CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 30, 2025

Ninja Forms Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Ninja Forms WordPress plugin, specifically in versions through 3.8.24. This issue arises from inadequate input sanitization and output escaping on user-supplied attributes within the plugin's shortcode. As a result, authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages, which will be executed when a user accesses the affected page.

5.7
Jan 30, 2025

Stratum Elementor Widgets WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Stratum – Elementor Widgets plugin for WordPress, affecting all versions through 1.4.7. The issue arises in the Image Hotspot widget, where inadequate input sanitization and output escaping on user-supplied attributes allow authenticated attackers with contributor-level access or higher to inject arbitrary scripts. These scripts execute when a user accesses the compromised page.

2.4
Jan 30, 2025

Event Tickets WordPress Plugin Insecure Direct Object Reference Vulnerability

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Event Tickets and Registration plugin for WordPress, affecting all versions through 5.18.1. The vulnerability arises from the tc-order-id parameter, which lacks proper validation, allowing unauthenticated attackers to access order details of other users. This includes sensitive information such as ticket prices, user emails, and order dates.

3.0
Jan 30, 2025

EthereumICO WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the EthereumICO plugin for WordPress, affecting all versions through 2.4.6. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's ethereum-ico shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.3
Jan 30, 2025

Bulk Me Now! WordPress Plugin Cross-Site Request Forgery Vulnerability

A vulnerability in the Bulk Me Now! WordPress plugin, affecting versions through 2.0, allows for Cross-Site Request Forgery (CSRF) attacks. The plugin lacks proper CSRF checks in certain areas, which could enable attackers to manipulate logged-in users into performing unintended actions.

3.3
Jan 30, 2025

Bulk Me Now! WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Bulk Me Now! WordPress plugin, affecting versions through 2.0. The issue arises because the plugin fails to properly validate and escape certain shortcode attributes before rendering them on pages or posts. This flaw enables users with contributor roles and above to inject malicious scripts that are stored and executed later.

2.9
Jan 30, 2025

Bulk Me Now! WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Bulk Me Now! WordPress plugin, affecting versions through 2.0. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.

3.4
Jan 30, 2025

Tourmaster WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Tourmaster WordPress plugin, affecting versions prior to 5.3.5. The issue arises because the plugin fails to properly escape generated URLs before inserting them into attributes, allowing for the injection of malicious scripts.

3.4
Jan 30, 2025

GoodLayers Core WordPress Plugin SVG Upload Vulnerability Allowing Malicious Payloads

A vulnerability exists in the GoodLayers Core WordPress plugin in versions prior to 2.1.3. It allows users with a subscriber role and above to upload SVG files containing malicious payloads. This could lead to stored cross-site scripting (XSS) vulnerabilities, as the uploaded SVGs could be used to execute scripts in the context of the user viewing the content.

3.0
Jan 30, 2025

Tracking Code Manager WordPress Plugin Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Tracking Code Manager WordPress plugin, affecting versions prior to 2.4.0. The issue arises because the plugin fails to properly sanitize and escape certain metabox settings before displaying them on the page. This flaw enables users with a minimum role of Contributor to execute cross-site scripting attacks.

3.9
Jan 30, 2025

Dell Networking Switches Enterprise SONiC OS Insertion of Sensitive Information into Log File Vulnerability

A vulnerability allowing the insertion of sensitive information into log files has been identified in Dell Networking Switches running Enterprise SONiC OS, versions prior to 4.4.1 and 4.2.3. This vulnerability could be exploited by a high-privileged attacker with remote access, leading to unauthorized information exposure.

1.5
Jan 30, 2025

FreeBSD Ktrace Uninitialized Memory Disclosure Vulnerability

A vulnerability in the ktrace facility of FreeBSD 14.2 has been identified, allowing unprivileged userspace programs to leak up to 14 bytes of uninitialized kernel heap memory to userspace. This occurs because ktrace improperly handles variable-sized sockaddr structures, copying the full size even when the actual data is shorter, thereby exposing unused bytes of kernel memory.

