CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
UkrSolution Print Barcode Labels for WooCommerce Missing Authorization Vulnerability
A broken access control vulnerability has been identified in the Print Barcode Labels for WooCommerce Products/Orders plugin, affecting versions through 3.4.10. This vulnerability allows unprivileged users to perform actions that require higher privileges, due to a lack of proper authorization checks.
WordPress RSVPMarker Plugin Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the WordPress RSVPMarker plugin, affecting versions through 11.4.5. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.
WisdmLabs Edwiser Bridge Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WisdmLabs Edwiser Bridge WordPress plugin, affecting versions through 3.0.8. This vulnerability arises from improper input neutralization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.
Haptiq Picu Online Photo Proofing Gallery Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the Haptiq Picu Online Photo Proofing Gallery plugin for WordPress, affecting versions through 2.4.0. This vulnerability arises from incorrectly configured access control security levels, allowing unprivileged users to perform actions reserved for higher privileges.
SeedProd WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Coming Soon Page, Under Construction & Maintenance Mode by SeedProd WordPress plugin, affecting versions through 6.18.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress BuddyPress Groups Extras Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress BuddyPress Groups Extras plugin, affecting versions through 3.6.10. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
The Events Calendar Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in The Events Calendar WordPress plugin, affecting versions through 6.7.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Fare Calculator Plugin Missing Authorization Vulnerability Allowing Stored Cross-Site Scripting
A missing authorization vulnerability in the WordPress Fare Calculator plugin, specifically in versions through 1.1, allows for stored cross-site scripting (XSS) attacks. This vulnerability arises from cross-site request forgery (CSRF) conditions, enabling malicious actors to exploit higher-privileged users into performing unintended actions.
WordPress PAPERCITE Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the WordPress PAPERCITE plugin, specifically in versions through 0.5.18. This vulnerability allows exploitation of improperly configured access control security levels, potentially leading to unauthorized actions by users with lower privileges.
LawPress WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the LawPress WordPress plugin, specifically in versions through 1.4.5. This issue allows attackers to inject malicious scripts that are executed when users visit the affected website.
Ulrich Sossou The Loops Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress plugin The Loops, affecting versions through 1.0.2. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress CGD Arrange Terms Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress CGD Arrange Terms plugin, specifically in versions through 1.1.3. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.
WP Smart Tooltip Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WP Smart Tooltip WordPress plugin, affecting versions through 1.0.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Donate Visa Plugin Missing Authorization Vulnerability Allowing Stored Cross-Site Scripting
A missing authorization vulnerability has been identified in the WordPress Donate Visa plugin, specifically in versions through 1.0.0. This vulnerability allows for stored cross-site scripting (XSS) attacks.
Jonathan Lau CubePM Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Jonathan Lau CubePM WordPress plugin, affecting versions through 1.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress RSVPMaker Volunteer Roles Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress RSVPMaker Volunteer Roles plugin, affecting versions through 1.5.1. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.
Blokhaus Minterpress Missing Authorization Vulnerability Allowing Arbitrary Content Deletion
A missing authorization vulnerability has been identified in the Blokhaus Minterpress WordPress plugin, affecting versions through 1.0.5. This vulnerability allows users to access functionalities that are not properly restricted by access control lists (ACLs), potentially leading to unauthorized deletion of content such as posts, pages, or media.
D-Link DIR-825 OS Command Injection Vulnerability in the CGl Interface
An OS command injection vulnerability has been identified in the D-Link DIR-825 REV B2.03 router. The issue resides in the CGl interface, specifically within the apc_client_pin.cgi script. This vulnerability allows remote attackers to execute arbitrary commands by sending a POST request with the 'wps_pin' parameter to the apc_client_pin.cgi binary.
TRENDnet TEW-632BRP OS Command Injection Vulnerability in NTP Synchronization CGI
An OS command injection vulnerability has been identified in TRENDnet TEW-632BRP devices running version 1.010B31. The issue resides in the CGI interface 'ntp_sync.cgi', where remote attackers can execute arbitrary commands by sending a POST request with the 'ntp_server' parameter.
Houzez WordPress Theme Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the Houzez WordPress theme, specifically in versions through 3.4.0. This vulnerability allows an unprivileged user to perform actions that require higher privileges, due to a lack of proper authorization checks.
Morkva UA Shipping Plugin Path Traversal Vulnerability Leading to Local File Inclusion
A path traversal vulnerability has been identified in the Morkva UA Shipping WordPress plugin, allowing for local file inclusion. This issue affects versions through 1.0.18 of the plugin.
