CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Exim SQL Injection Vulnerability in Version 4.98
A remote SQL injection vulnerability has been identified in Exim version 4.98, prior to 4.98.1. This issue arises when the SQLite hints database is used, and the ETRN command serialization is enabled. The vulnerability allows an attacker to manipulate SQL queries, potentially leading to unauthorized data access or modification.
Baiyi Cloud Asset Management System SQL Injection Vulnerability in admin.ticket.close.php
A critical SQL injection vulnerability has been identified in Baiyi Cloud Asset Management System version 8.142.100.161. The issue resides in the file /wuser/admin.ticket.close.php, where the ticket_id parameter can be manipulated to execute malicious SQL commands. This vulnerability can be exploited remotely without authentication, allowing attackers to bypass security measures and access sensitive information such as database names, table structures, and user data. The vulnerability could also be used to escalate privileges and disrupt service by corrupting database integrity.
WP-Appbox Stored Cross-Site Scripting Vulnerability for WordPress
A stored cross-site scripting vulnerability has been identified in the WP-Appbox plugin for WordPress, affecting all versions through 4.5.4. The issue arises from inadequate input sanitization and output escaping on user-supplied attributes within the plugin's appbox shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
Event Tickets and Registration WordPress Plugin Missing Authorization Vulnerability Allowing Unauthorized Ticket Deletion
A vulnerability exists in the Event Tickets and Registration plugin for WordPress, affecting all versions up to and including 5.19.1.1. The issue arises from a missing capability check in the 'ajax_ticket_delete' function, which allows authenticated attackers with Contributor-level access and above to delete arbitrary Attendee tickets. This vulnerability leads to unauthorized data loss.
Wyn Enterprise .NET Reflection-Based Server-Side Template Injection Vulnerability Allowing Remote Code Execution
A vulnerability in Wyn Enterprise's report generation feature allows for improper code inclusion, which can be exploited by low-privileged users to execute malicious code, load DLLs, and run OS commands with elevated privileges. This issue arises from the application's insufficient validation of code inputs in its templating engine, particularly within the Expression Editor used for customizing reports. The vulnerability affects all versions of Wyn Enterprise prior to 8.0.00204.0.
WordPress Head, Footer and Post Injections Plugin PHP Code Injection Vulnerability
A PHP code injection vulnerability exists in the Head, Footer and Post Injections plugin for WordPress, affecting all versions through 3.3.0. This vulnerability allows authenticated attackers with Administrator-level access to inject PHP code in multisite environments.
Indeed Ultimate Learning Pro WordPress Plugin SQL Injection Vulnerability
A time-based SQL injection vulnerability has been identified in the Indeed Ultimate Learning Pro plugin for WordPress, affecting all versions through 3.9. The vulnerability arises from inadequate escaping of user-supplied data in the 'post_id' parameter, coupled with a lack of proper preparation in the SQL query. This flaw allows authenticated attackers with Administrator-level access to inject additional SQL commands into existing queries, potentially leading to the extraction of sensitive database information.
WPExperts Square For GiveWP SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WPExperts Square For GiveWP plugin for WordPress, affecting all versions through 1.3.1. The vulnerability arises from inadequate escaping of user-supplied data in the 'post' parameter, allowing authenticated attackers with Subscriber-level access or higher to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information in the database.
igumbi Online Booking WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the igumbi Online Booking plugin for WordPress, affecting all versions through 1.40. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'igumbi_calendar' shortcode. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
Eclipse OMR Buffer Overflow Vulnerability in z/OS Atoe Print Functions
A buffer overflow vulnerability has been identified in Eclipse OMR versions 0.2.0 prior to 0.4.0. The issue arises in some z/OS atoe print functions that utilize a constant length buffer for string conversion. When the input format string and arguments exceed the buffer size, a buffer overflow occurs. This vulnerability has been addressed in version 0.5.0, where the conversion buffers are now properly sized and checked to prevent such overflows.
Eclipse OMR NULL Pointer Dereference Vulnerability in z/OS Atoe Function Consumers
A NULL pointer dereference vulnerability has been identified in Eclipse OMR, affecting versions from the initial contribution to 0.4.0. This issue arises in some internal port library and utilities that consume z/OS atoe functions, which do not properly check for NULL return values or memory allocation failures. As a result, these oversights can lead to crashes due to NULL pointer dereferences. However, starting from version 0.5.0, OMR's internal consumers of atoe functions have been updated to correctly handle NULL return values and memory allocation errors.
