CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Mar 3, 2025

Mini-Tmall SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Mini-Tmall versions prior to 2025-02-11. The issue arises in the 'select' function of 'ProductMapper.java', where the 'orderBy' parameter can be manipulated to execute arbitrary SQL commands. This vulnerability can be exploited remotely.

2.5
Mar 3, 2025

FITSTATS Technologies AthleteMonitoring Cross-Site Scripting Vulnerability in login.php

A cross-site scripting vulnerability has been identified in FITSTATS Technologies AthleteMonitoring versions prior to 20250302. The issue arises in the login.php file, where the username argument can be manipulated to inject malicious scripts. This vulnerability can be exploited remotely.

2.0
Mar 3, 2025

Bitaxe ESP-Miner Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Bitaxe ESP-Miner versions prior to 2.5.0, specifically in the AxeOS environment. This vulnerability allows an attacker to manipulate miner settings, such as the payout address for Bitcoin mining, by exploiting the lack of authentication and CSRF protections in the web interface. The issue arises when a user on the same local network visits a malicious website that sends unauthorized requests to the miner's API. As a result, the attack can silently change critical settings without the user's knowledge.

2.8
Mar 3, 2025

ESAFENET CDG SQL Injection Vulnerability in logManagement Component

A critical SQL injection vulnerability has been identified in ESAFENET CDG version 5.6.3.154.205. The issue arises in the logManagement component, specifically within the ClientSortLog.jsp file. The vulnerability is triggered by manipulating the startDate and endDate arguments, allowing for remote exploitation.

2.9
Mar 3, 2025

ESAFENET CDG SQL Injection Vulnerability in updateorg.jsp

A critical SQL injection vulnerability has been identified in ESAFENET CDG version 5.6.3.154.205. The issue arises in the file updateorg.jsp, where the argument flowId can be manipulated to execute arbitrary SQL commands. This vulnerability can be exploited remotely.

2.9
Mar 2, 2025

Incorta CSV Injection Vulnerability in Edit Insight Handler

A CSV injection vulnerability has been identified in Incorta version 2023.4.3. The issue arises in the Edit Insight Handler component, where an unknown function improperly handles the Service Name argument, allowing for remote exploitation. The vulnerability was disclosed to the vendor, but no response was received.

1.6
Mar 2, 2025

osuuu LightPicture Unrestricted File Upload Vulnerability in Api.php

A critical unrestricted file upload vulnerability has been identified in osuuu LightPicture version 1.2.2. The issue arises in the file upload function of the Api.php controller, where improper validation allows for unrestricted file uploads. This vulnerability can be exploited remotely.

1.2
Mar 2, 2025

ZZ_Resolve Unrestricted File Upload Vulnerability

A critical vulnerability allowing arbitrary file upload has been identified in ZZ_Resolve versions through 2024-8. The issue arises in the '/resolve' endpoint, where improper handling of the 'file' argument permits unrestricted file uploads. This vulnerability can be exploited remotely.

3.2
Mar 2, 2025

ZJ1983 ZZ Server-Side Request Forgery Vulnerability

A critical server-side request forgery (SSRF) vulnerability has been identified in ZJ1983 ZZ versions through 2024-8. The issue arises in the HTTP request handler, specifically within the 'sendNotice' function of 'Customer_noticeAction.java'. This vulnerability allows remote attackers to manipulate the 'url' argument, potentially leading to unauthorized requests being sent from the server.

3.0
Mar 2, 2025

ZJ1983 ZZ SQL Injection Vulnerability in ZroleAction Component

A critical SQL injection vulnerability has been identified in ZJ1983 ZZ versions up to August 2024. The issue resides in the 'getUserList' function of the 'ZroleAction.java' file. The vulnerability is triggered by manipulating the 'roleid' parameter, allowing remote attackers to inject malicious SQL code. This exploitation has been publicly disclosed.

3.0
Mar 2, 2025

zj1983 zz SQL Injection Vulnerability in UserLoginJson Endpoint

A critical SQL injection vulnerability has been identified in zj1983 zz versions through 2024-8. The issue resides in the GetDBUser function within ZorgAction.java. The vulnerability allows for remote exploitation by manipulating the user_id parameter, which is directly concatenated into the SQL query without proper sanitization.

