CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Samsung Mobile Out-of-Bounds Write Vulnerability in DNG Format Parsing Allowing Memory Corruption
A vulnerability exists in the DNG format parsing of the library libimagecodec.media.quram.so, prior to the SMR July 2026 Release 1. This out-of-bounds write issue allows remote attackers to write to memory locations outside of the intended boundaries, potentially leading to memory corruption.
Samsung FabricKeymaster Trustlet Time-of-Check Time-of-Use Race Condition Vulnerability Allowing Arbitrary Code Execution
A time-of-check time-of-use race condition has been identified in the fabricKeymaster trustlet, affecting Samsung devices running Android versions 14, 15, and 16, prior to the July 2026 Security Maintenance Release. This vulnerability allows local privileged attackers to execute arbitrary code by exploiting the timing of checks and usage in the trustlet.
Samsung Libimagecodec Out-of-Bounds Write Vulnerability Allowing Memory Corruption
A vulnerability exists in the TIFF parsing component of the library libimagecodec.media.quram.so, prior to the SMR July 2026 Release 1. This flaw allows remote attackers to perform out-of-bounds write operations, leading to memory corruption.
Samsung KnoxGuardManager Improper Authorization Vulnerability Allowing Configuration Bypass
A vulnerability in KnoxGuardManager prior to the SMR July 2026 Release 1 allows local attackers to bypass the application's persistence configuration due to improper authorization. This issue affects Samsung devices running Android versions 14, 15, and 16.
Samsung Wallpaper Service Path Traversal Vulnerability Allowing Privileged File Access
A path traversal vulnerability has been identified in the Wallpaper service on Samsung devices, affecting several different versions of Android. This vulnerability allows local privileged attackers to access files with system server privileges. The issue arises from improper input validation, which creates an opportunity for unauthorized file access.
Samsung Mobile Out-of-Bounds Write Vulnerability in libsavsac.so Allowing Arbitrary Code Execution
A vulnerability allowing out-of-bounds write has been identified in the libsavsac.so library, in versions prior to the Samsung Security Maintenance Release (SMR) July 2026 Release 1. This vulnerability allows local attackers to execute arbitrary code. The issue arises from improper input validation, which has been addressed in the SMR July 2026 Release 1.
Samsung SE Agent Service Improper Access Control Vulnerability Allowing Sensitive Information Access
A vulnerability exists in Samsung SE Agent Service prior to the SMR July 2026 Release 1, allowing local attackers to access sensitive information due to improper access control. This issue affects devices running Android versions 15 and 16.
Samsung Mobile IAFDService Improper Access Control Vulnerability Allowing Privileged API Access
A vulnerability exists in the IAFDService component of Samsung Mobile devices, specifically in versions prior to the July 2026 Security Maintenance Release. This vulnerability allows local privileged attackers to access and use privileged APIs, potentially leading to unauthorized actions or modifications within the application or system.
Samsung Mobile Settings Improper Access Control Vulnerability Allowing Theft Protection Configuration
A vulnerability exists in Samsung Mobile Settings prior to the SMR July 2026 Release 1, allowing local attackers to manipulate Theft protection settings. This issue arises from improper access control, which the latest security update addresses by implementing the necessary access restrictions.
zhayujie CowAgent Missing Authorization Vulnerability in Message Endpoint Remote Code Execution
A remote code execution vulnerability has been identified in zhayujie CowAgent versions through 2.1.0. The issue arises from a missing authorization in the Message Endpoint component, specifically within an unknown function in the file channel/channel.py. This flaw allows remote or authenticated users to execute arbitrary shell commands via the application's web chat interface, using the same privileges as the CowAgent process user.