Maps for WP Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Maps for WP plugin for WordPress, affecting all versions through 1.2.4. The issue arises from inadequate input sanitization and output escaping on user-supplied attributes in the 'MapOnePoint' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
Autoship Cloud for WooCommerce Subscription Products Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Autoship Cloud for WooCommerce Subscription Products plugin for WordPress, affecting all versions through 2.8.0. The vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'autoship-create-scheduled-order-action' shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected page.
Responsive Addons for Elementor Local File Inclusion Vulnerability
A local file inclusion vulnerability has been identified in the Responsive Addons for Elementor - Free Elementor Addons Plugin and Elementor Templates, affecting all versions through 1.6.4. The vulnerability allows authenticated attackers with Contributor-level access and above to include and execute arbitrary files on the server. This exploitation could be used to bypass access controls, access sensitive information, or execute code in cases where 'safe' file types like images can be uploaded and included.
Ziggeo WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Ziggeo plugin for WordPress, affecting all versions through 3.1. This issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'ziggeo_event' shortcode. As a result, authenticated attackers with contributor-level access or higher can inject arbitrary scripts into pages, which will execute when users access those pages.
Ultimate Member WordPress Plugin Second-Order SQL Injection Vulnerability
A second-order SQL injection vulnerability has been identified in the Ultimate Member WordPress plugin, specifically in versions through 2.9.2. This vulnerability arises from inadequate escaping of user-supplied parameters and insufficient preparation of SQL queries. Authenticated attackers with the ability to upload files and manage filenames, potentially through a third-party file manager plugin, can exploit this issue by appending malicious SQL queries to existing ones. This could lead to unauthorized extraction of sensitive database information. However, the vulnerability's risk is considered minimal, as it requires manipulation of filenames for successful exploitation.
Events Calendar Made Simple - Pie Calendar WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Events Calendar Made Simple - Pie Calendar plugin for WordPress, affecting all versions through 1.2.5. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's piecal shortcode. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary scripts into pages, which are executed when users access the affected pages.
Eclipse ThreadX NetX Duo HTTP Server Integer Underflow Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in the HTTP server functionality of Eclipse ThreadX NetX Duo, in versions prior to 6.4.2. The issue arises in the handling of HTTP PUT requests, where an integer underflow can be exploited by sending specially crafted packets with a Content-Length smaller than the actual data being transmitted. This manipulation can cause a very large file to be written to the file system, potentially exhausting available resources and leading to a denial-of-service condition.
Eclipse ThreadX NetX Duo HTTP Server Integer Underflow Vulnerability Leading to Denial-of-Service
An integer underflow vulnerability has been identified in the HTTP server functionality of Eclipse ThreadX NetX Duo, in versions prior to 6.4.2. This vulnerability allows an attacker to cause a denial-of-service by sending specially crafted HTTP PUT requests. The first packet can have a Content-Length header indicating a smaller size than the actual data in subsequent packets, leading to an underflow condition. This underflow can be exploited to write excessively large files, potentially consuming all file system resources.
Eclipse ThreadX NetX Duo HTTP Server Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the HTTP server component of Eclipse ThreadX NetX Duo, in versions through 6.4.1. The issue arises when the server processes HTTP PUT requests. If an error occurs after a file is opened for writing, the file is not properly closed. This oversight leads to subsequent file requests being met with a 404 error. The vulnerability can be exploited by sending specially crafted packets that, for example, include a 'Content-Length' value larger than the actual data sent, causing a timeout error that is not handled correctly.
Ajax Search Lite WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Ajax Search Lite WordPress plugin, affecting versions prior to 4.12.5. The issue arises because the plugin fails to properly sanitize and escape certain settings. This flaw enables high-privilege users, such as administrators, to execute stored cross-site scripting attacks, even in environments where the unfiltered_html capability is restricted, such as multisite setups.
WP Carousel, Slider, Gallery WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WP Carousel, Slider, Gallery WordPress plugin, affecting versions prior to 2.7.4. The issue arises because the plugin fails to properly sanitize and escape certain settings. This flaw enables high-privilege users, such as administrators, to execute stored cross-site scripting attacks, even in environments where the unfiltered_html capability is restricted, such as multisite setups.
Events Manager WordPress Plugin SQL Injection Vulnerability
A time-based SQL injection vulnerability has been identified in the Events Manager WordPress plugin, specifically in versions through 6.6.3. The issue arises from inadequate escaping of user-supplied data in the active_status parameter, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to the extraction of sensitive information from the database.
