CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Zettler TCP/IP Gateway Password Hash and Session Token Leakage Vulnerability
A vulnerability classified as CWE-598, involving the inappropriate use of the GET request method with sensitive query strings, has been identified in the Zettler 130.8005 TCP/IP Gateway operating on firmware version 12h. This vulnerability exposes the SHA-1 hash of passwords and session tokens in the URL, creating a risk of information leakage. An attacker who can access these values, such as through network traffic inspection or via the victim's browser, could exploit this issue to extract the password hash and session tokens, potentially bypassing authentication by using a pass-the-hash attack.
Zettler TCP/IP Gateway Buffer Over-read Vulnerability Allowing Authentication Token Leakage
A buffer over-read vulnerability has been identified in the Zettler 130.8005 TCP/IP Gateway, specifically in devices running firmware version 12h. This vulnerability allows remote, unauthenticated attackers to exploit a memory leak in the web server, leading to the unauthorized disclosure of valid authentication tokens from the process memory of users currently logged into the system. As a result, attackers can bypass the authentication mechanism.
Linux Kernel Race Condition Vulnerability in Ethnl Operations During Device Unregistration
A race condition vulnerability has been identified in the Linux kernel's handling of network device operations. This issue arises when a device is unregistered while its channel settings are being modified, potentially leading to improper synchronization and use of device locks. The vulnerability affects Linux kernel versions through 6.13.0-rc6.
WordPress TinyMCE Advanced qTranslate Cross-Site Request Forgery Vulnerability Allowing Stored XSS
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress TinyMCE Advanced qTranslate fix editor problems plugin, affecting versions through 1.0.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks.
WordPress Page/Post Specific Social Share Buttons Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Page/Post Specific Social Share Buttons plugin, affecting versions through 2.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks.
WordPress Simple Documentation Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Simple Documentation plugin, specifically in versions through 1.2.8. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.
WordPress DX-Auto-Publish Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress DX-auto-publish plugin, specifically in versions through 1.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts, which are then stored and executed later.
WordPress Google Drive WP Media Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Google Drive WP Media plugin for WordPress, affecting versions through 2.4.4. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress WP PHPList Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress WP PHPList plugin, specifically in versions through 1.7. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Wibiya Toolbar Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wibiya Toolbar WordPress plugin, affecting versions through 2.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Glance That Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Glance That plugin, affecting versions through 4.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Post Thumbs Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Post Thumbs plugin, specifically in versions through 1.5. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into posts.
WordPress Easy Amazon Product Information Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Easy Amazon Product Information plugin, affecting versions through 4.0.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.
WordPress Font Awesome WP Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress Font Awesome WP plugin, affecting versions through 1.0. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
WordPress RSS Filter Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress RSS Filter plugin, specifically in versions through 1.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could lead to the injection of malicious scripts.
Elfsight Yottie Lite Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Elfsight Yottie Lite WordPress plugin, affecting versions through 1.3.3. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Aparat Responsive Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress Aparat Responsive plugin, affecting versions through 1.3. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
badrHan Naver Syndication V2 Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the badrHan Naver Syndication V2 plugin, affecting versions through 0.8.3. This vulnerability arises from improper neutralization of input during web page generation, allowing malicious users to inject harmful scripts that are stored and executed later.
WordPress Bootstrap Collapse Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Bootstrap Collapse Plugin, specifically in versions through 1.0.4. This issue arises from improper input neutralization during web page generation, allowing malicious users to inject harmful scripts that are executed when the affected page is viewed.
WordPress Global Meta Keyword and Description Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Global Meta Keyword & Description plugin, specifically in versions through 2.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts, which are then stored and executed later.
WordPress WP Html Page Sitemap Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress WP Html Page Sitemap plugin, specifically in versions through 2.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.
WordPress My Login Logout Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress My Login Logout Plugin, affecting versions through 2.4. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could introduce malicious scripts that are permanently stored and executed later.
WordPress Related Posts Line-up-Exactly by Milliard Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress plugin 'Related Posts Line-up-Exactly' by Milliard, affecting versions through 0.0.22. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.
WordPress Simple Responsive Menu Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Simple Responsive Menu plugin, affecting versions through 2.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts, which are then stored and executed later.
WordPress Embed Google Map Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Embed Google Map plugin, affecting versions through 3.2. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress Prezi Embedder Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Prezi Embedder plugin, affecting versions through 2.1. This issue arises from improper input handling during web page generation, allowing malicious scripts to be injected and executed when users visit the site.
Red Hat Quarkus REST Request Parameter Leakage Vulnerability
A vulnerability exists in Red Hat Quarkus REST that allows request parameters to leak between concurrent requests. This issue arises when endpoints use field injection without a proper CDI scope, leading to the unintentional sharing of request data between users. As a result, attackers could manipulate request information, impersonate users, or access sensitive data. The vulnerability affects all versions of the Red Hat build of Quarkus prior to 3.15.3.SP1, as well as versions of Red Hat Build of Apache Camel 4.8 for Quarkus 3.15 prior to 3.15.3.SP1.