CowAgent Path Traversal Vulnerability in Skill Installation Handler
A path traversal vulnerability has been identified in zhayujie CowAgent versions through 2.1.0. The issue arises in the Skill Installation Handler, specifically within the _add_url and _add_package functions of agent/skills/service.py. The vulnerability allows an authenticated user to manipulate the 'name' argument, causing the application to write files outside the intended 'skills' directory. This could lead to unauthorized overwriting of workspace files and tampering with the agent's persistent state. The vulnerability can be exploited remotely via the cloud management interface.
zhayujie CowAgent Server-Side Request Forgery Vulnerability in Vision Tool
A server-side request forgery (SSRF) vulnerability has been identified in zhayujie CowAgent versions through 2.1.1. The issue resides in the Vision Tool component, specifically within the '_build_image_content' and '_download_to_data_url' functions of 'agent/tools/vision/vision.py'. The vulnerability allows remote attackers to manipulate the 'image' argument, causing the server to make unauthorized HTTP requests to internal services or cloud metadata endpoints. This exploitation can be triggered through the Web channel by sending a message that invokes the Vision tool with a crafted image URL.
ARMember Directory Traversal Vulnerability via X-FILENAME Header
A directory traversal vulnerability has been identified in the ARMember plugin for WordPress, affecting all versions through 4.0.27. The vulnerability allows unauthenticated attackers to upload and overwrite certain files, such as CSS files, to directories outside the 'wp-content/uploads/armember' directory. This exploitation is made possible through the 'X-FILENAME' HTTP header.
BuddyHolis TableSearch Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the BuddyHolis TableSearch plugin for WordPress, affecting all versions through 1.1.0. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts into pages. These scripts are executed when a user accesses the compromised page.
GEO My WP SQL Injection Vulnerability in Proximity Search Function
A SQL injection vulnerability has been identified in the GEO My WP plugin for WordPress, affecting versions through 4.5.4. The issue arises in the proximity search feature, where the 'distance', 'lat', and 'lng' parameters are improperly sanitized. The vulnerability allows attackers to inject malicious SQL payloads that could be executed by the database, potentially leading to unauthorized data access or manipulation.
Animation Addons for Elementor Stored Cross-Site Scripting Vulnerability in Weather Widget
A stored cross-site scripting vulnerability has been identified in the Animation Addons for Elementor plugin for WordPress, affecting all versions through 2.6.3. The issue arises in the Weather widget, where the 'weather_style' and 'move_direction' parameters are improperly sanitized before being outputted as HTML class attributes. This flaw allows authenticated users with Contributor-level access or higher to inject malicious scripts that are saved and executed on the frontend. The vulnerability requires an active OpenWeatherMap API key to reproduce, as it pertains to the normal functionality of the Weather widget.
TelSender WordPress Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the TelSender plugin for WordPress, affecting all versions through 1.14.14. The issue arises from inadequate input sanitization when handling responses from the Telegram API that include chat titles controlled by attackers. This vulnerability allows unauthenticated attackers to inject malicious scripts via Telegram chat titles. These scripts are executed when an administrator accesses the TelSender settings page and clicks the 'Tested' button.
Brevo Newsletter Plugin for WordPress Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Brevo (formerly Sendinblue) Newsletter, SMTP, Email Marketing, and Subscribe Forms plugin for WordPress. This vulnerability affects all versions through 3.1.77. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages. These scripts could be executed if a user is tricked into clicking a link.
affiliate-toolkit WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the affiliate-toolkit WordPress plugin, specifically in versions through 3.7.0. The issue arises from inadequate input sanitization and output escaping in the 'atkp_product' shortcode, allowing authenticated attackers with contributor-level access or higher to inject arbitrary scripts. These scripts are executed when users access the affected pages.
WP Business Intelligence Lite Authorization Bypass Vulnerability Allowing Privilege Escalation via SQL Modification
A vulnerability exists in the WP Business Intelligence Lite plugin for WordPress, in all versions up to and including 3.2.0. The issue stems from the plugin's failure to properly verify user authorization for certain actions. This flaw enables authenticated attackers with Subscriber-level access or higher to alter stored SQL queries. Such modifications can be exploited to escalate privileges by executing arbitrary SQL when the altered query is accessed by an administrator.
