CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
WordPress Admin and Site Enhancements Privilege Escalation Vulnerability
A privilege escalation vulnerability has been identified in the WordPress Admin and Site Enhancements (ASE) plugin, affecting versions through 7.6.2.1. This vulnerability allows users with low privileges to escalate their rights, potentially leading to full control of the website.
WP24 Domain Check Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WP24 Domain Check WordPress plugin, affecting versions through 1.10.14. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.
Tribulant Newsletters Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Tribulant Newsletters WordPress plugin, affecting versions through 4.9.9.6. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.
WP Mailster Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WP Mailster WordPress plugin, affecting versions through 1.8.17.0. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.
Optimize Worldwide Find Content IDs Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Optimize Worldwide Find Content IDs WordPress plugin, affecting versions through 1.0. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress World Cup Predictor Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress World Cup Predictor plugin, affecting versions through 1.9.8. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.
Ksher WordPress Plugin Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the Ksher WordPress plugin, affecting versions through 1.1.2. This vulnerability arises from missing authorization checks, allowing unprivileged users to perform actions reserved for higher privileges.
WordPress Traveler Code Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WordPress Traveler Code plugin, affecting versions prior to 3.1.3. This vulnerability allows for improper neutralization of special elements used in SQL commands, enabling potential arbitrary execution of SQL queries.
NotFound Traveler Code SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the NotFound Traveler Code plugin for WordPress, affecting versions prior to 3.1.2. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially leading to unauthorized execution of SQL queries.
CyberChimps Responsive Blocks Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the CyberChimps Responsive Blocks plugin for WordPress, affecting versions through 1.9.9. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.
WordPress EmbedPress Document Block Missing Authorization Vulnerability
A broken access control vulnerability has been identified in the WordPress Document Block – Upload & Embed Docs plugin, affecting versions through 1.1.0. This vulnerability allows unprivileged users to perform actions that require higher privileges, due to a lack of proper authorization checks.
WordPress Alert Box Block Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Alert Box Block plugin, specifically in versions through 1.1.0. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed on the front end when users visit the site.
Get Bowtied Product Blocks for WooCommerce Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Get Bowtied Product Blocks for WooCommerce plugin, affecting versions through 1.9.1. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress Survey Maker Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Survey Maker plugin, affecting versions through 5.1.3.5. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
SendPulse Email Marketing Newsletter Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the SendPulse Email Marketing Newsletter WordPress plugin, affecting versions through 2.1.5. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
Templaza Music Press Pro Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Templaza Music Press Pro WordPress plugin, affecting versions through 1.4.6. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
FameThemes OnePress Theme Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the FameThemes OnePress WordPress theme, specifically in versions through 2.3.11. This vulnerability allows exploitation of improperly configured access control security levels, potentially enabling unprivileged users to perform actions reserved for higher privileges.
RTO GmbH Dynamic Conditions WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the RTO GmbH Dynamic Conditions WordPress plugin, affecting versions through 1.7.4. This vulnerability arises from improper input neutralization during web page generation, allowing malicious actors to inject harmful scripts that are executed when users visit the affected site.
Prem Tiwari FM Notification Bar Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Prem Tiwari FM Notification Bar plugin for WordPress, affecting versions through 1.0.2. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Joomla JS Jobs Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the JS Jobs plugin for Joomla, affecting versions 1.1.5 through 1.4.2. This vulnerability allows authenticated administrators to execute arbitrary SQL commands by exploiting the 'fieldfor' parameter within the GDPR Field feature.
cpp-httplib CRLF Injection Vulnerability Leading to HTTP Response Splitting
A CRLF injection vulnerability has been identified in cpp-httplib versions 0.17.3 through 0.18.3. The issue arises because the library fails to properly filter CRLF characters when they are preceded by a null byte. This flaw allows attackers to inject CRLF sequences into HTTP headers, potentially leading to HTTP response splitting, cross-site scripting (XSS) attacks, and other exploits.
