CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Feb 19, 2025

Google Chrome Use-After-Free Vulnerability in Network Component Allowing Heap Corruption

A use-after-free vulnerability has been identified in the Network component of Google Chrome, prior to version 133.0.6943.126. This vulnerability allows remote attackers to potentially exploit heap corruption through a crafted web application. The issue arises when network communication errors occur, leading to improper management of stream closure callbacks, which can be manipulated to cause memory corruption.

5.9
Feb 19, 2025

Google Chrome V8 Heap Buffer Overflow Vulnerability Allowing Heap Corruption Exploitation

A heap buffer overflow vulnerability has been identified in the V8 JavaScript engine used by Google Chrome. This issue affects Chrome versions prior to 133.0.6943.126. The vulnerability allows remote attackers to potentially exploit heap corruption by crafting a malicious HTML page. The root cause of the vulnerability lies in the Wasm-to-JS wrapper compilation, where an overly large number of parameters can lead to out-of-bounds memory access, causing heap memory corruption.

6.3
Feb 19, 2025

IBM Cognos Controller and IBM Controller XML External Entity Injection Vulnerability

A vulnerability allowing XML External Entity (XXE) injection has been identified in IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3, as well as in IBM Controller 11.1.0. This vulnerability arises when the application processes XML data, potentially allowing remote attackers to access sensitive information or exhaust memory resources.

3.5
Feb 19, 2025

Cisco BroadWorks Application Delivery Platform Cross-Site Scripting Vulnerability

A cross-site scripting vulnerability has been identified in the web-based management interface of Cisco BroadWorks Application Delivery Platform. This issue allows an unauthenticated, remote attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information. The vulnerability arises because the interface fails to properly validate user-supplied input. An attacker could exploit this by persuading a user to click a crafted link.

3.0
Feb 19, 2025

Cisco Video Phone 8875 and Desk Phone 9800 Series Debug Shell Information Disclosure Vulnerability

A vulnerability exists in the debug shell of Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series. This vulnerability allows an authenticated, local attacker with administrative credentials and SSH access to access sensitive information from the device's underlying operating system. SSH access is disabled by default. The issue arises from inadequate validation of user input by the debug shell, enabling attackers to send crafted SSH client commands through the command-line interface (CLI) to exploit the vulnerability.

2.1
Feb 19, 2025

Cisco Secure Email Gateway Email Filter Bypass Vulnerability

A vulnerability exists in the email filtering mechanism of Cisco Secure Email Gateway, allowing an unauthenticated, remote attacker to bypass established email rules. This flaw enables emails that should have been blocked to be delivered through affected devices. The issue arises from improper handling of certain emails, which attackers can exploit by sending crafted messages that evade filters.

4.6
Feb 19, 2025

LMXCMS Code Injection Vulnerability in Maintenance Component

A code injection vulnerability has been identified in LMXCMS version 1.41, specifically within the Maintenance component's db.inc.php file. This vulnerability allows attackers to inject arbitrary code, which can be executed remotely. The exploitation process is complex and requires a certain level of authentication.

3.2
Feb 19, 2025

IBM Cognos Controller and IBM Controller Formula Injection Vulnerability Allowing Arbitrary Command Execution

A formula injection vulnerability has been identified in IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0. This vulnerability could enable an authenticated attacker to execute arbitrary commands on the system, stemming from inadequate validation of file contents.

2.8
Feb 19, 2025

IBM Cognos Controller and IBM Controller Incorrect Authorization Vulnerability Allowing Content Modification

An incorrect authorization vulnerability has been identified in IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3, as well as in IBM Controller 11.1.0. This vulnerability could enable an authenticated user to modify restricted content.

3.8
Feb 19, 2025

IBM Cognos Controller Cryptographic Weakness Leading to Decryption of Sensitive Information Vulnerability

A vulnerability exists in IBM Cognos Controller versions 11.0.0 to 11.0.1 FP3 and in the IBM Controller 11.1.0 Rich Client. These versions utilize cryptographic algorithms that are weaker than expected, potentially allowing an attacker to decrypt highly sensitive information.

