CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
HCL DFXAnalytics Internal File Path Disclosure Vulnerability
An internal file path disclosure vulnerability has been identified in HCL DFXAnalytics version 3.0 and below. This vulnerability arises because the application dashboard unintentionally reveals sensitive information about its internal file structure and directory paths. This leakage occurs through unhandled error messages, system logs, or debugging output. As a result, a remote attacker could potentially map the underlying server environment and identify targets for further exploitation.
HCL DFXAnalytics Buffer Overflow Vulnerability Leading to Denial-of-Service
A buffer overflow vulnerability has been identified in HCL DFXAnalytics version 3.0 and below, which can lead to a denial-of-service condition. The vulnerability arises because the application does not properly validate input sizes, allowing an attacker to send excessive data into a memory container. This overflow can cause the system to crash or become unresponsive.
HCL DFXAnalytics Deprecated Protocol Vulnerability Allowing Data Interception
A vulnerability exists in HCL DFXAnalytics versions through 3.0, related to the use of outdated TLS protocols 1.0 and 1.1. These legacy protocols are vulnerable to various cryptographic flaws, allowing for the interception and decryption of data. The issue arises because the application still supports these insecure protocols, exposing sensitive information to potential interception.
HCL DFXAnalytics Account Takeover Vulnerability via Response Manipulation
A vulnerability allowing account takeover through response manipulation has been identified in HCL DFXAnalytics versions 3.0 and below. This issue arises from the application's failure to properly secure HTTP responses, enabling remote attackers to intercept and modify response contents before they reach the client. By doing so, attackers can manipulate authentication or authorization processes, bypassing controls and gaining unauthorized access to user accounts.
HCL DFXAnalytics Missing HTTP Strict-Transport-Security Header Vulnerability
A vulnerability exists in HCL DFXAnalytics versions through 3.0, where the application does not implement the HTTP Strict Transport Security (HSTS) policy in its responses. This omission could enable a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP), potentially leading to man-in-the-middle (MitM) attacks.
HCL DFXAnalytics Missing SameSite Attribute Vulnerability Allowing Cross-Site Request Forgery
A vulnerability exists in HCL DFXAnalytics versions through 3.0, where the application does not set the 'SameSite' attribute on session cookies during authentication. This oversight could enable remote attackers to perform Cross-Site Request Forgery (CSRF) attacks, particularly if additional protections like Anti-CSRF tokens are not in place.
HCL DFXAnalytics Internal IP Address Disclosure Vulnerability
A vulnerability allowing internal IP address details to be included in server responses has been identified in HCL DFXAnalytics versions 3.0 and below. This internal IP address disclosure could enable remote attackers to gather sensitive network topology information, potentially mapping internal infrastructure for further targeted attacks.
HCL DFXAnalytics Login Replay Attack Vulnerability
A login replay attack vulnerability has been identified in HCL DFXAnalytics versions 3.0 and below. This vulnerability allows remote attackers to intercept, delay, or fraudulently retransmit valid authentication data, potentially leading to unauthorized access. The issue arises because the application does not include timestamps with authentication messages, allowing outdated messages to be accepted as valid.
HCL DFXAnalytics Missing Secure Attribute in SSL Cookie Vulnerability
A vulnerability exists in HCL DFXAnalytics versions 3.0 and below, where the application does not set the 'secure' attribute on session cookies during authentication. This oversight could enable remote attackers to intercept network traffic and capture sensitive cookies, session tokens, or credentials transmitted in cleartext over unencrypted channels.
Canonical Ubuntu Pro Client Information Disclosure Vulnerability
A vulnerability allowing information disclosure exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). This issue arises because the client validates Ubuntu Pro APT credentials by executing a command that embeds the secret bearer token directly into the cleartext URL of the command-line arguments. On systems with a default-mounted /proc file system and no process-hiding mitigations, an unprivileged local attacker can read the sensitive token from the process command line of the running helper process. This leaked token could then be used to access the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories without authorization.
