CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 30, 2025

Kubewarden AdmissionPolicyGroup Context-Aware Resource Information Leak Vulnerability

A vulnerability in the Kubewarden controller's AdmissionPolicyGroup resource allows non-admin users to create context-aware policies that can query the Kubernetes API and access sensitive information, such as Secrets, beyond their permissions. This issue arises because the AdmissionPolicyGroup, introduced in version 1.17.0, can be managed by users in their own namespaces. The vulnerability depends on the privileges of the ServiceAccount used by the Policy Server, with the default Helm chart granting broad access to cluster resources. The issue is present in Kubewarden versions 1.17.0 and later, and has been patched in version 1.21.0.

2.7
Jan 30, 2025

Kubewarden Admission Policies Vulnerability Allows Manipulation of PolicyReport Resources

A vulnerability exists in the Kubewarden controller for Kubernetes, specifically in versions 1.7.0 and above, prior to 1.21.0. This issue arises from the ability of AdmissionPolicy and AdmissionPolicyGroup to evaluate namespaced resources, including sensitive ones like PolicyReport, which tracks non-compliant objects within a namespace. An attacker could exploit this by using these policies to block the creation or update of PolicyReport resources, effectively concealing non-compliant items. Additionally, a mutating AdmissionPolicy could be employed to modify the contents of existing PolicyReports. The vulnerability stems from inadequate validation rules that allowed interactions with sensitive resources.

3.5
Jan 30, 2025

Argo CD Secret Exposure Vulnerability in Kubernetes Resource Sync

A vulnerability in Argo CD, a GitOps continuous delivery tool for Kubernetes, allows for the exposure of secret values in error messages and the diff view. This issue arises when an invalid Kubernetes Secret resource is synced from a repository. The vulnerability affects Argo CD versions through 2.13.3, 2.12.9, and 2.11.12. It requires the user to have write access to the repository, where they can commit an invalid Secret and trigger a sync. Once the vulnerability is exploited, any user with read access to Argo CD can access the exposed secret data.

3.8
Jan 30, 2025

VMware Aria Operations Information Disclosure Vulnerability

A vulnerability allowing information disclosure has been identified in VMware Aria Operations. This issue arises from a malicious user with non-administrative privileges being able to retrieve credentials for an outbound plugin, provided they know a valid service credential ID. VMware has assigned a severity level of 'Important' to this vulnerability, with a CVSSv3 base score of 7.7.

3.6
Jan 30, 2025

VMware Aria Operations for Logs Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in VMware Aria Operations for Logs. This vulnerability allows a malicious actor with admin privileges to inject a script that could be executed in the browser of a victim performing a delete action in the Agent Configuration.

3.4
Jan 30, 2025

VMware Aria Operations for Logs Privilege Escalation Vulnerability

A privilege escalation vulnerability has been identified in VMware Aria Operations for Logs. This vulnerability allows a malicious actor with non-administrative privileges and network access to the Aria Operations for Logs API to perform certain actions as an admin user.

3.7
Jan 30, 2025

VMware Aria Operations for Logs Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in VMware Aria Operations for Logs. This vulnerability allows a malicious actor with non-administrative privileges to inject a script that could be executed later, potentially leading to unauthorized actions being performed as an admin user.

3.5
Jan 30, 2025

Itsourcecode Tailoring Management System SQL Injection Vulnerability in Payment Addition Feature

A critical SQL injection vulnerability has been identified in the Itsourcecode Tailoring Management System version 1.0. The issue resides in the 'addpayment.php' file, where an unknown function improperly validates POST parameters, allowing attackers to inject malicious SQL queries. This vulnerability can be exploited remotely, potentially leading to unauthorized database access, data manipulation, and leakage of sensitive information.

