vulnerabilities addressed in the 1.13.0 release.
Juniper Networks CTPView HTTP Strict Transport Security Not Enforced Vulnerability
A vulnerability exists in Juniper Networks CTPView server versions 7.3 prior to 7.3R7 and 9.1 prior to 9.1R3, due to the server not enforcing HTTP Strict Transport Security (HSTS). This lack of HSTS can leave the system open to downgrade attacks, SSL-stripping man-in-the-middle attacks, and reduces protections against cookie hijacking.
Apple Multiple Products IOMobileFrameBuffer Memory Corruption Vulnerability Allowing Arbitrary Code Execution with Kernel Privileges
A memory corruption vulnerability has been identified in the IOMobileFrameBuffer component of multiple Apple operating systems, including macOS Big Sur, iOS, iPadOS, and watchOS. This vulnerability may allow an application to execute arbitrary code with kernel privileges. Apple is aware of reports suggesting that this issue may have been actively exploited.
Google Chrome and Chromium Portals Use-After-Free Vulnerability Allowing Sandbox Escape
A use-after-free vulnerability has been identified in the Portals feature of Google Chrome and Chromium, prior to version 94.0.4606.61. This vulnerability allows a remote attacker who has compromised the renderer process to potentially escape the sandbox by using a crafted HTML page. The issue arises because the renderer can manipulate frame-bound Mojo interfaces, bypassing normal security restrictions.
Apache HTTP Server Path Traversal and Remote Code Execution Vulnerability
A path traversal vulnerability allowing remote code execution has been identified in Apache HTTP Server versions 2.4.49 and 2.4.50. The issue arises from an insufficient fix for a previous vulnerability (CVE-2021-41773), which allowed attackers to map URLs to files outside the designated directories. If these files are not protected by the default 'require all denied' configuration, the requests can succeed. The vulnerability is particularly concerning when CGI scripts are enabled for the affected paths, as it could lead to arbitrary code execution.
Apache HTTP Server Path Traversal and Remote Code Execution Vulnerability
A path traversal vulnerability allowing remote code execution has been identified in Apache HTTP Server versions 2.4.49 and 2.4.50. The vulnerability arises from an improper handling of path normalization, which allows attackers to map URLs to files outside the designated document root. If these files are not secured by the default 'require all denied' directive, the requests may succeed. Additionally, if CGI scripts are enabled for the affected paths, this could lead to arbitrary code execution.
Akamai EAA Client Unquoted Path Vulnerability Allowing Privilege Escalation
A vulnerability exists in the Akamai Enterprise Application Access (EAA) Client for Windows, specifically in versions prior to 2.3.1, 2.4.x prior to 2.4.1, and 2.5.x prior to 2.5.3. The issue arises from an unquoted service path that can be exploited to hijack the execution flow. This unquoted path vulnerability, a type of path interception, takes advantage of how Windows processes paths with spaces when launching applications or services. If not properly quoted, the operating system may misinterpret the path, leading to the execution of unintended applications. In the case of the EAA Client, this could allow a malicious actor to place a harmful executable that would be run with administrative privileges, potentially escalating privileges on the system.
DataTables HTML Escape Function Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability exists in the DataTables library versions prior to 1.11.3. The issue arises because the HTML escape entities function does not properly escape the contents of an array if one is passed, leading to potential injection of malicious scripts.
Apache HTTP Server mod_proxy Server-Side Request Forgery Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in the Apache HTTP Server's mod_proxy component. This vulnerability allows an attacker to craft a request that is forwarded to an arbitrary origin server of their choice. The issue affects Apache HTTP Server versions 2.4.48 and earlier.
Vuelidate Inefficient Regular Expression Complexity Vulnerability Allowing ReDoS
A denial-of-service vulnerability has been identified in the Vuelidate library, specifically within the URL validation function of the @vuelidate/validators package. This vulnerability arises from inefficient regular expression processing, which can be exploited by providing crafted input that causes excessive CPU consumption. The issue has been fixed in version 2.0.4 of the @vuelidate/validators package.
Siemens SIPROTEC 5 Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Siemens SIPROTEC 5 relays with CPU variants CP050, CP100, and CP300, all running versions prior to V8.80. The issue arises because received webpackets are not properly processed, allowing an unauthenticated remote attacker with access to any Ethernet interface to send specially crafted packets that force the target device to restart.
Cloudflare OctoRPKI RPKI Validation Bypass Vulnerability Leading to BGP Hijacking
A vulnerability in Cloudflare's OctoRPKI RPKI validator, prior to version 1.3.0, allows any CA issuer in the RPKI to manipulate the validator into accepting an invalid VRP 'MaxLength' value. This manipulation causes RTR sessions to terminate, disrupting RPKI Origin Validation. As a result, networks relying on this validation, such as AS 13335 (Cloudflare), could inadvertently accept BGP routes that would normally be rejected due to RPKI invalidity. Furthermore, the resulting flapping of RTR sessions could create additional BGP routing instability, leading to availability issues.