Anapi Group h6web Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in Anapi Group's h6web application, which is used for managing guilds and online payments. This vulnerability allows an attacker to inject malicious JavaScript into a URL. When a user clicks on the link, the injected script runs in their browser, potentially leading to the theft of sensitive information, identity theft, or unauthorized actions being performed on behalf of the user.
Anapi Group h6web Insecure Direct Object Reference Vulnerability Allowing User Impersonation
An insecure direct object reference (IDOR) vulnerability has been identified in Anapi Group's h6web application, which is used for managing guilds and online payments. This vulnerability allows an authenticated attacker to access information belonging to other users by sending a POST request and altering the 'pkrelated' parameter in the '/h6web/ha_datos_hermano.php' endpoint to target another user. Additionally, this exploitation could enable the attacker to impersonate other users, causing all subsequent requests to be executed with the privileges of the impersonated user.
PostgreSQL SQL Injection Vulnerability in Quoting APIs
A SQL injection vulnerability has been identified in PostgreSQL's libpq quoting functions: PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn(). This issue arises from improper handling of quoting syntax, which can be exploited under certain conditions. Specifically, the vulnerability is present in PostgreSQL versions prior to 17.3, 16.7, 15.11, 14.16, and 13.19. The injection occurs when the function's output is used to create input for psql, the PostgreSQL interactive terminal. Additionally, similar quoting issues in PostgreSQL command line utilities can lead to SQL injection when the client_encoding is set to BIG5 and the server_encoding is either EUC_TW or MULE_INTERNAL.
WP Directorybox Manager Authentication Bypass Vulnerability
A vulnerability allowing authentication bypass has been identified in the WP Directorybox Manager plugin for WordPress, affecting all versions through 2.5. The issue arises from improper authentication in the 'wp_dp_parse_request' function, enabling unauthenticated attackers to log in as any existing user, including administrators.
Linux Kernel Privilege Escalation Vulnerability via Use-After-Free in Qdisc Management
A use-after-free vulnerability has been identified in the Linux kernel's network scheduling component, specifically within the management of queue disciplines (qdiscs). This vulnerability can be exploited for privilege escalation. The issue arises when a qdisc is replaced from one parent to another, allowing for manipulation of the qdisc's reference count and potentially leading to unauthorized access or privileges.
Listivo Classified Ads WordPress Theme Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Listivo - Classified Ads WordPress Theme, affecting all versions through 2.3.67. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link that contains the malicious payload.
JS Help Desk WordPress Plugin Sensitive Information Exposure Vulnerability
A vulnerability allowing sensitive information exposure exists in the JS Help Desk – The Ultimate Help Desk & Support Plugin for WordPress, affecting all versions through 2.8.8. The issue arises from the 'jssupportticketdata' directory, where unauthenticated attackers can access sensitive data, including file attachments from support tickets, stored insecurely in the '/wp-content/uploads/jssupportticketdata' directory.
Apache Atlas Cross-Site Scripting Vulnerability Allowing User Impersonation
A cross-site scripting (XSS) vulnerability has been identified in Apache Atlas, allowing an authenticated user to perform XSS attacks and potentially impersonate another user. This issue affects Apache Atlas versions 2.0.0 through 2.3.0. The vulnerability arises from insufficient input sanitization, which could be exploited to inject malicious scripts that are executed in the context of the user's browser.
GitLab EE Prompt Injection Vulnerability Leading to Unauthorized Data Exfiltration from Private Issues
A prompt injection vulnerability has been identified in GitLab EE versions 16.0 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. This vulnerability allows an attacker to exfiltrate information from private issues by injecting prompts that are processed by the application's AI features. The attack involves manipulating issue comments to create links or images that, when accessed, leak confidential data to the attacker.
WordPress Read More & Accordion Plugin Unauthorized Post Deletion Vulnerability
A vulnerability exists in the Read More & Accordion plugin for WordPress, specifically in versions through 3.4.2. The issue arises from a lack of proper capability checks in the expmDeleteData() function, allowing authenticated users with Subscriber-level access and above to delete arbitrary 'read more' posts. This flaw can lead to unauthorized data modification and loss.
Schneider Electric Enerlin'X IFE and eIFE Improper Input Validation Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in Schneider Electric's Enerlin'X IFE and Enerlin'X eIFE products, all versions. This vulnerability arises from improper input validation, allowing malicious IPv6 packets to disrupt the device's operation. The attack causes the IEC61850 services of the affected products to become unavailable, requiring a manual reboot to restore functionality.
Schneider Electric Enerlin'X IFE and eIFE Improper Input Validation Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in Schneider Electric's Enerlin'X IFE and eIFE products, all versions. This vulnerability arises from improper input validation, allowing malicious ICMPv6 packets to be sent to the device. The attack disrupts the availability of the IEC61850 services on the affected products, requiring a manual reboot to restore functionality.