4.3
Jan 30, 2025

Wildfly Server Role-Based Access Control Vulnerability Allows Unauthorized Server Suspension or Resumption

A vulnerability exists in the Wildfly Server's Role Based Access Control (RBAC) provider. It allows users with Monitor or Auditor roles, who should only have read access, to suspend or resume the server. This issue arises because the Suspend and Resume handlers do not properly check if the user has the necessary permissions before allowing these actions. As a result, unauthorized users can disrupt server operations by suspending it, which stops the server from processing user requests, and then resuming it, which restores normal functionality.

4.1
Jan 30, 2025

VMware Aria Operations for Logs Information Disclosure Vulnerability

A vulnerability allowing information disclosure has been identified in VMware Aria Operations for Logs. This issue arises from a flaw that enables a malicious actor with View Only Admin permissions to potentially access the credentials of a VMware product integrated with Aria Operations for Logs. VMware has assigned this vulnerability a severity rating of Important, with a maximum CVSSv3 base score of 8.5.

3.6
Jan 30, 2025

Maybecms Cross-Site Scripting Vulnerability in Article Management Component

A cross-site scripting (XSS) vulnerability has been identified in Maybecms version 1.2, specifically within the Add Article component of the administration panel. The issue arises in the article editing interface, where the 'data_info[content]' parameter can be manipulated to inject malicious scripts. This vulnerability is remotely exploitable and requires user interaction to be triggered.

2.9
Jan 30, 2025

DevDojo Voyager Arbitrary Code Execution Vulnerability via Bypassed File Type Verification

A vulnerability in DevDojo Voyager through version 1.8.0 allows authenticated users to bypass file type verification when uploading files through the '/admin/media/upload' endpoint. This flaw can be exploited to upload web shells, leading to arbitrary code execution on the server.

2.5
Jan 30, 2025

DevDojo Voyager Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in DevDojo Voyager versions through 1.8.0. The issue arises in the admin compass section, where an authenticated user can be manipulated into clicking a link that executes arbitrary JavaScript. This vulnerability is particularly concerning as it can be combined with other issues to escalate to remote code execution on the server.

3.0
Jan 30, 2025

DevDojo Voyager Path Traversal Vulnerability Allowing Arbitrary File Deletion or Access

A path traversal vulnerability has been identified in DevDojo Voyager versions through 1.8.0, specifically within the VoyagerCompassController. This vulnerability allows authenticated users with administrative privileges to manipulate file paths and delete or access arbitrary files on the server. The issue arises from insufficient input validation, enabling exploitation by crafting malicious requests that traverse outside of intended directories.

2.4
Jan 30, 2025

Files.gallery Command Injection Vulnerability in Video Thumbnail Rendering Component

A command injection vulnerability has been identified in Karl Ward's files.gallery versions 0.3.0 through 0.11.0. This vulnerability allows remote attackers to execute arbitrary code by uploading a crafted video file. The issue arises in the video thumbnail rendering component, where user-controlled input is not properly sanitized before being passed to a command execution function. Exploitation requires that ffmpeg is available in the system's PATH, that file uploads are allowed in the application's configuration, and that the exec function is enabled in the PHP configuration.

4.0
Jan 30, 2025

Elementor Website Builder Pro Sensitive Information Exposure Vulnerability

A vulnerability allowing sensitive information exposure exists in the Elementor Website Builder Pro plugin for WordPress, affecting all versions through 3.25.10. The issue arises from the 'elementor-template' shortcode, which authenticated attackers with Contributor-level access and above can exploit to access sensitive data. This includes the content of Private, Pending, and Draft Templates. Although version 3.24.4 partially addressed this vulnerability, it remains a concern in the subsequent release.

4.3
Jan 30, 2025

iControlWP WordPress Site Manager PHP Object Injection Vulnerability

A PHP Object Injection vulnerability has been identified in the iControlWP – Multiple WordPress Site Manager plugin, affecting all versions through 4.4.5. The vulnerability arises from the deserialization of untrusted input in the reqpars parameter, allowing unauthenticated attackers to inject PHP objects. While the vulnerable plugin itself does not have a known property-oriented programming (POP) chain, the impact could be significant if another plugin or theme with a POP chain is installed, potentially enabling actions such as deleting files, accessing sensitive information, or executing code, depending on the specific POP chain available.

