CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Drivin Soluções Cross-Site Scripting Vulnerability in API Handler
A cross-site scripting (XSS) vulnerability has been identified in Drivin Soluções versions prior to 20250226. The issue resides in the API Handler component, specifically within the '/api/school/registerSchool' endpoint. The vulnerability is triggered by manipulating the 'message' argument, which is not properly sanitized before being output to users. This flaw allows remote attackers to inject malicious scripts that are executed in the context of the user's browser.
X.Org X Server Race Condition Vulnerability Leading to Crashes
A race condition vulnerability has been identified in X.Org X Server versions 20.11 through 21.1.16. When a client application utilizes Easystroke for mouse gestures, the main thread can modify data structures used by the input thread without proper synchronization, creating a potential for data corruption. This issue arises because the AttachDevice function in dix/devices.c fails to acquire an input lock, allowing concurrent threads to interfere with each other. The vulnerability can lead to segmentation faults and application crashes, particularly when the system is under heavy load and Easystroke is used to scroll pages quickly.
Springboot-OpenAI-ChatGPT Improper Access Control Vulnerability in Chat History Deletion
An access control vulnerability has been identified in the Springboot-OpenAI-ChatGPT application, specifically in version e84f6f5. The issue arises in the Chat History Handler component, within the deleteChat function of the API endpoint /api/mjkj-chat/chat/ai/delete/chat. The vulnerability allows users to delete another user's chat history by manipulating the chatListId parameter, leading to unauthorized deletion of chat records. This vulnerability can be exploited remotely and has been publicly disclosed, with a proof-of-concept exploit available.
WordPress All In Menu Plugin SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in the WordPress All In Menu plugin, affecting versions through 1.1.5. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing attackers to manipulate database queries and potentially access or modify database information.
NotFound FS Poster WordPress Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the NotFound FS Poster WordPress plugin, affecting versions through 6.5.8. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing malicious actors to interact directly with the database. Such exploitation could lead to unauthorized data access or manipulation.
Aldo Latino PrivateContent SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the Aldo Latino PrivateContent WordPress plugin, affecting versions through 8.11.4. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing malicious actors to interact directly with the database. Such exploitation could lead to unauthorized data access or manipulation.
WordPress PrivateContent Plugin Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in the WordPress PrivateContent plugin, affecting versions through 8.11.5. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.
WordPress PrivateContent Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the WordPress PrivateContent plugin, affecting versions through 8.11.5. This vulnerability allows unprivileged users to perform actions reserved for higher privileges, due to a lack of proper checks in the plugin's functionality.
NotFound Fresh Framework Missing Authorization Vulnerability Allowing Unrestricted Access to Functionality
A missing authorization vulnerability has been identified in the NotFound Fresh Framework, specifically in versions through 1.70.0. This vulnerability allows users to access functionality that is not properly restricted by access control lists (ACLs), potentially leading to unauthorized actions or data exposure.
WordPress Pie Register Premium Path Traversal Vulnerability
A path traversal vulnerability has been identified in the WordPress Pie Register Premium plugin, affecting versions through 3.8.3.2. This vulnerability allows for non-arbitrary file deletion by exploiting the path traversal flaw.
NotFound Ohio Extra WordPress Plugin Code Injection Vulnerability
A code injection vulnerability has been identified in the NotFound Ohio Extra WordPress plugin, affecting versions through 3.4.7. This vulnerability allows for improper control over code generation, enabling malicious actors to inject their own content into pages and posts. Such an injection could be exploited to introduce phishing pages or other harmful content into the affected website.
WordPress Booking and Rental Manager Plugin PHP Object Injection Vulnerability
A deserialization vulnerability allowing object injection has been identified in the WordPress Booking and Rental Manager Plugin, affecting versions through 2.2.6. This vulnerability arises from the deserialization of untrusted data, which could potentially lead to various injection attacks or code execution if exploited.
Recapture for WooCommerce Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Recapture Cart Recovery and Email Marketing Recapture for WooCommerce plugin, affecting versions through 1.0.43. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress m1.DownloadList Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress m1.DownloadList plugin, affecting versions through 0.19. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts or HTML payloads on the site.
