CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Adobe Commerce Information Exposure Vulnerability Allowing Limited Disclosure of Sensitive Information
An information exposure vulnerability has been identified in Adobe Commerce. This vulnerability could lead to a limited disclosure of sensitive information. Exploitation of this issue depends on conditions beyond the attacker's control and does not require user interaction.
Adobe Commerce Open Redirect Vulnerability Allowing Security Feature Bypass
A vulnerability allowing improper redirection (open redirect) has been identified in Adobe Commerce. This issue could lead to a security feature bypass, as it allows an attacker to create a malicious URL that redirects a victim to an attacker-controlled site. Such redirection could facilitate credential theft and account takeover. Exploitation of this vulnerability requires user interaction, as the victim must click on the malicious link. The vulnerability affects multiple versions of Adobe Commerce, Adobe Commerce B2B, Magento Open Source, and Adobe Commerce Events.
Adobe Commerce Stored Cross-Site Scripting Vulnerability Allowing Privilege Escalation
A stored cross-site scripting vulnerability has been identified in Adobe Commerce. This issue allows a high-privileged attacker to inject malicious scripts into vulnerable form fields. When a victim interacts with the page containing the compromised field, the injected JavaScript is executed in their browser. The vulnerability is present in several versions of Adobe Commerce and Magento Open Source.
Adobe Commerce Incorrect Authorization Vulnerability Allowing Security Feature Bypass
A vulnerability has been identified in Adobe Commerce that involves incorrect authorization, potentially allowing for a security feature bypass. This issue could enable an attacker to circumvent security measures and gain unauthorized read access. The exploitation of this vulnerability depends on conditions beyond the attacker's control, and does not require user interaction. Affected versions include Adobe Commerce 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, 2.4.6-p15 and earlier, 2.4.5-p17 and earlier, 2.4.4-p18 and earlier, as well as Adobe Commerce B2B versions 1.5.3, 1.5.2-p5 and earlier, 1.4.2-p10 and earlier, 1.3.4-p17 and earlier, and 1.3.3-p18 and earlier.
Adobe Commerce Incorrect Authorization Vulnerability Allowing Security Feature Bypass
A vulnerability allowing security feature bypass through incorrect authorization has been identified in Adobe Commerce. This issue could enable an attacker to gain unauthorized read access by bypassing security measures. The vulnerability affects multiple versions of Adobe Commerce, Magento Open Source, and Adobe Commerce B2B, as well as Adobe Commerce Events. Exploitation of this vulnerability does not require user interaction, but depends on conditions beyond the attacker's control.
Adobe Commerce Incorrect Authorization Vulnerability Allowing Security Feature Bypass
A vulnerability has been identified in Adobe Commerce that involves incorrect authorization, potentially allowing a high-privileged attacker to bypass security measures and gain unauthorized read access. This vulnerability affects several versions of Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. Notably, exploitation does not require user interaction.
Adobe Commerce Stored Cross-Site Scripting Vulnerability Allowing Privilege Escalation
A stored Cross-Site Scripting vulnerability has been identified in Adobe Commerce. This issue allows a high-privileged attacker to inject malicious scripts into vulnerable form fields. When a victim accesses the page containing the compromised field, the injected JavaScript could execute in their browser, potentially leading to unauthorized access or control over the victim's account or session. The vulnerability affects multiple versions of Adobe Commerce, including Adobe Commerce B2B and Magento Open Source.
Adobe Commerce Stored Cross-Site Scripting Vulnerability Allowing Privilege Escalation
A stored cross-site scripting vulnerability has been identified in Adobe Commerce. This issue allows low-privileged attackers to inject malicious scripts into vulnerable form fields. When a victim interacts with the page containing the compromised field, the injected JavaScript could execute in their browser, potentially leading to unauthorized access or control over the victim's account or session. The vulnerability is present in several versions of Adobe Commerce and Magento Open Source.
