CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 11, 2025

Coupon X WordPress Plugin PHP Object Injection Vulnerability

A PHP Object Injection vulnerability has been identified in the Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress, affecting all versions through 1.3.5. The vulnerability arises from the deserialization of untrusted input in post content, which is sent to the capture_email AJAX action. This flaw allows authenticated attackers with Contributor-level access and above to inject PHP objects. While the vulnerable plugin does not have a known proof of concept chain, such a chain could potentially exist through an additional plugin or theme, allowing the attacker to delete files, access sensitive information, or execute code.

2.9
Jan 11, 2025

Trackserver WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Trackserver plugin for WordPress, affecting all versions through 5.0.2. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'tsmap' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access those pages.

2.7
Jan 11, 2025

Post Duplicator WordPress Plugin Information Exposure Vulnerability

A vulnerability allowing information exposure has been identified in the Post Duplicator plugin for WordPress, affecting all versions through 2.36. The issue arises in the mtphr_duplicate_post() function, where inadequate restrictions allow authenticated attackers with Contributor-level access and above to duplicate posts and access data from password-protected, private, or draft posts that should be off-limits.

3.3
Jan 11, 2025

CF Internal Link Shortcode WordPress Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the CF Internal Link Shortcode plugin for WordPress, affecting all versions through 1.1.0. The issue arises from inadequate escaping of user-supplied data in the 'post_title' parameter, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information within the database.

3.6
Jan 11, 2025

Coupon X WordPress Plugin Missing Authorization Vulnerability

A vulnerability exists in the Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress, in all versions through 1.3.5. The issue arises from inadequate capability checks in the class-cx-rest.php file, allowing authenticated attackers with Subscriber-level access or higher to gain unauthorized privileges. Exploitation of this vulnerability enables the creation of 100% off coupons, deletion of posts and leads, and modification of coupon statuses.

2.3
Jan 11, 2025

ClickWhale WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the ClickWhale WordPress plugin, specifically in the Link Manager, Link Shortener, and Click Tracker for Affiliate Links & Link Pages components, all versions through 2.4.1. The vulnerability arises from improper handling of URL parameters using add_query_arg and remove_query_arg, which allows unauthenticated attackers to inject arbitrary scripts. These scripts can execute if a user is tricked into clicking a link.

3.0
Jan 10, 2025

REDCap Cross-Site Request Forgery Vulnerability in Alert Title Handling

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in REDCap version 14.9.6. The issue arises when uploading a CSV file that includes a list of alert configurations. An attacker could craft a CSV file with an HTML injection payload in the alert title. Once the victim uploads this file, they are directed to a page displaying the uploaded data. If the victim clicks on the alert title, it can either trigger a logout request, terminating their session, or redirect them to a phishing website. This vulnerability exists due to the lack of CSRF protections on the logout functionality.

2.8
Jan 10, 2025

REDCap Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in REDCap version 14.9.6. This issue allows authenticated users to inject malicious scripts into the Survey field name. When a recipient of the survey clicks on the field name, the injected script is executed.

2.4
Jan 10, 2025

REDCap HTML Injection Vulnerability Allowing Phishing Redirection

A vulnerability allowing HTML injection has been identified in REDCap version 14.9.6. This issue arises in the Survey field name, where an attacker can inject malicious HTML that redirects users to a phishing website. When the survey recipient clicks on the field name, they are taken to the phishing site, potentially leading to unauthorized actions being performed without the user's consent.

2.8
Jan 10, 2025

REDCap Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in REDCap version 14.9.6. The issue arises in the email-subject field when a CSV file containing a list of alert configurations is uploaded. An attacker can craft a CSV file with an XSS payload embedded in the email-subject. When the victim uploads this file, they are directed to a page displaying the uploaded data. Clicking on the email-subject value activates the XSS payload.

