CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Ashlar-Vellum Cobalt Buffer Overflow Vulnerability Leading to Remote Code Execution
A buffer overflow vulnerability has been identified in Ashlar-Vellum Cobalt within the CO file parsing component. This flaw allows remote attackers to execute arbitrary code on affected systems. The vulnerability arises from inadequate validation of user-supplied data lengths before copying them to a buffer, creating an opportunity for code execution in the context of the current process. Exploitation requires user interaction, such as opening a malicious file or visiting a harmful webpage.
Ashlar-Vellum Cobalt VC6 File Parsing Type Confusion Remote Code Execution Vulnerability
A type confusion vulnerability allowing remote code execution has been identified in Ashlar-Vellum Cobalt, specifically within the VC6 file parsing process. This issue arises from inadequate validation of user-supplied data, leading to a type confusion condition. Exploitation of this vulnerability requires user interaction, as the target must open a malicious file or visit a harmful webpage.
Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in Ashlar-Vellum Cobalt, specifically within the parsing of VS files. This issue arises from improper validation of user-supplied data, leading to a type confusion condition. Exploitation of this vulnerability requires user interaction, as the target must open a malicious file or visit a harmful webpage. Once exploited, the vulnerability allows attackers to execute arbitrary code in the context of the current process.
Ashlar-Vellum Cobalt Remote Code Execution Vulnerability Due to Uninitialized Variable in VS File Parsing
A remote code execution vulnerability has been identified in Ashlar-Vellum Cobalt, specifically within the parsing of VS files. The issue arises from the improper initialization of memory before it is accessed, allowing remote attackers to execute arbitrary code on affected installations. Exploitation of this vulnerability requires user interaction, as the target must open a malicious file or visit a harmful webpage.
Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability
A use-after-free vulnerability has been identified in Ashlar-Vellum Cobalt, specifically within the CO file parsing process. This flaw allows remote attackers to execute arbitrary code on affected systems. The vulnerability arises from improper validation of object existence before performing operations, creating an opportunity for exploitation. Notably, user interaction is required, as the target must open a malicious CO file.
Ashlar-Vellum Cobalt Out-of-Bounds Read Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in Ashlar-Vellum Cobalt, specifically within the parsing of VS files. This issue arises from inadequate validation of user-supplied data, leading to a read past the end of an allocated buffer. Exploitation of this vulnerability requires user interaction, as the target must open a malicious file or visit a harmful webpage.
WordPress DP ALTerminator Missing ALT Manager Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress DP ALTerminator - Missing ALT manager plugin, affecting versions through 1.0.2. This issue arises from improper input neutralization during web page generation, which allows for the injection of malicious scripts that are executed when users visit the affected site.
WordPress Spam Byebye Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Spam Byebye plugin, specifically in versions through 2.2.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Back To Top Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Back To Top plugin, specifically in versions 2.0 and prior. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress WP Performance Pack Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the WordPress WP Performance Pack plugin, specifically in versions through 2.5.3. This vulnerability allows unprivileged users to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions that require higher privileges.
Lava Code Lava Ajax Search Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Lava Ajax Search WordPress plugin, affecting versions through 1.1.9. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Sakurapixel Lunar WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Sakurapixel Lunar WordPress plugin, affecting versions through 1.3.0. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress MaxA/B Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress MaxA/B plugin, specifically in versions through 2.2.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.
WordPress Insert Code Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Insert Code plugin, specifically in versions through 2.4. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the website.
DevriX WordPress Hashtags Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the DevriX WordPress Hashtags plugin, specifically in versions through 0.3.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.
WordPress List Mixcloud Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress List Mixcloud plugin, affecting versions through 1.4. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Vivek Marakana Tabbed Login Widget Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Tabbed Login Widget plugin, affecting versions through 1.1.2. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.
WordPress Display Template Name Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Display Template Name plugin, affecting versions through 1.7.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Post Read Time Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Post Read Time plugin, specifically in versions through 1.2.6. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Hieu Nguyen WATI Chat and Notification Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WATI Chat and Notification WordPress plugin, specifically in versions through 1.1.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser session.
WordPress No Disposable Email Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress No Disposable Email plugin, affecting versions through 2.5.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.
WordPress Go To Top Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Go To Top plugin, specifically in versions through 0.0.8. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.
WordPress Responsive Google Map Plugin Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the WordPress Responsive Google Map plugin, affecting versions through 3.1.5. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.
