CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Livewire Volt Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in Livewire Volt versions prior to 1.7.0. This issue arises from malicious, user-crafted request payloads that could potentially execute arbitrary code within Volt components.
Ampache Cross-Site Request Forgery Vulnerability in Private Messaging and Follow Functions
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Ampache versions through 6.6.0. This vulnerability affects the private messaging and follower management features, specifically through the 'pvmsg.php?action=add_message', 'pvmsg.php?action=confirm_delete', and 'ajax.server.php?page=user&action=flip_follow' endpoints. The absence of proper anti-CSRF measures allows malicious users to send or delete private messages and manipulate follow/unfollow actions without the user's consent.
Devolutions Server Incorrect Authorization Vulnerability in PAM Vaults
A vulnerability exists in Devolutions Server in versions through 2024.3.12, where incorrect authorization in Privileged Access Management (PAM) vaults allows an authenticated user to bypass the 'add in root' permission. This could lead to unauthorized modifications or additions within the PAM vaults, potentially disrupting access management or compliance processes.
Laravel Framework Wildcard Validation Bypass Vulnerability
A vulnerability exists in Laravel Framework versions prior to 11.44.1 and 12.1.1, allowing wildcard validation to be bypassed on file or image fields. This could enable a user to submit a crafted request that evades the intended validation rules.
OpenTelemetry .NET Denial-of-Service Vulnerability in Trace Context Propagation
A denial-of-service vulnerability has been identified in the OpenTelemetry.Api package, affecting versions 1.10.0 to 1.11.1. The issue arises when HTTP requests include tracestate and traceparent headers, leading to increased CPU usage. This vulnerability impacts web-accessible applications and backend services that process such headers, causing excessive resource consumption, higher latency, degraded performance, or potential downtime.
Vehicle Management System Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in Vehicle Management System version 1.0. The issue resides in the 'Name' parameter of the 'booking.php' file within the vehicle management module. This vulnerability allows attackers to inject malicious scripts that are executed when an administrator views the booking list on 'bookinglist.php'. Such exploitation could lead to session hijacking or unauthorized access to administrative accounts.
Peppermint Ticket Management Incorrect Access Control Vulnerability Allowing Privilege Escalation
A vulnerability in Peppermint Ticket Management version 0.4.6 allows regular registered users to elevate their privileges to admin. This issue arises because the authorization mechanism is only validated on the client side, leaving a gap that can be exploited to gain complete access to the system. An attacker could, for instance, create a new admin user, providing persistent administrative access.
Sysax Multi Server Denial-of-Service Vulnerability via Crafted SSH Packets
A denial-of-service vulnerability has been identified in Sysax Multi Server version 6.99. The issue arises when the server processes specially crafted SSH packets, leading to a crash of the SSH service.
Cisco TelePresence Management Suite Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of Cisco TelePresence Management Suite (TMS) Release 15.13.6. This vulnerability allows low-privileged, remote attackers to inject malicious scripts that could be executed in the context of the user's browser session, potentially accessing sensitive information.
Cisco Secure Client for Windows DLL Hijacking Vulnerability
A DLL hijacking vulnerability has been identified in Cisco Secure Client for Windows, specifically when the Secure Firewall Posture Engine is installed. This vulnerability allows an authenticated, local attacker to send a crafted interprocess communication (IPC) message to a Cisco Secure Client process, potentially leading to the execution of arbitrary code with SYSTEM privileges on the affected machine. The vulnerability arises from inadequate validation of resources loaded by the application at runtime. Exploitation requires valid user credentials on the Windows system.
Carbon Black Cloud Windows Sensor Information Leak Vulnerability
A vulnerability allowing information leakage has been identified in Carbon Black Cloud Windows Sensor versions prior to 4.0.3. This issue may expose sensitive information due to a flaw in the software.
OpenDJ Denial-of-Service Vulnerability via Alias Loop
A denial-of-service vulnerability has been identified in OpenDJ versions prior to 4.9.3. This vulnerability causes the server to become unresponsive to all LDAP requests, without crashing or restarting. The issue arises when an alias loop exists in the LDAP database. If an ldapsearch request is made with alias dereferencing set to 'always' on an entry involved in the loop, the server will stop responding to future requests. Fortunately, the server can be restarted without any data loss.
REDAXO CMS Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in REDAXO CMS versions 5.0.0 through 5.18.2. The issue arises on the AddOns page, where the rex-api-result parameter is not properly sanitized, allowing for the injection of malicious scripts. This vulnerability can be exploited by administrative users.
REDAXO Arbitrary File Upload Vulnerability in Mediapool Addon
An arbitrary file upload vulnerability exists in the REDAXO content management system, specifically in versions prior to 5.18.3. The issue is located on the mediapool/media page, where users can upload malicious files. This vulnerability has been reported to allow the execution of JavaScript code, potentially leading to malware distribution.