2.8
Jan 10, 2025

Arista NG Firewall Cross-Site Scripting Vulnerability Leaking Administrator Tokens

A cross-site scripting vulnerability has been identified in Arista Edge Threat Management - Arista NG Firewall, specifically in versions through 17.1.1. This vulnerability allows specially crafted queries to leak administrator authentication tokens. The issue arises from improper handling of query data, which can be exploited to access sensitive token information.

2.9
Jan 10, 2025

Arista Reporting Application SQL Injection Vulnerability Allowing Elevated OS Command Execution

Multiple SQL injection vulnerabilities have been identified in the Arista reporting application. A user with advanced reporting application access can exploit these vulnerabilities to execute commands on the underlying operating system with elevated privileges.

1.9
Jan 10, 2025

Arista NG Firewall Authentication Token Retrieval Vulnerability

A vulnerability exists in Arista Edge Threat Management - Arista NG Firewall, affecting versions through 17.1.1. A user with administrator privileges can retrieve authentication tokens, potentially leading to unauthorized access or actions within the application.

1.5
Jan 10, 2025

Arista NG Firewall Insecure Captive Portal Configuration Vulnerability

A vulnerability exists in Arista Edge Threat Management - Arista NG Firewall, all versions through 17.1.1, allowing administrators to configure an insecure captive portal script. This issue can be exploited by selecting the 'Custom' option in the Captive Page tab, potentially leading to unauthorized actions or information exposure.

2.0
Jan 10, 2025

Arista NG Firewall Command Injection Vulnerability

A command injection vulnerability has been identified in Arista Edge Threat Management - Arista NG Firewall, affecting versions through 17.1.1. This vulnerability allows users with administrator privileges to execute arbitrary commands on the underlying operating system.

1.7
Jan 10, 2025

Arista CloudVision Appliance Disk Encryption Vulnerability on DCA-350E-CV Releases

A vulnerability exists in certain Arista CloudVision Appliance (CVA) releases on DCA-350E-CV appliances, where hardware disk encryption may not be properly applied. This flaw leaves the disks unencrypted, exposing the data stored on them.

0.9
Jan 10, 2025

Arista NG Firewall Unauthorized Actions Vulnerability in Reporting Application

A vulnerability exists in Arista NG Firewall in versions through 17.1.1, allowing users with advanced report application access to perform unauthorized actions. This issue is linked to improper isolation or compartmentalization, enabling exploitation of SQL injection vulnerabilities in the reporting application. As a result, affected users could execute commands on the underlying operating system with elevated privileges.

2.1
Jan 10, 2025

Arista Edge Threat Management Backup Uploads Vulnerable to Man-in-the-Middle Interception

A vulnerability exists in Arista Edge Threat Management (ETM) Backup uploads to the Arista NG Firewall (NGFW) that allows for man-in-the-middle interception. This issue affects all NGFW versions through 17.1.1. When the Configuration Backup service is enabled, backups can be intercepted during the upload process to ETM.

2.3
Jan 10, 2025

Arista Edge Threat Management Remote Access Session Discovery Vulnerability

A vulnerability exists in Arista Edge Threat Management (ETM) for the Arista NG Firewall (NGFW) in versions through 17.1.1. This vulnerability allows specially crafted queries to discover active remote access sessions. The issue arises from expired and unusable administrator authentication tokens being revealed by units that have timed out from ETM access, creating a potential avenue for exploitation.

1.9
Jan 10, 2025

Arista Edge Threat Management NG Firewall Expired Token Disclosure Vulnerability

A vulnerability exists in Arista Edge Threat Management (ETM) units that have timed out from ETM access, allowing the revelation of expired and unusable administrator authentication tokens. This issue affects Arista NG Firewall (NGFW) versions 17.1.1 and prior.