Adobe Commerce SQL Injection Vulnerability Allowing Arbitrary Code Execution
A SQL injection vulnerability has been identified in Adobe Commerce, specifically in versions 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, 2.4.6-p15 and earlier, 2.4.5-p17 and earlier, and 2.4.4-p18 and earlier. This vulnerability arises from improper neutralization of special elements used in SQL commands, potentially allowing high-privileged attackers to execute malicious SQL commands. Exploitation of this vulnerability could lead to arbitrary code execution in the context of the current user, with elevated access or control over the victim's account or session. Notably, this vulnerability does not require user interaction.
Adobe Commerce Incorrect Authorization Vulnerability Allowing Security Feature Bypass
A vulnerability allowing incorrect authorization has been identified in Adobe Commerce. This issue could lead to a security feature bypass, allowing unauthorized read and write access. The vulnerability is present in Adobe Commerce versions 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, 2.4.6-p15 and earlier, 2.4.5-p17 and earlier, and 2.4.4-p18 and earlier. It also affects Adobe Commerce B2B versions 1.5.3, 1.5.2-p5 and earlier, 1.4.2-p10 and earlier, 1.3.4-p17 and earlier, and 1.3.3-p18 and earlier. Additionally, Magento Open Source versions 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, and 2.4.6-p15 and earlier are affected. The vulnerability exploitation does not require user interaction.
Adobe Commerce Incorrect Authorization Vulnerability Allowing Security Feature Bypass
A vulnerability allowing security feature bypass through incorrect authorization has been identified in Adobe Commerce. This issue could enable an attacker to gain unauthorized read and write access. The vulnerability is present in multiple versions of Adobe Commerce, Adobe Commerce B2B, and Magento Open Source, as well as in Adobe Commerce Events versions 1.6.0 to 1.20.0. Exploitation of this vulnerability does not require user interaction.
Puma Source IP Spoofing Vulnerability via PROXY Protocol v1 on Persistent Connections
A vulnerability in Puma, a Ruby/Rack web server, allows for source IP spoofing when PROXY protocol v1 is enabled and persistent connections are used. This issue affects Puma versions 5.5.0 prior to 7.2.1 and 8.0.2. The vulnerability arises because Puma incorrectly re-parses PROXY protocol headers after each keep-alive request on the same connection. An attacker could inject a second PROXY header, overwriting the REMOTE_ADDR variable. This misconfiguration can lead to security issues, as applications may rely on REMOTE_ADDR for security decisions, rate limiting, or auditing.
Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
A vulnerability in the Puma web server, affecting versions 5.5.0 prior to 7.2.1 and 8.0.2, allows for remote memory exhaustion when PROXY protocol v1 support is enabled. The server reads incoming data into an internal buffer, waiting for a carriage return and line feed (CRLF) to identify PROXY v1 lines. An attacker can exploit this by sending bytes without CRLF, causing unbounded memory growth and increased CPU usage as the server scans the expanding buffer. This issue can lead to out-of-memory conditions or degraded availability.
NVIDIA Triton Inference Server Denial-of-Service Vulnerability Due to Memory Management Issue
A denial-of-service vulnerability has been identified in NVIDIA Triton Inference Server for Linux, versions 0.0 through 26.04. The issue arises from a missing release of memory after its effective lifetime, which an attacker can exploit to cause a denial-of-service condition.
NVIDIA Triton Inference Server Authentication Bypass Vulnerability Allowing Code Execution and Privilege Escalation
An authentication bypass vulnerability has been identified in NVIDIA Triton Inference Server for Linux, affecting versions 0.0 through 26.04. This vulnerability allows attackers to bypass authentication through an alternative path or channel. Exploitation of this vulnerability could lead to unauthorized code execution, escalation of privileges, information disclosure, and data tampering.
NVIDIA Triton Inference Server Denial-of-Service Vulnerability via Uncaught Exception
A denial-of-service vulnerability has been identified in NVIDIA Triton Inference Server for Linux, where an attacker can cause an uncaught exception. This exploitation leads to a denial-of-service condition on the server.
