CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Stray Random Quotes WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Stray Random Quotes WordPress plugin, affecting versions through 1.9.9. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
Zarinpal Paid Download WordPress Plugin Arbitrary File Upload Vulnerability
A vulnerability exists in the Zarinpal Paid Download WordPress plugin, affecting versions through 2.3, due to improper validation of uploaded files. This flaw allows high-privilege users, such as administrators, to upload arbitrary files to the server, even in scenarios where such actions should be restricted, like in a multisite setup.
Zarinpal Paid Download WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Zarinpal Paid Download WordPress plugin, versions through 2.3. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
Hackney Server-Side Request Forgery Vulnerability
A Server-side Request Forgery (SSRF) vulnerability has been identified in the Hackney package, versions prior to 1.21.0. This vulnerability arises from improper URL parsing by the built-in URI module and Hackney itself. When the URL 'http://127.0.0.1?@127.2.2.2/' is processed, the URI module correctly identifies the host as '127.0.0.1', but Hackney mistakenly refers to the host as '127.2.2.2/'. This misinterpretation can be exploited in scenarios where users depend on the URI parsing for host validation.
1000 Projects Bookstore Management System Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Bookstore Management System version 1.0. The issue resides in the file process_book_add.php, within the Add Book Page component. The vulnerability is triggered by manipulating the 'Book Name' argument, allowing for the injection of malicious scripts that are executed when the book is viewed. This vulnerability can be exploited remotely and has been disclosed publicly.
1000 Projects Bookstore Management System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in the Bookstore Management System version 1.0. The issue arises in the file process_users_del.php, where the 'id' parameter is not properly sanitized before being included in SQL queries. This flaw allows remote attackers to manipulate the 'id' argument and execute arbitrary SQL commands, potentially leading to unauthorized data access or modification.
HT Mega – Absolute Addons For Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the HT Mega – Absolute Addons For Elementor plugin for WordPress, affecting all versions through 2.8.1. The issue arises in the Countdown widget, where inadequate input sanitization and output escaping on user-supplied attributes allow authenticated attackers with contributor-level access or higher to inject arbitrary web scripts. These scripts execute when a user accesses the affected page.
1000 Projects Bookstore Management System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in the Bookstore Management System version 1.0, developed by 1000 Projects. The issue arises in the 'addtocart.php' file, where the 'bcid' parameter is not properly sanitized before being included in the SQL query. This flaw allows for remote exploitation of the application.
Code-Projects Real Estate Property Management System Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Code-Projects Real Estate Property Management System version 1.0. The issue arises in the file /Admin/CustomerReport.php, where the Address parameter is not properly sanitized, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely and requires user interaction.
NetVision Information ISOinsight Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in NetVision Information ISOinsight versions 2.9.0.x and 3.0.0.x. This vulnerability allows unauthenticated remote attackers to execute arbitrary JavaScript in the user's browser, potentially through phishing methods.
Quanxun School Affairs System Sensitive Information Exposure Vulnerability
A vulnerability allowing the exposure of sensitive information has been identified in the Quanxun School Affairs System. This issue enables unauthenticated attackers to access specific pages, retrieve database information, and obtain plaintext credentials for administrators.
Billion Electric Routers Hard-Coded Credentials Vulnerability Allowing Root Access via SSH
A vulnerability exists in certain Billion Electric router models, including the M100, M150, M120N, and M500. These routers have hard-coded Linux credentials that can be used to log in through the SSH service, granting root privileges on the system.
Code-Projects Real Estate Property Management System Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Code-Projects Real Estate Property Management System version 1.0. The issue arises in an unknown function within the file /Admin/Category.php, where the argument 'Desc' can be manipulated to inject malicious scripts. This vulnerability can be exploited remotely.
SourceCodester Image Compressor Tool Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in SourceCodester Image Compressor Tool version 1.0. The issue arises from an unknown processing of the file '/image-compressor/compressor.php', where the 'image' argument can be manipulated to inject malicious scripts. This vulnerability can be exploited remotely.
SourceCodester Contact Manager SQL Injection Vulnerability in Export to VCF Feature
A critical SQL injection vulnerability has been identified in SourceCodester Contact Manager version 1.0, specifically within the export to VCF feature. The issue arises in the file '/endpoint/delete-contact.php', where the 'contact' parameter is manipulated, allowing attackers to inject SQL payloads. This vulnerability can be exploited remotely, with public knowledge of the exploit available.