3.9
Mar 2, 2025

zj1983 zz Cross-Site Scripting Vulnerability in Customer Information Handler

A cross-site scripting (XSS) vulnerability has been identified in zj1983 zz versions through 2024-8. This issue arises from the Customer Information Handler component, where the Customer Name argument can be manipulated to inject malicious scripts. The vulnerability can be exploited remotely and requires some user interaction.

2.9
Mar 2, 2025

TOTOLINK X18 OS Command Injection Vulnerability Allowing Remote Code Execution

A critical OS command injection vulnerability has been identified in the TOTOLINK X18 router, specifically in version 9.1.0cu.2024_B20220329. The issue arises in the '/cgi-bin/cstecgi.cgi' file, within the 'setMtknatCfg' function. The vulnerability is triggered by manipulating the 'mtkhnatEnable' parameter, allowing remote execution of arbitrary system commands with the same privileges as the web server.

5.3
Mar 2, 2025

ZJ1983 ZZ SQL Injection Vulnerability in ZorgAction.java

A critical SQL injection vulnerability has been identified in ZJ1983 ZZ versions up to 2024-08. The issue arises in the 'getUserOrgForUserId' function within 'ZorgAction.java', where improper handling of the 'userID' parameter allows for SQL injection. This vulnerability can be exploited remotely.

3.9
Mar 2, 2025

AMD Graphics Products Memory Leakage Vulnerability Allowing Confidentiality Breach

A vulnerability exists in certain AMD graphics products due to inadequate clearing of GPU global memory. This flaw could enable a malicious process on the same GPU to access residual memory values, potentially resulting in unauthorized information disclosure.

1.0
Mar 2, 2025

zj1983 zz SQL Injection Vulnerability in ZworkflowAction

A critical SQL injection vulnerability has been identified in zj1983 zz versions prior to 2024-8. The issue arises in the getOaWid function within the ZworkflowAction.java file, where improper handling of the tableId argument allows for SQL injection. This vulnerability can be exploited remotely.

3.0
Mar 2, 2025

Tenda AC7 Command Injection Vulnerability in Telnet Function

A critical command injection vulnerability has been identified in the Tenda AC7 1200M router, specifically in version 15.03.06.44. The issue arises in the 'TendaTelnet' function within the '/goform/telnet' file, where improper handling of the 'lan_ip' argument allows for operating system command injection. This vulnerability can be exploited remotely.

4.3
Mar 2, 2025

zj1983 zz Unrestricted File Upload Vulnerability in ZfileAction Component

A critical vulnerability allowing unrestricted file uploads has been identified in zj1983 zz versions through 2024-8. This issue arises from a lack of permission validation and file type restrictions in the ZfileAction.upload interface. The vulnerability can be exploited remotely, potentially leading to arbitrary file uploads.

3.9
Mar 2, 2025

IBM Cognos Analytics Mobile Debug Information Exposure Vulnerability

A vulnerability exists in IBM Cognos Analytics Mobile version 1.1 for Android, allowing a user with physical access to the device to retrieve sensitive information from debugging code log messages. This issue arises from the improper handling of sensitive information in a way that could be exposed through debugging tools.

2.0
Mar 2, 2025

IBM Cognos Analytics Mobile Weak Obfuscation Vulnerability Allowing Code Reverse Engineering

A vulnerability exists in the IBM Cognos Analytics Mobile 1.1 application for iOS, where weak code obfuscation may enable an attacker to reverse engineer the application. This could lead to the exposure of the codebase, including programming techniques, interface details, class definitions, algorithms, and functions.

1.5
Mar 2, 2025

Mini-Tmall Cross-Site Scripting Vulnerability in Admin Component

A cross-site scripting (XSS) vulnerability has been identified in Mini-Tmall versions prior to 20250211. The issue resides in the Admin Name Handler component, specifically within the /admin file. This vulnerability allows remote attackers to inject malicious scripts, which could be executed in the context of the user's browser.