Apple macOS TCC Privacy Preference Bypass Vulnerability
A permissions vulnerability in the Transparency, Consent, and Control (TCC) framework of Apple macOS has been identified, allowing a malicious application to bypass privacy preferences. This issue is present in macOS Big Sur 11.4 and was actively exploited, according to Apple.
Apple iOS WebKit Buffer Overflow Vulnerability Allowing Arbitrary Code Execution
A buffer overflow vulnerability has been identified in the WebKit component of Apple iOS, specifically in versions 12.5.3 and prior. This vulnerability arises from improper memory handling, which can be exploited by processing maliciously crafted web content, leading to arbitrary code execution. There are reports suggesting that this issue may have been actively exploited.
Apple WebKit Memory Corruption Vulnerability Allowing Arbitrary Code Execution
A memory corruption vulnerability has been identified in the WebKit component of multiple Apple operating systems, including iOS, iPadOS, macOS, watchOS, and tvOS. This vulnerability arises from improper state management, which can be exploited by processing maliciously crafted web content, leading to arbitrary code execution. Notably, there are reports suggesting that this vulnerability may have been actively exploited in the wild.
Apple WebKit Integer Overflow Vulnerability Allowing Arbitrary Code Execution
An integer overflow vulnerability has been identified in the WebKit component of multiple Apple products, including iOS, iPadOS, macOS, tvOS, and Safari. This vulnerability arises from inadequate input validation, which can be exploited by processing maliciously crafted web content, leading to arbitrary code execution. The issue has been actively exploited in the wild.
Apple WebKit Storage Use-After-Free Vulnerability Allowing Arbitrary Code Execution
A use-after-free vulnerability has been identified in the WebKit Storage component of multiple Apple products, including iOS, iPadOS, macOS, tvOS, watchOS, and Safari. This vulnerability arises from improper memory management, which can be exploited by processing maliciously crafted web content, leading to arbitrary code execution. Notably, this issue may have been actively exploited in the wild.
Apple macOS Gatekeeper Bypass Vulnerability in System Preferences
A logic vulnerability has been identified in the System Preferences component of Apple macOS. This issue allows a malicious application to bypass Gatekeeper checks, which are designed to prevent the execution of untrusted software. The vulnerability arises from an unspecified logic issue that could be exploited to manipulate the state management of the application. It affects multiple versions of macOS, including Big Sur and Catalina.
Apple iOS WebKit Use-After-Free Vulnerability Allowing Arbitrary Code Execution
A use-after-free vulnerability has been identified in the WebKit component of Apple iOS. This issue affects iOS devices including the iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad mini 2, iPad mini 3, and iPod touch (6th generation). The vulnerability arises from a memory corruption issue in the ASN.1 decoder, which was addressed by removing the vulnerable code. However, the vulnerability could still be exploited by processing maliciously crafted web content, leading to arbitrary code execution. Apple is aware of reports suggesting that this issue may have been actively exploited.
Apple iOS WebKit Memory Corruption Vulnerability Allowing Arbitrary Code Execution
A memory corruption vulnerability has been identified in the WebKit component of Apple iOS. This issue affects iOS devices including the iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad mini 2, iPad mini 3, and iPod touch (6th generation). The vulnerability arises from improper state management, which can be exploited by processing maliciously crafted web content, leading to arbitrary code execution. Apple is aware of reports suggesting that this vulnerability may have been actively exploited.
Next.js Cross-Site Scripting Vulnerability in Image Optimization API
A cross-site scripting vulnerability has been identified in Next.js, a React framework, affecting versions 10.0.0 prior to 11.1.0. The issue arises when the 'next.config.js' file includes an 'images.domains' array that allows user-provided SVGs. Instances deployed on Vercel or with a non-default 'images.loader' are not vulnerable.
Simply Gallery Blocks with Lightbox Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability exists in the WordPress plugin Simply Gallery Blocks with Lightbox, in versions through 2.2.0. This vulnerability allows users with low privileges to execute arbitrary script code within the application context. The issue arises from inadequate validation of image parameters in the metadata, particularly in the Lightbox feature.
WP Video Lightbox WordPress Plugin Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WP Video Lightbox WordPress plugin, affecting versions prior to 1.9.3. The issue arises because the plugin does not properly escape the attributes of its shortcodes. This flaw allows users with a minimum role of contributor to execute cross-site scripting attacks.
ShareThis Dashboard for Google Analytics WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the ShareThis Dashboard for Google Analytics WordPress plugin, affecting versions prior to 2.5.2. The issue arises because the plugin fails to properly sanitize or escape the 'ga_action' parameter in the stats view before rendering it in an attribute. This vulnerability is triggered when the plugin is linked to a Google Analytics account, allowing an attacker to execute malicious scripts in the context of a logged-in administrator.