Four-Faith F3x36 Router Authentication Bypass Vulnerability in Administrative Web Server
An authentication bypass vulnerability has been identified in the Four-Faith F3x36 router running firmware v2.0.0. This vulnerability allows remote, unauthenticated users to access certain administrative functions via the 'bapply.cgi' endpoint, which does not enforce authentication. Exploitation of this vulnerability could lead to unauthorized modification of router settings or could be combined with existing authenticated vulnerabilities to escalate the attack.
Four-Faith F3x36 Router Authentication Bypass Vulnerability via Hard-Coded Credentials
An authentication bypass vulnerability has been identified in the Four-Faith F3x36 router running firmware v2.0.0. This vulnerability arises from hard-coded credentials in the administrative web server, allowing an attacker who knows the credentials to gain administrative access by sending crafted HTTP requests.
Netgear FVS336Gv2 and FVS336Gv3 Telnet Command Injection Vulnerability Allowing Remote Code Execution
A command injection vulnerability has been identified in the Telnet interface of the Netgear FVS336Gv2 and FVS336Gv3 routers, both of which are end-of-life products. This vulnerability allows authenticated, remote attackers to execute arbitrary operating system commands as root. The issue arises when crafted 'util backup_configuration' commands are sent via Telnet.
Mozilla Firefox and Thunderbird Memory Safety Vulnerability Allowing Arbitrary Code Execution
A vulnerability exists in Firefox and Thunderbird versions prior to 135, stemming from memory safety issues that could lead to memory corruption. With sufficient effort, these flaws might have been exploited to execute arbitrary code.
Mozilla Firefox and Thunderbird Fullscreen Spoofing Vulnerability
A vulnerability exists in Firefox versions prior to 135 and Thunderbird versions prior to 135, allowing the z-order of browser windows to be manipulated. This manipulation can hide the fullscreen notification, potentially leading to a spoofing attack.
Mozilla Firefox and Thunderbird Fullscreen Notification Spoofing Vulnerability
A vulnerability exists in Firefox versions prior to 135 and Thunderbird versions prior to 135, where the fullscreen notification is unintentionally dismissed when fullscreen is quickly re-requested by the user. This behavior could be exploited to perform a spoofing attack.
Mozilla Firefox and Thunderbird Memory Safety Vulnerability Allowing Arbitrary Code Execution
A vulnerability has been identified in Mozilla Firefox and Thunderbird applications, specifically in versions prior to 135, as well as in Firefox ESR 128.6 and Thunderbird ESR 128.6. This vulnerability arises from memory safety issues that could lead to memory corruption. With sufficient effort, these issues might have been exploited to execute arbitrary code.
Mozilla Firefox and Thunderbird Memory Safety Vulnerability Allowing Potential Arbitrary Code Execution
A vulnerability has been identified in Mozilla Firefox and Thunderbird applications, specifically in versions prior to 135. This vulnerability arises from memory safety issues that could lead to memory corruption. With sufficient effort, these issues might have been exploited to execute arbitrary code. The vulnerability is present in Firefox 134, Firefox ESR 115.19 and 128.6, as well as Thunderbird 134, 115.19, and 128.6.
Mozilla Thunderbird Unsanitized Address Book URI Fields Vulnerability
A vulnerability exists in Mozilla Thunderbird versions prior to 128.7 and in the 134 series, where the Address Book URI fields contained unsanitized links. This flaw could allow an attacker to create and export an address book with a malicious payload embedded in a field, such as the 'Other' field in the Instant Messaging section. If another user imported this address book and clicked on the link, it could open a web page within Thunderbird that executes unprivileged JavaScript.
Mozilla Firefox and Thunderbird Certificate Length Validation Vulnerability
A vulnerability exists in Mozilla Firefox versions prior to 135, Firefox ESR versions prior to 128.7, and Thunderbird versions prior to 128.7 and in Thunderbird versions prior to 135. This vulnerability arises because the length of certificates was not properly validated when they were added to a certificate store. Although only trusted data was processed, the improper validation could potentially allow for the acceptance of excessively long certificates as valid.