3.4
Feb 19, 2025

IBM Cognos Controller and IBM Controller Unrestricted Deserialization Vulnerability Allowing Arbitrary Code Execution

A vulnerability allowing unrestricted deserialization has been identified in IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0. This vulnerability enables users to execute arbitrary code, escalate privileges, or cause denial-of-service attacks by exploiting the unrestricted deserialization of types within the application.

4.0
Feb 19, 2025

IBM Cognos Controller Cross-Site Scripting Vulnerability

A cross-site scripting vulnerability has been identified in IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3 and in version 11.1.0. This issue allows users to inject arbitrary JavaScript into the Web UI, potentially altering functionality and leading to credential disclosure within a trusted session.

2.6
Feb 19, 2025

IBM Cognos Controller Hard-Coded Database Password Vulnerability in Client Application

A vulnerability exists in the IBM Cognos Controller client application versions 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0. The issue stems from hard-coded database passwords in the source code, which could potentially be exploited for unauthorized access to the system.

3.5
Feb 19, 2025

Baiyi Cloud Asset Management System SQL Injection Vulnerability in Admin Interface

A critical SQL injection vulnerability has been identified in the Baiyi Cloud Asset Management System, specifically in versions prior to 20250204. The issue arises in the '/wuser/admin.house.collect.php' file, where the 'project_id' parameter can be manipulated to execute SQL injection attacks. This vulnerability allows attackers to bypass security measures and directly interact with the database, potentially accessing sensitive information such as database names and table data. The vulnerability can be exploited remotely without authentication, affecting multiple instances of the application.

3.9
Feb 19, 2025

ElementsKit Elementor Addons WordPress Plugin Sensitive Information Exposure Vulnerability

A vulnerability allowing sensitive information exposure exists in the ElementsKit Elementor Addons plugin for WordPress, in all versions through 3.4.0. The issue arises from inadequate capability checks in the 'get_megamenu_content()' function, enabling unauthenticated attackers to access any Elementor-created items, including posts, pages, templates, drafts, trashed, and private items.

3.2
Feb 19, 2025

YaySMTP and Email Logs WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the YaySMTP and Email Logs WordPress plugin, specifically in versions 2.4.9 to 2.6.2. This vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages. The injected scripts are executed when a user accesses the compromised page. Notably, this vulnerability was initially addressed in version 2.4.8 but reappeared in version 2.4.9 after the removal of the wp_kses_post() sanitization function.

3.1
Feb 19, 2025

Small Package Quotes WordPress Plugin Unauthenticated SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the Small Package Quotes – Worldwide Express Edition plugin for WordPress, affecting all versions through 5.2.18. The vulnerability arises from inadequate escaping of user-supplied parameters in the 'edit_id' and 'dropship_edit_id' fields, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to the extraction of sensitive information from the database.

4.4
Feb 19, 2025

Small Package Quotes USPS Edition SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the Small Package Quotes – USPS Edition plugin for WordPress, affecting all versions through 1.3.5. The vulnerability arises from inadequate escaping of user-supplied data in the 'edit_id' parameter, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information within the database.

4.4
Feb 19, 2025

Small Package Quotes for Customers of FedEx WordPress Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the Small Package Quotes – For Customers of FedEx plugin for WordPress, affecting all versions through 4.3.1. The vulnerability arises from inadequate escaping of user-supplied parameters in the 'edit_id' and 'dropship_edit_id' fields, coupled with a lack of proper preparation in the SQL query. This flaw allows unauthenticated attackers to inject additional SQL commands into existing queries, potentially leading to the extraction of sensitive information from the database.

4.4
Feb 19, 2025

LTL Freight Quotes – ABF Freight Edition SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the LTL Freight Quotes – ABF Freight Edition plugin for WordPress, affecting all versions through 3.3.7. The vulnerability arises from inadequate escaping of user-supplied parameters in the 'edit_id' and 'dropship_edit_id' fields, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information within the database.

