Monitor and prioritize what really matters — the 1% of vulnerabilities that can cause real impact.
This vulnerability is a stack-based buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway components. The root cause lies in improper bounds checking of input data processed by certain internal functions, leading to memory corruption. Affected versions include NetScaler ADC before 14.1-73.41, 13.1-64.28, and corresponding FIPS releases, as well as NetScaler Gateway before 14.1-73.41 and 13.1-64.28.
The vulnerability is a privilege escalation flaw rooted in improper permission handling within Zammad's local user management. Specifically, the local 'zammad' user account is able to escalate privileges to root due to insufficient access control enforcement in the underlying privilege separation mechanism. This affects all versions of the Zammad application, including the latest alpha releases, impacting the system's user privilege boundary.
This vulnerability in Arista Networks VeloCloud Orchestrator (VCO) On-Prem is a logic validation flaw classified under CWE-20 (Improper Input Validation). The root cause is inadequate validation of remote requests targeting privileged internal functions within the orchestrator's management interface. The affected component is the VCO on-premises orchestration platform, which processes unauthenticated network requests allowing unauthorized access to sensitive functionality.
This vulnerability is a permission bypass caused by a logic error within the Cellular Modem component of Google Android. The flaw arises from improper enforcement of access control checks, allowing unauthorized operations to proceed. The affected code fails to correctly validate permissions, leading to an escalation of privilege without requiring additional execution rights.
The vulnerability is an authorization bypass in the ConnectWise ScreenConnect client component that improperly controls file transfer and execution permissions during active remote sessions. The root cause lies in insufficient validation of user privileges and session state, allowing unauthorized file operations without host confirmation. This flaw specifically affects the client-side session management feature responsible for handling remote file transfers and execution commands.
This vulnerability is an authentication bypass in Mikrotik RouterOS's IPv4 UDP testing feature. The root cause lies in the acceptance of a "related" btest connection before the primary session completes authentication, allowing unauthenticated clients to initiate tests. Additionally, improper handling of packet size intervals leads to unsigned integer underflow and kernel packet buffer misuse, affecting the RouterOS kernel's network packet processing component.
This vulnerability is an authentication bypass (CWE-306) affecting TrueConf Server's internal function handling. The root cause is the presence of an undocumented function accessible over network port 4307/TCP that lacks authentication controls, allowing unauthorized invocation. The affected component is the TrueConf Server software versions 5.3.x through 5.5.5 on both Windows and Linux platforms.
This vulnerability is an authentication bypass rooted in improper token handling within JFrog Artifactory. Specifically, the system erroneously issues an internal anonymous-user token to unauthenticated requests despite anonymous access being disabled. The flaw resides in the authentication token generation and validation logic of the Artifactory server component responsible for managing access tokens.
This vulnerability is a denial of service caused by improper error handling within the Remote Access SSL VPN service of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software. The root cause is insufficient validation of HTTP request inputs, leading to unexpected device reloads when malformed requests are processed. The affected component is the HTTP request processing logic in the Remote Access SSL VPN feature.
This vulnerability is an authentication bypass caused by the presence of static user credentials embedded within the Cisco Secure Firewall Management Center (FMC) web interface. The root cause lies in the use of hardcoded low-privileged account credentials that allow unauthenticated remote access. The affected component is the FMC management software's web interface authentication mechanism, which fails to enforce unique or dynamic credential validation for this account.
This vulnerability is a privilege escalation issue arising from improper validation of token attributes in JFrog Artifactory (Self Hosted) versions prior to 7.133.11. Specifically, the system validates the token's signature and issuer but fails to verify the token’s scope, allowing unauthorized privilege elevation. The affected component is the token validation mechanism within the authentication subsystem of the Artifactory server.
VeloCloud Orchestrator on-prem exposes internal-only functionality on its remotely reachable interface, and that functionality passes data into an OS command context. The vendor states the capability was designed for internal use and was never meant to be remotely accessible, so the root cause is an exposure boundary error compounded by unsanitized command construction.
This vulnerability is a stack-based buffer overflow caused by the use of an unsafe strcpy operation within the UPnP handling code of DD-WRT's ssdp.c component. Specifically, the flaw exists in the ssdp_msearch function which processes M-SEARCH requests. The root cause is the lack of proper boundary checks when copying incoming data into a fixed-size internal buffer, affecting the UPnP feature of the router firmware.