3.6
Jan 30, 2025

FreeBSD etcupdate Unprivileged Access to Sensitive System Files Vulnerability

A vulnerability exists in the FreeBSD etcupdate utility, which is used to manage updates to system files. When etcupdate encounters conflicts while merging files, it creates a temporary version in /var/db/etcupdate/conflicts that contains conflict markers. This version is world-readable and does not preserve the original file permissions, potentially exposing sensitive information from files that typically have restricted access, such as /etc/master.passwd. An unprivileged local user could exploit this to read encrypted passwords for root and other users, but only if conflicts arise in the password file during an update, and the unprotected file is not deleted after the conflicts are resolved.

3.2
Jan 30, 2025

FreeBSD Stack Buffer Overflow Vulnerability in VOP_VPTOFH() Implementation on NFS-exported Filesystems

A stack buffer overflow vulnerability has been identified in the VOP_VPTOFH() implementation of the cd9660, tarfs, and ext2fs filesystems on 64-bit FreeBSD systems. This vulnerability occurs when the filesystem identifier (FID) buffer is overflowed by 4 bytes, leading to a stack buffer overflow. An NFS server exporting any of these filesystems can be made to panic by mounting and accessing the export with an NFS client. While further exploitation, such as bypassing file permission checks or remote kernel code execution, could potentially be achieved, this has not been demonstrated. Notably, release kernels have stack protection enabled, which catches some instances of the overflow and causes a panic.

3.6
Jan 30, 2025

CampCodes School Management Software Improper Authorization Vulnerability in Staff Handler Component

A critical vulnerability has been identified in CampCodes School Management Software version 1.0. The issue resides in the Staff Handler component, specifically within an unknown function of the file '/edit-staff/'. This vulnerability allows for improper authorization, enabling remote exploitation. The issue has been publicly disclosed and is associated with the Common Weakness Enumeration (CWE) identifiers CWE-285 and CWE-266.

3.1
Jan 30, 2025

Tenda A18 Stack-Based Buffer Overflow Vulnerability in HTTP POST Request Handler Allows Remote Code Execution

A critical stack-based buffer overflow vulnerability has been identified in the Tenda A18 router, specifically in versions through 15.13.07.09. The issue arises in the HTTP POST request handler, within the SetCmdlineRun function. The vulnerability is triggered by manipulating the wpapsk_crypto5g parameter, leading to a stack overflow that can be exploited remotely. This flaw allows attackers to overwrite the return address and execute arbitrary code on the device.

3.1
Jan 30, 2025

1000 Projects Employee Task Management System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in the 1000 Projects Employee Task Management System version 1.0. The issue resides in the Login component, specifically within the '/index.php' file. The vulnerability allows remote attackers to inject malicious SQL queries through the 'email' parameter, exploiting insufficient input validation. This could lead to unauthorized database access, data manipulation, and potential leakage of sensitive information.

3.6
Jan 30, 2025

1000 Projects Employee Task Management System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in the 1000 Projects Employee Task Management System version 1.0. The issue resides in the AdminLogin.php file, where the 'email' parameter is manipulated, allowing attackers to inject malicious SQL queries. This vulnerability can be exploited remotely, without any authentication, potentially leading to unauthorized database access, data modification or deletion, and exposure of sensitive information.

4.3
Jan 30, 2025

Needyamin Library Card System Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in Needyamin Library Card System version 1.0. The issue resides in the signup.php file within the Registration Page component. This vulnerability allows for the injection of malicious scripts through the firstname, lastname, email, borrow, and user_address fields. The injected scripts are executed when the data is viewed, potentially leading to malware distribution, unauthorized account access, data breaches, and reputational damage.

3.4
Jan 29, 2025

Microsoft Azure AI Face Service Authentication Bypass Vulnerability Allowing Privilege Escalation

A vulnerability in Azure AI Face Service allows an authorized attacker to bypass authentication by spoofing, potentially leading to unauthorized privilege escalation over the network. This issue affects all versions of the Azure AI Face Service.

1.8
Jan 29, 2025

Microsoft Account Privilege Escalation Vulnerability

A vulnerability in Microsoft Account allows unauthorized attackers to elevate privileges over a network due to missing authorization. This issue could enable attackers to gain elevated rights or access, potentially leading to unauthorized actions or changes within a system or application.