4.4
Feb 19, 2025

LTL Freight Quotes – SAIA Edition WordPress Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the LTL Freight Quotes – SAIA Edition plugin for WordPress, affecting all versions through 2.2.10. The vulnerability arises from inadequate escaping of user-supplied data in the 'edit_id' and 'dropship_edit_id' parameters, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information within the database.

4.4
Feb 19, 2025

LTL Freight Quotes – R+L Carriers Edition SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the LTL Freight Quotes – R+L Carriers Edition plugin for WordPress, affecting all versions through 3.3.4. The vulnerability arises from inadequate escaping of user-supplied data in the 'edit_id' and 'dropship_edit_id' parameters, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information within the database.

4.4
Feb 19, 2025

LTL Freight Quotes – SEFL Edition WordPress Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the LTL Freight Quotes – SEFL Edition plugin for WordPress, affecting all versions through 3.2.4. The vulnerability arises from inadequate escaping of user-supplied data in the 'dropship_edit_id' and 'edit_id' parameters, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information within the database.

4.4
Feb 19, 2025

LTL Freight Quotes TForce Edition SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the LTL Freight Quotes – TForce Edition plugin for WordPress, affecting all versions through 3.6.4. The vulnerability arises from inadequate escaping of user-supplied data in the 'dropship_edit_id' and 'edit_id' parameters, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to the extraction of sensitive information from the database.

4.4
Feb 19, 2025

Checkmk Sensitive Information Logging Vulnerability in LDAP Integration

A vulnerability exists in Checkmk versions prior to 2.3.0p27, prior to 2.2.0p40, and 2.1.0p51 (EOL), where LDAP credentials are logged to the Apache error log. This occurs when the 'LDAP' log level is set to 'Debug' and an LDAP integration is active. The logged information, including usernames and passwords, is accessible to administrators.

1.9
Feb 19, 2025

LTL Freight Quotes WordPress Plugin Unauthenticated SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the LTL Freight Quotes – Old Dominion Edition plugin for WordPress, affecting all versions through 4.2.10. The vulnerability arises from inadequate escaping of user-supplied parameters in the SQL query, allowing unauthenticated attackers to inject additional SQL commands. This exploitation could lead to unauthorized access to sensitive information in the database.

4.4
Feb 19, 2025

ChurchCRM Boolean-Based and Time-Based Blind SQL Injection Vulnerability in BatchWinnerEntry Functionality

A SQL injection vulnerability has been identified in ChurchCRM versions through 5.13.0. This vulnerability allows attackers to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL injection in the BatchWinnerEntry functionality. The issue arises because the CurrentFundraiser parameter is concatenated into an SQL query without proper sanitization, enabling attackers to manipulate database queries and execute arbitrary commands. Exploitation of this vulnerability could lead to unauthorized data access, modification, or deletion. Notably, this vulnerability requires administrator privileges to exploit.

3.7
Feb 19, 2025

ChurchCRM Boolean-Based and Time-Based Blind SQL Injection Vulnerability in DonatedItemEditor

A SQL injection vulnerability has been identified in ChurchCRM versions through 5.13.0. This vulnerability allows attackers to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL injection in the DonatedItemEditor functionality. The CurrentFundraiser parameter is concatenated into an SQL query without proper sanitization, enabling attackers to manipulate database queries and execute arbitrary commands. This could lead to unauthorized data exfiltration, modification, or deletion. Exploitation of this vulnerability requires administrator privileges.

3.7
Feb 19, 2025

ChurchCRM Boolean-Based Blind SQL Injection Vulnerability in EditEventAttendees Function

A boolean-based blind SQL injection vulnerability has been identified in ChurchCRM versions through 5.13.0. This vulnerability allows attackers with administrator privileges to execute arbitrary SQL queries by manipulating the EID parameter, which is directly concatenated into an SQL query without proper sanitization. Exploitation of this vulnerability could lead to unauthorized data access, modification, or deletion.

