CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
OTRS Improper Privilege Management Vulnerability in Generic Interface Module
A vulnerability allowing improper privilege management has been identified in the OTRS Generic Interface module. This issue allows users with read-only permissions to change the status of tickets. The vulnerability affects multiple OTRS versions, including 7.0.X, 8.0.X, 2023.X, 2024.X, and the Community Edition 6.0.x. Additionally, products based on the OTRS Community Edition are likely affected.
OTRS and OTRS Community Edition Missing X-Content-Type-Options Header Vulnerability
A vulnerability exists in OTRS and OTRS Community Edition that involves the absence of the X-Content-Type-Options HTTP response header, which is crucial for preventing MIME type sniffing. This flaw allows an attacker to upload or insert content that could be misinterpreted as a different MIME type than intended. The vulnerability affects OTRS versions 7.0.X, 8.0.X, 2023.X, and 2024.X, as well as OTRS Community Edition 6.0.x. Additionally, products based on OTRS Community Edition are likely affected.
Social Share Buttons for WordPress Unauthenticated Image Upload Vulnerability
A vulnerability in the Social Share Buttons for WordPress plugin, affecting versions through 2.7, allows unauthenticated users to upload arbitrary images and manipulate the upload path. This could potentially be exploited for path traversal attacks.
Crelly Slider WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Crelly Slider WordPress plugin, affecting versions prior to 1.4.7. The issue arises because the plugin fails to properly sanitize and escape certain settings. This flaw enables high-privilege users, such as administrators, to execute stored cross-site scripting attacks, even in environments where the unfiltered_html capability is restricted, such as multisite setups.
WP Triggers Lite WordPress Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WP Triggers Lite WordPress plugin, affecting versions through 2.5.3. The issue arises because the plugin fails to properly sanitize and escape a parameter before incorporating it into a SQL statement. This oversight enables administrators to execute SQL injection attacks.
WP Triggers Lite WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WP Triggers Lite WordPress plugin, affecting versions through 2.5.3. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
Dyn Business Panel WordPress Plugin Cross-Site Scripting Vulnerability via Cross-Site Request Forgery
A stored cross-site scripting vulnerability has been identified in the Dyn Business Panel WordPress plugin, affecting versions through 1.0.0. The issue arises because the plugin lacks proper cross-site request forgery (CSRF) checks in certain areas and fails to adequately sanitize and escape user input. This combination could enable attackers to exploit CSRF vulnerabilities, potentially leading to the injection of malicious scripts that are stored and executed later.
Dyn Business Panel WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Dyn Business Panel WordPress plugin, affecting versions through 1.0.0. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
Dyn Business Panel WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Dyn Business Panel WordPress plugin, affecting versions through 1.0.0. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
Dental Optimizer Patient Generator App WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Dental Optimizer Patient Generator App WordPress plugin, affecting versions through 1.0. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
Altra Side Menu WordPress Plugin Cross-Site Request Forgery Vulnerability
A cross-site request forgery (CSRF) vulnerability has been identified in the Altra Side Menu WordPress plugin, affecting versions through 2.0. The vulnerability arises because the plugin lacks adequate CSRF protections in certain areas, potentially allowing attackers to exploit logged-in administrators into deleting arbitrary menu items.
Altra Side Menu WordPress Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the Altra Side Menu WordPress plugin, affecting versions through 2.0. The issue arises because the plugin fails to properly sanitize and escape a parameter before incorporating it into a SQL statement. This oversight enables administrators to execute SQL injection attacks.
WP Customer Area WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP Customer Area WordPress plugin, affecting versions through 8.2.4. The vulnerability arises because the plugin lacks adequate CSRF protection in certain areas, potentially allowing attackers to exploit logged-in users into performing unintended actions.
WC Affiliate WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WC Affiliate WordPress plugin, affecting versions through 2.3.9. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
WP Customer Area WordPress Plugin Cross-Site Request Forgery Vulnerability in Log Deletion
A cross-site request forgery (CSRF) vulnerability has been identified in the WP Customer Area WordPress plugin, affecting versions through 8.2.4. The vulnerability arises because the plugin does not implement CSRF protection when logs are deleted. This lack of protection could enable attackers to exploit a logged-in user to delete logs on their behalf.