PublishPress Authors SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the PublishPress Authors WordPress plugin, affecting versions through 4.7.3. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially enabling malicious actors to interact with the database and steal information.
WordPress Multiple Shipping and Billing Address for WooCommerce SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WordPress plugin 'Multiple Shipping and Billing Address for WooCommerce', affecting versions through 1.3. This vulnerability allows attackers to improperly neutralize special elements used in SQL commands, potentially leading to unauthorized database manipulation or information disclosure.
WordPress WP AntiDDOS Plugin Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress WP AntiDDOS plugin, affecting versions through 2.0. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.
WordPress Debug Bar Extender Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress Debug Bar Extender plugin, specifically in versions through 0.5. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.
WordPress WP Discord Post Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress WP Discord Post plugin, affecting versions through 2.1.0. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.
Spring Devs Pre Order Addon for WooCommerce Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Spring Devs Pre Order Addon for WooCommerce, specifically in the Advance Order/Backorder Plugin, versions through 2.2. This vulnerability arises from improper input neutralization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.
NotFound Random Image Selector Plugin Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the NotFound Random Image Selector WordPress plugin, affecting versions through 2.4. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Random Posts, Mp3 Player + ShareButton Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress plugin 'Random Posts, Mp3 Player + ShareButton', affecting versions through 1.4.1. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.
Hikashop Component Privilege Escalation Vulnerability for Joomla
A privilege escalation vulnerability exists in the Hikashop component for Joomla, specifically in versions 1.0.0 prior to 5.1.3. This vulnerability allows authenticated administrators to escalate their privileges to Super Admin rights.
Springboot OpenAI ChatGPT Behavioral Workflow Vulnerability in Question Handler
A vulnerability exists in the Springboot OpenAI ChatGPT application, specifically in version e84f6f5. This issue allows any user to manipulate the number of questions they are permitted to ask by accessing the updateQuestionCou function through a specific API endpoint. The vulnerability arises from improper management of the workflow sequence, enabling users to bypass intended restrictions. As a result, this flaw could potentially be exploited to disrupt the application's expected behavior.
Springboot OpenAI ChatGPT Hard-Coded Credentials Vulnerability
A critical vulnerability has been identified in the Springboot OpenAI ChatGPT project, specifically in the commit e84f6f5. The issue arises from hard-coded credentials in the file OpenController.java, located in the chatgpt-boot module. This vulnerability allows remote exploitation without requiring authentication, potentially leading to unauthorized access with administrative privileges.
springboot-openai-chatgpt Business Logic Vulnerability in Data Addition API
A critical business logic vulnerability has been identified in the springboot-openai-chatgpt application, specifically in version e84f6f5. The issue arises in the API endpoint '/api/mjkj-chat/cgform-api/addData/', where the 'chatUserID' parameter can be manipulated. This vulnerability allows normal users to bypass permission checks and add data on behalf of other users, potentially leading to unauthorized actions or data manipulation.
GiveWP Donation Plugin Missing Capability Check Vulnerability in Earnings Report Function
A vulnerability exists in the GiveWP Donation Plugin for WordPress, specifically in versions through 3.22.0. The issue arises from a missing capability check in the give_reports_earnings() function, allowing unauthenticated users to access and disclose sensitive data from earnings reports. This unauthorized access could lead to the exposure of confidential information related to donations and fundraising activities.
Tripetto WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Arbitrary Results Deletion
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Tripetto plugin for WordPress, affecting all versions through 8.0.9. The vulnerability arises from inadequate nonce validation, enabling unauthenticated attackers to delete arbitrary results by sending a forged request, provided they can deceive a site administrator into clicking a link.
Keylime Strict Type Checking Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability exists in Keylime version 7.12.0 due to strict type checking that prevents the registrar from processing agent registration data from previous versions, such as 7.11.0. Older versions store registration data as bytes, while the updated registrar requires strings. This mismatch causes exceptions when handling registration requests, resulting in agent failures.
WP Test Email Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WP Test Email plugin for WordPress, affecting all versions through 1.1.8. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into email logs. These scripts are executed when a user accesses the compromised page.