2.2
Mar 2, 2025

Linux Kernel ALSA PCM OSS Race Condition Vulnerability

A race condition vulnerability has been identified in the Linux kernel's Advanced Linux Sound Architecture (ALSA) subsystem, specifically within the PCM OSS interface. This vulnerability arises in the 'snd_pcm_oss_sync()' function, which is invoked by the OSS PCM 'SNDCTL_DSP_SYNC' ioctl. The issue occurs because 'snd_pcm_oss_sync()' first calls 'snd_pcm_oss_make_ready()', and then acquires the 'params_lock' mutex. If another thread re-establishes the stream in between these actions, it can create an inconsistency. This may lead to unexpected outcomes, such as a NULL dereference of the OSS buffer, a scenario recently highlighted by a fuzzer.

5.2
Mar 2, 2025

FFmpeg Memory Leak Vulnerability in IAMF File Handler

A memory leak vulnerability has been identified in FFmpeg versions prior to 6e26f57f672b05e7b8b052007a83aef99dc81ccb. The issue arises in the IAMF File Handler component, specifically within the 'audio_element_obu' function of 'libavformat/iamf_parse.c'. The vulnerability is caused by improper handling of the 'num_parameters' argument, which leads to allocated memory not being properly tracked or released. This memory leak can be exploited remotely, without authentication, but requires user interaction.

6.0
Mar 2, 2025

Pbrong Hrms Improper Authorization Vulnerability in Resource Go File

A critical vulnerability allowing unauthorized access to user information has been identified in Pbrong Hrms version 1.0.1. The issue resides in the Resource Go file, specifically within the HrmsDB function. The vulnerability arises from inadequate permission verification during database queries, enabling attackers to bypass authorization by manipulating cookies and accessing user data. This flaw can be exploited remotely.

3.8
Mar 2, 2025

Tenda AC6 Stack-Based Buffer Overflow Vulnerability in WifiExtraSet Functionality

A critical stack-based buffer overflow vulnerability has been identified in the Tenda AC6 router, specifically in version 15.03.05.16. The issue arises within the file '/goform/WifiExtraSet', where the 'wpapsk_crypto' parameter can be manipulated, leading to the overflow. This vulnerability can be exploited remotely.

5.3
Mar 2, 2025

zj1983 zz Cross-Site Request Forgery Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in zj1983 zz versions prior to August 2024. This vulnerability allows remote attackers to manipulate an unknown functionality, potentially leading to unauthorized actions being performed on behalf of the user.

3.4
Mar 2, 2025

zj1983 zz SQL Injection Vulnerability in SuperZ.java

A critical SQL injection vulnerability has been identified in zj1983 zz versions through 2024-08. The issue arises in the GetUserOrg function within the SuperZ.java file, where improper handling of the userId parameter allows for SQL injection. This vulnerability can be exploited remotely.

3.0
Mar 2, 2025

AT Software Solutions ATSVD SQL Injection Vulnerability in Login Endpoint

A critical SQL injection vulnerability has been identified in AT Software Solutions ATSVD versions prior to 3.4.2. The issue resides in the login endpoint, specifically within the '/login.aspx' file. The vulnerability allows remote attackers to manipulate the 'txtUsuario' parameter, injecting malicious SQL queries that are executed against the application's database. This exploitation method is classified as Blind Boolean-Based SQL Injection, where the attacker can infer database information based on the application's response.

3.3
Mar 2, 2025

Pixsoft Vivaz Cross-Site Scripting Vulnerability in Login Endpoint

A cross-site scripting (XSS) vulnerability has been identified in Pixsoft Vivaz version 6.0.11. The issue arises in an unknown function of the Login Endpoint, specifically within the file '/servlet?act=login&submit=1&evento=0&pixrnd=0125021817031859360231'. The vulnerability is triggered by manipulating the 'sistema' argument, allowing remote attackers to execute the script.

2.0
Mar 2, 2025

Pixsoft Sol SQL Injection Vulnerability in Login Endpoint

A critical SQL injection vulnerability has been identified in Pixsoft Sol versions prior to 7.6.6. The issue arises in the Login Endpoint, specifically within the file processing of a certain servlet. The vulnerability allows remote attackers to manipulate the 'txtUsuario' parameter, injecting arbitrary SQL queries that are executed against the application's database. This type of injection can potentially lead to unauthorized data access or manipulation.

