CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Gtbabel WordPress Plugin Unauthenticated Cookie Theft Vulnerability
A vulnerability exists in the Gtbabel WordPress plugin in versions prior to 6.6.9. The issue arises because the plugin does not verify that the URL for code analysis belongs to the user's blog. This flaw could enable unauthenticated attackers to steal cookies from logged-in users, including administrators, by having them open a malicious URL. The analysis request would then inadvertently include those cookies.
Page Builder: Pagelayer WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress, affecting all versions through 1.9.8. The vulnerability arises from inadequate nonce validation in the 'pagelayer_save_post' function, allowing unauthenticated attackers to alter post content by sending a forged request, provided they can persuade a site administrator to click a link or perform a similar action.
Gallagher Milestone Integration Plugin Improper Certificate Validation Vulnerability
A vulnerability exists in the Gallagher Milestone Integration Plugin (MIP) versions 4.0 prior to 4.0.32, as well as all versions of 3.0 and prior. The issue stems from improper certificate validation, allowing unauthenticated messages, such as alarm events, to be sent to the plugin.
Gallagher Command Centre Improper Certificate Validation Vulnerability in SALTO Integration
A vulnerability exists in Gallagher Command Centre's SALTO integration, all versions prior to 9.20.1043, due to improper certificate validation. This flaw allows an attacker to spoof the SALTO server. The issue impacts sites using the Gallagher Command Centre SALTO integration before the specified version.
ftcms Cross-Site Scripting Vulnerability in News Edit Functionality
A cross-site scripting vulnerability has been identified in ftcms version 2.1. The issue arises in the news editing functionality of the admin panel, specifically within the file '/admin/index.php/news/edit'. The vulnerability is triggered by manipulating the 'title' argument, and it can be exploited remotely. There is a possibility that other parameters may also be affected.
FTCMS SQL Injection Vulnerability in Search Component
A critical SQL injection vulnerability has been identified in FTcms version 2.1. The issue arises in the Search component, specifically within an unknown function of the file '/admin/index.php/web/ajax_all_lists'. The vulnerability is triggered by manipulating the 'name' argument, allowing for remote exploitation. This SQL injection could potentially impact the application's database interactions, leading to unauthorized data access or manipulation.
Dayrui XunRuiCMS Stored Cross-Site Scripting Vulnerability in Friendly Links Component
A stored cross-site scripting vulnerability has been identified in Dayrui XunRuiCMS versions through 4.6.3. This issue arises in the Friendly Links Handler, where the Website Address input is not properly sanitized before being displayed. As a result, an attacker can inject malicious scripts that are executed when the link is viewed. The vulnerability can be exploited remotely, but requires authentication and user interaction.
OpenXE Cross-Site Scripting Vulnerability in Ticket Bearbeiten Page
A cross-site scripting (XSS) vulnerability has been identified in OpenXE versions through 1.12. This issue arises in the Ticket Bearbeiten Page, where the Notizen argument can be manipulated to inject malicious scripts. The vulnerability can be exploited remotely, requiring user interaction from the victim. Successful exploitation could lead to session hijacking by stealing cookies from higher-privileged users.
Mage AI Insecure Default Initialization Vulnerability Leading to Remote Code Execution
A vulnerability exists in Mage AI version 0.9.75, characterized by an insecure default authentication setup that can lead to zero-click remote code execution. The application does not require user authentication by default, allowing unauthorized access. Although there is an option to enable authentication, it is not prominently displayed, leaving users unaware of the need to secure their instances. This flaw has been publicly disclosed and is available as a proof-of-concept exploit.
JoomlaUX JUX Real Estate Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in JoomlaUX JUX Real Estate version 3.4.0. The issue arises in an unknown function of the file '/extensions/realestate/index.php/properties/list/list-with-sidebar/realties'. The vulnerability is triggered by manipulating the 'Itemid' and 'jp_yearbuilt' parameters, allowing remote attackers to inject malicious scripts. This exploitation requires user interaction from the victim.