Keysight Ixia Vision Product Family External XML Entity Injection Vulnerability Allowing Arbitrary File Download
A vulnerability allowing external XML entity injection has been identified in the Keysight Ixia Vision Product Family, specifically in version 6.3.1. This vulnerability allows for the arbitrary download of files, and although it requires a privileged account for exploitation, it could lead to further compromise of the device when combined with other issues. The vulnerability arises from improper restriction of XML external entity references, which could be exploited to inject malicious XML that the application processes, potentially leading to unauthorized file access or manipulation.
Keysight Ixia Vision Product Family Path Traversal Vulnerability Allowing Remote Code Execution
A path traversal vulnerability has been identified in the Keysight Ixia Vision Product Family, specifically in version 6.3.1. This vulnerability allows remote code execution by users with privileged accounts, such as device administrators. The issue arises from improper limitations on file paths, which could be exploited in conjunction with the 'Upload' functionality to execute arbitrary scripts or potentially run uploaded binaries.
Keysight Ixia Vision Product Family Path Traversal Vulnerability Leading to Arbitrary File Deletion
A path traversal vulnerability has been identified in the Keysight Ixia Vision Product Family, specifically in version 6.3.1. This vulnerability may allow for arbitrary file deletion. While the issue could be exploited by a user with administrative privileges, it is not accessible to regular users. Additionally, this vulnerability could be exploited in conjunction with other identified issues, potentially leading to a more significant compromise of the device.
Joomla Convert Forms SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the Convert Forms component for Joomla, affecting versions 1.0.0 through 4.4.9. This vulnerability allows authenticated administrators to execute arbitrary SQL commands in the submission management area of the backend.
Keysight Ixia Vision Product Family Path Traversal Vulnerability Allowing Arbitrary File Download
A path traversal vulnerability has been identified in the Keysight Ixia Vision Product Family, specifically in version 6.3.1. This vulnerability may allow remote code execution by exploiting the path traversal to access restricted directories, potentially leading to the execution of arbitrary scripts or uploaded binaries. Additionally, the vulnerability could be used to delete files arbitrarily. The issue arises from improper limitations on file paths, which could be exploited by users with administrative privileges.
Lucee Server Remote Code Execution Vulnerability via XML External Entity Attack
A remote code execution vulnerability has been identified in Lucee Server, all prior versions, through an XML external entity (XXE) attack on the Lucee REST endpoint. This issue arises from improper handling of XML data, allowing maliciously crafted XML to be processed in a way that executes arbitrary code on the server.
Perforce Gliffy Lack of Rate Limiting in Sign-up Workflow Vulnerability
A vulnerability exists in Perforce Gliffy Online versions prior to 4.14.0-7, where the sign-up workflow lacks proper rate limiting. This deficiency allows attackers to enumerate valid user email addresses and potentially perform a denial-of-service attack on the server.
OpenText Identity Manager Advanced Edition Insufficiently Protected Credentials Vulnerability Allowing Privilege Abuse
A vulnerability allowing insufficiently protected credentials has been identified in OpenText Identity Manager Advanced Edition versions 4.8.0.0 through 4.8.7.0102 and 4.9.0.0 on Windows and Linux (64-bit). This vulnerability could enable an authenticated user to access sensitive information of higher privileged users through crafted payloads, facilitating privilege abuse.
Merkur Software B2B Login Panel SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the B2B Login Panel application developed by Merkur Software. This issue allows for improper neutralization of special elements used in SQL commands, potentially enabling attackers to manipulate database queries and execute arbitrary SQL commands. The vulnerability affects versions of the B2B Login Panel prior to January 15, 2025.
Boceksoft E-Travel SQL Injection Vulnerability
A SQL injection vulnerability has been identified in Boceksoft E-Travel versions prior to 15.12.2024. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially enabling attackers to manipulate database queries and execute arbitrary SQL commands.
PozitifIK Pik Online Authorization Bypass Vulnerability Allowing Account Footprinting and Session Hijacking
A vulnerability in PozitifIK Pik Online, present through March 5, 2025, allows for authorization bypass via user-controlled keys, leading to exposure of private personal information, account footprinting, and session hijacking.
Ultimate Member WordPress Plugin Unauthenticated Time-Based SQL Injection Vulnerability
A time-based SQL injection vulnerability has been identified in the Ultimate Member WordPress plugin, specifically in versions through 2.10.0. The vulnerability arises from inadequate escaping of user-supplied data in the 'search' parameter, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to the extraction of sensitive information from the database.
WordPress Spreadsheet Integration Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Spreadsheet Integration plugin for WordPress, affecting all versions through 3.8.2. The issue arises from inadequate nonce validation in the 'class-wpgsi-show.php' file, allowing unauthenticated attackers to publish arbitrary posts, including private ones, by tricking a site administrator into clicking a link.