NVIDIA Triton Inference Server Uncontrolled Resource Consumption Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in NVIDIA Triton Inference Server for Linux, versions 0.0 through 26.04. This vulnerability allows an attacker to cause uncontrolled resource consumption, which could lead to a denial-of-service condition on the server.
NVIDIA Triton Inference Server Denial-of-Service Vulnerability via Expired File Descriptor
A denial-of-service vulnerability has been identified in NVIDIA Triton Inference Server for Linux, where an attacker can manipulate the use of an expired file descriptor. This exploitation can lead to a service disruption.
NVIDIA Triton Inference Server Stack-Based Buffer Overflow Vulnerability Leading to Denial-of-Service
A stack-based buffer overflow vulnerability has been identified in NVIDIA Triton Inference Server for Linux, affecting versions 0.0 through 26.04. This vulnerability allows an attacker to cause a buffer overflow, which could be exploited to beak the application, leading to a denial-of-service condition.
NVIDIA Triton Inference Server Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in NVIDIA Triton Inference Server for Linux, versions 0.0 through 26.04. This vulnerability allows an attacker to cause uncontrolled resource consumption, potentially leading to a denial-of-service condition.
Vitest Path Traversal Vulnerability Allowing Arbitrary File Read and Remote Code Execution
A vulnerability in Vitest's UI/API server on Windows prior to versions 3.2.5 and 4.1.0 allows for path traversal attacks. By exploiting the incorrect handling of file serving permissions, an attacker can read files outside the project directory. Additionally, the exposed API features for writing and re-running tests could be misused to execute arbitrary scripts. This vulnerability arises when the Vitest UI server is exposed to the network, particularly on Windows systems.
Vitest Browser Mode Cross-Site Scripting Vulnerability Allowing Token Theft and Remote Code Execution
A critical cross-site scripting vulnerability has been identified in Vitest, a testing framework powered by Vite. This issue affects Vitest versions 4.0.17 prior to 4.1.6 and 5.0.0-beta.3. The vulnerability arises in Vitest Browser Mode, where the 'otelCarrier' query parameter is unsanitized and directly injected into an inline module script. This flaw allows a crafted browser-runner URL to execute arbitrary JavaScript in the Vitest server origin, potentially leading to the theft of the 'VITEST_API_TOKEN', which is used for authenticated API calls. Exploitation of this vulnerability can be chained with server-side code execution by writing a payload into 'vite.config.ts', which is then executed in Node when the config is reloaded.
DOMPurify Cross-Site Scripting Vulnerability via 'selectedcontent' Element
A cross-site scripting (XSS) vulnerability has been identified in DOMPurify version 3.4.4. The issue arises from the default allowance of the 'selectedcontent' element, which enables a mechanism where browsers can 're-clone' an XSS payload after it has been sanitized. This process results in the return of unsanitized markup within the 'selectedcontent' element. The vulnerability is present in DOMPurify versions prior to 3.4.5.
Symfony Twilio Notifier Webhook HMAC Signature Verification Vulnerability
A vulnerability exists in the Symfony framework's Twilio SMS notifier webhook parser, specifically in versions prior to 6.4.40, 7.4.12, and 8.0.12. The issue arises because the webhook parser's 'doParse' method receives the configured webhook secret but fails to verify the 'X-Twilio-Signature' HMAC header. This oversight allows unauthenticated POST requests to inject fake Twilio status payloads, potentially leading to delivery-metrics fraud and unauthorized automation triggers.
Symfony DomCrawler XXE Vulnerability in addXmlContent Method Allows Local File Disclosure
A vulnerability exists in the Symfony DomCrawler component, specifically in the Crawler class's addXmlContent method, prior to versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. The issue arises because the method enables DOMDocument's validateOnParse property before loading XML. This reactivates external entity resolution, allowing attacker-controlled XML to access local files by expanding file:// entities. Exploitation could lead to unauthorized disclosure of sensitive file contents, such as the passwd file.
