CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Feb 11, 2025

Stray Random Quotes WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Stray Random Quotes WordPress plugin, affecting versions through 1.9.9. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.

3.8
Feb 11, 2025

Zarinpal Paid Download WordPress Plugin Arbitrary File Upload Vulnerability

A vulnerability exists in the Zarinpal Paid Download WordPress plugin, affecting versions through 2.3, due to improper validation of uploaded files. This flaw allows high-privilege users, such as administrators, to upload arbitrary files to the server, even in scenarios where such actions should be restricted, like in a multisite setup.

3.3
Feb 11, 2025

Zarinpal Paid Download WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Zarinpal Paid Download WordPress plugin, versions through 2.3. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.

3.8
Feb 11, 2025

Hackney Server-Side Request Forgery Vulnerability

A Server-side Request Forgery (SSRF) vulnerability has been identified in the Hackney package, versions prior to 1.21.0. This vulnerability arises from improper URL parsing by the built-in URI module and Hackney itself. When the URL 'http://127.0.0.1?@127.2.2.2/' is processed, the URI module correctly identifies the host as '127.0.0.1', but Hackney mistakenly refers to the host as '127.2.2.2/'. This misinterpretation can be exploited in scenarios where users depend on the URI parsing for host validation.

3.8
Feb 11, 2025

1000 Projects Bookstore Management System Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Bookstore Management System version 1.0. The issue resides in the file process_book_add.php, within the Add Book Page component. The vulnerability is triggered by manipulating the 'Book Name' argument, allowing for the injection of malicious scripts that are executed when the book is viewed. This vulnerability can be exploited remotely and has been disclosed publicly.

2.8
Feb 11, 2025

1000 Projects Bookstore Management System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in the Bookstore Management System version 1.0. The issue arises in the file process_users_del.php, where the 'id' parameter is not properly sanitized before being included in SQL queries. This flaw allows remote attackers to manipulate the 'id' argument and execute arbitrary SQL commands, potentially leading to unauthorized data access or modification.

2.9
Feb 11, 2025

HT Mega – Absolute Addons For Elementor Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the HT Mega – Absolute Addons For Elementor plugin for WordPress, affecting all versions through 2.8.1. The issue arises in the Countdown widget, where inadequate input sanitization and output escaping on user-supplied attributes allow authenticated attackers with contributor-level access or higher to inject arbitrary web scripts. These scripts execute when a user accesses the affected page.

4.4
Feb 11, 2025

1000 Projects Bookstore Management System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in the Bookstore Management System version 1.0, developed by 1000 Projects. The issue arises in the 'addtocart.php' file, where the 'bcid' parameter is not properly sanitized before being included in the SQL query. This flaw allows for remote exploitation of the application.

2.9
Feb 11, 2025

Code-Projects Real Estate Property Management System Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Code-Projects Real Estate Property Management System version 1.0. The issue arises in the file /Admin/CustomerReport.php, where the Address parameter is not properly sanitized, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely and requires user interaction.

3.7
Feb 11, 2025

NetVision Information ISOinsight Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in NetVision Information ISOinsight versions 2.9.0.x and 3.0.0.x. This vulnerability allows unauthenticated remote attackers to execute arbitrary JavaScript in the user's browser, potentially through phishing methods.

2.0
Feb 11, 2025

Quanxun School Affairs System Sensitive Information Exposure Vulnerability

A vulnerability allowing the exposure of sensitive information has been identified in the Quanxun School Affairs System. This issue enables unauthenticated attackers to access specific pages, retrieve database information, and obtain plaintext credentials for administrators.

2.6
Feb 11, 2025

Billion Electric Routers Hard-Coded Credentials Vulnerability Allowing Root Access via SSH

A vulnerability exists in certain Billion Electric router models, including the M100, M150, M120N, and M500. These routers have hard-coded Linux credentials that can be used to log in through the SSH service, granting root privileges on the system.

2.6
Feb 11, 2025

Code-Projects Real Estate Property Management System Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Code-Projects Real Estate Property Management System version 1.0. The issue arises in an unknown function within the file /Admin/Category.php, where the argument 'Desc' can be manipulated to inject malicious scripts. This vulnerability can be exploited remotely.