Schneider Electric Products Denial-of-Service Vulnerability via Malicious IEC61850-MMS Packets
A denial-of-service vulnerability has been identified in certain Schneider Electric products, caused by improper input validation. When malicious IEC61850-MMS packets are sent to the device, network services can be disrupted, leading to a denial-of-service condition. However, the core functionality of the device remains unaffected during the attack.
DethemeKit For Elementor Information Exposure Vulnerability
A vulnerability allowing information exposure has been identified in the DethemeKit For Elementor plugin for WordPress, affecting all versions through 2.1.8. The issue arises in the duplicate_post() function, where inadequate restrictions allow authenticated attackers with Contributor-level access and above to duplicate posts and access data from password-protected, private, draft, or scheduled posts that should otherwise be restricted.
Schneider Electric EcoStruxure Process Expert Improper Privilege Management Vulnerability
A vulnerability allowing improper privilege management has been identified in Schneider Electric's EcoStruxure Process Expert and EcoStruxure Process Expert for AVEVA System Platform. This vulnerability affects versions 2020R2, 2021, and 2023, prior to v4.8.0.5715. The issue arises when an attacker with standard privileges modifies the executable path of certain Windows services, one of which manages audit trail data while the other handles client requests. Exploitation of this vulnerability requires restarting the affected services, and could lead to a local privilege escalation, causing a loss of confidentiality, integrity, and availability on the engineering workstation.
Synology Active Backup for Business Path Traversal Vulnerability Allowing File Read by Admins
A path traversal vulnerability has been identified in Synology Active Backup for Business versions prior to 2.7.1-13234, 2.7.1-23234, and 2.7.1-3234. This vulnerability allows remote authenticated users with administrator privileges to read specific files containing non-sensitive information through improper limitation of pathnames to restricted directories. The issue arises in the share file list functionality and can be exploited via unspecified vectors.
Synology Active Backup for Business Path Traversal Vulnerability in Encrypted Share Umount Functionality
A path traversal vulnerability has been identified in Synology Active Backup for Business versions prior to 2.7.1-13234, 2.7.1-23234, and 2.7.1-3234. This vulnerability allows remote authenticated users to write specific files by improperly limiting the pathname to a restricted directory during the encrypted share unmounting process.
Synology Active Backup for Business Path Traversal Vulnerability Allowing Arbitrary File Deletion
A path traversal vulnerability has been identified in Synology Active Backup for Business versions prior to 2.7.1-13234, 2.7.1-23234, and 2.7.1-3234. This vulnerability allows remote authenticated users with administrator privileges to delete arbitrary files through unspecified vectors. The issue arises from improper limitations on file paths, enabling unauthorized file deletion within agent-related functionality.
Avada WordPress Theme Shortcode Execution Vulnerability
A vulnerability allowing arbitrary shortcode execution exists in the Avada WordPress theme, specifically in versions prior to and including 7.11.13. This issue arises because the theme permits users to execute actions without proper validation, allowing unauthenticated attackers to run arbitrary shortcodes.
Avada Builder WordPress Plugin Unauthenticated Arbitrary Shortcode Execution Vulnerability
A vulnerability exists in the Avada Builder plugin for WordPress, allowing unauthenticated users to execute arbitrary shortcodes. This issue affects all versions of the plugin up to and including 3.11.13. The vulnerability arises because the plugin does not properly validate values before executing them with the do_shortcode function.
Schneider Electric ASCO 5310 and 5350 Remote Annunciators Unrestricted File Upload Vulnerability
A vulnerability allowing unrestricted upload of files with dangerous types has been identified in Schneider Electric's ASCO 5310 Single-Channel Remote Annunciator and ASCO 5350 Eight-Channel Remote Annunciator. This vulnerability could lead to the device becoming inoperable if a malicious file is downloaded. The issue affects all versions of both products.
Schneider Electric ASCO 5310 and 5350 Remote Annunciators Cleartext Transmission of Sensitive Information Vulnerability
A vulnerability allowing cleartext transmission of sensitive information has been identified in the ASCO 5310 Single-Channel Remote Annunciator and ASCO 5350 Eight-Channel Remote Annunciator. This vulnerability could lead to data exposure if network traffic is intercepted by an attacker.
Schneider Electric ASCO 5310 and 5350 Remote Annunciators Resource Allocation Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in the ASCO 5310 Single-Channel Remote Annunciator and ASCO 5350 Eight-Channel Remote Annunciator. This vulnerability, classified under CWE-770, allows for the allocation of resources without limits or throttling. When malicious packets are sent to the device's web server, communications can be disrupted, potentially causing a loss of availability or integrity for the remote annunciator functions. However, the basic operation of the transfer switch itself remains unaffected.