Stoatchat Unauthenticated Server-Side Request Forgery Vulnerability in January Proxy and Embed Endpoints
A server-side request forgery (SSRF) vulnerability has been identified in Stoatchat versions prior to 0.13.5. The vulnerability exists in the January service's /proxy and /embed endpoints, which accept arbitrary URLs from unauthenticated users without proper validation. This lack of filtering allows attackers to enumerate internal services, fingerprint applications, and access instance metadata endpoints in cloud environments by supplying malicious URLs or exploiting redirect chains to reach internal infrastructure.
AVideo OS Command Injection Vulnerability in FFmpeg JSON Endpoint
A command injection vulnerability has been identified in AVideo versions through 29.0, specifically within the FFmpeg JSON endpoint. The issue arises because the notifyCode and callback parameters are concatenated into a shell command without proper escaping. This flaw allows attackers who can create a valid encrypted payload to inject arbitrary shell metacharacters, executing OS commands as the web server user.
AVideo OS Command Injection Vulnerability in FFmpeg Process Management
A command injection vulnerability has been identified in AVideo versions through 29.0. The issue resides in the 'plugin/API/standAlone/functions.php' file, specifically within the 'listFFmpegProcesses()' function. This function improperly handles keyword parameters by interpolating them into a shell command without proper sanitization or escaping. As a result, attackers can craft encrypted payloads to break out of the single-quoted context and execute arbitrary commands on the server as the web server user.
Canonical Ubuntu Pro Client Insecure Symlink Vulnerability in Log Collection Command
A vulnerability allowing insecure symlink following has been identified in Canonical Ubuntu Pro Client (formerly Ubuntu Advantage Tools) within the 'pro collect-logs' command framework. This issue arises because the utility creates or uses predictable temporary file paths or user-accessible log directories for gathering diagnostic information, without verifying the file type or ownership. An unprivileged local attacker can exploit this by creating a symbolic link at a predictable destination that points to an arbitrary, root-readable file, such as '/etc/shadow' or private files in '/root'. When a root administrator executes the 'pro collect-logs' command, the tool follows the symlink, reads the target file, and compresses its contents into a diagnostic support archive. Since the output archive is accessible to the unprivileged user, the attacker can extract and read the sensitive root-owned files, resulting in complete information disclosure of system secrets.
Canonical Ubuntu Pro Client Input Validation and Injection Vulnerability Allowing Arbitrary Code Execution
A vulnerability allowing input validation and injection has been identified in Canonical Ubuntu Pro Client (formerly Ubuntu Advantage Tools). This issue arises because the client creates APT source files using data from the contract server response, specifically the directives.suites[] and directives.aptURL fields. The client employs Python's str.format() method to generate these files without proper escaping, validation, or filtering of newline characters. As a result, a malicious or altered contract response containing embedded newline characters can inject arbitrary, attacker-controlled Debian configuration lines into root-owned APT sources. When this vulnerability is exploited in conjunction with the unvalidated additionalPackages[] field— which is directly passed to a root-executed apt-get install command—an attacker who can manipulate the contract response can force the client to download and install malicious packages. This chain of events ultimately leads to arbitrary code execution with root privileges on the affected system. This vulnerability affects all supported Ubuntu Server releases and is automatically included by default on cloud provider Ubuntu Pro images.
Stoatchat Webhook Token Disclosure Vulnerability Allowing Unauthorized Message Sending
A vulnerability in Stoatchat (Delta/Revolt) versions 20241213-1 prior to 20250210-1 allows users with only ViewChannel (read) permission to access a channel's webhooks and tokens. This issue arises because the webhook fetch endpoint verified ViewChannel instead of ManageWebhooks. An attacker could use the retrieved token to send arbitrary messages to the channel, bypassing permissions and impersonating a bot or webhook.
stoatchat Delta Logic Error in Message Query Route Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in stoatchat (delta) versions prior to 20250210-1 (0.8.2). The issue arises from a logic error in the query messages route, where a message limit of zero is interpreted by the database as 'no limit'. This flaw allows a remote unauthenticated attacker to craft requests that download an entire channel's message history in a single, resource-intensive request. Additionally, attackers can send multiple such requests in parallel, causing significant resource exhaustion.