IBM Security Directory Integrator and IBM Security Verify Directory Integrator Session Cookie Security Vulnerability
A vulnerability exists in IBM Security Directory Integrator versions 7.2.0 and 10.0.0 that stems from the absence of the secure attribute on authorization tokens and session cookies. This oversight allows attackers to intercept cookie values by sending a link via HTTP to a user or by embedding such a link on a site the user visits. The cookies would be transmitted over the insecure link, enabling the attacker to snoop on the traffic and capture the cookie values.
IBM Security Directory Integrator and IBM Security Verify Directory Integrator Session Cookie Vulnerability
A vulnerability exists in IBM Security Directory Integrator version 7.2.0 and IBM Security Verify Directory Integrator version 10.0.0, where the secure attribute is not applied to authorization tokens or session cookies. This oversight allows attackers to intercept cookie values by sending a link to a user or embedding it in a site the user visits. The cookie would then be transmitted to the insecure link, enabling the attacker to snoop on the traffic and capture the cookie value.
IBM Security Directory Integrator Sensitive Information Disclosure Vulnerability
A vulnerability in IBM Security Directory Integrator versions 7.2.0 and 10.0.0 could lead to the unintentional disclosure of sensitive directory information. This information could be leveraged to conduct further attacks against the system.
IBM InfoSphere Master Data Management Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in IBM InfoSphere Master Data Management versions 11.6, 12.0, and 14.0. This issue allows users to inject arbitrary JavaScript into the Web UI, potentially altering functionality and leading to credential disclosure within a trusted session.
Needyamin Image Gallery Unrestricted File Upload Vulnerability in Cover Image Handler
A critical unrestricted file upload vulnerability has been identified in Needyamin's Image Gallery version 1.0. The issue resides in the admin/gallery.php file, specifically within the Cover Image Handler component. This vulnerability allows remote attackers to upload files without restriction, potentially leading to malware distribution, remote code execution, data breaches, denial-of-service conditions, web shell installations, and bypassing security controls.
Needyamin Image Gallery Cross-Site Scripting Vulnerability in view.php
A cross-site scripting (XSS) vulnerability has been identified in Needyamin Image Gallery version 1.0. The issue arises in the view.php file, specifically within the image_gallery function, where the Username parameter is not properly sanitized. This flaw allows remote attackers to inject malicious scripts that could be executed in the context of the user's browser. The vulnerability has been publicly disclosed and could potentially lead to an admin account takeover, as the injected scripts could be used to steal cookies and impersonate the user.
Microword eScan Antivirus Stack-Based Buffer Overflow Vulnerability
A stack-based buffer overflow vulnerability has been identified in Microword eScan Antivirus version 7.0.32 for Linux. The issue resides in the 'removeExtraSlashes' function of the 'rtscanner' file, which is part of the Folder Watch List Handler component. This vulnerability allows for local exploitation, as the 'rtscanner' binary runs as a system service and can be manipulated by unprivileged users. The vulnerability disrupts the application's real-time protection by overwriting the stack with excessive data, potentially leading to arbitrary code execution.
Itechscripts School Management Software SQL Injection Vulnerability in Notice Edit Feature
A critical SQL injection vulnerability has been identified in Itechscripts School Management Software version 2.75. The issue arises in the notice-edit.php file, where the aid parameter can be manipulated to execute arbitrary SQL commands. This vulnerability can be exploited remotely, potentially leading to unauthorized data access or modification.
IBM Common Licensing Broken Authorization Vulnerability Allowing Unauthorized Configuration File Modification
A vulnerability in IBM Common Licensing version 9.0 could enable an authenticated user to improperly modify a restricted configuration file. This issue arises from a flawed authorization mechanism that fails to adequately restrict user access to certain files.
IBM Common Licensing Password Exposure Vulnerability
A vulnerability exists in IBM Common Licensing version 9.0, where user credentials are stored in plain text, allowing local users to read them. This issue could lead to unauthorized access to user accounts if an attacker gains access to the logged-in user's session. The vulnerability is present in both the IBM License Key Server Administration and Reporting Tool and its Agent.
IBM Cognos Mobile Client Information Disclosure Vulnerability Due to Lack of Certificate Pinning
A vulnerability allowing information disclosure through man-in-the-middle techniques has been identified in IBM Cognos Mobile Client version 1.1 for iOS. This issue arises from the absence of certificate pinning, which could otherwise prevent such interception of data.
IBM Automation Decision Services Local File Storage Vulnerability Allowing Unauthorized Access
A vulnerability in IBM Automation Decision Services version 23.0.2 allows web pages to be stored locally and accessed by another user on the same system. This could lead to unauthorized access to potentially sensitive information.