Mayuri K Employee Management System SQL Injection Vulnerability in Update_User.php
A critical SQL injection vulnerability has been identified in the Mayuri K Employee Management System, affecting versions up to 192.168.70.3. The issue arises in the file '/hr_soft/admin/Update_User.php', where the 'id' parameter can be manipulated to execute arbitrary SQL commands. This vulnerability can be exploited remotely, potentially allowing attackers to access or modify sensitive database information.
SourceCodester Food Menu Manager Unrestricted File Upload Vulnerability
A critical unrestricted file upload vulnerability has been identified in SourceCodester Food Menu Manager version 1.0. The issue resides in the file endpoint/update.php, where the upload logic fails to properly validate file types. This flaw allows attackers to bypass image type detection using a crafted GIF file and upload malicious PHP scripts, such as Trojans, that can execute arbitrary code on the server.
SAP Supplier Relationship Management File Download Vulnerability in Master Data Management Catalog
A vulnerability in SAP Supplier Relationship Management's Master Data Management Catalog allows an unauthenticated attacker to download arbitrary files over the network using a publicly available servlet. This issue can be exploited without user interaction, potentially exposing highly sensitive information while not affecting the integrity or availability of the system.
SAP Applications Missing Authorization Check Vulnerability in Overtime Requests Management
A vulnerability exists in certain SAP applications due to a missing authorization check. This flaw allows logged-in attackers to view or delete 'My Overtime Requests', potentially accessing sensitive employee information. The issue arises from inadequate authorization controls, leading to a low impact on the application's confidentiality and integrity, with no effect on availability.
SAP Approuter Node.js Package Authentication Bypass Vulnerability
An authentication bypass vulnerability has been identified in the SAP Approuter Node.js package, specifically in version 16.7.1 and earlier. This vulnerability allows an attacker to steal a victim's session by injecting malicious payloads while exchanging an authorization code. The issue arises from a flaw in the authorization code handling process, leading to a high impact on the application's confidentiality and integrity.
SAP Commerce SameSite Cookie Vulnerability in Authentication Cookies
A vulnerability exists in SAP Commerce due to certain cookies, including authentication cookies used in SAP Commerce Backoffice, being set with the SameSite attribute configured to None. This default setting weakens protection against Cross-Site Request Forgery (CSRF) attacks and may cause compatibility issues in the future.
SAP Commerce Clickjacking Vulnerability via Deprecated X-FRAME-OPTIONS Header
A vulnerability exists in SAP Commerce (Backoffice) due to the use of the outdated X-FRAME-OPTIONS header for clickjacking protection. While this method is currently effective, it may become inadequate in the future as browsers could phase out support for this header in favor of the frame-ancestors Content Security Policy directive. If that occurs, clickjacking could be feasible, potentially leading to the exposure and unauthorized modification of sensitive information.
SAP ABAP Platform Unauthorized Access Vulnerability in ABAP Build Framework
A vulnerability in the ABAP Build Framework of SAP ABAP Platform allows authenticated attackers to gain unauthorized access to specific transactions. By using the add-on build functionality within the framework, attackers can invoke transactions and view their details. This vulnerability has a limited impact on application confidentiality, with no effects on integrity or availability.
SAP GUI for Windows Privilege Escalation Vulnerability via Insecure Credential Storage
A vulnerability exists in SAP GUI for Windows, where RFC service credentials are improperly stored in the program's memory. This flaw allows an unauthenticated attacker to access sensitive information within systems, potentially leading to privilege escalation. The issue does not affect the integrity or availability of the system.
SAP NetWeaver Application Server Java Information Disclosure Vulnerability
An information disclosure vulnerability has been identified in SAP NetWeaver Application Server Java. This vulnerability allows an attacker to access an endpoint that reveals details about deployed server components, including their XML definitions. Ideally, this information should be restricted to customer administrators. The exposed XML files, while not entirely internal to SAP, are deployed with the server. As a result, sensitive information could be leaked without compromising its integrity or availability.
SAP HANA XS Advanced Model User Account and Authentication Service Open Redirect Vulnerability
A vulnerability in the User Account and Authentication service for SAP HANA extended application services, advanced model, allows an unauthenticated attacker to create a malicious link that, when clicked by a victim, redirects the browser to a harmful site. This exploitation takes advantage of inadequate validation of redirect URLs. Successful exploitation could lead to a limited impact on the system's confidentiality, integrity, and availability.
SAP BusinessObjects Platform Cross-Site Scripting Vulnerability in BI Launchpad
A cross-site scripting (XSS) vulnerability has been identified in SAP BusinessObjects Platform, specifically within the BI Launchpad component. This issue arises because the application does not adequately sanitize user input, allowing an unauthenticated attacker to create a URL that includes a malicious script embedded in an unprotected parameter. When a user clicks on the link, the script is executed in their browser, potentially enabling the attacker to access or modify information related to the web client, without impacting the application's availability.