DesignThemes Core Features WordPress Plugin Missing Authorization Vulnerability Allowing Unauthenticated Arbitrary File Read
A vulnerability exists in the DesignThemes Core Features plugin for WordPress, in all versions through 4.7. The issue arises from a missing capability check in the 'dt_process_imported_file' function, allowing unauthenticated attackers to read arbitrary files from the underlying operating system.
WordPress Sparkling Theme Missing Capability Check Vulnerability Allows Unauthenticated Plugin Management
A vulnerability exists in the Sparkling theme for WordPress, specifically in versions through 2.4.9. The issue arises from a lack of proper capability checks in the 'sparkling_activate_plugin' and 'sparkling_deactivate_plugin' functions. This flaw enables unauthenticated users to activate or deactivate any plugin on the site.
WAGO libwagosnmp Unchecked Return Value Vulnerability Leading to Application Crash
A vulnerability exists in the WAGO PFC firmware SDK-G2 component of libwagosnmp, affecting several WAGO products, including various PFC, Edge Controller, and TP600 models, all prior to specific firmware versions. This vulnerability allows an attacker with low privileges to manipulate requested memory sizes, causing the application to access invalid memory areas. The result is a crash of the application, although other applications remain unaffected.
Homey WordPress Theme Privilege Escalation Vulnerability
A privilege escalation vulnerability exists in the Homey theme for WordPress, affecting all versions through 2.4.2. The issue arises because the theme allows users registering new accounts to choose their own roles. This functionality can be exploited by unauthenticated attackers to create accounts with elevated privileges, such as Editor or Shop Manager roles.
Homey Login Register WordPress Plugin Privilege Escalation Vulnerability
A privilege escalation vulnerability has been identified in the Homey Login Register plugin for WordPress, affecting all versions through 2.4.0. The vulnerability arises because the plugin allows users to choose their own roles when registering new accounts. This functionality can be exploited by unauthenticated attackers to create accounts with administrative privileges.
Content Control WordPress Plugin Sensitive Information Exposure Vulnerability
A vulnerability allowing sensitive information exposure exists in the Content Control WordPress plugin, specifically in versions through 2.5.0. This issue arises from the plugin's interaction with the WordPress core search feature, enabling unauthenticated attackers to access sensitive data from posts restricted to higher-level roles, such as logged-in users.
Elastic Kibana Prototype Pollution Vulnerability Leading to Arbitrary Code Execution
A prototype pollution vulnerability in Elastic Kibana allows for arbitrary code execution through a manipulated file upload and specially crafted HTTP requests. This issue affects Kibana versions 8.15.0 and 8.16.6, as well as versions 8.17.0 to 8.17.2. In versions 8.15.0 to 8.17.1, the vulnerability can be exploited by users with the Viewer role. However, in Kibana versions 8.17.1 and 8.17.2, exploitation is limited to users with roles that include the 'fleet-all', 'integrations-all', and 'actions:execute-advanced-connectors' privileges. Notably, this vulnerability does not impact self-managed Kibana instances on Basic or Platinum licenses, but affects Kibana instances on Elastic Cloud, where the code execution is confined within the Kibana Docker container.
WP Real Estate Manager Authentication Bypass Vulnerability Allowing Account Takeover
A vulnerability allowing authentication bypass has been identified in the WP Real Estate Manager plugin for WordPress, affecting all versions through 2.8. This vulnerability arises from inadequate identity verification in the LinkedIn login process, enabling unauthenticated attackers to bypass authentication and gain access as any user, including administrators.
WooCommerce Recover Abandoned Cart PHP Object Injection Vulnerability
A PHP Object Injection vulnerability has been identified in the WooCommerce Recover Abandoned Cart plugin for WordPress, affecting all versions through 24.4.0. The vulnerability arises from the deserialization of untrusted data from the 'raccookie_guest_email' cookie, allowing unauthenticated attackers to inject PHP objects. While the vulnerable plugin itself does not have a known payload execution chain, the vulnerability could be exploited if another plugin or theme with a compatible chain is installed, potentially leading to unauthorized file deletion, sensitive data exposure, or arbitrary code execution.
WP Online Contract Missing Authorization Vulnerability in WordPress Plugin
A vulnerability exists in the WP Online Contract plugin for WordPress, all versions through 5.1.4, due to a lack of proper capability checks in the json_import() and json_export() functions. This flaw allows unauthenticated attackers to import and export the plugin's settings, potentially leading to unauthorized modifications or data exposure.