JoomlaUX JUX Real Estate SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in JoomlaUX JUX Real Estate version 3.4.0. The issue arises in the component's GET parameter handler, specifically within the file '/extensions/realestate/index.php/properties/list/list-with-sidebar/realties'. The vulnerability allows remote attackers to manipulate the 'title' parameter, leading to unauthorized database access. This exploitation could result in data modification or application disruption.
Control iD RH iD Resource Injection Vulnerability in PDF Document Handler
A resource injection vulnerability has been identified in Control iD RH iD version 25.2.25.0. This issue arises in the PDF Document Handler component, specifically within the file '/v2/report.svc/comprovante_marcacao/?companyId=1'. The vulnerability is triggered by manipulating the 'nsr' parameter, leading to improper control of resource identifiers. This flaw allows unauthorized access to sensitive PDF documents of employees by modifying the 'nsr' value, with the attack being executable remotely.
Control iD RH iD Cross-Site Scripting Vulnerability in API Password Change Service
A cross-site scripting (XSS) vulnerability has been identified in Control iD RH iD version 25.2.25.0. The issue arises in the API handler, specifically within the 'change_password' service of the customer database. The vulnerability allows for remote exploitation by manipulating the 'message' argument, which is not properly sanitized before being output to users. This flaw could lead to the execution of malicious scripts in the context of the user's browser.
GeSHi Cross-Site Scripting Vulnerability in CSS Handler Component
A cross-site scripting (XSS) vulnerability has been identified in GeSHi versions through 1.0.9.1. The issue resides in the CSS Handler component, specifically within the 'get_var' function of the 'contrib/cssgen.php' file. This vulnerability allows remote attackers to inject malicious HTML, which is executed when the affected page is viewed. The flaw impacts systems that use Composer to install the GeSHi library and have not removed the 'contrib' directory. Affected applications may include Dokuwiki, Mambo, phpBB, and WikkaWiki.
Thinkware Car Dashcam F800 Pro Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the Thinkware Car Dashcam F800 Pro, affecting versions prior to 20250226. The issue arises from the connection handler component, which allows an attacker to disrupt the dashcam's functionality by connecting to it over the local network. This vulnerability is particularly problematic because the dashcam can only maintain a single connection at a time, meaning that an attacker could effectively lock out the legitimate user.
Apache Camel Header Injection Vulnerability in HTTP Components
A bypass/injection vulnerability has been identified in Apache Camel versions 4.10.0 prior to 4.10.2, 4.8.0 prior to 4.8.5, and 3.10.0 prior to 3.22.4. This vulnerability arises from an issue in the default header filtering mechanism, which only blocks headers starting with 'Camel', 'camel', or 'org.apache.camel.'. Attackers can exploit this by injecting custom headers that may alter the behavior of certain Camel components. For instance, in the 'camel-bean' component, an injected header could invoke a different method on a bean than originally intended. Similarly, with the 'camel-jms' component, a malicious header could redirect a message to an unintended queue on the same broker.
Thinkware Car Dashcam F800 Pro File Storage Component Access Control Vulnerability
A critical vulnerability has been identified in the Thinkware Car Dashcam F800 Pro, affecting versions through 20250226. The issue arises from improper access controls in the file storage component, allowing an attacker to write arbitrary files or malware to the dashcam. This vulnerability can be exploited remotely within the local network.
Thinkware Car Dashcam F800 Pro Cleartext Credential Storage Vulnerability
A vulnerability exists in the Thinkware Car Dashcam F800 Pro, affecting versions through 20250226. The issue arises from the Configuration File Handler component, which improperly processes the file /tmp/hostapd.conf. This mismanagement leads to the storage of user credentials in cleartext on the device. The vulnerability can be exploited physically on the device.
Thinkware Car Dashcam F800 Pro Device Registration Handler Vulnerability Allowing Default Credential Bypass
A vulnerability exists in the Thinkware Car Dashcam F800 Pro, affecting versions through 20250226. The issue arises in the Device Registration Handler component, where default credentials are used, allowing an attacker to bypass the second-factor device registration requirement. This vulnerability can be exploited directly on the physical device, although the attack's complexity is considered high.