3.9
Mar 2, 2025

libarchive and bsdtar Buffer Overflow Vulnerability Leading to Denial-of-Service

A buffer overflow vulnerability has been identified in libarchive versions through 3.7.7, specifically within the bsdtar utility. The issue arises in the tar/util.c file, where the 'list_item_verbose' function fails to properly validate the return value of 'strftime'. This oversight can be exploited by a crafted TAR archive, particularly when read with a verbose flag of 2, potentially causing a denial-of-service or unspecified additional impacts. For instance, a 100-byte buffer may be inadequate for certain custom locales.

5.5
Mar 2, 2025

Pixsoft E-Saphira SQL Injection Vulnerability in Login Endpoint

A critical SQL injection vulnerability has been identified in Pixsoft E-Saphira version 1.7.24. The issue arises in the Login Endpoint, specifically within the '/servlet?act=login&tipo=1' file. The vulnerability allows remote attackers to manipulate the 'txtUsuario' parameter, injecting arbitrary SQL queries that are executed against the application's database. This flaw has been publicly disclosed, and the vendor has not responded to initial reports.

3.5
Mar 2, 2025

Eastnets PaymentSafe Cross-Site Scripting Vulnerability

A cross-site scripting vulnerability has been identified in Eastnets PaymentSafe version 2.5.26.0. The issue arises in the Edit Manual Reply Handler component, specifically within the /directRouter.rfc file. The vulnerability is triggered by manipulating the Title argument, allowing for basic cross-site scripting. This issue can be exploited remotely and has been disclosed publicly.

1.6
Mar 2, 2025

Eastnets PaymentSafe Improper Authorization Vulnerability in URL Handler

A vulnerability allowing improper authorization has been identified in Eastnets PaymentSafe version 2.5.26.0. The issue arises in an unknown functionality of the file Default.aspx within the URL Handler component. This vulnerability can be exploited remotely, and has been disclosed publicly. Upgrading to version 2.5.27.0 addresses this issue.

1.8
Mar 1, 2025

Blizzard Battle.Net Uncontrolled Search Path Vulnerability in profapi.dll

A critical vulnerability has been identified in Blizzard Battle.Net versions prior to 2.39.0.15212 on Windows. The issue arises from an unknown functionality in the library profapi.dll, leading to an uncontrolled search path. This vulnerability requires local exploitation, and while the attack complexity is high, the vendor has assessed the risk level as low.

3.8
Mar 1, 2025

D-Link DAR-7000 Command Injection Vulnerability in HTTP POST Request Handler

A critical command injection vulnerability has been identified in the D-Link DAR-7000 router, specifically in version 3.2. The issue arises in the HTTP POST request handler, within the function 'get_ip_addr_details' of the file '/view/vpn/sxh_vpn/sxh_vpnlic.php'. The vulnerability allows remote exploitation by manipulating the 'ethname' argument. This router model is no longer supported by D-Link, and the vulnerability affects all hardware revisions.

3.1
Mar 1, 2025

Zorlan SkyCaiji Server-Side Request Forgery Vulnerability

A critical server-side request forgery (SSRF) vulnerability has been identified in Zorlan SkyCaiji version 2.9. The issue arises in the 'previewAction' function within 'vendor/skycaiji/app/admin/controller/Tool.php'. The vulnerability allows remote exploitation by manipulating the 'data' argument, potentially leading to unauthorized requests being sent from the server.

1.1
Mar 1, 2025

Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operations System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Hunan Zhonghe Baiyi Information Technology's Baiyiyun Asset Management and Operations System, versions prior to 20250217. The issue resides in an unknown functionality of the file '/wuser/anyUserBoundHouse.php', where the 'huid' argument can be manipulated to execute SQL injection attacks. This vulnerability can be exploited remotely, and details of the exploit have been disclosed publicly.

3.9
Mar 1, 2025

IBM Controller Weak Password Policy Vulnerability

A vulnerability exists in IBM Controller versions 11.0.0 through 11.0.1 and 11.1.0, where the default password policy does not enforce strong passwords. This weakness can make it easier for attackers to compromise user accounts.

2.1
Mar 1, 2025

Zorlan SkyCaiji Unrestricted File Upload Vulnerability in Tool.php

A critical unrestricted file upload vulnerability has been identified in Zorlan SkyCaiji version 2.9. The issue resides in the file vendor/skycaiji/app/admin/controller/Tool.php, specifically within the fileAction function. The vulnerability is triggered by manipulating the save_data argument, allowing for unauthorized file uploads. This vulnerability can be exploited remotely.