AMO Team Showcase Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the AMO Team Showcase plugin for WordPress, affecting all versions through 1.1.4. The issue arises from inadequate input sanitization and output escaping on user-supplied attributes, particularly within the 'amoteam_skills' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
Newpost Catch WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Newpost Catch plugin for WordPress, affecting all versions through 1.3.19. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's npc shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the injected pages.
WPUpper Share Buttons WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WPUpper Share Buttons plugin for WordPress, affecting all versions through 3.51. The issue arises from inadequate nonce validation in the 'save_custom_css_request' function, allowing unauthenticated attackers to inject custom CSS. This could be exploited by tricking a site administrator into clicking a link that sends a forged request.
WordPress Registration Forms Plugin Sensitive Information Exposure Vulnerability
A vulnerability allowing sensitive information exposure has been identified in the Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress. This issue affects all versions through 3.8.4 and arises from publicly accessible log files. As a result, unauthenticated attackers can potentially access sensitive user information contained in these logs.
3D Photo Gallery WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the 3D Photo Gallery plugin for WordPress, affecting all versions through 1.3. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Subscriber-level access and above to inject arbitrary scripts into pages. These scripts are executed when a user accesses the compromised page.
Mini Course Generator WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Mini Course Generator WordPress plugin, specifically in versions through 1.0.5. This issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'mcg' shortcode. As a result, authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages, which will execute when users access the affected pages.
C9 Blocks WordPress Plugin Full Path Disclosure Vulnerability
A full path disclosure vulnerability exists in the C9 Blocks plugin for WordPress, affecting all versions through 1.7.7. The issue arises because the plugin includes a publicly accessible 'composer-setup.php' file with error display enabled. This configuration allows unauthenticated attackers to retrieve the full path of the web application, potentially facilitating further attacks. While the disclosed information requires the presence of another vulnerability to cause harm, it could still be leveraged in a targeted exploitation scenario.
TCBD Tooltip WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the TCBD Tooltip plugin for WordPress, affecting all versions through 1.0. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'tcbdtooltip_text' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
C9 Admin Dashboard Stored Cross-Site Scripting Vulnerability via SVG Uploads
A stored cross-site scripting vulnerability has been identified in the C9 Admin Dashboard plugin for WordPress, affecting all versions through 1.3.5. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Author-level access or higher to inject arbitrary scripts into pages. These scripts are executed when a user accesses the uploaded SVG file.
Pinpoint Booking System WordPress Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the Pinpoint Booking System WordPress plugin, affecting all versions through 2.9.9.5.4. The vulnerability arises from inadequate escaping of user-supplied data in the 'language' parameter, allowing authenticated attackers with Subscriber-level access or higher to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information within the database.
Ivanti Connect Secure and Policy Secure Arbitrary File Write Vulnerability
A vulnerability allowing external control of file names has been identified in Ivanti Connect Secure versions prior to 22.7R2.4 and Ivanti Policy Secure versions prior to 22.7R1.3. This vulnerability allows remote authenticated attackers with admin privileges to write arbitrary files on the server.
Medixant RadiAnt DICOM Viewer Improper Certificate Validation Vulnerability Allowing Machine-in-the-Middle Attacks
A vulnerability exists in Medixant RadiAnt DICOM Viewer version 2024.02 due to the update mechanism's failure to verify the update server's certificate. This flaw could enable an attacker to intercept and alter network traffic, executing a machine-in-the-middle (MITM) attack. Consequently, the attacker could modify the server's response to deliver a malicious update to the user.
lakeFS Authenticated Denial-of-Service Vulnerability via Memory Exhaustion
A denial-of-service vulnerability has been identified in lakeFS, an open-source tool that manages object storage like a Git repository. In versions prior to 1.50.0, an authenticated user can cause the server to crash by depleting its memory resources. This issue has been addressed in version 1.50.0. Users on versions 1.49.1 and below are vulnerable and are advised to upgrade. For those unable to upgrade, it's recommended to disable pre-signed multipart uploads by either setting the environment variable 'LAKEFS_BLOCKSTORE_S3_DISABLE_PRE_SIGNED_MULTIPART' to 'true' or by configuring the 'disable_pre_signed_multipart' key to true in the application’s config YAML file.
oxyno-zeta s3-proxy Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in oxyno-zeta/s3-proxy, an AWS S3 proxy written in Go. This vulnerability is present in versions prior to v4.18.1. The issue arises in the folder-list template, where the Request.URL.Path variable is rendered into the HTML without proper sanitization. Attackers can exploit this by crafting malicious URLs that inject scripts into the web application. When these URLs are visited, the injected scripts are executed in the context of the user, potentially leading to session hijacking or phishing attacks on a trusted domain.