3.7
Jan 30, 2025

WP Image Uploader WordPress Plugin Arbitrary File Deletion Vulnerability

A vulnerability allowing arbitrary file deletion has been identified in the WP Image Uploader plugin for WordPress, affecting all versions through 1.0.1. The issue arises from inadequate file path validation in the gky_image_uploader_main_function(), enabling unauthenticated attackers to delete arbitrary files on the server. This vulnerability could easily lead to remote code execution if a critical file, such as wp-config.php, is deleted.

3.4
Jan 30, 2025

zStore Manager Basic Missing Authorization Vulnerability in Cache Clearing Function

A vulnerability exists in the zStore Manager Basic plugin for WordPress, affecting all versions through 3.311. The issue arises from a lack of proper capability checks in the zstore_clear_cache() function, allowing authenticated users with Subscriber-level access and above to clear the plugin's cache. This vulnerability could lead to unauthorized data loss.

3.1
Jan 30, 2025

WP Image Uploader WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Arbitrary File Deletion

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP Image Uploader plugin for WordPress, affecting all versions through 1.0.1. The issue arises from inadequate nonce validation in the gky_image_uploader_main_function(), allowing unauthenticated attackers to delete arbitrary files by sending a forged request. This exploitation requires tricking a site administrator into performing an action, such as clicking a link.

2.5
Jan 30, 2025

WordPress StageShow Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the StageShow plugin for WordPress, affecting all versions through 9.8.6. The issue arises from the use of remove_query_arg without proper escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link that contains the malicious payload.

3.9
Jan 30, 2025

Embed Swagger UI WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Embed Swagger UI plugin for WordPress, affecting all versions through 1.0.0. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'wpsgui' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when a user views the injected page.

1.6
Jan 30, 2025

Music Sheet Viewer WordPress Plugin Arbitrary File Read Vulnerability

A vulnerability allowing arbitrary file read has been identified in the Music Sheet Viewer plugin for WordPress, affecting all versions through 4.1. The issue arises in the read_score_file() function, where unauthenticated attackers can access and read the contents of arbitrary files on the server, potentially exposing sensitive information.

3.5
Jan 30, 2025

Music Sheet Viewer WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Music Sheet Viewer plugin for WordPress, affecting all versions through 4.1. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'pn_msv' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.

2.6
Jan 30, 2025

WP Post List Table Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WP Post List Table plugin for WordPress, affecting all versions through 1.0.3. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'wpb_post_list_table' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.4
Jan 30, 2025

WordPress Table Editor Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Table Editor plugin for WordPress, affecting all versions through 1.5.1. The issue arises from inadequate input sanitization and output escaping on user-supplied attributes, particularly within the 'wptableeditor_vtabs' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.7
Jan 30, 2025

ECPay Ecommerce for WooCommerce Missing Authorization Vulnerability Allowing Log Deletion

A vulnerability exists in the ECPay Ecommerce for WooCommerce plugin for WordPress, in all versions through 1.1.2411060. The issue arises from a lack of proper capability checks on the 'clear_ecpay_debug_log' AJAX action. This flaw enables authenticated attackers with Subscriber-level access or higher to delete the plugin's log files, leading to unauthorized data loss.

3.0
Jan 30, 2025

WordPress Single-User Chat Plugin Data Modification Vulnerability Leading to Denial-of-Service

A vulnerability exists in the Single-user-chat plugin for WordPress, all versions through 0.5, allowing authenticated attackers with subscriber-level access and above to unauthorizedly modify data. The issue arises from inadequate validation in the 'single_user_chat_update_login' function, enabling attackers to change option values to 'login'. This could disrupt normal site operations by introducing errors that affect legitimate users or by altering settings related to user registration. Such changes could potentially be exploited to cause a denial-of-service condition on the site.