Quantico Tecnologia PRMV SQL Injection Vulnerability in Login Endpoint
A critical SQL injection vulnerability has been identified in Quantico Tecnologia PRMV version 6.48. The issue arises in the login endpoint, specifically within the admin login.php file, where the username argument can be manipulated to execute unauthorized SQL commands. This vulnerability can be exploited remotely.
Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System version 3.0. The issue arises in the 'electricDocList' function of the file '/newsedit/report/reportCenter.do', where improper handling of the 'fvID' and 'catID' arguments allows for SQL injection. This vulnerability can be exploited remotely.
Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System Server-Side Request Forgery Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System version 3.0. The issue arises in the file protocol handler component, specifically within an unknown functionality of the file 'imageProxy.do'. The vulnerability is triggered by manipulating the 'xyImgUrl' argument, allowing remote attackers to send unauthorized requests from the server.
zzskzy Warehouse Refinement Management System Unrestricted File Upload Vulnerability in AcceptZip.ashx
A critical vulnerability allowing unrestricted file uploads has been identified in zzskzy Warehouse Refinement Management System version 3.1. The issue arises in the ProcessRequest function of the AcceptZip.ashx file, where manipulation of the 'file' argument enables the upload of potentially malicious files. This vulnerability can be exploited remotely and may lead to arbitrary file execution or other malicious activities.
Contact Us By Lord Linus WordPress Plugin Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Contact Us By Lord Linus WordPress plugin, affecting versions through 2.6. The issue arises from the plugin's lack of proper Cross-Site Request Forgery (CSRF) checks in certain areas, combined with inadequate data sanitization and escaping. This vulnerability could enable attackers to exploit CSRF to inject malicious scripts that would be executed when a logged-in admin interacts with the affected content.
URL Shortener WooCommerce WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the URL Shortener WooCommerce WordPress plugin, affecting versions through 9.0.2. The issue arises because the plugin fails to properly sanitize and escape certain settings. This flaw enables high-privilege users, such as administrators, to execute stored cross-site scripting attacks, even in environments where the unfiltered_html capability is restricted, such as multisite setups.
WordPress URL Shortener WooCommerce Plugin Cross-Site Request Forgery Vulnerability
A vulnerability in the URL Shortener WordPress plugin, specifically in versions through 9.0.2, allows for Cross-Site Request Forgery (CSRF) attacks. The plugin lacks CSRF protection in certain bulk action features, which could enable attackers to manipulate logged-in administrators into performing undesired actions, such as deleting customer accounts.
Shenzhen Sixun Software Sixun Shanghui Group Business Management System Improper Authorization Vulnerability in Reset Password Interface
A vulnerability allowing improper authorization has been identified in Shenzhen Sixun Software's Sixun Shanghui Group Business Management System version 7. This issue arises in the Reset Password Interface, specifically within the file '/WebPages/Adm/OperatorStop.asp'. The vulnerability is triggered by manipulating the 'OperId' argument, which leads to unauthorized access or actions. The vulnerability can be exploited remotely, without any authentication, but the exploitation is considered difficult.
AT Software Solutions ATSVD SQL Injection Vulnerability in Password Recovery Feature
A critical SQL injection vulnerability has been identified in AT Software Solutions ATSVD versions prior to 3.4.1. The issue arises in the 'Esqueceu a senha' (Forgot Password) feature, specifically through the 'txtCPF' parameter. This vulnerability allows remote exploitation without authentication, enabling attackers to manipulate SQL queries and potentially access or modify database information.
MariaDB Server Denial-of-Service Vulnerability in JOIN Optimization
A denial-of-service vulnerability has been identified in MariaDB Server versions 10.10 through 10.11.*, as well as 11.0 through 11.4.*. The issue arises in the JOIN optimization process, specifically within the 'fix_all_splittings_in_plan' function, where certain queries can trigger a crash. This vulnerability is related to how the optimizer handles subqueries involving outer joins, leading to an assertion failure and server crash.