Stoatchat Unrestricted Account Creation Vulnerability
A vulnerability exists in Stoatchat versions prior to 0.7.8, allowing unrestricted account creation. The application fails to enforce essential account creation protocols such as invite-only mode, email verification, captcha, and shield verification. This oversight enables attackers to generate an unlimited number of accounts using unverified email addresses, which could lead to increased denial-of-service risks and undermine the integrity of the service.
Elixir Mint HTTP Response Smuggling Vulnerability
A vulnerability allowing HTTP response smuggling has been identified in the Elixir Mint library, specifically in versions 0.1.0 prior to 1.9.3. This issue arises from an inconsistent interpretation of HTTP chunked transfer encoding, where the Mint HTTP/1 client accepts sign-prefixed chunk sizes that are rejected by strict intermediaries. Exploitation of this vulnerability can lead to desynchronization between the client and intermediary, allowing for response-queue poisoning on pooled connections.
HCL DFXServer Authentication Bypass Vulnerability via Server Response Manipulation
An authentication bypass vulnerability has been identified in HCL DFXServer versions 2.5 and below. This vulnerability allows unauthorized users to gain access to the application by intercepting and altering the server's authentication responses, thereby bypassing the need for valid credentials.
HCL DFXServer Missing Access Control Vulnerability
A missing access control vulnerability has been identified in HCL DFXServer versions 2.5 and below. Certain endpoints can be accessed without authentication, allowing any network user to invoke these APIs and interact with the application without verifying their identity or authorization level.
HCL DFXServer Broken Authentication Vulnerability via Direct API Access
A broken authentication vulnerability has been identified in HCL DFXServer versions 2.5 and below. This vulnerability allows unauthenticated attackers to access specific API endpoints without valid credentials. The application fails to properly verify user authentication status, enabling unauthorized interactions with the APIs and the execution of unauthorized actions.
HCL DFXServer Unencrypted Communication Vulnerability
A vulnerability allowing unencrypted communication has been identified in HCL DFXServer versions 2.5 and below. The application allows users to connect over unencrypted HTTP channels, potentially enabling remote attackers to intercept network traffic and access sensitive data exchanged between users and the application.
X-Rite Spectrophotometer Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the X-Rite MA-T6 Kohinoor firmware versions prior to v2.33. This issue arises from improper sanitization of user input in the SetParameter command, allowing unauthenticated remote attackers to execute arbitrary code.
X-Rite Spectrophotometer Unauthorized Command Execution Vulnerability
A vulnerability in the X-Rite MA-T6 Kohinoor spectrophotometer firmware, prior to version 2.33, allows unauthenticated remote attackers to execute arbitrary commands on the affected device. This issue arises from inadequate verification of the origin of communication channels, leading to unauthorized access control.
Spring Security Authorization Server Authentication Bypass Vulnerability Allowing Privilege Escalation and XSS
A vulnerability in Spring Security Authorization Server's Dynamic Client Registration endpoints allows for authentication bypass by primary weakness. This issue arises from insufficient validation of client metadata fields when dynamic registration is enabled. An attacker with a valid Initial Access Token could register a malicious client with crafted metadata, potentially leading to Stored Cross-Site Scripting (XSS), Privilege Escalation, or Server-Side Request Forgery (SSRF). The vulnerability affects Spring Authorization Server versions 7.0.0 through 7.0.4, 1.5.0 through 1.5.6, 1.4.0 through 1.4.9, and 1.3.0 through 1.3.10.
Breakdance WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Breakdance plugin for WordPress, affecting versions through 2.7.1. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the 'fields' parameter. These scripts execute when a user accesses the compromised page.