3.2
Feb 11, 2025

SourceCodester Image Compressor Tool Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in SourceCodester Image Compressor Tool version 1.0. The issue arises from an unknown processing of the file '/image-compressor/compressor.php', where the 'image' argument can be manipulated to inject malicious scripts. This vulnerability can be exploited remotely.

3.4
Feb 11, 2025

SourceCodester Contact Manager SQL Injection Vulnerability in Export to VCF Feature

A critical SQL injection vulnerability has been identified in SourceCodester Contact Manager version 1.0, specifically within the export to VCF feature. The issue arises in the file '/endpoint/delete-contact.php', where the 'contact' parameter is manipulated, allowing attackers to inject SQL payloads. This vulnerability can be exploited remotely, with public knowledge of the exploit available.

3.2
Feb 11, 2025

Mayuri K Employee Management System SQL Injection Vulnerability in Update_User.php

A critical SQL injection vulnerability has been identified in the Mayuri K Employee Management System, affecting versions up to 192.168.70.3. The issue arises in the file '/hr_soft/admin/Update_User.php', where the 'id' parameter can be manipulated to execute arbitrary SQL commands. This vulnerability can be exploited remotely, potentially allowing attackers to access or modify sensitive database information.

3.1
Feb 11, 2025

SourceCodester Food Menu Manager Unrestricted File Upload Vulnerability

A critical unrestricted file upload vulnerability has been identified in SourceCodester Food Menu Manager version 1.0. The issue resides in the file endpoint/update.php, where the upload logic fails to properly validate file types. This flaw allows attackers to bypass image type detection using a crafted GIF file and upload malicious PHP scripts, such as Trojans, that can execute arbitrary code on the server.

3.1
Feb 11, 2025

SAP Supplier Relationship Management File Download Vulnerability in Master Data Management Catalog

A vulnerability in SAP Supplier Relationship Management's Master Data Management Catalog allows an unauthenticated attacker to download arbitrary files over the network using a publicly available servlet. This issue can be exploited without user interaction, potentially exposing highly sensitive information while not affecting the integrity or availability of the system.

3.4
Feb 11, 2025

SAP Applications Missing Authorization Check Vulnerability in Overtime Requests Management

A vulnerability exists in certain SAP applications due to a missing authorization check. This flaw allows logged-in attackers to view or delete 'My Overtime Requests', potentially accessing sensitive employee information. The issue arises from inadequate authorization controls, leading to a low impact on the application's confidentiality and integrity, with no effect on availability.

2.1
Feb 11, 2025

SAP Approuter Node.js Package Authentication Bypass Vulnerability

An authentication bypass vulnerability has been identified in the SAP Approuter Node.js package, specifically in version 16.7.1 and earlier. This vulnerability allows an attacker to steal a victim's session by injecting malicious payloads while exchanging an authorization code. The issue arises from a flaw in the authorization code handling process, leading to a high impact on the application's confidentiality and integrity.

2.1
Feb 11, 2025

SAP Commerce SameSite Cookie Vulnerability in Authentication Cookies

A vulnerability exists in SAP Commerce due to certain cookies, including authentication cookies used in SAP Commerce Backoffice, being set with the SameSite attribute configured to None. This default setting weakens protection against Cross-Site Request Forgery (CSRF) attacks and may cause compatibility issues in the future.

3.4
Feb 11, 2025

SAP Commerce Clickjacking Vulnerability via Deprecated X-FRAME-OPTIONS Header

A vulnerability exists in SAP Commerce (Backoffice) due to the use of the outdated X-FRAME-OPTIONS header for clickjacking protection. While this method is currently effective, it may become inadequate in the future as browsers could phase out support for this header in favor of the frame-ancestors Content Security Policy directive. If that occurs, clickjacking could be feasible, potentially leading to the exposure and unauthorized modification of sensitive information.