Sudoku Shortcode Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Sudoku Shortcode plugin for WordPress, affecting all versions through 1.0.0. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into pages. These scripts are executed when users access the affected pages.
Chat Help WordPress Plugin Sensitive Information Exposure Vulnerability
A vulnerability allowing sensitive information exposure exists in the Chat Help – Click to Chat Button & Form plugin for WordPress, in all versions through 3.1.3. The issue arises from the plugin's REST API endpoints, which lack proper authentication and authorization checks. This vulnerability enables unauthenticated attackers to access sensitive data such as customer names, email addresses, phone numbers, WhatsApp messages, full geolocation details (including IP addresses, city, country, ISP, and coordinates), device fingerprinting data (browser, operating system, screen resolution), and WordPress account information (user IDs, usernames, emails, names) of logged-in users who have submitted forms.
Ultimate Member WordPress Plugin Blind SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in the Ultimate Member WordPress plugin, specifically in the Member Directory feature. This vulnerability affects all versions of the plugin up to and including 2.10.1. The issue arises from inadequate escaping of user-supplied input in the search parameter, allowing unauthenticated attackers to inject additional SQL queries. Exploitation of this vulnerability could lead to unauthorized access to sensitive information in the database. Notably, this vulnerability was partially addressed in version 2.9.2, which aimed to fix a related issue (CVE-2025-0308).
Booking Calendar Appointment Booking System SQL Injection Vulnerability
A time-based SQL injection vulnerability has been identified in the Booking Calendar, Appointment Booking System plugin for WordPress, affecting all versions up to and including 3.2.17. The vulnerability arises from inadequate escaping of user-supplied data in the 'wpdevart_id' parameter, allowing unauthenticated attackers to inject additional SQL queries. Exploitation of this vulnerability requires the Pro version of the plugin to be active, with the 'Delete previous dates' option enabled.
SureForms WordPress Plugin Improper Input Validation Vulnerability Allowing Unauthenticated Stripe Payment Amount Manipulation
A vulnerability exists in the SureForms – Drag and Drop Form Builder for WordPress plugin, affecting all versions up to and including 2.2.1. The issue arises from improper input validation, as the plugin allows payment amounts to be submitted via user-controlled POST data in the 'create_payment_intent' and 'create_subscription_intent' functions, without verifying it against the form's set price. This flaw enables unauthenticated attackers to alter the payment amount to any desired value when using a Stripe payment form, potentially leading to the purchase of products or services at greatly reduced prices.
rtMedia for WordPress, BuddyPress and bbPress SQL Injection Vulnerability
A time-based SQL injection vulnerability has been identified in the rtMedia for WordPress, BuddyPress and bbPress plugin, affecting all versions through 4.6.18. The vulnerability arises from inadequate escaping of the user-supplied 'order_by' parameter, coupled with a lack of proper preparation in the SQL query. This flaw allows authenticated attackers with subscriber access and above to inject additional SQL queries into existing ones, potentially leading to the extraction of sensitive information from the database.
Kadence WP Gutenberg Blocks with AI WordPress Plugin Unauthorized Post Publication Vulnerability
A vulnerability exists in the 'Gutenberg Blocks with AI by Kadence WP – Page Builder Features' plugin for WordPress, affecting all versions up to and including 3.5.32. The issue arises from a misconfigured capability check in the 'process_pattern' REST API endpoint, which allows authenticated attackers with Contributor-level access or higher to create and publish posts of any type, including pages. This bypasses the standard WordPress review process, where contributions must be approved by an administrator.
Plus Addons for Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Plus Addons for Elementor plugin for WordPress. This issue affects versions through 6.4.11 and allows authenticated users with Contributor privileges or higher to inject malicious scripts. The vulnerability arises in the Button widget's 'custom_attributes' setting, where the 'render' function in 'modules/widgets/tp_button.php' improperly sanitizes the 'custom_attributes' string. The vulnerability has been patched in version 6.4.12.