1.8
Jan 10, 2025

Arista EOS SNMP Memory Leak Vulnerability in snmpd Process

A memory leak vulnerability has been identified in the snmpd process of Arista EOS platforms with SNMP enabled. When the 'snmp-server transmit max-size' option is configured, a specially crafted packet can cause the snmpd process to consume excessive memory. This may lead to the snmpd process being terminated, causing SNMP request timeouts until snmpd is manually restarted. The increased memory usage can also affect other processes on the switch, potentially leading to their unexpected termination.

1.7
Jan 10, 2025

Arista EOS VLAN Tag Vulnerability Leading to Control Plane Disruptions

A vulnerability exists in Arista EOS on certain platforms, where a specially crafted packet with an incorrect VLAN tag can be mistakenly sent to the CPU. This misrouting may disrupt normal control plane operations, potentially causing issues such as route flaps or incorrect handling of multicast routes.

3.8
Jan 10, 2025

MonicaHQ Client-Side Injection Vulnerability Leading to Stored Cross-Site Scripting

A client-side injection vulnerability has been identified in MonicaHQ version 4.1.2. This authenticated vulnerability allows attackers to inject malicious code into the 'reason' parameter of the 'Add Debt' form, located at '/people/h:[id]/debts/create'. The injected code can lead to stored cross-site scripting (XSS) attacks.

3.2
Jan 10, 2025

MonicaHQ Client-Side Injection Vulnerability in Journal Entry Editing

A client-side injection vulnerability has been identified in MonicaHQ version 4.1.1. This vulnerability allows authenticated users to inject malicious content through the entry text field while editing journal entries.

3.2
Jan 10, 2025

MonicaHQ Client-Side Template Injection Vulnerability Leading to Stored Cross-Site Scripting

A Client-Side Template Injection vulnerability has been identified in MonicaHQ version 4.1.2. This vulnerability allows authenticated attackers to inject malicious code into the title and description fields of the reminders creation form. The issue is located in the '/people/ID/reminders/create' endpoint.

3.2
Jan 10, 2025

MonicaHQ Client-Side Injection Vulnerability in Relationship Management Feature

Multiple client-side injection vulnerabilities have been identified in MonicaHQ version 4.1.2. These vulnerabilities arise in the 'Add a new relationship' feature, specifically through the 'first_name' and 'last_name' parameters.

3.7
Jan 10, 2025

Microweber Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in Microweber versions through 2.0.9. This vulnerability allows remote attackers to execute arbitrary JavaScript code by injecting it into the First Name or Last Name fields within the user management module. The injected script is executed when the user module view is accessed.

3.3
Jan 10, 2025

Microweber Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in Microweber versions through 2.0.9. This vulnerability allows remote attackers to execute arbitrary JavaScript code by exploiting the 'create new backup' function within the admin backup module.

3.3
Jan 10, 2025

Microweber Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in Microweber versions through 2.0.9. This vulnerability allows remote attackers to execute arbitrary JavaScript code by injecting it into the campaign Name field within the 'Add new campaign' function. The injected script is executed when the campaign list is viewed or when adding a new subscriber.

3.3
Jan 10, 2025

Netgear DGN1000 and DGN2200 v1 Authentication Bypass Vulnerability Allowing Unauthenticated Remote Code Execution

An authentication bypass vulnerability has been identified in the Netgear DGN1000 router, affecting firmware versions prior to 1.1.00.48, as well as the DGN2200 v1 model. This vulnerability allows remote, unauthenticated attackers to execute arbitrary operating system commands with root privileges by sending crafted HTTP requests to the setup.cgi endpoint. The embedded web server bypasses authentication checks for certain URLs, enabling exploitation. This vulnerability has been actively exploited since 2017.

6.7
Jan 10, 2025

Wikimedia Foundation MediaWiki ArticleFeedbackv5 Extension Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the Wikimedia Foundation MediaWiki ArticleFeedbackv5 extension, specifically in versions 1.42.X prior to 1.42.2. This vulnerability arises from improper input sanitization during web page generation, allowing malicious users to inject harmful scripts that could be executed in the context of the user's browser.