2.5
Jan 29, 2025

Needyamin Library Card System SQL Injection Vulnerability in Admin Panel

A critical SQL injection vulnerability has been identified in the Needyamin Library Card System version 1.0. The issue arises in the Admin Panel, specifically within the 'admindashboard.php' file. The vulnerability allows remote attackers to manipulate the 'email' and 'password' arguments, leading to unauthorized database access. This flaw could be exploited to bypass authentication and gain access to the admin dashboard.

3.1
Jan 29, 2025

JFinalCMS SQL Injection Vulnerability in Content Filtering

A SQL injection vulnerability has been identified in JFinalCMS version 1.0, specifically within the Content entity file. The issue arises because the 'title' parameter is directly concatenated into the SQL filter without proper sanitization. This flaw allows for the manipulation of SQL queries, potentially leading to unauthorized data access or modification. The vulnerability is exploitable only when the 'categoryId' parameter is null.

4.7
Jan 29, 2025

Deep Java Library Path Traversal Vulnerability in Zip and Tar Utilities

A path traversal vulnerability has been identified in the Deep Java Library (DJL) version 0.1.0 prior to 0.31.0. This issue affects the ZipUtils.unzip and TarUtils.untar functions across all platforms, allowing an attacker to write files to arbitrary locations. Exploitation of this vulnerability could lead to unauthorized SSH access by injecting an SSH key into the authorized_keys file, or the upload of HTML files that could be used to exploit cross-site scripting vulnerabilities.

2.1
Jan 29, 2025

Needyamin Library Card System SQL Injection Vulnerability in Login Component

A critical SQL injection vulnerability has been identified in Needyamin Library Card System version 1.0. The issue arises in the admin.php file within the Login component, where the application fails to properly sanitize the email and password input, allowing for malicious SQL code to be executed. This vulnerability can be exploited remotely, potentially leading to unauthorized access and manipulation of the application's database.

3.1
Jan 29, 2025

Bento4 Floating-Point Exception Vulnerability in TfraAtom Function

A floating-point exception vulnerability has been identified in the Bento4 media processing library, specifically within the 'mp42hevc' component. This vulnerability arises in the 'AP4_TfraAtom::AP4_TfraAtom' function, where improper handling of data can lead to a floating-point exception, potentially causing a denial-of-service condition.

3.8
Jan 29, 2025

Bento4 Mp42avc Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

A buffer overflow vulnerability has been identified in Bento4's mp42avc application, specifically in the commit related to this issue. This vulnerability allows a local attacker to execute arbitrary code by exploiting the AP4_MemoryByteStream::WritePartial function. The issue arises from improper handling of data, leading to memory corruption that can be manipulated to execute malicious code.

2.6
Jan 29, 2025

Bento4 mp42avc Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

A buffer overflow vulnerability has been identified in Bento4's mp42avc application, specifically in the commit related to this issue. This vulnerability allows a local attacker to execute arbitrary code by exploiting the AP4_File::ParseStream function and related stream parsing functions. The issue arises from improper handling of data streams, leading to memory corruption that can be manipulated to execute malicious code.

2.6
Jan 29, 2025

Safety Production Process Management System Password Vulnerability Allowing Privilege Escalation and Arbitrary Code Execution

A vulnerability exists in Safety Production Process Management System version 1.0, allowing remote attackers to escalate privileges, execute arbitrary code, and access sensitive information. This issue arises from inadequate password handling, as the application improperly validates the password and account number parameters.

4.0
Jan 29, 2025

Teedy LDAP Injection Vulnerability Allowing Account Creation and Password Spraying

A vulnerability allowing LDAP injection has been identified in Teedy versions 1.9 to 1.12, when LDAP connection is enabled. The issue arises from inadequate sanitization of user input in the username field of the login form. This flaw allows an unauthenticated attacker to manipulate LDAP queries, potentially leading to the creation of arbitrary user accounts and password spraying attacks.

3.8
Jan 29, 2025

Teedy Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in Teedy versions through 1.12, due to inadequate CSRF protection. This flaw allows unauthenticated remote attackers to manipulate users into performing unintended actions, such as altering profile details or modifying application data. While most API requests are susceptible, those involving password changes are not, as passwords cannot be predicted by an attacker. The absence of a 'SameSite' attribute in the session cookie further complicates matters, leaving POST CSRF exploitation reliant on the victim's browser.