King Addons for Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the King Addons for Elementor WordPress plugin, affecting versions through 51.1.62. The issue arises from inadequate input sanitization in the 'add_to_submissions()' function, which uses 'sanitize_text_field()'—a method that retains double-quote characters—before saving the data to post meta. This flaw is compounded by a lack of proper output escaping in the 'king_addons_submissions_custom_column_content()' function, which directly adds the stored value into an HTML href attribute via 'admin_url()' without using 'esc_url()' to sanitize it. As a result, authenticated attackers with subscriber-level access or higher can inject malicious scripts into pages, where they will be executed when a user views the affected page.
WPvivid Backup for MainWP Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WPvivid Backup for MainWP plugin for WordPress, affecting all versions through 0.9.33. The vulnerability arises from inadequate input sanitization and output escaping, allowing authenticated attackers with administrator-level permissions to inject arbitrary scripts into pages. These scripts are executed when a user accesses the affected page. This issue is present in multi-site installations where unfiltered_html has been disabled.
Instant Appointment WordPress Plugin Unauthenticated Arbitrary File Upload Vulnerability
A vulnerability allowing unauthenticated arbitrary file uploads has been identified in the Instant Appointment WordPress plugin, affecting all versions through 1.2. The issue arises from inadequate file type validation in the 'insapp_upload_image_as_attachment' function. This flaw enables attackers to upload arbitrary files to the server, potentially leading to remote code execution.
Fluent Forms WordPress Plugin Incorrect Authorization Vulnerability Allowing Arbitrary Subscription Cancellation
A vulnerability exists in the Fluent Forms plugin for WordPress, specifically in versions through 6.2.1. The issue arises from inadequate authorization checks in the payment cancellation AJAX process, allowing authenticated users with subscriber-level access or higher to cancel subscriptions belonging to other users by manipulating the 'subscription_id' parameter.
OpenStack Ironic IPMI Command Injection Vulnerability Allowing RBAC Bypass
A vulnerability in OpenStack Ironic versions prior to 37.0.1 allows users with node deployment privileges to exploit the IPMI management interface. By using the 'send_raw' step, these users can send arbitrary IPMI commands to nodes, bypassing Ironic's access controls. This issue arises because the 'send_raw' functionality is available in manual cleaning and servicing steps, as well as through the VendorPassthru interface, which is normally restricted to system administrators. The vulnerability could be exploited to manipulate BMC settings, including user accounts and network configurations, potentially leading to unauthorized persistent access.
OpenStack Ironic Insufficient Access Control Vulnerability in Node Management
A vulnerability exists in OpenStack Ironic versions prior to 37.0.1, allowing unauthorized cross-project creation or modification of nodes. This issue arises from inadequate role-based access control (RBAC) checks, enabling project managers to manipulate node associations with Volume Connectors or Volume Targets, potentially altering access permissions for sensitive data, particularly in environments using iSCSI for boot volumes. Additionally, project managers can exploit this vulnerability by reparenting nodes to disrupt normal operations, such as power management, on parent nodes.
Zhayujie CowAgent Browser Tool Information Disclosure Vulnerability
An information disclosure vulnerability has been identified in Zhayujie CowAgent versions through 2.1.0. The issue arises in the Browser Tool component, specifically within the function BrowserTool._do_navigate in the file agent/tools/browser/browser_tool.py. This vulnerability allows an authenticated user to manipulate the tool into navigating to a local file via a file:// URL, effectively exfiltrating its contents. The flaw occurs because the tool does not properly validate URL schemes before forwarding them to the Playwright browser automation library, bypassing the intended trust boundary and transforming a feature meant for web navigation into a local file reader.