3.5
Feb 11, 2025

SAP ABAP Platform Unauthorized Access Vulnerability in ABAP Build Framework

A vulnerability in the ABAP Build Framework of SAP ABAP Platform allows authenticated attackers to gain unauthorized access to specific transactions. By using the add-on build functionality within the framework, attackers can invoke transactions and view their details. This vulnerability has a limited impact on application confidentiality, with no effects on integrity or availability.

3.8
Feb 11, 2025

SAP GUI for Windows Privilege Escalation Vulnerability via Insecure Credential Storage

A vulnerability exists in SAP GUI for Windows, where RFC service credentials are improperly stored in the program's memory. This flaw allows an unauthenticated attacker to access sensitive information within systems, potentially leading to privilege escalation. The issue does not affect the integrity or availability of the system.

4.1
Feb 11, 2025

SAP NetWeaver Application Server Java Information Disclosure Vulnerability

An information disclosure vulnerability has been identified in SAP NetWeaver Application Server Java. This vulnerability allows an attacker to access an endpoint that reveals details about deployed server components, including their XML definitions. Ideally, this information should be restricted to customer administrators. The exposed XML files, while not entirely internal to SAP, are deployed with the server. As a result, sensitive information could be leaked without compromising its integrity or availability.

4.9
Feb 11, 2025

SAP HANA XS Advanced Model User Account and Authentication Service Open Redirect Vulnerability

A vulnerability in the User Account and Authentication service for SAP HANA extended application services, advanced model, allows an unauthenticated attacker to create a malicious link that, when clicked by a victim, redirects the browser to a harmful site. This exploitation takes advantage of inadequate validation of redirect URLs. Successful exploitation could lead to a limited impact on the system's confidentiality, integrity, and availability.

3.3
Feb 11, 2025

SAP BusinessObjects Platform Cross-Site Scripting Vulnerability in BI Launchpad

A cross-site scripting (XSS) vulnerability has been identified in SAP BusinessObjects Platform, specifically within the BI Launchpad component. This issue arises because the application does not adequately sanitize user input, allowing an unauthenticated attacker to create a URL that includes a malicious script embedded in an unprotected parameter. When a user clicks on the link, the script is executed in their browser, potentially enabling the attacker to access or modify information related to the web client, without impacting the application's availability.

2.0
Feb 11, 2025

SAP NetWeaver Server ABAP User-Based Information Disclosure Vulnerability

An information disclosure vulnerability has been identified in SAP NetWeaver Server ABAP. This issue allows an unauthenticated attacker to exploit the server's response behavior based on the presence of a specific user, potentially leading to the revelation of sensitive information. The vulnerability does not permit data modification and does not affect server availability.

4.9
Feb 11, 2025

SAP Fiori for SAP ERP Host Header Injection Vulnerability Allowing OData Cache Poisoning

A vulnerability exists in the SAP OData endpoint within SAP Fiori for SAP ERP, where cached values can be poisoned by altering the Host header in an HTTP GET request. This manipulation could redirect the 'atom:link' values in the metadata response from the SAP server to a malicious link specified by the attacker. Exploitation of this vulnerability could lead to a low integrity impact on the application.

3.8
Feb 11, 2025

SAP Missing Authorization Check Vulnerability Allowing Unauthorized Data Access

A vulnerability exists in certain SAP products due to a lack of proper authorization checks. This flaw enables an authenticated attacker to invoke a remote-enabled function module, potentially accessing data that should be restricted. However, the attacker cannot alter data or affect system availability.

1.1
Feb 11, 2025

SAP RFC Authorization Bypass Vulnerability in Transaction SDCCN Allowing Integrity Impact

A vulnerability exists in an RFC-enabled function module within transaction SDCCN due to a lack of proper authorization checks. This flaw allows authenticated attackers to generate technical metadata, potentially leading to a low impact on data integrity. The vulnerability does not affect confidentiality or availability.

1.7
Feb 11, 2025

SAP NetWeaver Missing Authorization Check in RFC Function Module Vulnerability in Transaction SDCCN

A vulnerability exists in an RFC-enabled function module within the SAP NetWeaver platform, specifically in transaction SDCCN. The issue arises from a missing authorization check, allowing an unauthenticated attacker to generate technical metadata. This vulnerability has a low impact on integrity, with no effects on confidentiality or availability.