3.3
Jan 29, 2025

Celk Sistemas Celk Saude HTML Injection Vulnerability

A HTML injection vulnerability exists in Celk Sistemas Celk Saude version 3.1.252.1. This vulnerability allows remote attackers to inject arbitrary HTML code through the 'erro' parameter.

3.4
Jan 29, 2025

Celk Sistemas Celk Saude Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in Celk Sistemas Celk Saude version 3.1.252.1. This vulnerability allows remote attackers to inject arbitrary JavaScript code via the 'erro' parameter.

3.4
Jan 29, 2025

Software AG webMethods Integration Server Incorrect Access Control Vulnerability Allowing Information Disclosure

A vulnerability exists in the Software AG webMethods Integration Server version 10.15.0 prior to Core_Fix7, specifically on the /WmAdmin/,/invoke/vm.server/login login page. This vulnerability allows remote attackers to access the administration panel and obtain hostname and version information. Exploitation involves sending an arbitrary username and a blank password to the login URI.

3.9
Jan 29, 2025

ISC BIND 9 DNS-over-HTTPS Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in ISC BIND 9's DNS-over-HTTPS (DoH) implementation. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1. The vulnerability allows clients to exhaust a DNS resolver's CPU and memory by flooding it with crafted valid or invalid HTTP/2 traffic. As a result, the server can become overwhelmed, causing high resource usage and disrupting DoH connections for other clients.

5.4
Jan 29, 2025

ISC BIND 9 Zone Query Vulnerability Leading to CPU Exhaustion

A denial-of-service vulnerability has been identified in ISC BIND 9, specifically in versions 9.11.0 prior to 9.11.37, 9.16.0 prior to 9.16.50, 9.18.0 prior to 9.18.32, 9.20.0 prior to 9.20.4, 9.21.0 prior to 9.21.3, as well as in the BIND Supported Preview Edition versions 9.11.3-S1 prior to 9.11.37-S1, 9.16.8-S1 prior to 9.16.50-S1, and 9.18.11-S1 prior to 9.18.32-S1. This vulnerability allows for excessive CPU resource consumption by exploiting zones crafted to generate responses with numerous records in the Additional section. An attacker can send multiple such queries, causing either the authoritative server or an independent resolver to process these queries using disproportionate resources. This exploitation can lead to a significant degradation of server performance, especially for resolvers, and effectively prevent the server from responding to other client queries.

5.4
Jan 29, 2025

Kube-Audit-Rest Kubernetes Secrets Disclosure Vulnerability

A vulnerability in Kube-Audit-Rest prior to version 1.0.16 allows for the unintentional disclosure of Kubernetes secret values in the audit log. This issue arises when the 'full-elastic-stack' example vector configuration is applied to a real cluster, as it fails to properly redact secret data before it is logged.

2.4
Jan 29, 2025

Snowflake Connector for Python Temporary Credential Caching Vulnerability on Linux

A vulnerability exists in the Snowflake Connector for Python, specifically in versions 2.3.7 through 3.13.0, when temporary credential caching is enabled. On Linux systems, the connector caches temporary credentials in a file that is readable by all users. This issue arises when using EXTERNALBROWSER or USERNAME_PASSWORD_MFA authentication methods with temporary credential caching turned on.

3.7
Jan 29, 2025

Snowflake Connector for Python OCSP Response Cache Deserialization Vulnerability Leading to Privilege Escalation

A vulnerability exists in the Snowflake Connector for Python, specifically in versions 2.7.12 through 3.13.0, where the OCSP response cache is serialized using pickle. This serialization method can be exploited to achieve local privilege escalation, particularly if an attacker can write to the OCSP response cache file.

3.7
Jan 29, 2025

Snowflake Connector for Python SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the Snowflake Connector for Python, specifically in the 'snowflake.connector.pandas_tools' module. This issue affects versions 2.2.5 through 3.13.0. The vulnerability arises because a function in the 'pandas_tools' module does not properly sanitize all input arguments, allowing an attacker to inject malicious SQL that is executed within the context of the current session.