Eniture Technology LTL Freight Quotes Worldwide Express Edition SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the Eniture Technology LTL Freight Quotes plugin, specifically in the Worldwide Express Edition, for WordPress versions through 5.0.20. This vulnerability allows for improper neutralization of special elements used in SQL commands, enabling attackers to manipulate database queries and potentially access or modify database information.
WordPress Shipping for Nova Poshta SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WordPress Shipping for Nova Poshta plugin, affecting versions through 1.19.6. This vulnerability allows for improper neutralization of special elements used in SQL commands, enabling attackers to manipulate database queries and potentially access or modify database information.
ThimPress FundPress PHP Object Injection Vulnerability
A deserialization vulnerability allowing object injection has been identified in the ThimPress FundPress WordPress plugin, affecting versions through 2.0.6. This vulnerability could lead to various types of code injection, including SQL injection, path traversal, and denial-of-service, especially if a suitable property-oriented programming chain is available.
BdThemes Ultimate Store Kit Elementor Addons Missing Authorization Vulnerability
A broken access control vulnerability has been identified in BdThemes Ultimate Store Kit Elementor Addons, affecting versions through 2.3.0. This vulnerability arises from missing authorization checks, allowing users with lower privileges to perform actions reserved for higher privileged users.
WordPress MetaSlider Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress MetaSlider Responsive Slider plugin, specifically in versions through 3.92.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Passwordless WP Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress Passwordless WP – Login with your glance or fingerprint plugin, affecting versions through 1.1.6. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.
Clodeo Shipdeo Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Clodeo Shipdeo WordPress plugin, affecting versions through 1.2.8. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
NotFound Simple Locator Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the NotFound Simple Locator WordPress plugin, affecting versions through 2.0.4. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.
Eura7 CMSmanager Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in Eura7 CMSmanager versions 4.6 and below. This issue arises from improper neutralization of input in the 'return' GET request parameter, which can be manipulated and sent to a specific endpoint. The vulnerability has been addressed in patch 17012022, which is applicable to all affected versions.
Red Hat Advanced Cluster Security Cross-Site Scripting Vulnerability in Portal
A cross-site scripting (XSS) vulnerability has been identified in the Red Hat Advanced Cluster Security (RHACS) portal. This issue arises when the portal renders a table view, particularly on endpoints under '/main/configmanagement/*'. The front-end creates a DOM table element with the id 'pdf-table', which is filled with unsanitized data using innerHTML. An attacker with some control over the rendered data can exploit this vulnerability.
Xerox Workplace Suite Session Storage Token Exposure Vulnerability
A vulnerability exists in Xerox Workplace Suite due to the storage of tokens in session storage, which could be accessed if a user's session is compromised. This issue will be addressed in a future release of Workplace Suite, with customers to be notified through an update to the security bulletin.
Cesanta Frozen NULL Pointer Dereference Vulnerability Allowing Denial-of-Service
A NULL pointer dereference vulnerability has been identified in Cesanta Frozen versions prior to 1.7. This vulnerability allows an attacker to cause a crash in the component that embeds the library by sending a maliciously crafted JSON input.
Cesanta Frozen Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Cesanta Frozen versions prior to 1.7. This vulnerability allows an attacker to cause a crash in the component that embeds the library by sending a maliciously crafted JSON as input.
INW Krbyyyzo Resource Consumption Vulnerability in Daily Huddle Site Component
A resource consumption vulnerability has been identified in INW Krbyyyzo version 25.2002, specifically within the Daily Huddle Site component. The issue arises in the file '/gbo.aspx', where the manipulation of the argument 's' leads to excessive resource usage. This vulnerability can be exploited locally and requires authentication.
Apache Solr Privilege Escalation Vulnerability via Untrusted Config Files
A vulnerability in Apache Solr core creation allows users to replace "trusted" configset files with arbitrary, potentially untrusted files from the filesystem. This issue affects Solr instances using the "FileSystemConfigSetService" component, which is the default in "standalone" or "user-managed" mode", and are running without authentication and authorization. The replacement config files are treated as "trusted" and can include "<lib>" tags to modify Solr's classpath, potentially leading to the execution of malicious code as a search component or other plugin. This vulnerability exists in all Apache Solr versions prior to 9.8.0.