ESET Linux Products Use-After-Free Vulnerability Leading to Kernel Panic
A use-after-free vulnerability has been identified in ESET security products for Linux, including ESET Endpoint Antivirus for Linux and ESET Server Security for Linux. This vulnerability potentially allows an attacker to trigger a kernel panic, causing a denial-of-service condition on the system. The issue arises when an attacker exploits specific timing to access memory pages that are no longer in use, leading to a system crash.
ESET Inspect Connector Local Privilege Escalation Vulnerability
A local privilege escalation vulnerability has been identified in ESET Inspect Connector for Windows, specifically in version 3.0.5775.0 and earlier. The vulnerability arises from improper authentication in an inter-process communication (IPC) channel, allowing an attacker to send crafted Advanced Local Procedure Call (ALPC) requests to the vulnerable process. Without adequate authentication or origin validation, these requests could be accepted and processed, granting access to restricted functionalities.
ThemeXpert Quix Page Builder Unauthenticated SQL Injection Vulnerability
A vulnerability allowing unauthenticated SQL injection has been identified in the Quix Page Builder Pro extension for Joomla. This issue is present in version 6.2.0 and all prior releases. The vulnerability arises from a front-end AJAX endpoint that processes article IDs from anonymous requests. The endpoint fails to properly sanitize the IDs before using them in database queries, allowing an anonymous visitor to manipulate the input and extract data from any database table. This includes sensitive information such as user accounts, password hashes, and other Joomla API secrets. The vulnerability has been confirmed to allow complete database read access through error-based SQL injection, where the database error messages are reflected back to the attacker, facilitating data extraction.
WP Bulk Delete WordPress Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WP Bulk Delete plugin for WordPress, affecting all versions up to and including 1.4.2. The vulnerability arises from inadequate escaping of user-supplied data in the 'delete_user_roles' parameter, allowing authenticated attackers with administrator-level access to inject additional SQL queries. This could be exploited to extract sensitive information from the database. The issue is exacerbated by the use of wp_unslash() on the raw POST data, which removes WordPress's magic quotes protection, leaving the injected values unescaped before they are processed by the SQL query.
WP TripAdvisor Review Slider SQL Injection Vulnerability in WordPress
A SQL injection vulnerability has been identified in the WP TripAdvisor Review Slider plugin for WordPress, affecting all versions through 14.6. The vulnerability arises from inadequate escaping of user-supplied data in the 'filtersource' parameter, allowing authenticated attackers with administrator-level access to manipulate SQL queries. Exploitation of this vulnerability could lead to unauthorized access to sensitive information in the database.
WPBot AI ChatBot for Live Support Authorization Bypass Vulnerability
A vulnerability allowing authorization bypass has been identified in the WPBot - AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress. This issue affects all versions through 8.5.6. The vulnerability arises because the plugin fails to properly verify user authorization for certain actions. As a result, authenticated attackers with subscriber-level access or higher can exploit this flaw to trigger unauthorized re-embedding of stored RAG documents. This exploitation modifies the rag_documents database table and misuses the site owner's paid third-party AI API credits, specifically for OpenAI, Gemini, OpenRouter, or xAI.
Themify Builder WordPress Plugin Authorization Bypass Vulnerability Allowing Arbitrary Stylesheet Modification
A vulnerability exists in the Themify Builder plugin for WordPress, allowing authorization bypass in all versions up to and including 7.7.7. The issue arises because the plugin fails to properly verify user authorization for certain actions. This flaw enables authenticated attackers with subscriber-level access or higher to overwrite or delete the CSS stylesheet files of arbitrary posts, including private and draft posts belonging to other users. Additionally, the vulnerability allows modification of font options within the plugin's scope. The required CSRF nonce, 'tf_nonce', is easily accessible to any authenticated user on public front-end builder pages.