Apple Core Telephony Sandbox Bypass Vulnerability
A deserialization vulnerability in the Core Telephony framework of Apple iOS, macOS, and watchOS allows a sandboxed process to bypass sandbox restrictions. This issue was addressed with improved validation and is fixed in multiple Apple software updates. At the time of the release, Apple was aware of reports suggesting that this vulnerability may have been actively exploited.
Apple iOS and iPadOS Buffer Overflow Vulnerability Allowing Arbitrary Code Execution with Kernel Privileges
A buffer overflow vulnerability has been identified in Apple iOS and iPadOS, specifically in versions prior to 15.2. This vulnerability allows an application to execute arbitrary code with kernel privileges. The issue arises from improper memory handling, which creates an opportunity for exploitation.
Apple WebKit Integer Overflow Vulnerability Allowing Arbitrary Code Execution
A vulnerability exists in the WebKit component of multiple Apple products, including iOS, iPadOS, macOS Monterey, tvOS, and watchOS. This vulnerability is an integer overflow that was introduced through the processing of maliciously crafted web content. The issue has been addressed with improved input validation. However, the vulnerability could be exploited to execute arbitrary code on the affected device.
Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability in GPU Drivers Allowing Arbitrary Code Execution with Kernel Privileges
A vulnerability exists in the GPU drivers of Apple iOS, iPadOS, and macOS Big Sur. This out-of-bounds write issue could enable a malicious application to execute arbitrary code with kernel privileges. The vulnerability has been addressed with improved bounds checking. Notably, Apple is aware of reports suggesting that this vulnerability may have been actively exploited.
Apple iOS, iPadOS, and macOS Type Confusion Vulnerability Allowing Arbitrary Code Execution with Kernel Privileges
A type confusion vulnerability has been identified in the XNU component of Apple iOS, iPadOS, and macOS. This vulnerability may allow a malicious application to execute arbitrary code with kernel privileges. It affects multiple versions of iOS, iPadOS, and macOS, including iOS 12.5.5, iOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, and Security Update 2021-001 Mojave. Apple is aware of reports that an exploit for this issue exists in the wild.
Apple CoreGraphics Integer Overflow Vulnerability Leading to Arbitrary Code Execution
A vulnerability exists in the CoreGraphics component of multiple Apple products, including iOS 14.8, iPadOS 14.8, macOS Big Sur 11.6, and watchOS 7.6.2. This vulnerability arises from an integer overflow that was introduced with JBIG2 image processing. It allows for arbitrary code execution when a maliciously crafted PDF is processed. Apple has acknowledged reports of active exploitation of this vulnerability.
ReCaptcha Solver Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability exists in ReCaptcha Solver version 5.7. When the extension receives a response from various captcha-solving services, including Anti-Captcha.com, RuCaptcha.com, 2captcha.com, DEATHbyCAPTCHA.com, ImageTyperz.com, and BestCaptchaSolver.com, the data is inserted into the DOM as HTML. This flaw allows these services to gain full control over the user's browser.
Amazon AWS CloudFront Weak Cipher Support Vulnerability
A vulnerability exists in Amazon AWS CloudFront's TLSv1.2_2019 security policy, which allows the use of ciphers TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384. These ciphers are considered weak by some security standards. While CloudFront offers a newer security policy, TLSv1.2_2020, that does not include these ciphers, it is not clear when or if this policy will be available to all users.
Sitecore File Upload Vulnerability Leading to Remote Code Execution
A vulnerability in Sitecore versions through 10.1, when the Update Center is enabled, allows remote authenticated users to upload arbitrary files. This could lead to remote code execution by accessing the uploaded .aspx file through the admin/Packages URL.
Next.js Open Redirect Vulnerability in Error Pages
A vulnerability allowing open redirects has been identified in Next.js versions 10.0.5 prior to 10.2.0 and 11.0.0 prior to 11.0.1, when using 'pages/_error.js' without 'getInitialProps' or with 'next export'. This issue does not affect Vercel deployments or those with 'pages/404.js'. The vulnerability arises from improperly handled path parsing, which could be exploited to redirect users from a trusted domain to an attacker's domain, potentially leading to phishing attacks.
jszip Prototype Pollution Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in the jszip package, affecting versions prior to 3.7.0. The issue arises when a zip file is created with filenames that correspond to Object prototype values, such as __proto__ or toString. This manipulation results in an object with a altered prototype, which can disrupt normal functionality. The vulnerability can be exploited by crafting a zip file that includes these prototype-related filenames, causing the jszip library to process the file in a way that modifies the object's prototype and potentially leads to application errors or crashes.