WordPress Multiple Plugins Featherlight.js Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in multiple WordPress plugins, including 'Responsive Lightbox & Gallery' and 'WP Featherlight'. This issue arises from the plugins' bundled Featherlight.js library, versions 1.7.13 to 1.7.14, which lacks proper input sanitization and output escaping for user-supplied attributes. As a result, authenticated attackers with contributor-level access or higher can inject arbitrary scripts into pages, which will execute when users access the affected pages.
Staff Directory Plugin: Company Directory Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Staff Directory Plugin: Company Directory for WordPress, affecting all versions through 4.3. The issue arises from the use of the add_query_arg function without proper escaping, allowing unauthenticated attackers to inject arbitrary scripts. These scripts could be executed if a user is tricked into clicking a link.
Listingo WordPress Theme Arbitrary Shortcode Execution Vulnerability
A vulnerability allowing arbitrary shortcode execution has been identified in the Listingo theme for WordPress, affecting all versions through 3.2.7. The issue arises because the theme allows users to execute actions without proper validation, enabling unauthenticated attackers to run arbitrary shortcodes.
Lafka WordPress Theme Demo Import Vulnerability for Authenticated Users
A vulnerability exists in the Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme for WordPress, in all versions through 4.5.7. The issue arises from a missing capability check on the 'lafka_import_lafka' AJAX action, allowing authenticated users with Subscriber-level access and above to import demo data that can overwrite existing site content.
Zass WooCommerce Theme Missing Authorization Vulnerability in Demo Import Feature
A vulnerability exists in the Zass - WooCommerce Theme for Handmade Artists and Artisans, all versions through 3.9.9.10. The issue arises from a lack of proper capability checks on the 'zass_import_zass' AJAX action, allowing authenticated users with Subscriber-level access and above to import demo content and overwrite existing site data.
Hero Slider WordPress Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the Hero Slider - WordPress Slider Plugin, affecting all versions through 1.3.5. The issue arises from inadequate escaping of user-supplied parameters and insufficient preparation of the SQL query, allowing authenticated attackers with Subscriber-level access or higher to inject additional SQL commands. This exploitation could lead to unauthorized access to sensitive database information.
VEDA MultiPurpose WordPress Theme PHP Object Injection Vulnerability
A PHP Object Injection vulnerability has been identified in the VEDA - MultiPurpose WordPress Theme, affecting all versions through 4.2. This vulnerability arises from the deserialization of untrusted input in the 'veda_backup_and_restore_action' function, allowing authenticated attackers with Subscriber-level access and above to inject a PHP object. While the vulnerable theme itself does not have a known PHP Object Injection chain, the impact could be significant if another plugin or theme with such a chain is installed, potentially enabling the attacker to delete files, access sensitive information, or execute code, depending on the nature of the injected object.
Hero Mega Menu WordPress Plugin Arbitrary Directory Deletion Vulnerability
A vulnerability allowing arbitrary file deletion has been identified in the Hero Mega Menu - Responsive WordPress Menu Plugin, affecting all versions through 1.16.5. The issue arises from inadequate file path validation in the hmenu_delete_menu() function, enabling unauthenticated attackers to delete arbitrary directories on the server.
Hero Mega Menu WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Hero Mega Menu - Responsive WordPress Menu Plugin, affecting all versions through 1.16.5. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link that contains the malicious payload.
Hero Mega Menu WordPress Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the Hero Mega Menu - Responsive WordPress Menu Plugin, affecting all versions through 1.16.5. The issue arises from inadequate escaping of user-supplied parameters and insufficient preparation of existing SQL queries. This vulnerability allows authenticated attackers with Subscriber-level access and above to inject additional SQL queries into existing ones, potentially leading to the extraction of sensitive information from the database.
ZoomSounds WordPress Plugin PHP Object Injection Vulnerability
A PHP Object Injection vulnerability has been identified in the ZoomSounds - WordPress Wave Audio Player with Playlist plugin, affecting all versions through 6.91. The vulnerability arises from the deserialization of untrusted input in the 'margs' parameter, allowing unauthenticated attackers to inject PHP objects. While the vulnerable plugin itself does not have a known object injection chain, the impact could be significant if another plugin or theme with such a chain is installed, potentially enabling actions like deleting files, accessing sensitive information, or executing code, depending on the specific object injection chain available.
Master Slider WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Master Slider – Responsive Touch Slider plugin for WordPress, affecting all versions through 3.10.6. The issue arises from inadequate input sanitization and output escaping on user-supplied attributes within the ms_layer shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.
WooMail WooCommerce Email Customizer Missing Authorization Vulnerability Allowing SQL Injection
A vulnerability exists in the WooMail - WooCommerce Email Customizer plugin for WordPress, in all versions through 3.0.34. The issue arises from a lack of proper capability checks in the 'template_delete_saved' function, allowing authenticated attackers with Subscriber-level access or higher to inject SQL into a post deletion query, potentially leading to unauthorized data manipulation.