Symfony Mailer SendmailTransport Argument Injection Vulnerability
A vulnerability exists in the Symfony Mailer component's SendmailTransport when used in '-t' mode. Prior to versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12, recipient addresses were added to the sendmail command line without a proper end-of-options separator. This oversight allowed addresses starting with a dash to be misinterpreted as command-line options instead of valid recipient addresses. The issue has been addressed by ensuring the correct separator is used before the list of recipients.
libsoup Out-of-Bounds Read Vulnerability in Multipart Processing
A vulnerability allowing out-of-bounds read has been identified in libsoup's multipart processing subsystem. This issue arises in the 'soup_multipart_input_stream_read_headers()' function within 'soup-multipart-input-stream.c'. The vulnerability occurs because the function fails to properly validate the size of incoming multipart boundary strings. As a result, when a crafted HTTP response with a malformed or oversized boundary parameter is processed, the internal stream reader can read beyond the allocated buffer limits. This flaw can be exploited by a remote, unauthenticated attacker to cause a denial-of-service (DoS) by crashing the application or potentially reading fragments of unauthorized memory metadata.
libsoup HTTP/2 Memory Leak Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in libsoup's HTTP/2 protocol implementation. The issue arises because the library does not properly release memory context blocks under certain stream termination conditions, such as window exhaustion or explicit stream resets. This flaw allows a remote, unauthenticated attacker to manipulate the connection engine into leaking allocated stream states during cleanup. Over time, this memory leakage can exhaust the application's heap allocations, causing an Out-of-Memory crash. The vulnerability affects libsoup versions prior to the fixed version in Red Hat Enterprise Linux 10.
libsoup WebSocket Oversized Control Frame Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in libsoup's WebSocket frame parsing. The issue arises because the library does not properly validate the length of control frames, such as PING, PONG, and CLOSE, as required by RFC 6455 §5.5. This section specifies that control frames must have a payload of 125 bytes or less. A remote, unauthenticated attacker can exploit this vulnerability by sending an oversized control frame that violates the protocol. Instead of immediately terminating the connection, the parser mishandles the violation, leading to a crash in the internal processing. This flaw causes a remote denial-of-service condition for applications that use libsoup WebSockets.
libsoup WebSocket Decompression Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in libsoup's WebSocket implementation, specifically when the permessage-deflate extension is used. The issue arises because the decompression loop in the extension processes data in chunks without enforcing a maximum limit on the output buffer size. Although libsoup restricts the size of incoming compressed frames, it does not monitor or limit memory allocation during decompression. This flaw allows a remote, unauthenticated attacker to send a small, highly compressed payload that decompresses to a much larger size, causing unbounded memory allocation. The resulting memory exhaustion leads to an out-of-memory crash, disrupting service.
SonicWall SMA1000 Appliances Code Injection Vulnerability
A post-authentication code injection vulnerability has been identified in the SonicWall SMA1000 Appliance Management Console (AMC). Under specific conditions, this vulnerability could allow a remote authenticated attacker with administrative privileges to execute arbitrary operating system commands.
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
A server-side request forgery (SSRF) vulnerability exists in the SonicWall SMA1000 Appliance Work Place interface. This vulnerability allows remote, unauthenticated attackers to manipulate the appliance into making requests to unintended locations. Affected models include the SMA1000 Models 6210, 7210, and 8200v, specifically versions 12.4.3-03245, 12.4.3-03387, 12.4.3-03434 (platform-hotfix), 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800 (platform-hotfix).
Podlove Podcast Publisher Arbitrary File Upload Vulnerability Allowing Remote Code Execution
A vulnerability in the Podlove Podcast Publisher plugin for WordPress, present in all versions prior to 4.5.1, allows for arbitrary file uploads. This issue arises from inadequate file type validation in the 'podlove_handle_cache_files' function. As a result, unauthenticated attackers can upload arbitrary files to the server, potentially leading to remote code execution.