WordPress Easy Image Display Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Easy Image Display plugin, affecting versions through 1.2.5. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress Featured Image Thumbnail Grid Plugin Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Featured Image Thumbnail Grid plugin, affecting versions through 6.8. The issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.
ThemeEgg Toolkit WordPress Plugin Arbitrary File Upload Vulnerability
A vulnerability allowing unrestricted upload of files with dangerous types has been identified in the ThemeEgg Toolkit WordPress plugin, affecting versions through 1.2.9. This vulnerability could be exploited to upload a web shell to the server, potentially leading to unauthorized access or control over the website.
WordPress Login Form to Anywhere Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Login Form to Anywhere plugin, specifically in versions through 0.2. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that are executed when users visit the affected site.
WordPress WP Add Active Class To Menu Item Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress plugin 'WP Add Active Class To Menu Item' versions through 1.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Custom Dashboard Page Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Custom Dashboard Page plugin, specifically in versions through 1.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress WP Hide Admin Bar Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Hide Admin Bar plugin for WordPress, specifically in versions through 2.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress WP No-Bot Question Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress WP No-Bot Question plugin, affecting versions through 0.1.7. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
pipdig pipDisqus WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the pipdig pipDisqus WordPress plugin, affecting versions through 1.6. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when guests visit the site.
WordPress WP Last Modified Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress WP Last Modified plugin, affecting versions through 0.1. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject harmful scripts that are executed when users visit the affected site.
Thiago S.F. Skitter Slideshow Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Thiago S.F. Skitter Slideshow WordPress plugin, affecting versions through 2.5.2. This vulnerability arises from improper input sanitization during web page generation, allowing malicious actors to inject scripts that are executed when users visit the affected site.
Chaser324 Featured Posts Grid Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Chaser324 Featured Posts Grid plugin for WordPress, affecting versions through 1.7. This vulnerability arises from improper input sanitization during web page generation, allowing malicious users to inject harmful scripts that are executed when the affected page is viewed.
WordPress Contact Form 7 Select Box Editor Button CSRF Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Contact Form 7 Select Box Editor Button plugin, affecting versions through 0.6. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Members Page Only for Logged-in Users Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Members Page Only for Logged-in Users plugin, affecting versions through 1.4.2. This vulnerability allows for Stored Cross-Site Scripting, as it enables attackers to trick users with higher privileges into performing actions that could introduce malicious scripts, which are then permanently stored and potentially executed later.
WordPress TabGarb Pro Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress TabGarb Pro plugin, affecting versions through 2.6. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.
Steveorevo Domain Theme Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Steveorevo Domain Theme, specifically in versions through 1.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the theme's insufficient protection against CSRF, enabling attackers to manipulate users with higher privileges into performing actions that could introduce malicious scripts, which are then permanently stored and executed.
Akshar Soft Solutions AS English Admin Open Redirect Vulnerability
A URL redirection vulnerability allowing untrusted site redirection (open redirect) has been identified in the Akshar Soft Solutions AS English Admin plugin, affecting versions through 1.0.0. This vulnerability could be exploited for phishing attacks by redirecting users to malicious sites.
WordPress Custom Top Bar Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Custom Top Bar plugin, specifically in versions through 2.0.2. This issue arises from improper input neutralization during web page generation, allowing malicious users to inject harmful scripts that are executed when the page is viewed.
WordPress List of Posts from Each Category Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the 'List of Posts from each Category' plugin for WordPress, affecting versions through 2.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.
WordPress FTP Sync Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress FTP Sync plugin, specifically in versions through 1.1.6. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.
WordPress Price-Calc Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Price-Calc plugin, specifically in versions through 0.6.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.
WordPress Fastmover Plugins Last Updated Column Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Fastmover WordPress plugin 'Last Updated Column', affecting versions through 0.1.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress REST API TO MiniProgram Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress REST API TO MiniProgram plugin, affecting versions through 4.7.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress WP Bulk Post Duplicator Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress WP Bulk Post Duplicator plugin, affecting versions through 1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress WP Compare Tables Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress WP Compare Tables plugin, specifically in versions through 1.0.5. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the application.
WordPress Mobile Themes Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Mobile Themes plugin, specifically in versions through 1.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Bee Layer Slider Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Bee Layer Slider WordPress plugin, affecting versions through 1.1. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