This vulnerability is a deserialization flaw in Microsoft Office SharePoint Server 2016, stemming from improper handling of untrusted serialized data. The root cause lies in insecure deserialization logic within SharePoint's data processing components, which fail to validate or sanitize incoming serialized objects. This affects the SharePoint Enterprise Server 2016 platform, specifically its data deserialization routines that process network-received payloads.
This vulnerability is a remote code execution flaw resulting from insecure deserialization of untrusted data within PTC Windchill PDMLink and FlexPLM components. Specifically, the deserialization process fails to properly validate or sanitize incoming serialized objects, allowing malicious payloads to be executed during object reconstruction. The affected components include all CPS versions and Windchill/FlexPLM releases prior to 11.0 M030, where the deserialization functionality is exposed to network input.
This vulnerability is a stack-based buffer overflow occurring within the CGI program of the Zyxel GS1900-48HPv2 firmware. It results from improper bounds checking on input data processed by the CGI component, allowing excessive data to overwrite the stack memory. The flaw specifically affects firmware versions up to 2.90(ABTQ.1)C0, compromising the integrity of the device's HTTP request handling subsystem.
The vulnerability involves a supply chain compromise where a maliciously altered version (18.95.0) of the Nx Console extension was published briefly on the Visual Studio Marketplace and OpenVSX. This tampered package contains unauthorized code injected into the extension's distribution, affecting the integrity of the Nx Console user interface component for Nx & Lerna. The root cause is the introduction of malicious payload within the extension's published package, bypassing normal validation or review processes.
This vulnerability is a Path Traversal flaw (CWE-22) in Ubiquiti UniFi OS Server and related firmware components. The root cause is insufficient validation of user-supplied file path inputs, allowing traversal sequences to access files outside the intended directory scope. The affected components include UniFi OS Server and various UniFi device firmware versions that handle file requests without proper sanitization.
This vulnerability is a supply chain compromise affecting the build and distribution process of AVB Disc Soft's DAEMON Tools Lite Windows installer packages, specifically versions 12.5.0.2421 through 12.5.0.2434. The root cause is unauthorized access to the vendor's build infrastructure, allowing attackers to inject malicious code into three signed binaries (DTHelper.exe, DiscSoftBusServiceLite.exe, DTShellHlp.exe). The trojanized binaries maintain valid digital signatures, impacting the integrity verification mechanism of the installation process.
This vulnerability is an improper input validation flaw within Ivanti Endpoint Manager Mobile's administrative interface. The root cause lies in insufficient sanitization of inputs processed by privileged functions, enabling crafted input to bypass validation controls. The affected component is the administrative access functionality in versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1.
This vulnerability is a command injection flaw rooted in improper input validation within VMware Aria Operations. Specifically, the support-assisted product migration component fails to sanitize user-supplied input, allowing execution of arbitrary system commands. The affected feature processes migration-related commands without adequate filtering, enabling injection through crafted inputs during migration operations.
This vulnerability is a file overwrite flaw caused by improper file handling in the API interface of Cisco Catalyst SD-WAN Manager. Specifically, the API allows authenticated users with read-only credentials to upload files without sufficient validation or restrictions, enabling arbitrary file overwrite on the local filesystem. The affected component is the API subsystem responsible for processing file uploads within the SD-WAN Manager product.
This vulnerability is an information disclosure flaw caused by insufficient file system access controls within Cisco Catalyst SD-WAN Manager. The root cause lies in the improper enforcement of access restrictions on API endpoints, allowing unauthorized read access to sensitive files on the underlying operating system. The affected component is the API interface of the Cisco Catalyst SD-WAN Manager software.
This vulnerability is a hardcoded credential flaw within Dell RecoverPoint for Virtual Machines prior to version 6.0.3.1 HF1. The root cause is the presence of static, embedded authentication credentials in the software, which are accessible without authentication. The affected component is the authentication mechanism of the RecoverPoint for Virtual Machines management interface, allowing unauthorized access to privileged functions.
This vulnerability is an OS command injection flaw in Soliton Systems K.K. FileZen, specifically triggered when the FileZen Antivirus Check Option is enabled. The root cause lies in insufficient input validation of user-supplied data within HTTP requests, allowing injection of arbitrary operating system commands. The affected component is the FileZen web interface handling these specially crafted requests from authenticated users.