3.4
Jan 10, 2025

Hasleo Backup Suite Free Insecure Permissions Vulnerability Allowing Privilege Escalation

A vulnerability exists in Hasleo Backup Suite Free versions through 4.9.4, allowing insecure permissions via the file recovery function. This flaw can be exploited by low-privileged users to perform arbitrary file writes, potentially overwriting critical system files or placing malicious executables in sensitive directories. Such actions could lead to unauthorized administrative access on the Windows system.

2.5
Jan 10, 2025

Wikimedia MediaWiki Breadcrumbs2 Extension Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the Wikimedia Foundation MediaWiki Breadcrumbs2 extension. This issue affects versions 1.39.X prior to 1.39.11, 1.41.X prior to 1.41.5, and 1.42.X prior to 1.42.4. The vulnerability arises from improper input sanitization during web page generation, allowing malicious users to inject scripts that could be executed in the context of the user's browser.

3.4
Jan 10, 2025

MegaBIP Path Disclosure Vulnerability in Administrative Portal

A path disclosure vulnerability has been identified in MegaBIP software versions prior to 5.15. During the installation process, users are advised to change the default administrative portal path, as keeping it secret is recommended for protection. However, the publicly available source code of '/registered.php' reveals this path, potentially allowing attackers to conduct further attacks.

1.5
Jan 10, 2025

MegaBIP Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in MegaBIP versions prior to 5.15. The issue arises because the form located at '/edytor/index.php?id=7,7,0' lacks proper protection against CSRF attacks. This vulnerability could be exploited by tricking a user into visiting a malicious website that sends a POST request to the vulnerable endpoint. If the user is a logged-in administrator, this could result in the unauthorized creation of new accounts with administrative privileges.

1.5
Jan 10, 2025

Linksys E7350 Command Injection Vulnerability in Vif_Disable Function

A command injection vulnerability has been identified in the Linksys E7350 router, specifically in firmware version 1.1.00.032. The issue arises in the '/usr/lib/lua/luci/controller/mtkwifi.lua' file within the 'vif_disable' function, where the 'iface' parameter can be manipulated to inject and execute arbitrary commands.

3.2
Jan 10, 2025

Linksys E7350 Command Injection Vulnerability in WPS Function

A command injection vulnerability has been identified in the Linksys E7350 router, specifically in version 1.1.00.032. The issue arises in the 'apcli_do_enr_pbc_wps' function, where the 'ifname' parameter is vulnerable to injection attacks.

4.3
Jan 10, 2025

Linksys E7350 Command Injection Vulnerability in Vif_Enable Function

A command injection vulnerability has been identified in the Linksys E7350 router, specifically in firmware version 1.1.00.032. The issue arises in the 'vif_enable' function within the '/usr/lib/lua/luci/controller/mtkwifi.lua' file, where the 'iface' parameter can be manipulated to execute arbitrary commands.

3.0
Jan 10, 2025

Linksys E7350 Command Injection Vulnerability in reset_wifi Function

A command injection vulnerability has been identified in the Linksys E7350 router, specifically in version 1.1.00.032. The issue arises in the reset_wifi function, where the devname parameter is vulnerable to injection attacks.

4.3
Jan 10, 2025

Linksys E7350 Command Injection Vulnerability in WPS PIN Management Function

A command injection vulnerability has been identified in the Linksys E7350 router, specifically in firmware version 1.1.00.032. The issue arises in the 'apcli_do_enr_pin_wps' function within the '/usr/lib/lua/luci/controller/mtkwifi.lua' file. The vulnerability is triggered through the 'ifname' parameter, allowing injected commands to be executed on the device.

2.7
Jan 10, 2025

Linksys E7350 Command Injection Vulnerability in WPS Pin Generation Function

A command injection vulnerability has been identified in the Linksys E7350 router, specifically in firmware version 1.1.00.032. The issue arises in the 'apcli_wps_gen_pincode' function within the '/usr/lib/lua/luci/controller/mtkwifi.lua' file. The vulnerability is triggered through the 'ifname' parameter, allowing injected commands to be executed on the device.