2.8
Jan 30, 2025

WordPress Survey & Poll Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the WordPress Survey & Poll plugin, specifically in versions through 1.7.5. The issue arises from inadequate escaping of user-supplied data in the 'id' attribute of the 'survey' shortcode, allowing authenticated attackers with Contributor-level access or higher to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information in the database.

3.2
Jan 30, 2025

All Bootstrap Blocks WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the All Bootstrap Blocks plugin for WordPress, affecting all versions through 1.3.26. The issue arises in the 'Accordion' widget, where inadequate input sanitization and output escaping allow authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts. These scripts are executed when a user accesses the affected page.

3.2
Jan 30, 2025

Wonder FontAwesome WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Wonder FontAwesome plugin for WordPress, affecting all versions through 0.8. The vulnerability arises from inadequate nonce validation, allowing unauthenticated attackers to manipulate settings and inject malicious scripts. Exploitation requires tricking a site administrator into clicking a link that initiates the forged request.

2.0
Jan 30, 2025

WE Testimonial Slider Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WE – Testimonial Slider plugin for WordPress, affecting all versions through 1.5. This issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into testimonial author names. The injected scripts are executed when users view the affected testimonials.

1.7
Jan 30, 2025

Kona Gallery Block Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Kona Gallery Block plugin for WordPress, specifically in the 'Kona: Instagram for Gutenberg' Block. The issue resides within the 'align' attribute and affects all versions through 1.7. The vulnerability arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access and above to inject arbitrary web scripts into pages. These scripts would execute when a user accesses the compromised page.

2.5
Jan 30, 2025

Stockdio Historical Chart WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Stockdio Historical Chart plugin for WordPress, affecting all versions through 2.8.18. The vulnerability arises from inadequate input sanitization and output escaping on user-supplied attributes, particularly within the 'stockdio-historical-chart' shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.

3.1
Jan 30, 2025

W2S Migrate WooCommerce to Shopify Plugin Arbitrary File Read Vulnerability

A vulnerability allowing arbitrary file read has been identified in the W2S – Migrate WooCommerce to Shopify plugin for WordPress, affecting all versions through 1.2.1. The issue arises from the 'viw2s_view_log' AJAX action, which lacks proper authorization. This vulnerability enables authenticated attackers with Subscriber-level access and above to read arbitrary files on the server, potentially exposing sensitive information.

2.7
Jan 30, 2025

Media Manager for UserPro Missing Authorization Vulnerability Allowing Privilege Escalation

A vulnerability exists in the Media Manager for UserPro plugin for WordPress, all versions through 3.11.0, allowing unauthorized data modification that could lead to privilege escalation. The issue arises from a missing capability check in the add_capto_img() function, enabling unauthenticated attackers to update arbitrary options on the WordPress site. This vulnerability could be exploited to change the default registration role to administrator and activate user registration, granting administrative access to the attacker on the compromised site.

2.6
Jan 30, 2025

Media Manager for UserPro Missing Authorization Vulnerability in WordPress

A vulnerability exists in the Media Manager for UserPro plugin for WordPress, affecting all versions through 3.12.0. The issue arises from a lack of proper capability checks in the upm_upload_media() function, allowing authenticated attackers with Subscriber-level access or higher to unauthorizedly modify data. This vulnerability can be exploited to change arbitrary options on the WordPress site, such as updating the default role for new users to administrator and enabling user registration, potentially granting administrative access to the attacker.

1.8
Jan 30, 2025

HTML5 Chat WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the HTML5 Chat plugin for WordPress, affecting all versions through 1.04. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'HTML5CHAT' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.6
Jan 30, 2025

WP Dispensary Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WP Dispensary plugin for WordPress, affecting all versions through 4.5.0. The issue arises from inadequate input sanitization and output escaping on user-supplied attributes in the 'wpd_menu' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.