Mozilla Firefox and Thunderbird Race Condition Vulnerability Leading to Privacy Leak
A race condition vulnerability has been identified in Mozilla Firefox and Thunderbird, which could have allowed private browsing tabs to be opened in normal browsing windows, potentially leading to a privacy leak. This issue affects Firefox versions prior to 135, Firefox ESR versions prior to 128.7, and Thunderbird versions prior to 128.7 and 135.
Mozilla Firefox and Thunderbird Use-After-Free Vulnerability Due to Concurrent Delazification
A use-after-free vulnerability has been identified in Mozilla Firefox and Thunderbird. This issue arises from a race condition during concurrent delazification, which could potentially be exploited. The vulnerability affects multiple versions of Firefox and Thunderbird, including Firefox prior to 135, Firefox ESR versions prior to 115.20 and 128.7, as well as Thunderbird versions prior to 128.7 and 135.
Mozilla Firefox and Thunderbird WebAssembly Code Generation Vulnerability Leading to Potential Code Execution
A vulnerability exists in the WebAssembly code generation process in Mozilla Firefox and Thunderbird. This issue could have caused a crash, and there is a possibility that an attacker could exploit it to execute arbitrary code. The vulnerability affects multiple versions of Firefox and Thunderbird, including Firefox versions prior to 135, Firefox ESR versions prior to 128.7, and Thunderbird versions prior to 128.7 and 135.
Mozilla Firefox and Thunderbird Use-After-Free Vulnerability in Custom Highlight API
A use-after-free vulnerability has been identified in Mozilla Firefox versions prior to 135, Firefox ESR versions prior to 115.20 and 128.7, as well as in Thunderbird versions prior to 128.7 and 135. This vulnerability could have been exploited to cause a crash, potentially leading to arbitrary code execution.
Mozilla Firefox and Thunderbird Use-After-Free Vulnerability in XSLT Processing
A use-after-free vulnerability has been identified in Mozilla Firefox and Thunderbird applications, specifically in versions prior to Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135. This vulnerability arises from the improper handling of crafted XSLT data, which could lead to a crash that might be exploitable.
Mozilla Thunderbird Sender Address Spoofing Vulnerability
A vulnerability in Mozilla Thunderbird allows for the spoofing of sender addresses in emails. This issue arises when the From field uses an invalid group name syntax, as detailed in CVE-2024-49040. The vulnerability is present in Thunderbird versions prior to 128.7 and prior to 135.
Authentik Stored Cross-Site Scripting Vulnerability via SVG File Upload
A stored cross-site scripting vulnerability has been identified in the Authentik project, affecting all versions prior to 2024.10.4. This issue allows authenticated admin users to upload manipulated SVG files that are then used as application icons. When other users click on these icons, the embedded scripts in the SVG files are executed in their browsers.
Qi Addons For Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Qi Addons For Elementor plugin for WordPress, affecting all versions through 1.8.7. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into pages. These scripts are executed when users access the compromised pages.
Apache Cassandra Incorrect Authorization Vulnerability in Network Authorizers Allowing Unauthorized Access to Datacenters
A vulnerability has been identified in Apache Cassandra that allows users to bypass authorization and access datacenters or IP/CIDR groups they should not be able to. This issue arises when using the CassandraNetworkAuthorizer or CassandraCIDRAuthorizer. Affected users with restricted datacenter access can manipulate their own permissions through data control language (DCL) statements. The vulnerability is present in Apache Cassandra versions 4.0.0 to 4.0.15, 4.1.0 to 4.1.7, and 5.0.0 to 5.0.2.