Survey Maker WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Survey Maker plugin for WordPress, affecting all versions through 5.1.3.3. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with administrator-level access to inject arbitrary web scripts into survey questions. This injected script executes when a user accesses the affected survey page. The vulnerability is present in multi-site installations where the 'unfiltered_html' capability has been disabled.
WC Affiliate WooCommerce Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WC Affiliate – A Complete WooCommerce Affiliate Plugin for WordPress, affecting all versions through 2.4. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link or performing a similar action.
Zox News WordPress Theme Missing Authorization Vulnerability in Options Update
A vulnerability exists in the Zox News theme for WordPress, all versions through 3.16.0, allowing unauthorized data modification that could lead to privilege escalation. This issue arises from a lack of capability checks in the 'backup_options' and 'restore_options' functions. As a result, authenticated attackers with Subscriber-level access or higher can manipulate arbitrary options on the WordPress site. This vulnerability could be exploited to change the default registration role to administrator and enable user registration, granting administrative access to the attacker on the compromised site.
VikBooking Hotel Booking Engine & PMS WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the VikBooking Hotel Booking Engine & PMS plugin for WordPress, affecting all versions through 1.7.2. The vulnerability arises from inadequate nonce validation in the 'save' function, allowing unauthenticated attackers to manipulate plugin access rights by tricking an administrator into clicking a link. Exploitation of this vulnerability enables attackers with subscriber-level privileges or higher to upload arbitrary files to the site's server, potentially leading to remote code execution.
Develocity Incorrect Access Control Vulnerability Disables Project-Level Access Control on Upgrade
A vulnerability in Develocity (formerly Gradle Enterprise) prior to version 2024.1.8 allows for incorrect access control management. When upgrading from versions 2023.3.X or 2023.4.X to 2024.1.X (up to and including 2024.1.7), project-level access control settings are reset to default values, disabling access control and disclosing previously restricted project information. This issue arises because the migration functionality from Enterprise Config schema version 8 to versions 9 and 10 does not include the projects section, leading to a loss of customized settings. The vulnerability can only be exploited by administrators during the upgrade process.
Membership Plugin Restrict Content Sensitive Information Exposure Vulnerability
A vulnerability allowing sensitive information exposure has been identified in the Membership Plugin – Restrict Content for WordPress, affecting all versions through 3.2.13. This vulnerability arises from an improper handling of content restrictions, allowing unauthenticated users to access sensitive data in posts restricted to higher-level roles, such as administrators. The issue can be exploited through the WordPress core search feature.
Multiple Page Generator Plugin for WordPress Server-Side Request Forgery Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in the Multiple Page Generator Plugin (MPG) for WordPress, affecting all versions through 4.0.5. The vulnerability arises in the 'mpg_download_file_by_link' function, allowing authenticated attackers with editor-level access or higher to make web requests to arbitrary locations. This could be exploited to query and modify information from internal services.
Develocity Password Hash Exposure Vulnerability
A vulnerability in Develocity (formerly Gradle Enterprise) versions prior to 2024.3.1 allows an attacker with network access to a Develocity server to retrieve the hashed password of the system user. While the hashing algorithm follows best practices for password storage and offers some resistance to brute-force attacks, the vulnerability's severity is heightened if the server is accessible to external or unauthorized users, and depends on the complexity of the system user's password.
Quiz Maker WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Quiz Maker WordPress plugin, specifically in the Business, Developer, and Agency versions. This vulnerability affects all versions up to and including 8.8.0 (Business), 21.8.0 (Developer), and 31.8.0 (Agency). The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the 'content' parameter. These injected scripts could be executed if a user is tricked into clicking a link.
Quiz Maker WordPress Plugin Unauthenticated Arbitrary Shortcode Execution Vulnerability
A vulnerability allowing unauthenticated users to execute arbitrary shortcodes has been identified in the Quiz Maker WordPress plugin. This issue affects the Business, Developer, and Agency versions of the plugin, all prior to the latest patched releases. The vulnerability arises because the plugin does not properly validate values before executing shortcodes, allowing for unauthorized shortcode execution.