Xunruicms Cross-Site Scripting Vulnerability Allowing Privilege Escalation
A cross-site scripting (XSS) vulnerability has been identified in Xunruicms versions through 4.6.3. This vulnerability allows remote attackers to escalate privileges by uploading a crafted SVG file that exploits the whitelisted file extension. The issue arises from inadequate validation of uploaded files, enabling the execution of malicious scripts.
Tenda i12 Buffer Overflow Vulnerability in formWifiMacFilterSet Function
A buffer overflow vulnerability has been identified in the Tenda i12 router, specifically in version V1.0.0.10(3805). The issue arises in the formWifiMacFilterSet function, where the index parameter is improperly handled, leading to potential memory corruption.
Tenda i12 Buffer Overflow Vulnerability in funcpara1 Parameter
A buffer overflow vulnerability has been identified in the Tenda i12 router, specifically in version V1.0.0.10(3805). The issue arises in the formSetCfm function, where the funcpara1 parameter is improperly handled, leading to potential memory corruption.
Tenda i12 Buffer Overflow Vulnerability in formwrlSSIDset Function
A buffer overflow vulnerability has been identified in the Tenda i12 router, specifically in version 1.0.0.10(3805). The issue arises in the formwrlSSIDset function, where the list parameter is improperly handled, leading to potential memory corruption.
Tenda AC10 Command Injection Vulnerability Allowing Arbitrary Command Execution
A command injection vulnerability has been identified in the Tenda AC10 router, specifically in version V1.0 V15.03.06.23. The issue arises in the formexeCommand function, where the cmdinput parameter from a POST request is improperly handled. This parameter is assigned to the cmd_buf variable, which is then used in the doSystemCmd function, leading to arbitrary command execution on the device.
Tenda AC10 Buffer Overflow Vulnerability in fast_setting_wifi_set
A buffer overflow vulnerability has been identified in the Tenda AC10 router, version V15.03.06.23. The issue arises in the 'fast_setting_wifi_set' function, where the 'ssid' parameter is not properly validated, allowing for a buffer overflow condition.
Tenda AC8V4 Stack Overflow Vulnerability in the shareSpeed Parameter
A stack overflow vulnerability has been identified in the Tenda AC8V4 router, specifically in version V16.03.34.06. The issue arises in the sub_47D878 function, where the shareSpeed parameter is improperly handled, leading to potential memory corruption.
Tenda AC8V4 Stack Overflow Vulnerability in Parent Control Function
A stack overflow vulnerability has been identified in the Tenda AC8V4 router, specifically in version V16.03.34.06. The issue arises in the 'get_parentControl_list_Info' function, where the 'urls' parameter is improperly handled, leading to potential memory corruption.
Tenda AC8V4 Stack Overflow Vulnerability in the shareSpeed Parameter
A stack overflow vulnerability has been identified in the Tenda AC8V4 router, specifically in version V16.03.34.06. The issue arises in the sub_49E098 function, where the shareSpeed parameter is processed.
Tenda AC8V4 Stack-Based Buffer Overflow Vulnerability in WifiExtraSet Function
A stack-based buffer overflow vulnerability has been identified in the Tenda AC8V4 router, specifically in version V16.03.34.06. The issue arises in the function SUB_0046AC38 within the file /goform/WifiExtraSet. Exploitation of this vulnerability is possible through manipulation of the wpapsk_crypto argument.
Tenda O4 Buffer Overflow Vulnerability in Mac Filter List Management
A buffer overflow vulnerability has been identified in the Tenda O4 router, specifically in version 3.0 V1.0.0.10(2936). The issue arises in the 'SafeSetMacFilter' function within the '/goform/setMacFilterList' file. The vulnerability is triggered by the 'remark', 'type', and 'time' arguments.
QiboSoft QiboCMS Sensitive Information Disclosure Vulnerability
A vulnerability in QiboSoft QiboCMS version X1.0 allows remote attackers to access sensitive information. This issue arises from the http_curl() function in the '/application/common.php' file, which retrieves the content of URL request responses.
GZDoom Remote Code Execution Vulnerability via Malicious ZScript in PK3 Files
A remote code execution vulnerability has been identified in GZDoom versions through 4.13.1. This issue arises from how ZScript, the game's primary scripting language, handles large arrays. An attacker can allocate an array of approximately 1 billion 32-bit integers, which allows access to uninitialized memory and the ability to overwrite other objects in memory. This vulnerability can be exploited by embedding malicious ZScript in a PK3 file, which is then executed by GZDoom.
