CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 24, 2025

Microsoft Edge (Chromium-based) Spoofing Vulnerability

A vulnerability has been identified in Microsoft Edge (Chromium-based) that involves user interface misrepresentation of critical information. This flaw allows an unauthorized attacker to perform spoofing over a network. The vulnerability exists in Microsoft Edge versions through 132.0.2957.127.

4.7
Jan 24, 2025

CampCodes School Management Software Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in CampCodes School Management Software version 1.0. The issue arises from an unknown function in the file '/notice-list' within the Notice Board component. Manipulating the 'Notice' argument allows for the injection of malicious scripts, which can be executed remotely. This vulnerability has been publicly disclosed and is exploitable.

2.9
Jan 24, 2025

Dcat-Admin Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in Dcat-Admin version 2.2.1-beta. This issue arises from an unknown processing of the file '/admin/auth/roles' within the Roles Page component. The vulnerability allows for the injection of malicious scripts, which can be executed in the context of the user.

5.5
Jan 24, 2025

Fumiao OpenCMS Cross-Site Scripting Vulnerability in Add Model Management Page

A cross-site scripting (XSS) vulnerability has been identified in Fumiao OpenCMS version 2.2. The issue arises in the Add Model Management Page, specifically within the admin/model/addOrUpdate file. The vulnerability is triggered by manipulating the 模板前缀 argument, allowing for remote exploitation.

2.9
Jan 24, 2025

Rise Group Rise Mode Temp CPU Untrusted Search Path Vulnerability in CRYPTBASE.dll

A critical vulnerability has been identified in Rise Group Rise Mode Temp CPU version 2.1, specifically within the CRYPTBASE.dll library. This vulnerability involves an untrusted search path in the Startup component, which could potentially be exploited locally.

1.2
Jan 24, 2025

JoeyBling Bootplus Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in JoeyBling Bootplus versions prior to commit 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. The issue arises from the application's failure to properly sanitize input on the admin/sys/admin.html page, allowing attackers to inject malicious JavaScript. This vulnerability can be exploited remotely.

2.8
Jan 24, 2025

InnoShop Cross-Site Scripting Vulnerability via SVG File Upload

A stored cross-site scripting vulnerability has been identified in InnoShop versions through 0.3.8. This issue allows attackers to upload malicious SVG files that can execute JavaScript, potentially leading to the theft of cookies from users, including those of administrators.

2.9
Jan 24, 2025

Go-CMS SQL Injection Vulnerability Allowing Arbitrary Code Execution

A SQL injection vulnerability has been identified in Go-CMS version 1.1.10. This vulnerability allows remote attackers to execute arbitrary code by sending a crafted payload. The issue arises when exporting user or role data, as the application improperly concatenates IDs into SQL queries, creating an opportunity for injection.

3.2
Jan 24, 2025

NodeBB Persistent Cross-Site Scripting Vulnerability

A persistent cross-site scripting vulnerability has been identified in NodeBB version 3.11.0. This vulnerability allows remote attackers to store arbitrary scripts in the 'about me' section of user profiles, which are executed when the profile is viewed by others.

4.4
Jan 24, 2025

HL7 FHIR IG Publisher Implementation Guide Publisher CLI GitHub Credentials Exposure Vulnerability

A vulnerability exists in the HL7 FHIR IG Publisher prior to version 1.8.9, where the IG Publisher CLI can unintentionally expose GitHub usernames and credentials. This occurs in continuous integration (CI) environments when the tool uses Git commands to fetch the repository URL. If the repository is cloned using a credentials-based URL, the full URL, including sensitive information, is incorporated into the generated Implementation Guide. This issue does not affect users who clone public repositories without credentials, such as those utilizing the auto-ig-build CI infrastructure.

2.1
Jan 24, 2025

JoeyBling Bootplus Open Redirect Vulnerability in QrCodeController

An open redirect vulnerability has been identified in JoeyBling Bootplus versions prior to commit 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. The issue arises in the qrCode function of the QrCodeController.java file, where the text parameter is not properly validated. This lack of restriction allows attackers to create QR codes that direct users to malicious URLs. The vulnerability can be exploited remotely.