MariaDB Server Denial-of-Service Vulnerability in Item Direct View Reference Processing
A denial-of-service vulnerability has been identified in MariaDB Server versions 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, 11.0 through 11.0.*, and 11.1 through 11.4.*. The issue causes the server to crash when processing certain SQL queries that involve derived tables and the target table of an insert operation. This crash occurs in the 'Item_direct_view_ref::derived_field_transformer_for_where' function, indicating a problem with how the server handles view references in derived tables during query execution.
MariaDB Server Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in MariaDB Server versions 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, and 11.0 through 11.0.*. Under certain conditions, the server can crash without generating a backtrace log. This issue may be associated with the 'make_aggr_tables_info' function and the second stage of query optimization.
MariaDB Server Denial-of-Service Vulnerability in Derived Table Handling
A denial-of-service vulnerability has been identified in MariaDB Server versions 10.4 prior to 10.4.33, 10.5 prior to 10.5.24, 10.6 prior to 10.6.17, 10.7 through 10.11 prior to 10.11.7, 11.0 prior to 11.0.5, and 11.1 prior to 11.1.4. The issue arises when the server processes derived tables that are not yet prepared, leading to a crash. This occurs because the server incorrectly handles the 'NOW' keyword as a field name in this context, causing an assertion failure and a subsequent segmentation fault.
User-Xiangpeng Yaoqishan SQL Injection Vulnerability in MediaInfoService
A critical SQL injection vulnerability has been identified in the Yaoqishan Video Management System, specifically in the MediaInfoService component. The issue arises in the getMediaLisByFilter function, where the typeId argument is manipulated, allowing for SQL injection attacks. This vulnerability can be exploited remotely, and details of the exploit have been made public.
Espressif ESP32 Bluetooth Chips Undocumented HCI Commands Vulnerability
A vulnerability exists in Espressif ESP32 chips due to 29 undocumented HCI commands that can read and write memory, including flash memory. These commands, which are not documented by the manufacturer, could potentially be exploited to modify the chip's behavior or to conduct attacks on connected devices. The vulnerability arises from the Bluetooth Host Controller Interface (HCI), which allows commands to be sent from a host device to the Bluetooth controller.
Starter Templates by FancyWP WordPress Plugin Blind Server-Side Request Forgery Vulnerability
A Blind Server-Side Request Forgery (SSRF) vulnerability has been identified in the Starter Templates by FancyWP plugin for WordPress, affecting all versions through 2.0.0. The vulnerability arises from the 'http_request_host_is_external' filter, allowing unauthenticated attackers to send web requests to arbitrary locations from the web application. This could be exploited to query and modify information from internal services.
RomethemeKit For Elementor Missing Authorization Vulnerability in WordPress Plugin
A vulnerability exists in the RomethemeKit For Elementor WordPress plugin, all versions through 1.5.3, allowing unauthorized data modification. This issue arises from a lack of capability checks in the save_options and reset_widgets functions. As a result, authenticated attackers with Subscriber-level access or higher can alter plugin settings or reset plugin widgets to their default state, with all widgets enabled. Version 1.5.3 partially addresses this vulnerability.
Essential Blocks WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress. This issue affects all versions through 5.3.1 and arises from inadequate input sanitization and output escaping in the Parallax slider. The vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary scripts into pages, which are executed when users view the affected pages.
SlingBlocks Gutenberg Blocks by FunnelKit Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress. This issue affects all versions through 1.5.0 and arises from inadequate input sanitization and output escaping. The vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
Xpro Addons For Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the '140+ Widgets | Xpro Addons For Elementor - FREE' plugin for WordPress, affecting all versions through 1.4.6.7. The vulnerability arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into pages. These scripts are executed when a user accesses the compromised page.