Halo Theme Installation Path Traversal Vulnerability Allowing Arbitrary File Write
A path traversal vulnerability has been identified in the Halo open-source project, specifically in versions through 2.24.2. The issue arises in the ThemeUtils.unzipThemeTo function within ThemeUtils.java, where the argument metadata.name is not properly validated. This lack of validation allows for path traversal attacks, enabling files to be written outside the intended theme directory. The vulnerability can be exploited remotely, and the exploit is publicly available.
MyEMS Stored Cross-Site Scripting Vulnerability in Admin Backend
A stored cross-site scripting vulnerability has been identified in MyEMS versions prior to 6.4.0. The issue resides in the Admin Backend, specifically within the 'on_post' function of 'myems-api/core/svg.py'. This vulnerability allows remote attackers to inject malicious SVG data that is saved and later executed, potentially leading to session cookie theft and account takeover, including administrative accounts.
Salon Booking System WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Remote Code Execution
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Salon Booking System – Free Version plugin for WordPress, affecting all versions through 10.30.32. The vulnerability arises from inadequate nonce validation in the 'setCustomText' function, allowing unauthenticated attackers to inject arbitrary PHP code into the publicly accessible 'translate-constants.php' file within the plugin directory. This exploitation could lead to remote code execution on the server, provided the attacker can deceive a site administrator into clicking a link or performing a similar action. While the 'value' parameter is sanitized, the applied function does not remove certain characters necessary for breaking out of the PHP string literal, enabling the injection of malicious code that could be executed on the server.
Super Forms WordPress Plugin Arbitrary File Upload Vulnerability Allowing Remote Code Execution
A vulnerability allowing arbitrary file upload has been identified in the Super Forms – Drag & Drop Form Builder plugin for WordPress, affecting all versions prior to 6.3.314. The issue arises in the submit_form function, where there is a lack of proper file type validation and capability checks on the submit_form nopriv AJAX handler. This handler's only protection is a session nonce, which can be easily obtained by unauthenticated users through a separate nopriv endpoint. As a result, unauthenticated attackers can upload potentially executable files, leading to remote code execution. The nonce requirement can be easily bypassed, allowing exploitation with two unauthenticated HTTP requests.
Post Export Import with Media WordPress Plugin Arbitrary File Upload Vulnerability
A vulnerability allowing arbitrary file upload has been identified in the Post Export Import with Media plugin for WordPress, affecting all versions through 1.13.1. The issue arises in the import_media_file_secure function, where inadequate validation of file extensions allows for the upload of potentially executable files. This vulnerability exploits a trailing-dot filename bypass, which interferes with the extension allow-list check. Authenticated attackers with administrator-level access can leverage this flaw to upload files that could be executed remotely.
WPCafe WordPress Plugin Authorization Bypass Vulnerability Allowing Arbitrary Modifications via REST API
A vulnerability exists in the WPCafe WordPress plugin, specifically in the Restaurant Menu, Online Food Ordering & Table Booking System version 3.0.14 and earlier. The issue stems from the plugin's failure to properly verify user authorization for certain actions. This flaw enables authenticated users with subscriber-level access and above to manipulate notification flow workflows—such as listing, creating, updating, deleting, cloning, and bulk-deleting—tasks that should be restricted to administrators. The only safeguard on these endpoints is a wp_rest nonce check, which any logged-in user can access from the frontend page source.
WP Hotel Booking Plugin WordPress Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WP Hotel Booking plugin for WordPress, affecting all versions prior to and including 2.3.1. The vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages. These scripts could be executed if the attacker successfully convinces a user to perform a specific action, such as clicking a link.
Sipeed PicoClaw Missing Authorization Vulnerability in WebSocket Channel
A vulnerability exists in Sipeed PicoClaw versions up to 0.2.9, specifically within the WebSocket channel handling. The issue arises in the 'rt.ReloadConfig' function, where the 'message.send' argument can be manipulated to bypass authorization. This flaw allows authenticated Pico WebSocket clients to trigger an unauthorized configuration reload action, exploiting a control-plane mutation path. The vulnerability can be exploited remotely, and the details of the exploit are publicly available.