Foreman and Red Hat Satellite Temporary File Permission Vulnerability Allowing Information Disclosure
A vulnerability exists in Foreman/Red Hat Satellite due to improper file permissions on temporary files created under /var/tmp during job execution. This flaw enables low-privileged OS users to access and read command outputs, potentially exposing sensitive information such as system credentials or configuration details. While this vulnerability does not directly escalate privileges, it increases the risk of information disclosure, which could be exploited in further attacks.
WordPress Thumbnail Carousel Slider SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the Thumbnail Carousel Slider plugin for WordPress, affecting all versions through 1.0.4. The issue arises from inadequate escaping of user-supplied parameters in the 'id' parameter, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information within the database.
tj-actions/changed-files GitHub Action Memory Dump Vulnerability Allowing Secret Exposure
A vulnerability in the GitHub Action 'tj-actions/changed-files' was introduced by a malicious commit that retroactively updated all version tags to point to the compromised code. This vulnerability, which has been assigned CVE-2025-30066, allows for the unauthorized dumping of CI/CD secrets from the GitHub Actions runner's memory. The leaked secrets are then printed in the workflow logs, where they can be accessed by anyone.
Traveler WordPress Theme Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Traveler theme for WordPress, affecting all versions through 3.1.8. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages. These scripts could be executed if a user is tricked into clicking a link or performing a similar action.
Traveler WordPress Theme Local File Inclusion Vulnerability
A local file inclusion vulnerability has been identified in the Traveler theme for WordPress, affecting all versions through 3.1.8. The issue arises in the 'hotel_alone_load_more_post' function, specifically through the 'style' parameter. This vulnerability allows unauthenticated attackers to include and execute arbitrary files on the server, potentially executing any PHP code contained in those files. Exploitation could lead to bypassing access controls, accessing sensitive data, or executing code in scenarios where PHP files can be uploaded and included.
WordPress Tripetto Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Tripetto WordPress plugin, which is used for creating contact forms, surveys, and quizzes. This vulnerability exists in all versions up to and including 8.0.9. It arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to upload attachments that inject arbitrary scripts. These scripts execute when users access the uploaded files.
WP01 Plugin for WordPress Arbitrary File Download Vulnerability
A vulnerability allowing arbitrary file download has been identified in the WP01 plugin for WordPress, affecting all versions through 2.6.2. The issue arises from a missing capability check and inadequate restrictions on the make_archive() function, enabling authenticated attackers with Subscriber-level access and above to download and access the contents of arbitrary files on the server, potentially exposing sensitive information.
WordPress Pixelstats Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Pixelstats plugin for WordPress, affecting all versions through 0.8.2. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link or performing a similar action.
Zoorum Comments WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Zoorum Comments plugin for WordPress, affecting all versions through 0.9. The issue arises from inadequate nonce validation in the zoorum_set_options() function, allowing unauthenticated attackers to manipulate settings and inject malicious scripts. Exploitation requires tricking a site administrator into clicking a link that initiates the forged request.
WPSchoolPress SQL Injection Vulnerability in WordPress Plugin
A SQL injection vulnerability has been identified in the WPSchoolPress WordPress plugin, specifically in the School Management System version 2.2.16 and earlier. The issue arises from inadequate escaping of user-supplied data in the 'cid' parameter, allowing authenticated attackers with Custom-level access or higher to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information within the database.
WPSchoolPress WordPress Plugin Privilege Escalation Vulnerability Allowing Account Takeover
A privilege escalation vulnerability has been identified in the WPSchoolPress WordPress plugin, specifically in the School Management System version 2.2.16 and prior. The issue arises from a missing capability check in the 'wpsp_UpdateTeacher()' function, which allows authenticated attackers with teacher-level access or higher to modify user details, including email addresses. This exploitation could lead to unauthorized access to user accounts, such as administrators, by facilitating a password reset request.
WC Affiliate WooCommerce Plugin Missing Capability Check Vulnerability Allowing Data Export
A vulnerability exists in the WC Affiliate – A Complete WooCommerce Affiliate Plugin for WordPress, in all versions through 2.5.3. The issue arises from a missing capability check in the 'export_all_data' function, which allows authenticated users with Subscriber-level access and above to export sensitive affiliate information, including personally identifiable information (PII).