Apache Solr Relative Path Traversal Vulnerability in Configset Upload API on Windows
A relative path traversal vulnerability has been identified in Apache Solr versions 6.6 through 9.7.0, specifically in instances running on Windows. This vulnerability allows arbitrary write access to the filesystem due to inadequate input sanitation in the 'configset upload' API. Maliciously crafted ZIP files can exploit this flaw, using relative paths to write data to unexpected locations on the filesystem. This issue is commonly referred to as a 'zipslip' vulnerability.
OTRS Session Hijacking Vulnerability Due to Missing Cookie Attributes
A session hijacking vulnerability exists in OTRS Application Server and reverse proxy settings, caused by missing attributes for sensitive cookie settings in HTTPS sessions. This issue affects OTRS versions 7.0.X, 8.0.X, 2023.X, and 2024.X.
OTRS and OTRS Community Edition Sensitive Information Disclosure Vulnerability
A vulnerability exists in OTRS versions 7.0.X, 8.0.X, 2023.X, 2024.X, and in OTRS Community Edition 6.0.x. This issue arises from certain errors in upstream libraries that inadvertently introduce sensitive information, such as SMTP passwords, into the OTRS log files and in emails sent to the system administrator. Products based on OTRS Community Edition are also likely affected.
OTRS Improper Privilege Management Vulnerability in Generic Interface Module
A vulnerability allowing improper privilege management has been identified in the OTRS Generic Interface module. This issue allows users with read-only permissions to change the status of tickets. The vulnerability affects multiple OTRS versions, including 7.0.X, 8.0.X, 2023.X, 2024.X, and the Community Edition 6.0.x. Additionally, products based on the OTRS Community Edition are likely affected.
OTRS and OTRS Community Edition Missing X-Content-Type-Options Header Vulnerability
A vulnerability exists in OTRS and OTRS Community Edition that involves the absence of the X-Content-Type-Options HTTP response header, which is crucial for preventing MIME type sniffing. This flaw allows an attacker to upload or insert content that could be misinterpreted as a different MIME type than intended. The vulnerability affects OTRS versions 7.0.X, 8.0.X, 2023.X, and 2024.X, as well as OTRS Community Edition 6.0.x. Additionally, products based on OTRS Community Edition are likely affected.
Social Share Buttons for WordPress Unauthenticated Image Upload Vulnerability
A vulnerability in the Social Share Buttons for WordPress plugin, affecting versions through 2.7, allows unauthenticated users to upload arbitrary images and manipulate the upload path. This could potentially be exploited for path traversal attacks.
Crelly Slider WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Crelly Slider WordPress plugin, affecting versions prior to 1.4.7. The issue arises because the plugin fails to properly sanitize and escape certain settings. This flaw enables high-privilege users, such as administrators, to execute stored cross-site scripting attacks, even in environments where the unfiltered_html capability is restricted, such as multisite setups.
WP Triggers Lite WordPress Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WP Triggers Lite WordPress plugin, affecting versions through 2.5.3. The issue arises because the plugin fails to properly sanitize and escape a parameter before incorporating it into a SQL statement. This oversight enables administrators to execute SQL injection attacks.
WP Triggers Lite WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WP Triggers Lite WordPress plugin, affecting versions through 2.5.3. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
Dyn Business Panel WordPress Plugin Cross-Site Scripting Vulnerability via Cross-Site Request Forgery
A stored cross-site scripting vulnerability has been identified in the Dyn Business Panel WordPress plugin, affecting versions through 1.0.0. The issue arises because the plugin lacks proper cross-site request forgery (CSRF) checks in certain areas and fails to adequately sanitize and escape user input. This combination could enable attackers to exploit CSRF vulnerabilities, potentially leading to the injection of malicious scripts that are stored and executed later.
Dyn Business Panel WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Dyn Business Panel WordPress plugin, affecting versions through 1.0.0. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
Dyn Business Panel WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Dyn Business Panel WordPress plugin, affecting versions through 1.0.0. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
Dental Optimizer Patient Generator App WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Dental Optimizer Patient Generator App WordPress plugin, affecting versions through 1.0. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
Altra Side Menu WordPress Plugin Cross-Site Request Forgery Vulnerability
A cross-site request forgery (CSRF) vulnerability has been identified in the Altra Side Menu WordPress plugin, affecting versions through 2.0. The vulnerability arises because the plugin lacks adequate CSRF protections in certain areas, potentially allowing attackers to exploit logged-in administrators into deleting arbitrary menu items.