The Cache Purger WordPress Plugin Authorization Bypass Vulnerability Allowing Log Deletion
A vulnerability exists in The Cache Purger plugin for WordPress, affecting all versions up to and including 2.3.20. The issue stems from the plugin's failure to properly verify user authorization, allowing authenticated users with subscriber-level access and above to bypass authorization and delete log entries. This is achieved by exploiting the 'the_log_purge' parameter, which is accessible through a nonce that is inadvertently made available to all authenticated users via the admin bar.
SysBasics Customize My Account for WooCommerce Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the SysBasics Customize My Account for WooCommerce plugin, specifically in versions through 4.4.14. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with shop manager-level access or higher to inject arbitrary scripts. These scripts are executed when a user accesses the affected page.
WPBot WordPress Plugin Authorization Bypass Vulnerability Allowing Unauthenticated Deletion of Chat Sessions
A vulnerability exists in the WPBot - AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress, in all versions up to and including 8.5.6. The issue stems from the plugin's failure to properly verify user authorization, allowing unauthenticated attackers to delete arbitrary chat session records from the wpbot_user and wpbot_conversation database tables. This deletion includes chat histories and conversation logs, which can be exploited by supplying a crafted userid value.
WPFunnels Privilege Escalation Vulnerability in WordPress WooCommerce Plugin
A privilege escalation vulnerability has been identified in the WPFunnels plugin for WordPress, specifically in versions through 3.12.8. The issue arises in the 'update_settings()' REST callback, which fails to properly validate the 'group_id' path parameter against an allowlist of permitted option names. This oversight allows authenticated attackers with the 'wpf_manage_funnels' capability to target the 'wp_user_roles' option. By crafting a specific role definition and injecting it into the 'wp_user_roles' option, attackers can elevate their privileges to administrator level, granting full site access. The 'wpf_manage_funnels' capability is typically assigned to the Funnel Manager role, making this the minimum requirement for exploitation.
Delicious Recipes WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Delicious Recipes plugin for WordPress, affecting versions through 1.10.2. The issue arises from inadequate input sanitization and output escaping in the 'wrap_direction_text' function, which directly incorporates user-supplied href values from nested link nodes into an anchor tag without proper URL validation. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts, including JavaScript, into pages. The injected scripts execute when a user, such as an editor or administrator previewing a pending post, clicks on the malicious link.
Tutor LMS SQL Injection Vulnerability via Stored Quiz Answers
A SQL injection vulnerability has been identified in the Tutor LMS WordPress plugin, specifically in versions through 4.0.0. The issue arises from inadequate escaping of user-supplied data in the quiz answer array, allowing authenticated attackers with custom-level access or higher to inject malicious SQL. This injected SQL could be appended to existing queries, potentially leading to the extraction of sensitive database information. The vulnerability is exploited by sending a payload during the quiz attempt, which is then executed when a privileged user or Tutor REST API key holder accesses the quiz attempt details endpoint, creating a second-order injection scenario.
wpForo Forum Stored Cross-Site Scripting Vulnerability in 'location' Profile Field
A stored cross-site scripting vulnerability has been identified in the wpForo Forum plugin for WordPress, affecting all versions through 3.1.1. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with subscriber-level access or higher to inject arbitrary scripts into pages. These scripts execute when users access the compromised pages. The vulnerability exploits the 'location' profile field, where the sanitize_text_field() function fails to properly encode double quotes, enabling attribute breakout and the injection of event handler attributes.
Uncanny Automator WordPress Plugin Arbitrary File Deletion Vulnerability
A vulnerability allowing arbitrary file deletion has been identified in the Uncanny Automator WordPress plugin, specifically in versions through 7.3.1.4. This issue arises from inadequate file path validation in the 'fr_token' function, enabling unauthenticated attackers to delete arbitrary files on the server. Exploitation of this vulnerability could lead to remote code execution, particularly if sensitive files like 'wp-config.php' are targeted. The vulnerability can be exploited by submitting a malicious serialized payload through an unauthenticated Forminator form connected to an Uncanny Automator recipe set for 'Everyone'.