Directory Listings WordPress Plugin - uListing Missing Authorization Vulnerability Allowing Arbitrary Post Meta Update and PHP Object Injection
A vulnerability exists in the Directory Listings WordPress plugin, specifically in the uListing plugin, versions through 2.2.0. The issue arises from a missing capability check on the 'stm_listing_ajax' AJAX action, allowing authenticated attackers with subscriber-level access and above to unauthorizedly modify post meta data and inject PHP objects that could be unserialized. Although a capability check was introduced in version 2.1.8, the vulnerability related to unserialization remains unaddressed.
uListing WordPress Plugin Privilege Escalation Vulnerability
A privilege escalation vulnerability exists in the uListing WordPress plugin, specifically in the Directory Listings plugin by Stylemix, in all versions through 2.2.0. The issue arises because the stm_listing_profile_edit AJAX action lacks proper restrictions on the user meta that can be modified. This flaw enables authenticated attackers with Subscriber-level access or higher to elevate their privileges to that of an administrator.
Springboot-OpenAI-ChatGPT Improper Authorization Vulnerability
A critical improper authorization vulnerability has been identified in the Springboot-OpenAI-ChatGPT application, specifically in version e84f6f5. The issue arises in the User Handler component, within the submit function of the file /api/blade-user/submit. This vulnerability allows ordinary users to create super administrator accounts by exploiting the lack of permission checks, thereby exceeding their authorized privileges. The vulnerability can be exploited remotely, without any authentication requirements.
EDK2 Integer Overflow Vulnerability in iSCSI DXE Component Leading to Denial-of-Service
A vulnerability exists in the EDK2 iSCSI DXE component, specifically in versions through 202502, where a user can cause an integer overflow or wraparound via network means. This vulnerability arises when the iSCSI 'Ready To Transfer' (R2T) Protocol Data Units (PDUs) are processed. The exploitation of this vulnerability can lead to a denial-of-service condition by causing the BIOS to reveal memory contents from the iSCSI target, creating a remote memory exposure issue.
HDF5 Heap-Based Buffer Overflow Vulnerability in Metadata Attribute Decoder
A critical heap-based buffer overflow vulnerability has been identified in HDF5 version 1.14.6. The issue arises in the Metadata Attribute Decoder component, specifically within the H5MM_strndup function. This vulnerability allows for memory corruption and application crashes, and could potentially be exploited for arbitrary code execution. The buffer overflow occurs when the library reads 5 bytes beyond the boundary of a 320-byte heap-allocated memory region. Exploitation of this vulnerability requires local access.
HDF5 Heap-Based Buffer Overflow Vulnerability in Type Conversion Logic
A critical heap-based buffer overflow vulnerability has been identified in HDF5 version 1.14.6. This issue arises in the 'H5T__bit_copy' function within the type conversion logic, where the library improperly handles data copying, leading to a memory corruption vulnerability. Local access is required to exploit this vulnerability, which has been publicly disclosed and is available as a proof-of-concept exploit.
HDF5 Heap-Based Buffer Overflow Vulnerability in Scale-Offset Filter Decompression Function
A critical heap-based buffer overflow vulnerability has been identified in HDF5 version 1.14.6. This issue arises in the Scale-Offset Filter's decompression function, H5Z__scaleoffset_decompress_one_byte, where the library improperly handles data, leading to a heap memory overflow. The vulnerability requires local exploitation.
WeGIA Stored Cross-Site Scripting Vulnerability in Document Type Management Endpoint
A stored cross-site scripting vulnerability has been identified in the WeGIA application, specifically in versions prior to 3.2.17. The issue resides in the 'adicionar_tipo_docs_atendido.php' endpoint, where the 'tipo' parameter is vulnerable to script injection. Malicious scripts injected through this parameter are stored on the server and executed automatically when the affected page is accessed by users, creating a significant security risk. This vulnerability allows for various attacks, including session hijacking, credential theft, and the distribution of malware.