3.7
Jan 29, 2025

Snowflake Connector for .NET Temporary File Permission Vulnerability

A vulnerability exists in the Snowflake Connector for .NET, specifically in versions 2.0.12 through 4.2.0 on Linux and macOS. The issue arises because files downloaded from stages are temporarily stored in a world-readable local directory. This configuration allows unauthorized users on the same machine to access these files during their brief existence. The vulnerability has been addressed in version 4.3.0 of the connector.

3.8
Jan 29, 2025

Aridius XYZ OpenCart Modules Deserialization Vulnerability in News Component

A critical deserialization vulnerability has been identified in multiple Aridius OpenCart modules, specifically in the 'News' component, up to version 20240927. This vulnerability arises from the 'loadMore' function, where untrusted data is deserialized without proper validation, leading to PHP object injection. The issue can be exploited remotely without authentication, potentially allowing attackers to write arbitrary files or execute remote code, compromising the affected site.

4.0
Jan 29, 2025

mySCADA myPRO OS Command Injection Vulnerability

A command injection vulnerability has been identified in mySCADA myPRO Manager versions prior to 1.3 and myPRO Runtime versions prior to 9.2.1. The issue arises because the application does not properly sanitize POST requests containing email information, allowing attackers to execute arbitrary commands on the affected system.

3.1
Jan 29, 2025

mySCADA myPRO OS Command Injection Vulnerability

A command injection vulnerability has been identified in mySCADA myPRO Manager versions prior to 1.3 and myPRO Runtime versions prior to 9.2.1. The issue arises because the application does not properly sanitize POST requests sent to a specific port, allowing attackers to execute arbitrary commands on the affected system.

3.1
Jan 29, 2025

GNU Binutils Stack-Based Buffer Overflow Vulnerability in Objdump Component

A stack-based buffer overflow vulnerability has been identified in GNU Binutils versions prior to 2.43. The issue arises in the 'disassemble_bytes' function within 'binutils/objdump.c', where improper handling of the 'buf' argument creates the potential for a stack-based overflow. This vulnerability can be exploited remotely, although the attack's complexity is considered high, requiring user interaction.

6.0
Jan 29, 2025

ABB FLEXON Insertion of Sensitive Information into Log File Vulnerability

A vulnerability allowing the insertion of sensitive information into log files has been identified in ABB FLEXON versions through 9.3.4. This issue may lead to improper disclosure of information via HTTPS access.

2.5
Jan 29, 2025

ABB FLXEON WebSockets Vulnerability Allowing Unauthorized HTTPS Requests

A vulnerability exists in ABB FLXEON versions through 9.3.4, due to inadequate session management that fails to properly validate the Origin in WebSockets. This flaw allows unauthorized HTTPS requests to be sent, potentially leading to unauthorized actions or data exposure.

2.5
Jan 29, 2025

GitHub Enterprise Server Code Injection Vulnerability Allowing DOM Manipulation and Data Exfiltration

A code injection vulnerability has been identified in GitHub Enterprise Server. This vulnerability allows attackers to inject malicious code into the query selector via the identity property in the message handling function. The injected code can exfiltrate sensitive data by manipulating the DOM, including authentication tokens. To exploit this vulnerability, the victim must be logged into GitHub and interact with a malicious webpage controlled by the attacker, which contains a hidden iframe. This issue affects all versions of GitHub Enterprise Server prior to 3.11.16, 3.12.10, 3.13.5, 3.14.2, and 3.15.0.

3.2
Jan 29, 2025

Regclient Digest Validation Vulnerability in Docker and OCI Registry Client

A vulnerability exists in regclient, a Docker and OCI Registry Client written in Go, prior to version 0.7.1. This issue allows a malicious registry to return a different digest for a pinned manifest, potentially leading to undetected manipulation. The vulnerability arises because the client may not properly validate the digest against the registry's response, allowing discrepancies to go unnoticed.

2.4
Jan 29, 2025

Snowflake JDBC Driver Temporary Credential Caching Vulnerability on Linux

A vulnerability exists in the Snowflake JDBC Driver, specifically in versions 3.6.8 through 3.21.0, that relates to how temporary credentials are cached on Linux systems. When temporary credential caching is enabled and certain authentication methods are used, the driver stores these credentials in a local file with world-readable permissions. This issue could expose sensitive information to other users on the same system.

3.8