3.7
Feb 19, 2025

ChurchCRM Time-Based Blind SQL Injection Vulnerability in EditEventAttendees.php

A time-based blind SQL injection vulnerability has been identified in ChurchCRM versions through 5.13.0. The issue resides in the EditEventAttendees.php file, specifically within the EN_tyid parameter, which is vulnerable to injection as it is directly included in an SQL query without adequate sanitization. This vulnerability requires administrator permissions to exploit. Attackers can use this flaw to introduce malicious SQL commands, potentially leading to unauthorized data access or manipulation by exploiting the time-based nature of the injection to extract information from the database.

3.7
Feb 19, 2025

ChurchCRM Reflected Cross-Site Scripting Vulnerability in EditEventAttendees.php Allowing Session Hijacking

A reflected cross-site scripting vulnerability has been identified in ChurchCRM version 5.13.0, specifically on the EditEventAttendees.php page. This issue allows an attacker with administrative privileges to execute arbitrary JavaScript in the context of a victim's browser, targeting the EID parameter. The exploitation of this vulnerability could lead to session hijacking, as attackers can steal session cookies, impersonate users, and gain unauthorized access to the application.

3.6
Feb 19, 2025

OpenVSX Improper Authorization Vulnerability in Namespace Details API

A vulnerability exists in OpenVSX versions 0.9.0 through 0.20.0, allowing users to edit namespace details via the '/user/namespace/{namespace}/details' API, regardless of their ownership or contribution status. Affected details include the namespace name, description, website, support link, and social media links. The vulnerability also extends to the '/user/namespace/{namespace}/details/logo' endpoint, where users could change the namespace logo without proper authorization.

3.8
Feb 19, 2025

Raptive Ads WordPress Plugin Missing Authorization Vulnerability Allowing Unauthenticated Data Reset

A vulnerability exists in the Raptive Ads plugin for WordPress, all versions through 3.6.3, due to a lack of proper capability checks in the site_ads_files_reset() and cls_file_reset() functions. This flaw enables unauthenticated attackers to reset ad and CLS files, potentially disrupting ad management and performance optimization settings.

2.5
Feb 19, 2025

Raptive Ads WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Raptive Ads plugin for WordPress, affecting all versions through 3.6.3. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link or performing a similar action.

2.7
Feb 19, 2025

DeBounce Email Validator WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the DeBounce Email Validator plugin for WordPress, affecting all versions through 5.7. The vulnerability arises from inadequate nonce validation on the 'debounce_email_validator' page, allowing unauthenticated attackers to manipulate settings and inject malicious scripts. Exploitation requires tricking a site administrator into clicking a link.

2.5
Feb 19, 2025

Disable Auto Updates WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Disable Auto Updates plugin for WordPress, affecting all versions through 1.4. The issue arises from inadequate nonce validation on the 'disable-auto-updates' page, allowing unauthenticated attackers to disable auto updates by sending a forged request, provided they can persuade a site administrator to click a link.

2.0
Feb 19, 2025

WordPress Portfolio Builder - Portfolio Gallery Missing Authorization Vulnerability in Video Addition Function

A vulnerability exists in the WordPress Portfolio Builder - Portfolio Gallery plugin, specifically in versions through 1.1.7. The issue arises from a lack of proper capability checks in the 'add_video' function, allowing unauthenticated users to add arbitrary videos to any portfolio gallery. This unauthorized data modification could be exploited by attackers to manipulate portfolio content without authentication.

3.5
Feb 19, 2025

WP Media Category Management Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP Media Category Management plugin for WordPress, affecting versions 2.0 to 2.3.3. The vulnerability arises from inadequate nonce validation in the 'wp_mcm_handle_action_settings()' function, allowing unauthenticated attackers to manipulate plugin settings. This could include changing the media taxonomy, the base slug for media categories, and the default media category, by tricking a site administrator into clicking a link that triggers the forged request.