2.3
Jan 30, 2025

WordPress Team Rosters Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Team Rosters plugin for WordPress, affecting all versions through 4.7. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if the attacker successfully persuades a user to perform an action, such as clicking a link.

2.7
Jan 30, 2025

System Dashboard WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the System Dashboard plugin for WordPress, affecting all versions through 2.8.17. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages. These scripts could execute if an administrative user is tricked into clicking a link or performing a similar action.

2.7
Jan 30, 2025

Safe Ai Malware Protection for WP Missing Authorization Vulnerability Allowing Unauthenticated Database Export

A vulnerability exists in the Safe Ai Malware Protection for WP plugin for WordPress, in all versions through 1.0.17. The issue arises from a lack of proper capability checks in the export_db() function, allowing unauthenticated attackers to access and download a complete dump of the site's database.

4.1
Jan 30, 2025

Ai Image Alt Text Generator for WP Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Ai Image Alt Text Generator for WP plugin for WordPress, affecting all versions through 1.0.6. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the 'page' parameter. These scripts could be executed if a user is tricked into clicking a link.

3.6
Jan 30, 2025

Royal Core WordPress Plugin Privilege Escalation Vulnerability

A vulnerability in the Royal Core plugin for WordPress allows for unauthorized data modification that could lead to privilege escalation. This issue arises from a missing capability check in the 'royal_restore_backup' function, affecting all versions up to and including 2.9.2. As a result, authenticated attackers with Subscriber-level access or higher can manipulate arbitrary options on the WordPress site. This vulnerability could be exploited to change the default role for new users to administrator and enable user registration, allowing attackers to gain administrative access on the site.

1.8
Jan 30, 2025

Typer Core WordPress Plugin Information Exposure Vulnerability

A vulnerability allowing information exposure exists in the Typer Core plugin for WordPress, affecting all versions through 1.9.6. The issue arises from inadequate restrictions on which posts can be included via the 'elementor-template' shortcode. This flaw enables authenticated attackers with Contributor-level access and above to access and extract data from private or draft posts created with Elementor, which they should not be able to view.

1.7
Jan 30, 2025

Borderless WordPress Plugin Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the Borderless WordPress plugin, specifically in the 'write_config' function. This issue affects all versions of the plugin up to and including 1.6.0. The vulnerability arises from inadequate sanitization of an imported JSON file, allowing authenticated attackers with Administrator-level access to execute arbitrary code on the server.

3.6
Jan 30, 2025

Borderless WordPress Plugin Missing Authorization Vulnerability in Icon Font Deletion

A vulnerability exists in the Borderless WordPress plugin, specifically in the 'remove_zipped_font' function, all versions through 1.5.9. The issue arises from a lack of proper capability checks, allowing authenticated attackers with Subscriber-level access or higher to delete previously uploaded icon fonts. This unauthorized data loss could impact users relying on custom icon packs for their WordPress sites.

3.2
Jan 30, 2025

Storely WordPress Theme Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Storely theme for WordPress, affecting all versions through 18. This issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts. These scripts execute when users access the compromised pages.

1.6
Jan 30, 2025

MWB HubSpot for WooCommerce Privilege Escalation Vulnerability

A vulnerability in the MWB HubSpot for WooCommerce plugin, specifically in versions through 1.5.9, allows authenticated users with Contributor-level access and above to bypass authorization checks and modify arbitrary data. This could lead to privilege escalation by enabling these users to change the default role of new users to administrator, potentially giving them full administrative access on the site.

3.8
Jan 30, 2025

Axiomatic Bento4 Heap-Based Buffer Overflow Vulnerability in AP4_DataBuffer::GetData

A critical heap-based buffer overflow vulnerability has been identified in Axiomatic Bento4 versions through 1.6.0-641. The issue arises in the function AP4_DataBuffer::GetData within the library Ap4DataBuffer.h. This vulnerability can be exploited remotely, although the complexity of the attack is high and the exploitation is known to be difficult.

4.0