1.2
Mar 1, 2025

Rizin Heap-Based Buffer Overflow Vulnerability in UTF-8 Encoding Function

A critical heap-based buffer overflow vulnerability has been identified in Rizin versions prior to 0.8.0. The issue arises in the function 'rz_utf8_encode' within the file '/librz/util/utf8.c'. This vulnerability requires local exploitation.

3.8
Mar 1, 2025

WP Posts Carousel Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WP Posts Carousel plugin for WordPress, affecting all versions through 1.3.7. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts via the 'auto_play_timeout' parameter. These scripts are executed when a user accesses the affected page.

2.7
Mar 1, 2025

Secure Copy Content Protection and Content Locking WordPress Plugin Missing Authorization Vulnerability

A vulnerability exists in the Secure Copy Content Protection and Content Locking plugin for WordPress, affecting all versions through 4.4.7. The issue arises from a missing capability check in the 'ays_sccp_reports_user_search()' function, which allows unauthenticated users to access a list of registered user emails. This vulnerability could be exploited by attackers to gather email addresses without authorization.

4.3
Mar 1, 2025

Album Gallery WordPress Plugin PHP Object Injection Vulnerability

A PHP Object Injection vulnerability has been identified in the Album Gallery WordPress Gallery plugin, affecting all versions through 1.6.3. The issue arises from the deserialization of untrusted data in the gallery meta, allowing authenticated attackers with Editor-level access or higher to inject PHP objects. While the vulnerable plugin itself does not have a known Payload Object Injection chain, the vulnerability could be exploited if another plugin or theme with such a chain is present, potentially leading to unauthorized file deletion, sensitive data exposure, or arbitrary code execution.

2.8
Mar 1, 2025

Rizin Buffer Overflow Vulnerability in PDB Handling Prior to Version 0.7.4

A critical buffer overflow vulnerability has been identified in Rizin versions prior to 0.7.4. The issue arises in the PDB handling function 'msf_stream_directory_free' within the PDB parsing library. This vulnerability requires local access to exploit.

3.4
Mar 1, 2025

GenerateBlocks WordPress Plugin Sensitive Information Exposure Vulnerability

A vulnerability allowing sensitive information exposure exists in the GenerateBlocks plugin for WordPress, affecting all versions through 1.9.1. The issue arises in the 'get_image_description' function, where authenticated attackers with Contributor-level access or higher can access sensitive data, including the contents of private, draft, and scheduled posts and pages.

2.4
Mar 1, 2025

Kadence WP Gutenberg Blocks Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress. This issue affects all versions through 3.4.9 and arises from inadequate input sanitization and output escaping. The vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

4.8
Mar 1, 2025

Database Backup and Check Tables Automated With Scheduler 2024 Arbitrary File Deletion Vulnerability

A vulnerability allowing arbitrary file deletion has been identified in the Database Backup and Check Tables Automated With Scheduler 2024 plugin for WordPress, affecting all versions through 2.35. This issue arises from inadequate file path validation in the 'database_backup_ajax_delete' function, enabling authenticated attackers with Administrator-level access and above to delete arbitrary files on the server. Such deletions could lead to remote code execution if critical files, like wp-config.php, are removed. Version 2.36 includes a partial patch for this vulnerability.

2.4
Mar 1, 2025

Better Messages WordPress Plugin Server-Side Request Forgery Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin, affecting all versions through 2.7.4. The vulnerability arises in the 'nice_links' feature, allowing unauthenticated attackers to send web requests to arbitrary locations from the web application. This could be exploited to query and modify information from internal services. Successful exploitation requires the 'Enable link previews' option to be activated, which is the default setting.

2.7
Mar 1, 2025

Better Messages WordPress Plugin Sensitive Information Exposure Vulnerability

A vulnerability allowing sensitive information exposure exists in the Better Messages WordPress plugin, specifically in the Live Chat feature for BuddyPress, PeepSo, Ultimate Member, and BuddyBoss. This vulnerability affects all versions through 2.6.9. The issue arises from an unprotected directory, 'bp-better-messages', which allows unauthenticated attackers to access sensitive data, including file attachments from chat messages, stored in the '/wp-content/uploads/bp-better-messages' directory.

4.1