This vulnerability is a protection mechanism failure within the MSHTML Framework, specifically involving an improper enforcement of security boundaries. The root cause lies in the component's inability to correctly validate or restrict certain operations, allowing bypass of embedded security controls. The flaw affects MSHTML, the rendering engine responsible for processing HTML content in affected Windows 10 versions.
FortiOS exposes sensitive information to an unauthorized actor through crafted HTTP requests that bypass the patch Fortinet developed for the symbolic link persistency mechanism seen in earlier post-exploit cases. The flaw is therefore a bypass of a prior remediation rather than a new primitive: the original persistence path was closed, and this reopens it. FortiOS 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, and all versions of 7.2, 7.0 and 6.4 are affected.
This vulnerability is a heap-based buffer overflow occurring in Fortinet FortiSwitchManager and FortiOS versions specified. The root cause lies in improper bounds checking during packet processing, which leads to memory corruption on the heap. The flaw affects the packet handling routines within the FortiSwitchManager component and FortiOS network processing modules.
This vulnerability is a stored Cross-Site Scripting (XSS) flaw affecting the Classic UI component of Zimbra Collaboration Suite (ZCS). The root cause lies in improper sanitization of Cascading Style Sheets (CSS) @import directives embedded within HTML email messages, allowing malicious CSS to be stored and later executed in the user interface. The flaw exists in ZCS versions prior to 10.0.18 and 10.1.13, specifically in the handling of HTML email content rendering.
This vulnerability originates from unauthorized modifications introduced into specific builds of the ASUS Live Update client through a supply chain compromise. The root cause is the presence of altered code within the update client binary that triggers unintended actions under certain targeting conditions. The affected component is the ASUS Live Update client software, which has reached End-of-Support as of October 2021.
This vulnerability is a command injection flaw rooted in improper input validation within Array Networks ArrayOS AG versions prior to 9.4.5.9. The issue arises from insufficient sanitization of user-supplied data passed to system-level commands in the VPN appliance's management interface. The affected component is the ArrayOS AG software responsible for handling administrative command inputs, enabling attackers with elevated privileges to inject arbitrary commands.
This vulnerability is a type confusion flaw within the V8 JavaScript engine component of Google Chrome. The root cause lies in improper type handling during object manipulation, leading to inconsistent assumptions about object structure and memory layout. Specifically, this occurs in the V8 engine's internal representation of JavaScript objects prior to version 142.0.7444.175, which affects memory safety and integrity during script execution.
This vulnerability is a use-after-free condition arising from improper memory management in the processing of web content. The flaw occurs within Apple's WebKit rendering engine, specifically affecting Safari and related system components on macOS, iOS, and iPadOS. The root cause is the premature release of memory objects that are subsequently accessed, leading to memory corruption.
The vulnerability in MOTEX Inc. Lanscope Endpoint Manager (On-Premises) arises from improper verification of the origin of incoming network requests. Specifically, the Client program (MR) and Detection agent (DA) components fail to validate the authenticity of packets received, enabling an attacker to craft and send malicious packets that are processed without adequate origin checks. This flaw is rooted in insufficient input validation within the network communication handling modules of the endpoint management system.
This vulnerability is a remote code execution flaw arising from improper handling of specific malicious traffic within the Access Policy Manager (APM) feature of F5 BIG-IP virtual servers. The root cause lies in the APM access policy processing logic failing to adequately validate or sanitize crafted input, enabling execution of arbitrary code. The affected component is the BIG-IP APM access policy configured on virtual servers.
This vulnerability is a command injection flaw rooted in improper input validation of compressed email attachments processed by Libraesva Email Security Gateway. The affected component fails to sanitize or securely handle shell commands embedded within these attachments, allowing crafted data to be executed on the underlying system. The flaw specifically impacts versions 4.5 through 5.5.x prior to designated patch releases, compromising the email attachment processing module.
This vulnerability is an out-of-bounds write occurring within the libimagecodec.quram.so library used in Samsung mobile devices. The root cause is improper bounds checking during image codec operations, which leads to memory corruption when processing malformed input data. The flaw specifically affects the image codec component responsible for decoding certain image formats on Samsung Android 13.0 platforms prior to the SMR September 2025 Release 1.
This vulnerability is an authenticated remote command injection in the Parental Control feature of TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 firmware. The root cause lies in improper input validation on the Parental Control page, allowing shell commands to be injected and executed with elevated privileges. The flaw resides specifically in the firmware component handling user inputs on the Parental Control management interface.