3.2
Jan 10, 2025

Linksys E7350 Command Injection Vulnerability in WPS Cancellation Function

A command injection vulnerability has been identified in the Linksys E7350 router, specifically in version 1.1.00.032. The issue arises in the 'apcli_cancel_wps' function, where the 'ifname' parameter is vulnerable to injection attacks.

4.3
Jan 10, 2025

Vtiger CRM Cross-Site Scripting Vulnerability in Documents Module

A cross-site scripting (XSS) vulnerability has been identified in Vtiger CRM versions through 6.1. The issue arises in the Documents module, specifically within the uploadAndSaveFile function of CRMEntity.php.

5.0
Jan 10, 2025

TOTOLINK A6000R Command Injection Vulnerability in reset_wifi Function

A command injection vulnerability has been identified in the TOTOLINK A6000R router, specifically in firmware version V1.0.1-B20201211.2000. The vulnerability arises in the reset_wifi function, where the devname parameter can be manipulated to inject and execute arbitrary commands on the device.

3.1
Jan 10, 2025

TOTOLINK A6000R Command Injection Vulnerability in Password Change Function

A command injection vulnerability has been identified in the TOTOLINK A6000R router, specifically in version 1.0.1-B20201211.2000. The issue arises in the action_passwd function, where the newpasswd parameter is improperly sanitized, allowing attackers to inject and execute arbitrary commands.

4.4
Jan 10, 2025

TOTOLINK A6000R Command Injection Vulnerability in the Reboot Action

A command injection vulnerability has been identified in the TOTOLINK A6000R router, specifically in firmware version V1.0.1-B20201211.2000. The vulnerability arises in the 'action_reboot' function within the '/usr/lib/lua/luci/controller/admin/system.lua' file. It allows for arbitrary command execution by injecting commands through the 'opmode' parameter when the reboot action is called.

3.0
Jan 10, 2025

TOTOLINK A6000R Command Injection Vulnerability in WSH Enable Function

A command injection vulnerability has been identified in the TOTOLINK A6000R router, specifically in firmware version V1.0.1-B20201211.2000. The vulnerability arises in the 'enable_wsh' function within the 'system.lua' file, where the 'modifyOne' parameter can be exploited to inject arbitrary commands.

3.1
Jan 10, 2025

CP Plus CP-VNR-3104 Timing Attack Vulnerability Allowing Private Key Extraction and Man-in-the-Middle Access

A vulnerability exists in the CP Plus CP-VNR-3104 model, specifically in the firmware version B3223P22C02424. This issue allows attackers to exploit a timing discrepancy in the device's encryption process, particularly within the Elliptic Curve mathematics library. By observing the timing of multiple deterministic ECDSA signature generations, an attacker can extract the second RSA private key. This key extraction could lead to unauthorized access to sensitive information or facilitate a man-in-the-middle attack.

2.8
Jan 10, 2025

CP Plus CP-VNR-3104 Improper Certificate Handling Vulnerability Allowing Decryption and Man-in-the-Middle Attacks

A vulnerability in the CP Plus CP-VNR-3104 model, specifically in the B3223P22C02424 version, arises from improper management and storage of certificates. This flaw enables attackers to decrypt communications or conduct man-in-the-middle attacks, intercepting and potentially altering the communication between two parties.

2.8
Jan 10, 2025

CP Plus CP-VNR-3104 Diffie-Hellman Parameter Exposure Vulnerability

A vulnerability in the CP Plus CP-VNR-3104 model allows attackers to access the Diffie-Hellman (DH) parameters, potentially leading to the exposure of sensitive data or the execution of a man-in-the-middle attack. This issue arises from the device's handling of DH parameters, which can be exploited to intercept or manipulate communications.

6.7