2.5
Feb 11, 2025

Lumsoft ERP Unrestricted File Upload Vulnerability

A critical unrestricted file upload vulnerability has been identified in Lumsoft ERP version 8. The issue resides in the DoUpload/DoWebUpload function of the FileUploadApi.ashx file. This vulnerability allows for remote exploitation by manipulating the file upload argument, potentially leading to unauthorized file uploads on the server.

4.0
Feb 11, 2025

SAP BusinessObjects Business Intelligence Central Management Console Secret Passphrase Vulnerability Allowing User Impersonation

A vulnerability exists in the Central Management Console of the SAP BusinessObjects Business Intelligence platform. Under certain conditions, an attacker with admin rights can generate or retrieve a secret passphrase. This passphrase can be used to impersonate any user in the system, leading to significant breaches of confidentiality and integrity.

3.5
Feb 11, 2025

SAP NetWeaver Application Server Java Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in SAP NetWeaver Application Server Java. This issue arises because the application does not adequately sanitize user input, allowing attackers with basic user privileges to inject a JavaScript payload that is saved on the server. When executed in a victim's web browser, this payload could potentially be used to read or modify information related to the affected web page.

3.7
Feb 11, 2025

Police FIR Record Management System Stack-Based Buffer Overflow Vulnerability

A stack-based buffer overflow vulnerability has been identified in the Police FIR Record Management System version 1.0. The issue arises in the Add Record Handler component, where an unknown processing flaw allows for manipulation that leads to the buffer overflow. This vulnerability requires local access to exploit.

2.8
Feb 11, 2025

Vehicle Parking Management System Stack-Based Buffer Overflow Vulnerability

A critical stack-based buffer overflow vulnerability has been identified in the Vehicle Parking Management System version 1.0. This issue arises in the Authentication component, specifically within the login function, where improper handling of the username argument creates the potential for memory corruption. The vulnerability requires local exploitation.

2.6
Feb 10, 2025

Lemmy Server-Side Request Forgery Vulnerability in ActivityPub Federation Dependency

A server-side request forgery (SSRF) vulnerability has been identified in Lemmy, a link aggregator and forum for the fediverse. This issue arises from a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. The vulnerability is present in Lemmy versions through 0.19.8 and in activitypub_federation versions through 0.6.2. The flaw allows users to bypass hardcoded URL path restrictions and security measures intended to prevent access to localhost services, enabling arbitrary GET requests to any host, port, and URL via a Webfinger request.

5.2
Feb 10, 2025

Code-Projects Job Recruitment SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Code-Projects Job Recruitment version 1.0. The issue arises in the file '_parse/load_user-profile.php', where improper handling of the 'userhash' argument allows for SQL injection. This vulnerability can be exploited remotely.

2.5
Feb 10, 2025

SourceCodester Employee Management System Default Credentials Vulnerability

A critical vulnerability exists in SourceCodester Employee Management System version 1.0, specifically within the login functionality of index.php. The issue arises from the use of default credentials, allowing remote authentication bypass. Exploitation involves manipulating the username and password fields to gain unauthorized access.

3.9
Feb 10, 2025

Apache Netty Denial-of-Service Vulnerability in Windows Applications

A denial-of-service vulnerability has been identified in Apache Netty, an asynchronous, event-driven network application framework, in versions prior to and including 4.1.118.Final. When running on a Windows application, Netty improperly reads the environment file, leading to a crash if an attacker creates a large file that fills the application's buffer. This issue arises because the initial fix for a similar vulnerability, CVE-2024-47535, was incomplete; it failed to account for null bytes in the input limit. The vulnerability can be exploited by creating a file filled with null bytes, which Netty's input stream handling will mismanage, causing the application to crash.