3.0
Feb 19, 2025

Education Addon for Elementor Insecure Direct Object Reference Vulnerability

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Education Addon for Elementor plugin for WordPress, affecting all versions through 1.3.1. The vulnerability arises from missing validation on a user-controlled key in the naedu_elementor_template shortcode. This flaw enables authenticated attackers with Contributor-level access and above to access and extract information from non-public posts, including drafts, password-protected content, and restricted posts. The issue specifically pertains to posts created with Elementor.

2.1
Feb 19, 2025

Pure Chat WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Pure Chat – Live Chat & More! WordPress plugin, affecting all versions through 2.4. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts would execute when a user accesses the compromised page.

2.4
Feb 19, 2025

PeproDev Ultimate Invoice WordPress Plugin Insecure Direct Object Reference Vulnerability

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the PeproDev Ultimate Invoice plugin for WordPress, affecting all versions through 2.0.8. The vulnerability arises in the invoicing viewer, where missing validation on a user-controlled key allows unauthenticated attackers to access invoices for completed orders. These invoices may contain personally identifiable information (PII) of users.

2.0
Feb 19, 2025

Pollin WordPress Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the Pollin plugin for WordPress, affecting all versions through 1.01.1. The issue arises from inadequate escaping of user-supplied data in the 'question' parameter, coupled with insufficient preparation of the SQL query. This vulnerability allows unauthenticated attackers to inject additional SQL commands into existing queries, potentially leading to the extraction of sensitive information from the database.

2.5
Feb 19, 2025

Pollin WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Pollin plugin for WordPress, affecting all versions through 1.01.1. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link.

2.5
Feb 19, 2025

Widget BUY.BOX Stored Cross-Site Scripting Vulnerability for WordPress

A stored cross-site scripting vulnerability has been identified in the Widget BUY.BOX plugin for WordPress, affecting all versions through 3.1.5. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'buybox-widget' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected page.

2.3
Feb 19, 2025

Categorized Gallery Plugin SQL Injection Vulnerability for WordPress

A SQL injection vulnerability has been identified in the Categorized Gallery Plugin for WordPress, affecting all versions up to and including 2.0. The issue arises from inadequate escaping of user-supplied parameters in the 'field' attribute of the 'image_gallery' shortcode, coupled with a lack of proper preparation in the SQL query. This vulnerability allows authenticated attackers with Contributor-level access and above to inject additional SQL queries into existing ones, potentially leading to the extraction of sensitive information from the database.

2.7
Feb 19, 2025

Cosmic Blocks WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Cosmic Blocks (40+) Content Editor Blocks Collection plugin for WordPress, affecting all versions through 1.3.0. The vulnerability arises from inadequate input sanitization and output escaping on user-supplied attributes, particularly within the 'cwp_social_share' shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the compromised pages.

1.6
Feb 19, 2025

Coaching Staffs WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Coaching Staffs plugin for WordPress, affecting all versions through 1.4. The issue arises from inadequate input sanitization and output escaping on user-supplied attributes, particularly within the 'mstw-cs-table' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.

2.7
Feb 19, 2025

Responsive Flickr Slideshow WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Responsive Flickr Slideshow plugin for WordPress, affecting all versions through 2.6.1. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'fshow' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected page.

2.3
Feb 19, 2025

Store Locator Widget for WordPress Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Store Locator Widget plugin for WordPress, affecting all versions prior to 20200131. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'storelocatorwidget' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected page.

2.3
Feb 19, 2025

Team Builder For WPBakery Page Builder Local File Inclusion Vulnerability

A local file inclusion vulnerability has been identified in the Team Builder For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress, affecting all versions through 1.0. The vulnerability arises in the 'team-builder-vc' shortcode, allowing authenticated attackers with Contributor-level access and above to include and execute arbitrary files on the server. This exploitation can be used to bypass access controls, access sensitive data, or execute code by including files that contain PHP code, especially in scenarios where 'safe' file types like images can be uploaded and included.

1.9