3.8
Jan 24, 2025

JoeyBling Bootplus Resource Consumption Vulnerability in QrCodeController Allowing Denial-of-Service

A resource consumption vulnerability has been identified in JoeyBling Bootplus versions through commit 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. The issue arises in the qrCode method of the QrCodeController.java file, where the width and height parameters are not properly restricted. This lack of validation can lead to excessive resource usage, causing a denial-of-service condition. The vulnerability can be exploited remotely.

3.9
Jan 24, 2025

JoeyBling Bootplus Path Traversal Vulnerability in SysFileController

A path traversal vulnerability has been identified in JoeyBling Bootplus versions up to commit 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. The issue arises in the file 'src/main/java/io/github/controller/SysFileController.java', where the download method fails to properly validate the 'name' parameter. This lack of input sanitization allows for the manipulation of file paths, enabling remote attackers to download arbitrary files from the server.

3.0
Jan 24, 2025

HL7 FHIR IG Publisher XML External Entity Injection Vulnerability

A vulnerability allowing XML external entity (XXE) injection has been identified in the HL7 FHIR IG Publisher tool, in versions prior to 1.7.4. This issue arises from XSLT transformations that can be manipulated with a malicious XML file containing a harmful DTD tag. The exploitation of this vulnerability could lead to the disclosure of data from the host system. This issue is particularly concerning in scenarios where the FHIR IG Publisher is used in an environment that accepts XML submissions from external clients.

2.6
Jan 24, 2025

WordPress Roi Calculator Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Roi Calculator plugin, specifically in versions through 1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Jan 24, 2025

WordPress PDF Invoices for WooCommerce Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress PDF Invoices for WooCommerce plugin, specifically in versions through 4.6.0. This issue arises from improper input neutralization during web page generation, allowing malicious actors to inject scripts that are executed when users visit the site.

1.7
Jan 24, 2025

Kadence WP Gutenberg Blocks Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the Kadence WP Gutenberg Blocks plugin, specifically in versions through 3.3.1. This vulnerability allows exploitation of improperly configured access control, potentially enabling users with lower privileges to perform actions reserved for higher privileged users.

1.8
Jan 24, 2025

GoDaddy CoBlocks Missing Authorization Vulnerability Allowing Access Control Exploitation

A missing authorization vulnerability has been identified in the GoDaddy CoBlocks WordPress plugin, specifically in versions through 3.1.13. This vulnerability allows unprivileged users to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions or access.

3.8
Jan 24, 2025

ExactMetrics WordPress Plugin Missing Authorization Vulnerability Allowing Broken Access Control

A broken access control vulnerability has been identified in the ExactMetrics WordPress plugin, specifically in versions through 8.1.0. This vulnerability arises from missing authorization checks, which can be exploited by users with lower privileges to perform actions reserved for higher privileged users.

4.8
Jan 24, 2025

Popup Maker Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Popup Maker WordPress plugin, affecting versions through 1.20.2. This issue allows attackers to inject malicious scripts that are executed when users visit the site.

4.2
Jan 24, 2025

FluentSMTP WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the FluentSMTP WordPress plugin, specifically in versions through 2.2.80. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

4.2
Jan 24, 2025

NowButtons.com Call Now Button Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the NowButtons.com Call Now Button plugin for WordPress, specifically in versions through 1.4.13. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

3.4
Jan 24, 2025

Metaphor Creations Post Duplicator Missing Authorization Vulnerability Allowing Access Control Exploitation

A missing authorization vulnerability has been identified in the Metaphor Creations Post Duplicator plugin, affecting versions through 2.35. This vulnerability allows exploitation of improperly configured access control security levels, potentially enabling unprivileged users to perform actions reserved for higher privileges.

1.8
Jan 24, 2025

AddonMaster Post Grid Master Local File Inclusion Vulnerability

A local file inclusion vulnerability has been identified in the AddonMaster Post Grid Master plugin, affecting versions through 3.4.12. This vulnerability arises from improper control of filenames in include or require statements, allowing PHP remote file inclusion.

2.1
Jan 24, 2025

BookingPress DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the BookingPress WordPress plugin, specifically in versions through 1.1.25. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.

3.0
Jan 24, 2025

IP2Location Download Country Blocker Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the IP2Location Download IP2Location Country Blocker plugin for WordPress, affecting versions through 2.38.3. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

2.8
Jan 24, 2025

Rextheme WP VR Plugin DOM-Based Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the Rextheme WP VR plugin, affecting versions through 8.5.14. This issue allows for DOM-based XSS, where malicious scripts can be injected and executed in the context of the user's browser.