Zyxel DSL CPE Insecure Default Credentials Vulnerability in Telnet Function
A vulnerability exists in certain legacy Zyxel DSL CPE models, including the VMG4325-B10A, due to insecure default credentials for the Telnet function. This vulnerability allows an attacker to access the management interface if administrators do not change the default credentials. The issue is present in the VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615.
Apache Cassandra RMI Registry Manipulation Vulnerability Allowing JMX Credential Capture
A vulnerability exists in Apache Cassandra versions 4.0.2 prior to 4.0.15, 4.1.0 prior to 4.1.8, and 5.0-beta1 prior to 5.0.3, all running Java 11. This vulnerability allows a local attacker, without access to the Cassandra process or configuration files, to manipulate the RMI registry. This manipulation can lead to a man-in-the-middle attack, where the attacker intercepts and captures usernames and passwords used to access the JMX interface. Once obtained, these credentials can be used to access JMX and perform unauthorized operations.
Apache Cassandra Privilege Escalation Vulnerability via Unsafe Actions
A vulnerability allowing privilege escalation to superuser has been identified in Apache Cassandra. This issue affects users with MODIFY permission on all keyspaces, who can exploit unsafe actions to a system resource within the targeted Cassandra cluster. The vulnerability is present in Apache Cassandra versions 3.0.0 prior to 3.0.30, 3.1.0 prior to 3.11.17, 4.0.0 prior to 4.0.15, 4.1.0 prior to 4.1.7, and 5.0.0 prior to 5.0.2.
Zyxel DSL CPE Command Injection Vulnerability in VMG4325-B10A
A post-authentication command injection vulnerability has been identified in the management commands of the Zyxel VMG4325-B10A DSL CPE model, specifically in the firmware version 1.00(AAFR.4)C0_20170615. This vulnerability allows an authenticated attacker to execute operating system commands on the affected device via Telnet. However, it is important to note that WAN access and the Telnet function are disabled by default on these devices. Exploitation of this vulnerability would require knowledge of the user-configured passwords, which, if compromised, could lead to unauthorized command execution on the device.
Zyxel VMG4325-B10A Command Injection Vulnerability in Legacy DSL CPE
A post-authentication command injection vulnerability has been identified in the CGI program of the Zyxel VMG4325-B10A DSL CPE, running firmware version 1.00(AAFR.4)C0_20170615. This vulnerability allows authenticated attackers to execute operating system commands on the affected device by sending a crafted HTTP POST request. The issue arises because the device's default WAN access is disabled, meaning the attack can only be successful if user-configured passwords have been compromised.
SKT Blocks WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the SKT Blocks Gutenberg-based Page Builder plugin for WordPress, affecting all versions through 1.7. The issue arises in the 'post-carousel' block, where inadequate input sanitization and output escaping allow authenticated attackers with contributor-level access or higher to inject arbitrary scripts. These scripts are executed when a user accesses the affected page.
SocialV WordPress Theme Missing Authorization Vulnerability Allowing Arbitrary File Download
A vulnerability exists in the SocialV - Social Network and Community BuddyPress Theme for WordPress, in all versions through 2.0.15. The issue arises from a missing capability check in the 'socialv_send_download_file' function, which allows authenticated attackers with Subscriber-level access or higher to download arbitrary files from the server.
ShopSite WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the ShopSite plugin for WordPress, affecting all versions through 1.5.10. The vulnerability arises from inadequate nonce validation, allowing unauthenticated attackers to manipulate settings and inject harmful scripts by tricking an administrator into clicking a link.
DSGVO All in One for WP WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Account Deletion
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the DSGVO All in One for WP WordPress plugin, affecting all versions through 4.6. The issue arises from inadequate nonce validation in the user_remove_form.php file, enabling unauthenticated attackers to delete admin user accounts by tricking an administrator into clicking a link.
WPForms Lite Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WPForms Lite plugin for WordPress, specifically in versions through 1.9.3.1. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into pages. These scripts are executed when a user accesses the affected page.