This vulnerability is a command injection flaw caused by improper input validation in N-able N-central. The root cause lies in the failure to sanitize user-supplied inputs in specific components, enabling crafted inputs to be interpreted as operating system commands. The affected component is the N-central management platform prior to version 2025.3.1, where input handling mechanisms do not adequately restrict command execution vectors.
This vulnerability is a command injection flaw rooted in insufficient input validation within the Trend Micro Apex One on-premise management console. The flaw allows unauthenticated remote attackers to upload and execute arbitrary code by exploiting the console's file upload handling mechanism. The affected component is the management console interface responsible for processing incoming requests without proper authentication checks or sanitization.
This vulnerability is an authentication bypass caused by improper validation in the Single Sign-On (SSO) authentication mechanism of Quest KACE Systems Management Appliance (SMA). The root cause lies in the flawed handling of authentication tokens or session states, allowing the system to incorrectly grant access without verifying legitimate credentials. The affected component is the SSO authentication handler across multiple SMA software versions prior to specified patch levels.
This vulnerability is a Cross-Site Scripting (XSS) flaw rooted in insufficient sanitization of HTML content within the Zimbra Classic UI. The issue arises from improper handling of crafted tag structures and attribute values that include @import directives and other script injection vectors. The affected component is the Classic UI rendering engine that processes email message content, failing to neutralize malicious JavaScript payloads embedded in email bodies.
This vulnerability is a logic flaw in the media processing component of Apple iOS and iPadOS, specifically when handling photos or videos shared via iCloud Link. The root cause lies in insufficient validation and improper processing logic for maliciously crafted media files, leading to incorrect handling of input data within the media parsing routines. This flaw affects the media handling subsystem across multiple Apple operating systems including iOS, iPadOS, macOS, visionOS, and watchOS.
This vulnerability is a use-after-free memory corruption occurring within the Adreno GPU driver component used by Qualcomm Snapdragon devices. The flaw arises from improper management of memory objects during graphics rendering operations in the Chrome environment, specifically related to the handling of GPU command buffers. The affected component is the Adreno GPU driver firmware across multiple Qualcomm firmware versions, leading to unsafe memory access conditions.
This vulnerability is an information disclosure flaw stemming from an exposed heap dump endpoint in the TeleMessage service's Spring Boot Actuator configuration. The root cause is the unsecured exposure of the /heapdump URI, which allows unauthenticated access to JVM heap memory dumps. The affected component is the Spring Boot Actuator's heap dump feature within TeleMessage service versions prior to 2025-05-05.
This vulnerability is a deserialization flaw in the SAP NetWeaver Visual Composer Metadata Uploader component. The root cause is improper validation and handling of serialized metadata content uploaded by privileged users, allowing untrusted or malicious data to be deserialized. This flaw affects the Visual Composer development server within SAP NetWeaver 7.5, specifically the metadata upload functionality that processes serialized input without sufficient integrity checks.
The vulnerability is an information exposure flaw caused by the TeleMessage archiving backend storing message data in cleartext form. This occurs within the backend component responsible for archiving messages from the TM SGNL (Archive Signal) application. The root cause is the backend's failure to apply end-to-end encryption to archived messages, contrary to the documented encryption claims.
This vulnerability is a server-side file injection issue rooted in improper handling of session data in Craft CMS. The system stores arbitrary content from unauthenticated users directly into session files located on the server without sanitization. The affected component is the session management mechanism that writes user-supplied return URLs into session files named with predictable patterns under '/var/lib/php/sessions'.
This vulnerability is a directory traversal flaw caused by improper sanitization of file path parameters in Srimax Output Messenger versions prior to 2.0.63. The affected component fails to correctly validate or normalize user-supplied input containing "../" sequences, allowing traversal outside the intended directory scope. This weakness resides in the file handling routines responsible for managing resource access within the messaging application.
This vulnerability is a ViewState code injection issue affecting ASP.NET Web Forms used by ConnectWise ScreenConnect versions 25.2.3 and earlier. The root cause lies in the reliance on ViewState, which encodes page and control state data in Base64 and protects it using machine keys. If an attacker obtains these machine keys, they can craft malicious ViewState payloads that the server deserializes, leading to code injection via the ViewState mechanism.