SAP NetWeaver Server ABAP User-Based Information Disclosure Vulnerability
An information disclosure vulnerability has been identified in SAP NetWeaver Server ABAP. This issue allows an unauthenticated attacker to exploit the server's response behavior based on the presence of a specific user, potentially leading to the revelation of sensitive information. The vulnerability does not permit data modification and does not affect server availability.
SAP Fiori for SAP ERP Host Header Injection Vulnerability Allowing OData Cache Poisoning
A vulnerability exists in the SAP OData endpoint within SAP Fiori for SAP ERP, where cached values can be poisoned by altering the Host header in an HTTP GET request. This manipulation could redirect the 'atom:link' values in the metadata response from the SAP server to a malicious link specified by the attacker. Exploitation of this vulnerability could lead to a low integrity impact on the application.
SAP Missing Authorization Check Vulnerability Allowing Unauthorized Data Access
A vulnerability exists in certain SAP products due to a lack of proper authorization checks. This flaw enables an authenticated attacker to invoke a remote-enabled function module, potentially accessing data that should be restricted. However, the attacker cannot alter data or affect system availability.
SAP RFC Authorization Bypass Vulnerability in Transaction SDCCN Allowing Integrity Impact
A vulnerability exists in an RFC-enabled function module within transaction SDCCN due to a lack of proper authorization checks. This flaw allows authenticated attackers to generate technical metadata, potentially leading to a low impact on data integrity. The vulnerability does not affect confidentiality or availability.
SAP NetWeaver Missing Authorization Check in RFC Function Module Vulnerability in Transaction SDCCN
A vulnerability exists in an RFC-enabled function module within the SAP NetWeaver platform, specifically in transaction SDCCN. The issue arises from a missing authorization check, allowing an unauthenticated attacker to generate technical metadata. This vulnerability has a low impact on integrity, with no effects on confidentiality or availability.
Lumsoft ERP Unrestricted File Upload Vulnerability
A critical unrestricted file upload vulnerability has been identified in Lumsoft ERP version 8. The issue resides in the DoUpload/DoWebUpload function of the FileUploadApi.ashx file. This vulnerability allows for remote exploitation by manipulating the file upload argument, potentially leading to unauthorized file uploads on the server.
SAP BusinessObjects Business Intelligence Central Management Console Secret Passphrase Vulnerability Allowing User Impersonation
A vulnerability exists in the Central Management Console of the SAP BusinessObjects Business Intelligence platform. Under certain conditions, an attacker with admin rights can generate or retrieve a secret passphrase. This passphrase can be used to impersonate any user in the system, leading to significant breaches of confidentiality and integrity.
SAP NetWeaver Application Server Java Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in SAP NetWeaver Application Server Java. This issue arises because the application does not adequately sanitize user input, allowing attackers with basic user privileges to inject a JavaScript payload that is saved on the server. When executed in a victim's web browser, this payload could potentially be used to read or modify information related to the affected web page.
Police FIR Record Management System Stack-Based Buffer Overflow Vulnerability
A stack-based buffer overflow vulnerability has been identified in the Police FIR Record Management System version 1.0. The issue arises in the Add Record Handler component, where an unknown processing flaw allows for manipulation that leads to the buffer overflow. This vulnerability requires local access to exploit.
Vehicle Parking Management System Stack-Based Buffer Overflow Vulnerability
A critical stack-based buffer overflow vulnerability has been identified in the Vehicle Parking Management System version 1.0. This issue arises in the Authentication component, specifically within the login function, where improper handling of the username argument creates the potential for memory corruption. The vulnerability requires local exploitation.
Lemmy Server-Side Request Forgery Vulnerability in ActivityPub Federation Dependency
A server-side request forgery (SSRF) vulnerability has been identified in Lemmy, a link aggregator and forum for the fediverse. This issue arises from a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. The vulnerability is present in Lemmy versions through 0.19.8 and in activitypub_federation versions through 0.6.2. The flaw allows users to bypass hardcoded URL path restrictions and security measures intended to prevent access to localhost services, enabling arbitrary GET requests to any host, port, and URL via a Webfinger request.
Code-Projects Job Recruitment SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Code-Projects Job Recruitment version 1.0. The issue arises in the file '_parse/load_user-profile.php', where improper handling of the 'userhash' argument allows for SQL injection. This vulnerability can be exploited remotely.
SourceCodester Employee Management System Default Credentials Vulnerability
A critical vulnerability exists in SourceCodester Employee Management System version 1.0, specifically within the login functionality of index.php. The issue arises from the use of default credentials, allowing remote authentication bypass. Exploitation involves manipulating the username and password fields to gain unauthorized access.