Sipeed PicoClaw Improper Access Control Vulnerability in Launcher Component
A vulnerability allowing improper access control has been identified in Sipeed PicoClaw versions through 0.2.9. The issue resides in the Launcher component, specifically within the IPAllowlist function of the access_control.go file. This vulnerability can be exploited remotely, bypassing intended network restrictions and exposing sensitive launcher endpoints.
Sipeed PicoClaw MQTT Channel Authorization Bypass Vulnerability
An authorization bypass vulnerability has been identified in Sipeed PicoClaw versions through 0.2.9, specifically within the MQTT channel handler. The issue arises because the authorization process relies on the client-defined 'client_id' segment of the MQTT topic, which can be easily spoofed. This manipulation allows unauthorized messages to be sent to the agent, bypassing the intended safeguards. The vulnerability can be exploited remotely, and a public exploit is available.
Langroid Neo4jChatAgent Cypher Query Injection Vulnerability Allowing Data Manipulation and Potential Remote Code Execution
A vulnerability in Langroid's Neo4jChatAgent prior to version 0.65.5 allows for prompt-injection attacks that can manipulate LLM-generated Cypher queries. These unvalidated queries are sent directly to the Neo4j database driver, enabling an attacker to read or delete all graph data. Furthermore, if certain procedures are enabled on the database, this could lead to unauthorized access to the filesystem, network, or operating system, depending on the configuration. This issue mirrors a similar vulnerability in the SQLChatAgent, which has been addressed in a previous update.
Langroid Direct Tool Invocation Vulnerability in Chat Interface
A vulnerability in Langroid applications prior to version 0.65.7 allows untrusted users to invoke tools directly by sending raw JSON payloads through the chat interface. This issue arises because the tool invocation process does not verify the message source, enabling users to execute handlers for tools registered as 'handle-only' and not meant for direct use.
Langroid Sandbox Escape Vulnerability in TableChatAgent and VectorStore Leading to Remote Code Execution
A critical sandbox escape vulnerability allowing remote code execution (RCE) has been identified in Langroid versions prior to 0.65.2. This issue arises in the 'TableChatAgent' and 'VectorStore' capabilities when the agents evaluate LLM-generated tool messages with 'full_eval=True'. The vulnerability exploits an incomplete mitigation in Python's 'eval()' function, where the 'locals' parameter is set to an empty dictionary. This oversight fails to remove 'builtins' from the 'globals' dictionary, allowing access to functions like 'os.system()'. Consequently, an attacker can inject a payload that is executed on the host system, leading to unauthorized actions such as file manipulation or system command execution.
Langroid SQLChatAgent SQL Injection Mitigation Bypass Vulnerability
A vulnerability exists in Langroid's SQLChatAgent prior to version 0.65.1, allowing SQL injection by bypassing the default SQL-injection mitigation. The issue arises because the agent's regex blocklist for dangerous SQL patterns can be evaded using PostgreSQL's schema qualification, quoted identifiers, or inline comments. This exploitation can restore access to the 'pg_read_file' function, enabling unauthorized file reads from the server. The vulnerability is present when untrusted user input can influence the SQL generated by the agent.
Langroid Path Traversal Vulnerability in File Tools Allowing Unauthorized File Access
A path traversal vulnerability has been identified in Langroid's file handling tools, specifically in versions through 0.63.0. The issue arises because the ReadFileTool and WriteFileTool do not properly enforce directory boundaries when performing file operations. Instead of validating that the final file path remains within the designated current directory, the tools allow traversal sequences to escape this boundary. This flaw can be exploited to read or write files outside the intended workspace, potentially exposing sensitive information or modifying files in unintended ways. The vulnerability is particularly concerning in applications that delegate file operations to an LLM agent or similar user-controlled context.