TP-Link Deco M5 Weak Password Hashing Vulnerability Allowing Credential Disclosure
A vulnerability exists in the TP-Link Deco M5 v1 due to the use of a weak password hashing method for storing user credentials. This flaw allows an attacker who gains access to the password hash, either through system compromise or privileged access, to execute brute-force or dictionary attacks. Successful exploitation could lead to the unauthorized disclosure of authentication credentials, granting access to device management functions based on the privileges associated with the recovered password.
Symfony Runtime Argument Parsing Vulnerability Allows Environment Variable Manipulation
A vulnerability exists in Symfony's runtime component that can be exploited to manipulate application environment variables. This issue arises in Symfony versions 5.4.46 prior to 5.4.52, 6.4.14 prior to 6.4.40, 7.1.7 prior to 7.4.12, and 8.0.0 prior to 8.0.12. The vulnerability exploits a mismatch between how the web server and the 'parse_str()' function handle query strings, allowing an attacker to send crafted flags that alter the 'APP_ENV' and 'APP_DEBUG' variables. The problem is exacerbated when the 'register_argc_argv' directive is enabled, as it allows the server to pass these flags through '$_SERVER['argv']' to the application.
Microsoft Visual Studio Remote Code Execution Vulnerability
A protection mechanism failure in Microsoft Visual Studio creates a vulnerability that allows unauthorized attackers to execute code locally. This issue affects Visual Studio 2022 versions 17.12 and 17.14, as well as Visual Studio 2026 version 18.7.
Microsoft .NET Cryptographic Signature Verification Vulnerability Allowing Security Feature Bypass
A vulnerability exists in .NET due to improper verification of cryptographic signatures, which allows unauthorized attackers to bypass security features over a network. This vulnerability affects multiple versions of Microsoft Visual Studio, including 2022 versions 17.12 and 17.14, as well as Visual Studio 2026 version 18.7.
Microsoft ASP.NET Core Authentication Bypass Vulnerability Allowing Privilege Escalation
A vulnerability in ASP.NET Core allows an authorized attacker to bypass authentication and elevate privileges over a network. This issue arises from an authentication bypass by assumed-immutable data, which could be exploited to gain SYSTEM privileges.
.NET Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in .NET, allowing an unauthorized attacker to disrupt service over a network. This issue arises from the allocation of resources without proper limits or throttling.
Microsoft Configuration Manager Elevation of Privilege Vulnerability
A vulnerability allowing improper access control in Microsoft Configuration Manager has been identified. This issue enables an authorized attacker to elevate privileges over a network. The vulnerability exists in Microsoft Configuration Manager versions 2503, 2603, and 2509.
Microsoft ASP.NET Core Elevation of Privilege Vulnerability
A vulnerability allowing privilege escalation has been identified in ASP.NET Core. This issue arises from an incorrect implementation of the authentication algorithm, which enables an authorized attacker to elevate privileges over a network. The vulnerability affects several versions of ASP.NET Core, as well as .NET 8.0, 9.0, and 10.0 across different operating systems.
Symfony Mailtrap Webhook HMAC Signature Verification Vulnerability
A vulnerability exists in the Symfony Mailtrap Mailer Bridge webhook request parser, specifically in versions 7.2 through 7.4.11 and 8.0 prior to 8.0.12. The issue arises because the parser's 'doParse' method receives the configured webhook secret but fails to verify the 'X-Mt-Signature' HMAC header. This oversight allows unauthenticated POST requests to inject fake Mailtrap delivery, bounce, open, click, or spam events. As a result, applications can experience corruption of suppression lists and fraudulent delivery metrics.
Symfony Mailjet Mailer and LOX24 Notifier Webhook Secret Verification Vulnerability
A vulnerability exists in the Symfony Mailjet mailer bridge and LOX24 notifier bridge webhook parsers, prior to versions 6.4.40, 7.4.12, and 8.0.12. The parsers received configured webhook secrets but failed to verify them, allowing unauthenticated POST requests to inject forged event payloads. This lack of verification could lead to the corruption of suppression lists and manipulation of delivery metrics.