Apache Netty Denial-of-Service Vulnerability in Windows Applications
A denial-of-service vulnerability has been identified in Apache Netty, an asynchronous, event-driven network application framework, in versions prior to and including 4.1.118.Final. When running on a Windows application, Netty improperly reads the environment file, leading to a crash if an attacker creates a large file that fills the application's buffer. This issue arises because the initial fix for a similar vulnerability, CVE-2024-47535, was incomplete; it failed to account for null bytes in the input limit. The vulnerability can be exploited by creating a file filled with null bytes, which Netty's input stream handling will mismanage, causing the application to crash.
ZOO-Project Web Processing Service EchoProcess Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in the ZOO-Project Web Processing Service (WPS) Server, specifically within the EchoProcess service, in versions prior to the commit 7a5ae1a. This vulnerability arises because the EchoProcess service improperly sanitizes user input when processing complex data, such as XML, JSON, and SVG, allowing malicious JavaScript to be executed in the context of the victim's browser. The issue is particularly concerning as it involves a service designed to reflect user input, creating a reliable vector for XSS attacks, especially when SVG content is handled and returned with the image/svg+xml MIME type.
ZOO-Project Web Processing Service Reflective Cross-Site Scripting Vulnerability
A reflected Cross-Site Scripting vulnerability has been identified in the ZOO-Project Web Processing Service (WPS) publish.py CGI script, affecting versions prior to 7a5ae1a. The vulnerability arises because the script reflects user input from the 'jobid' parameter in the HTTP response without adequate HTML encoding or sanitization. This flaw allows attackers to execute arbitrary JavaScript in the context of the victim's browser. The issue is exacerbated by the fact that this endpoint is accessible from the main WPS interface, potentially facilitating phishing attacks against WPS users.
Apache Netty SslHandler Packet Validation Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in Apache Netty, specifically in the SslHandler component, within versions 4.1.91.Final through 4.1.117.Final. The issue arises because SslHandler fails to properly validate certain crafted packets, particularly when using the native SSLEngine, which can result in a native crash.
CampCodes School Management Software Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in CampCodes School Management Software version 1.0. The issue arises from an unknown functionality in the file '/academic-calendar', allowing remote attackers to inject malicious scripts. This vulnerability has been publicly disclosed and could potentially be exploited.
ESAFENET CDG SQL Injection Vulnerability in addPolicyToSafetyGroup.jsp
A critical SQL injection vulnerability has been identified in ESAFENET CDG version 5.6.3.154.205_20250114. The issue arises in the file addPolicyToSafetyGroup.jsp, where an unknown function improperly handles the safetyGroupId argument. This vulnerability can be exploited remotely, allowing attackers to manipulate the argument and execute SQL injection attacks.
Allims Lab Online SQL Injection Vulnerability in Password Recovery Model Processing
A critical SQL injection vulnerability has been identified in Allims Lab Online versions prior to 20250201. The issue arises in the file 'model_recuperar_senha.php', where improper handling of the 'recuperacao' argument allows for SQL injection. This vulnerability can be exploited remotely.
Pix Software Vivaz SQL Injection Vulnerability in Login Servlet
A critical SQL injection vulnerability has been identified in Pix Software Vivaz version 6.0.10. The issue arises in the login servlet, specifically within the code that handles the 'usuario' argument. This vulnerability can be exploited remotely, allowing attackers to manipulate the input and execute arbitrary SQL commands. The exploit has been publicly disclosed, and although the vendor was notified, there has been no response.
MicroDicom DICOM Viewer Improper Certificate Validation Vulnerability Allowing Machine-in-the-Middle Attacks
A vulnerability exists in MicroDicom DICOM Viewer version 2024.03 due to improper validation of the update server's certificate. This flaw could enable attackers in a privileged network position to intercept and alter network traffic, executing a machine-in-the-middle (MITM) attack. Such an attack would allow the modification of the server's response to the user, potentially delivering a malicious update.
Wazuh Remote Code Execution Vulnerability via Unsafe Deserialization
A remote code execution vulnerability has been identified in Wazuh servers, affecting versions 4.4.0 prior to 4.9.1. The issue arises from an unsafe deserialization of DistributedAPI parameters, which are serialized as JSON and deserialized using the 'as_wazuh_object' method. An attacker can inject an unsanitized dictionary into DAPI request or response, allowing them to forge an unhandled exception that evaluates arbitrary Python code. This vulnerability can be exploited by anyone with API access, or in some cases, by a compromised agent.