VikRentCar WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Arbitrary File Upload
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the VikRentCar Car Rental Management System plugin for WordPress, affecting all versions through 1.4.2. The vulnerability arises from inadequate nonce validation in the 'save' function, allowing unauthenticated attackers to manipulate plugin access rights by tricking a site administrator into clicking a link. Exploitation of this vulnerability enables users with subscriber-level privileges or higher to upload arbitrary files to the server, potentially leading to remote code execution.
Gallery Styles WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Gallery Styles plugin for WordPress, affecting all versions through 1.3.4. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into pages. These scripts are executed when a user views the affected page.
WP-Recall WordPress Plugin Shortcode Execution Vulnerability
A vulnerability allowing arbitrary shortcode execution has been identified in the WP-Recall – Registration, Profile, Commerce & More plugin for WordPress, in versions through 16.26.10. This issue arises from a missing capability check on the 'rcl_preview_post' AJAX endpoint, which allows authenticated attackers with Subscriber-level access and above to execute arbitrary shortcodes.
WP-Recall Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WP-Recall – Registration, Profile, Commerce & More plugin for WordPress, affecting all versions through 16.26.10. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'public-form' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
WP-Recall WordPress Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WP-Recall – Registration, Profile, Commerce & More plugin for WordPress, affecting all versions through 16.26.10. The vulnerability arises from inadequate escaping of user-supplied data in the 'databeat' parameter, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information within the database.
WP-Recall WordPress Plugin Information Exposure Vulnerability
A vulnerability allowing information exposure has been identified in the WP-Recall – Registration, Profile, Commerce & More plugin for WordPress, affecting all versions through 16.26.10. The issue arises from insufficient restrictions on which posts can be included via the 'feed' shortcode. This flaw enables unauthenticated attackers to access data from password-protected, private, or draft posts that should otherwise be restricted.
Product Input Fields for WooCommerce Unauthenticated File Upload Vulnerability
A vulnerability allowing arbitrary file uploads has been identified in the Product Input Fields for WooCommerce plugin for WordPress, affecting all versions through 1.12.0. The issue arises from inadequate file type validation in the 'add_product_input_fields_to_order_item_meta()' function. This vulnerability could enable unauthenticated attackers to upload arbitrary files to the server, potentially leading to remote code execution. By default, the plugin is only susceptible to double extension file upload attacks, unless an administrator leaves the accepted file extensions field blank, which could allow .php file uploads.
The Plus Addons for Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in The Plus Addons for Elementor WordPress plugin, specifically in versions through 6.2.2. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts into pages via the Countdown, Syntax Highlighter, and Page Scroll widgets. The injected scripts are executed when users access the affected pages, exploiting insufficient input sanitization and output escaping.
Javo Core WordPress Plugin Privilege Escalation Vulnerability
A privilege escalation vulnerability has been identified in the Javo Core plugin for WordPress, affecting all versions through 3.0.0.080. The vulnerability arises because the plugin allows users registering new accounts to choose their own roles. This functionality can be exploited by unauthenticated attackers to create accounts with administrative privileges.
Aiomatic WordPress Plugin Arbitrary File Upload Vulnerability Allowing Remote Code Execution
A vulnerability exists in the Aiomatic WordPress plugin, specifically in the 'aiomatic_generate_featured_image' function, all versions through 2.3.8. The issue arises from inadequate file type validation, allowing authenticated users with Contributor-level access or higher to upload arbitrary files to the server. This could potentially lead to remote code execution.
Aiomatic WordPress Plugin Missing Authorization Vulnerability Allows Unauthorized Data Modification
A vulnerability exists in the Aiomatic WordPress plugin, specifically in the Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit version 2.3.6 and prior. The issue stems from inadequate capability checks on several functions, enabling authenticated attackers with Subscriber-level access or higher to unauthorized access, modification, and deletion of various data. Exploitation allows these attackers to update and delete posts, manage batches, access and delete uploaded files, remove personas, forms, and templates, and clear logs. This vulnerability was partially addressed in version 2.3.5.