3.0
Jan 24, 2025

ElementInvader Addons for Elementor Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the ElementInvader Addons for Elementor plugin, affecting versions through 1.3.3. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.3
Jan 24, 2025

Yannick Lefebvre Bug Library SQL Injection Vulnerability

A blind SQL injection vulnerability has been identified in the WordPress Bug Library plugin, affecting versions through 2.1.4. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing malicious actors to interact with the database and potentially steal information.

1.7
Jan 24, 2025

CodePeople Contact Form Email Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the CodePeople Contact Form Email plugin, affecting versions through 1.3.52. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.

2.5
Jan 24, 2025

HT Plugins HT Contact Form 7 Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the HT Contact Form 7 WordPress plugin, affecting versions through 1.2.1. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.

1.7
Jan 24, 2025

ThimPress Thim Elementor Kit Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the Thim Elementor Kit WordPress plugin, specifically in versions through 1.2.8. This vulnerability allows exploitation of improperly configured access control, potentially enabling users to perform actions reserved for higher privileges.

1.8
Jan 24, 2025

WordPress Side Menu Lite Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Side Menu Lite plugin, affecting versions through 5.3.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.4
Jan 24, 2025

CodePeople Booking Calendar Contact Form Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the CodePeople Booking Calendar Contact Form plugin, affecting versions through 1.2.55. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

2.8
Jan 24, 2025

WordPress FAQ Builder AYS Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress FAQ Builder AYS plugin, affecting versions through 1.7.3. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.5
Jan 24, 2025

Aleksandar Urošević Easy YouTube Gallery Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Easy YouTube Gallery plugin by Aleksandar Urošević, affecting versions through 1.0.4. This vulnerability allows for the injection of malicious scripts that could be executed when users visit the affected site.

1.7
Jan 24, 2025

Wow-Company Sticky Buttons WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wow-Company Sticky Buttons WordPress plugin, affecting versions through 4.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.7
Jan 24, 2025

WordPress Widget Countdown Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Widget Countdown plugin, affecting versions through 2.7.1. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.7
Jan 24, 2025

Wow-Company Modal Window Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wow-Company Modal Window plugin for WordPress, affecting versions through 6.1.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.4
Jan 24, 2025

Wow-Company Herd Effects WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wow-Company Herd Effects WordPress plugin, affecting versions through 6.2.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.4
Jan 24, 2025

Wow-Company Counter Box Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wow-Company Counter Box WordPress plugin, affecting versions through 2.0.5. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.5
Jan 24, 2025

WordPress Bubble Menu Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Bubble Menu – circle floating menu plugin, affecting versions through 4.0.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.4
Jan 24, 2025

WordPress Button Generator Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Button Generator - Easily Button Builder plugin, affecting versions through 3.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.4
Jan 24, 2025

RadiusTheme Radius Blocks Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the RadiusTheme Radius Blocks plugin for WordPress, affecting versions through 2.1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 24, 2025

WordPress Popup Box Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Popup Box plugin, specifically in versions through 3.2.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.5
Jan 24, 2025

Plethora Plugins Tabs + Accordions Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress plugin Plethora Plugins Tabs + Accordions, affecting versions through 1.1.5. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.7
Jan 24, 2025

MultiVendorX WC Marketplace Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the MultiVendorX WC Marketplace plugin for WordPress, affecting versions through 4.2.13. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

3.0
Jan 24, 2025

Arshid WooCommerce Quick View Missing Authorization Vulnerability Allowing Sensitive Data Exposure

A missing authorization vulnerability in the Arshid WooCommerce Quick View plugin, affecting versions through 1.1.1, allows exploitation of improperly configured access control. This vulnerability could lead to unauthorized exposure of sensitive data that regular users typically cannot access.

2.5
Jan 24, 2025

WordPress Magic the Gathering Card Tooltips Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Magic the Gathering Card Tooltips plugin, affecting versions through 3.4.0. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.

1.6
Jan 24, 2025

WordPress DLX Plugins Comment Edit Core Server-Side Request Forgery Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability exists in the WordPress Comment Edit Core – Simple Comment Editing plugin, affecting versions through 3.0.33. This vulnerability allows attackers to manipulate the server into making requests to arbitrary domains, potentially leading to the exposure of sensitive information from other services running on the system.

1.5