Quiz Maker WordPress Plugins SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the Quiz Maker Business, Developer, and Agency plugins for WordPress. This issue affects all versions prior to and including 8.8.0 (Business), 21.8.0 (Developer), and 31.8.0 (Agency). The vulnerability arises from inadequate escaping of user-supplied data in the 'id' parameter, allowing unauthenticated attackers to inject additional SQL queries. Exploitation of this vulnerability could lead to unauthorized access to sensitive information in the database.
Quiz Maker WordPress Plugin Unauthorized Data Modification Vulnerability
A vulnerability exists in the Quiz Maker WordPress plugin, specifically in the Business, Developer, and Agency versions, all prior to the latest release. The issue stems from a missing capability check in the 'ays_save_google_credentials' function, which allows unauthorized users to modify Google Sheets integration credentials within the plugin's settings. Additionally, the vulnerability could be exploited to inject arbitrary web scripts into pages, executing them when a user accesses the injected page.
libxml2 Use-After-Free Vulnerability in xmlXIncludeAddNode Function
A use-after-free vulnerability has been identified in libxml2 versions prior to 2.11.0, specifically within the xmlXIncludeAddNode function in xinclude.c. This vulnerability can be exploited by manipulating XML data to create a memory management issue, leading to potential memory corruption.
G DATA Security Client Local Privilege Escalation Vulnerability
A local privilege escalation vulnerability has been identified in G DATA Security Client. This issue arises from an incorrect assignment of privileges to directories, allowing a local, unprivileged attacker to escalate privileges on affected installations. The vulnerability can be exploited by placing an arbitrary executable in a globally writable directory, which is then executed by the SetupSVC.exe service with SYSTEM privileges.
G DATA Management Server Local Privilege Escalation Vulnerability
A local privilege escalation vulnerability has been identified in G DATA Management Server. The issue arises from an incorrect assignment of privileges to temporary files during the update process. This vulnerability allows an unprivileged local attacker to escalate privileges by placing a specially crafted ZIP archive in a globally writable directory. The archive is then unpacked with SYSTEM privileges, leading to arbitrary file write capabilities.
IBM Maximo Application Suite Log Injection Vulnerability in Monitor Component
A log injection vulnerability has been identified in the Monitor Component of IBM Maximo Application Suite. This issue affects versions 8.10.12, 8.11.0, 9.0.1, and 9.1.0. The vulnerability arises because the application does not properly sanitize output before it is logged, potentially allowing an attacker to insert misleading log entries.
IBM Maximo Application Suite Monitor Component SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the Monitor Component of IBM Maximo Application Suite, affecting versions 8.10.10, 8.11.7, and 9.0. This vulnerability allows remote attackers to send specially crafted SQL statements that could be used to view, add, modify, or delete information in the back-end database.
IBM Maximo Application Suite Monitor Component Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been identified in the IBM Maximo Application Suite Monitor Component version 9.0.0. This issue allows an unauthenticated attacker to inject arbitrary JavaScript into the Web UI, potentially altering functionality and leading to credential disclosure within a trusted session.
IBM Maximo Application Suite Monitor Component Web Application Source Code Disclosure Vulnerability
A vulnerability exists in the Monitor Component of IBM Maximo Application Suite versions 8.10, 8.11, and 9.0. This vulnerability involves the improper storage of source code on the web server, which could be exploited to facilitate further attacks against the system.
IBM Analytics Content Hub Buffer Overflow Vulnerability Allowing Arbitrary Code Execution
A buffer overflow vulnerability has been identified in IBM Analytics Content Hub version 2.0. This issue arises from improper return length checking, which could allow a remote authenticated attacker to overflow a buffer, potentially leading to arbitrary code execution on the system or causing the server to crash.
IBM Analytics Content Hub Improper Error Handling Vulnerability Allowing Information Disclosure
An improper error handling vulnerability has been identified in IBM Analytics Content Hub version 2.0. This vulnerability could allow a remote attacker to obtain sensitive information from the application. The issue arises when detailed technical error messages are returned in the browser, potentially exposing information that could be used in further attacks against the system.
IBM Control Center User Enumeration Vulnerability
A user enumeration vulnerability has been identified in IBM Control Center versions 6.2.1 and 6.3.1. This vulnerability allows remote attackers to enumerate usernames by exploiting an observable discrepancy in login attempt responses.
IBM Control Center Directory Listing Vulnerability Allowing Information Exposure
A directory listing vulnerability has been identified in IBM Control Center versions 6.2.1 and 6.3.1. This issue could enable an authenticated user to access sensitive information exposed through the directory listing.