Loco Translate Cross-Site Request Forgery Vulnerability Allowing Remote Code Execution
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Loco Translate plugin for WordPress, affecting all versions through 2.8.5. The issue arises from inadequate nonce validation in the 'execTemplate' function, enabling unauthenticated attackers to execute arbitrary PHP code on the server. Exploitation involves sending a forged request with a 'template' parameter that includes a php://filter stream wrapper URI, bypassing path validation. This crafted request can trick a site administrator into inadvertently executing the malicious code.
Quiz Master Next WordPress Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the Quiz Master Next WordPress plugin, affecting versions through 11.2.0. The issue arises from inadequate escaping of the user-supplied 'pages' parameter in the qsm_ajax_save_pages() AJAX handler, which only applies basic sanitization. Additionally, the SQL query in qsm_options_questions_tab_content() at line 143 fails to properly prepare the interpolated page IDs before executing the query. This vulnerability allows authenticated attackers with Author-level access or higher to inject SQL payloads that are executed second-order when the quiz's Questions tab is viewed, potentially leading to unauthorized access to sensitive database information.
Tickera WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Tickera WordPress plugin, specifically in versions up to and including 3.6.0.0. The issue arises from inadequate input sanitization and output escaping in the 'price_wrapper' shortcode attribute. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages. The injected scripts are executed when a user accesses the page, but only if the corresponding ticket ID is present in their cart cookie.
Tickera WordPress Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the Tickera – Sell Tickets & Manage Events plugin for WordPress, affecting all versions through 3.6.0.0. The vulnerability arises from inadequate escaping of user-supplied data in the 's' parameter, allowing authenticated attackers with custom-level access or higher to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information in the database.
Digits WordPress Plugin Privilege Escalation Vulnerability
A privilege escalation vulnerability has been identified in the Digits: WordPress Mobile Number Signup and Login plugin, affecting all versions through 9.1.0.5. The issue arises from inadequate authorization and role validation in the 'dig_update_wpwc_custom_fields()' function. This vulnerability allows authenticated attackers with Subscriber-level access or higher to escalate their privileges to Administrator by submitting a fake 'digits_reg_userrole' value during profile updates, provided the site administrator has enabled the DIGITS User Role field.
Snowflake Connector for Python Improper TLS Hostname Verification Vulnerability
A vulnerability exists in Snowflake Connector for Python in versions prior to 4.7.1, where improper TLS hostname verification may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections. This flaw could be exploited by intercepting or redirecting network traffic and presenting a certificate signed by any trusted Certificate Authority for any domain. As a result, the connector could accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires on-path traffic interception capabilities, such as ARP or DNS poisoning, a rogue access point, BGP hijacking, or through a malicious proxy or exit node. This vulnerability could have exposed credentials, query data, and staged file contents to interception and tampering, and may have allowed the attacker to execute arbitrary SQL within the context of the victim's connector session, limited by the privileges of the affected Snowflake role.
FunnelKit WordPress Plugin Path Traversal Vulnerability Allowing Arbitrary File Deletion
A vulnerability exists in the FunnelKit WordPress plugin in versions prior to 3.15.0.6. The issue arises because the plugin does not properly validate user-supplied file paths before deleting files during a template import process. This flaw enables users with administrator privileges to exploit path traversal to delete arbitrary .json files outside the designated directory. Such actions can disrupt the functionality of other FunnelKit components or WordPress plugins, leading to a denial-of-service condition.
FunnelKit WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the FunnelKit WordPress plugin, affecting versions prior to 3.15.0.6. The issue arises because the plugin fails to properly escape user-supplied parameters before including them in the HTML response of a page-builder AJAX action. This flaw allows unauthenticated attackers to execute scripts that are reflected back to logged-in users who visit a manipulated page. The vulnerability is only present when the Divi builder is active.