2.5
Feb 10, 2025

ZOO-Project Web Processing Service EchoProcess Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the ZOO-Project Web Processing Service (WPS) Server, specifically within the EchoProcess service, in versions prior to the commit 7a5ae1a. This vulnerability arises because the EchoProcess service improperly sanitizes user input when processing complex data, such as XML, JSON, and SVG, allowing malicious JavaScript to be executed in the context of the victim's browser. The issue is particularly concerning as it involves a service designed to reflect user input, creating a reliable vector for XSS attacks, especially when SVG content is handled and returned with the image/svg+xml MIME type.

3.4
Feb 10, 2025

ZOO-Project Web Processing Service Reflective Cross-Site Scripting Vulnerability

A reflected Cross-Site Scripting vulnerability has been identified in the ZOO-Project Web Processing Service (WPS) publish.py CGI script, affecting versions prior to 7a5ae1a. The vulnerability arises because the script reflects user input from the 'jobid' parameter in the HTTP response without adequate HTML encoding or sanitization. This flaw allows attackers to execute arbitrary JavaScript in the context of the victim's browser. The issue is exacerbated by the fact that this endpoint is accessible from the main WPS interface, potentially facilitating phishing attacks against WPS users.

2.8
Feb 10, 2025

Apache Netty SslHandler Packet Validation Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability has been identified in Apache Netty, specifically in the SslHandler component, within versions 4.1.91.Final through 4.1.117.Final. The issue arises because SslHandler fails to properly validate certain crafted packets, particularly when using the native SSLEngine, which can result in a native crash.

7.6
Feb 10, 2025

CampCodes School Management Software Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in CampCodes School Management Software version 1.0. The issue arises from an unknown functionality in the file '/academic-calendar', allowing remote attackers to inject malicious scripts. This vulnerability has been publicly disclosed and could potentially be exploited.

2.9
Feb 10, 2025

ESAFENET CDG SQL Injection Vulnerability in addPolicyToSafetyGroup.jsp

A critical SQL injection vulnerability has been identified in ESAFENET CDG version 5.6.3.154.205_20250114. The issue arises in the file addPolicyToSafetyGroup.jsp, where an unknown function improperly handles the safetyGroupId argument. This vulnerability can be exploited remotely, allowing attackers to manipulate the argument and execute SQL injection attacks.

2.5
Feb 10, 2025

Allims Lab Online SQL Injection Vulnerability in Password Recovery Model Processing

A critical SQL injection vulnerability has been identified in Allims Lab Online versions prior to 20250201. The issue arises in the file 'model_recuperar_senha.php', where improper handling of the 'recuperacao' argument allows for SQL injection. This vulnerability can be exploited remotely.

1.7
Feb 10, 2025

Pix Software Vivaz SQL Injection Vulnerability in Login Servlet

A critical SQL injection vulnerability has been identified in Pix Software Vivaz version 6.0.10. The issue arises in the login servlet, specifically within the code that handles the 'usuario' argument. This vulnerability can be exploited remotely, allowing attackers to manipulate the input and execute arbitrary SQL commands. The exploit has been publicly disclosed, and although the vendor was notified, there has been no response.

2.5
Feb 10, 2025

MicroDicom DICOM Viewer Improper Certificate Validation Vulnerability Allowing Machine-in-the-Middle Attacks

A vulnerability exists in MicroDicom DICOM Viewer version 2024.03 due to improper validation of the update server's certificate. This flaw could enable attackers in a privileged network position to intercept and alter network traffic, executing a machine-in-the-middle (MITM) attack. Such an attack would allow the modification of the server's response to the user, potentially delivering a malicious update.

1.3
Feb 10, 2025

Wazuh Remote Code Execution Vulnerability via Unsafe Deserialization

A remote code execution vulnerability has been identified in Wazuh servers, affecting versions 4.4.0 prior to 4.9.1. The issue arises from an unsafe deserialization of DistributedAPI parameters, which are serialized as JSON and deserialized using the 'as_wazuh_object' method. An attacker can inject an unsanitized dictionary into DAPI request or response, allowing them to forge an unhandled exception that evaluates arbitrary Python code. This vulnerability can be exploited by anyone with API access, or in some cases, by a compromised agent.

6.0