Symfony UrlAttributeSanitizer Missing URL Validation Leads to XSS Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in the Symfony framework, specifically in the UrlAttributeSanitizer component of the HtmlSanitizer. This issue affects Symfony versions 6.1.0-BETA1 prior to 6.4.40, as well as versions 7.4.12 and 8.0.12. The vulnerability arises because the UrlAttributeSanitizer's method getSupportedAttributes() fails to include several URL-valued attributes, such as action, formaction, poster, and cite. As a result, configurations that allow these attributes can inadvertently permit javascript: URIs to remain unsanitized. When the rendered HTML is interacted with, such as by submitting a form or clicking a button, this oversight can be exploited to execute malicious scripts.
Symfony YAML Component Parser Catastrophic Backtracking Vulnerability in Cleanup Method
A denial-of-service vulnerability has been identified in the Symfony YAML component's parser. The issue arises in the `Parser::cleanup()` method, which uses regular expressions with overlapping quantifiers to clean up YAML directives, comments, and document markers. This flaw allows specially crafted input to cause the parsing process to hang indefinitely. The vulnerability affects Symfony versions prior to 5.4.52, as well as 6.4.0 through 6.4.39, 7.0.0 through 7.4.11, and 8.0.0 through 8.0.11.
Symfony and Symfony Components Yaml Collection Alias Resolution Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in the Symfony YAML component, specifically in versions prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12. The issue arises in the 'Symfony\Component\Yaml\Parser' class, where YAML collection aliases are resolved recursively. This recursive resolution allows a small, untrusted YAML input to expand into a multi-gigabyte structure, exhausting memory resources. The vulnerability is akin to the 'Billion Laughs' attack, targeting any parser that processes untrusted YAML.
Symfony YAML Parser Stack Exhaustion Vulnerability Allowing Denial-of-Service
A denial-of-service vulnerability has been identified in the Symfony YAML parser component. Prior to versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the parser could be exposed to attacker-controlled input that, when deeply nested mappings or sequences were introduced, caused both block-level and inline parsers to recurse without a depth limit. This unbounded recursion led to a stack exhaustion, crashing the PHP worker. The issue has been reported by Pietro Tirenna (Shielder) and fixed by Nicolas Grekas.
Symfony Method-Scoped Attributes HEAD Request Bypass Vulnerability
A vulnerability exists in Symfony's method-scoped attributes #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] in versions prior to 7.4.12 and 8.0.12. These attributes can be configured to apply only to GET requests. However, Symfony routes HEAD requests to the GET handler while skipping the attribute checks. This oversight allows protected controllers to execute, potentially leaking headers or causing other side effects.
Symfony PdoAdapter SQL Injection Vulnerability in Cache Component
A SQL injection vulnerability has been identified in the PdoAdapter of Symfony's Cache component, affecting versions prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12. The issue arises in the clear() method, where the $prefix parameter is used to construct a DELETE SQL statement without proper binding or escaping. This allows an attacker to manipulate the $prefix value, break out of the LIKE literal, and alter the query's behavior or the scope of deletion. Although this method is not typically exposed to untrusted input, its design should safely accommodate any prefix string, making the vulnerability a flaw in the adapter's implementation.
Symfony Twig Bridge Web Profiler Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Symfony Twig Bridge's Web Profiler component. This issue affects Symfony versions 6.4.24 prior to 6.4.40, 7.2.9 prior to 7.4.12, and 8.0.12. The vulnerability arises because the 'file_excerpt' Twig filter in the Web Profiler's CodeExtension improperly handles non-PHP files. While PHP files are correctly escaped, lines from non-PHP files are interpolated directly into code elements without escaping. This flaw allows an attacker to inject malicious scripts into files that, when opened by a developer in the profiler, execute the injected scripts, leading to cross-site scripting.
