CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Trash Duplicate and 301 Redirect WordPress Plugin Missing Authorization Vulnerability Allowing Unauthenticated Post Deletion
A vulnerability exists in the Trash Duplicate and 301 Redirect plugin for WordPress, in all versions through 1.9. The issue arises from a missing capability check on the 'duplicates-action-top' action, allowing unauthenticated attackers to delete arbitrary posts or pages. This unauthorized data deletion could lead to significant content loss for users.
WP Wiki Tooltip Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WP Wiki Tooltip plugin for WordPress, affecting all versions through 2.0.2. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'wiki' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
Apptivo Business Site CRM Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Apptivo Business Site CRM plugin for WordPress, affecting all versions through 5.3. The issue arises from inadequate nonce validation on the 'awp_ip_deny' page, allowing unauthenticated attackers to block IP addresses by sending a forged request, provided they can persuade a site administrator to click a link.
ADFO WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the ADFO – Custom Data in Admin Dashboard plugin for WordPress, affecting all versions through 1.9.1. The vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'adfo_list' shortcode. This flaw allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages, which are executed when users access the compromised pages.
Yay! Forms WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Yay! Forms WordPress plugin, specifically in versions through 1.2.1. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'yayforms' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.
Digihood HTML Sitemap Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Digihood HTML Sitemap plugin for WordPress, affecting all versions through 3.1.1. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link.
Lexicata WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Lexicata plugin for WordPress, affecting all versions through 1.0.16. The issue arises from the use of add_query_arg without proper escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could execute if a user is tricked into clicking a specially crafted link.
CanadaHelps Embedded Donation Form WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the CanadaHelps Embedded Donation Form plugin for WordPress, affecting all versions through 1.0.1. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'embedcdn' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected page.
UMich OIDC Login WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the UMich OIDC Login plugin for WordPress, affecting all versions up to and including 1.2.0. The vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'umich_oidc_button' shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
UltraEmbed Advanced Iframe WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the UltraEmbed – Advanced Iframe Plugin for WordPress, specifically in versions through 1.0.3. This vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'iframe' shortcode. As a result, authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages, which will execute when a user views the affected page.
iniparser Heap-Based Buffer Overflow Vulnerability in iniparser_dumpsection_ini()
A heap-based buffer overflow vulnerability has been identified in the iniparser library, specifically in the function iniparser_dumpsection_ini(). This vulnerability allows attackers to read out-of-bounds memory. The issue arises from the use of sprintf() to copy a string that exceeds the destination buffer's size, leading to a buffer overflow. The vulnerability was discovered through fuzz testing.
Movable Type Reflected Cross-Site Scripting Vulnerability in User Information Edit Page
A reflected cross-site scripting vulnerability has been identified in Movable Type, affecting versions through 8.4.1 in the 8.4.x series, versions through 8.0.5 in the 8.0.x series, and several versions in the 2.x series. This vulnerability occurs on the user information edit page when the Multi-Factor Authentication plugin is enabled. A logged-in user who accesses a crafted page may have arbitrary scripts executed in their web browser.
Movable Type Stored Cross-Site Scripting Vulnerability in MT Block Editor HTML Edit Mode
A stored cross-site scripting vulnerability has been identified in Movable Type, specifically in versions through 8.4.1 of the 8.4.x and 8.0.x series, as well as in Movable Type Premium 2.06 and earlier. This vulnerability occurs in the HTML edit mode of the MT Block Editor when TinyMCE6 is used as a rich text editor. It allows for the execution of arbitrary scripts in the web browser of a logged-in user.
Movable Type Stored Cross-Site Scripting Vulnerability in MT Block Editor
A stored cross-site scripting vulnerability has been identified in Movable Type and Movable Type Advanced, affecting versions through 8.4.1 and 8.0.5, as well as various 2.x and cloud editions. The vulnerability resides in the custom block edit page of the MT Block Editor, where an attacker can execute arbitrary scripts in the web browser of a logged-in user.
Visualizer: Tables and Charts Manager for WordPress Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Visualizer: Tables and Charts Manager for WordPress plugin, affecting all versions through 3.11.8. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's Import Data From File feature. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when a user accesses the injected page.
User Private Files WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress, affecting all versions through 2.1.3. The vulnerability arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Subscriber-level access and above to inject arbitrary web scripts. These scripts are executed when a user accesses the compromised page.
Master Slider WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Master Slider WordPress plugin, affecting versions prior to 3.10.5. The issue arises because the plugin fails to properly sanitize and escape certain settings. This flaw enables high-privilege users, such as Editors and above, to execute stored cross-site scripting attacks, even in environments where the unfiltered_html capability is restricted, such as multisite setups.
Royal Elementor Addons and Templates WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Royal Elementor Addons and Templates plugin for WordPress, affecting all versions through 1.7.1007. The vulnerability arises from inadequate nonce validation in the 'wpr_filter_woo_products' function, allowing unauthenticated attackers to inject malicious scripts by tricking a site administrator into clicking a link.
Age Verification for Checkout - WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Age Verification for Your Checkout Page WordPress plugin, specifically in version 1.20.0. The issue arises because the plugin dynamically generates web content without properly validating the source of potentially untrusted data, particularly in the 'myapp/class-wc-integration-agechecker-integration.php' file.
Easypromos Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Easypromos Plugin for WordPress, affecting all versions through 1.3.8. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's Easypromos shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
Subscribe2 WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress, affecting all versions through 10.43. The vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages. These scripts are executed when users access the compromised pages.
Synway SMG Gateway Management Software Command Injection Vulnerability in 9-12ping.php
A command injection vulnerability has been identified in the Synway SMG Gateway Management Software, specifically in versions prior to 20250204. The issue resides in the 9-12ping.php file, where the 'retry' parameter can be manipulated to execute arbitrary commands on the server. This vulnerability can be exploited remotely without authentication, potentially leading to unauthorized command execution, disclosure of sensitive information, and disruption of service.
Barebox Integer Overflow Vulnerability in ext4 Filesystem Handling
A vulnerability exists in barebox versions prior to 2025.01.0 within the ext4 filesystem handling, specifically in the 'ext4fs_read_symlink' function. The issue arises from an integer overflow when the function processes a crafted ext4 filesystem that includes an inode size of 0xffffffff. This overflow occurs because the function adds one to a little-endian 32-bit variable, leading to a zero allocation when the 'zalloc' function is called. Consequently, the function later uses the invalid inode size to copy data, allowing for a memory overwrite. This vulnerability is related to CVE-2024-57256.
Barebox Integer Overflow Vulnerability in Request2size Function Allows Memory Corruption
An integer overflow vulnerability has been identified in the Barebox bootloader, specifically in versions prior to 2025.01.0. The issue arises in the 'request2size' function within 'common/dlmalloc.c', where a size_t variable is improperly cast to a long. This casting can lead to an overflow, allowing values close to LONG_MAX to be misinterpreted, causing the function to return an incorrect minimum size. This vulnerability is related to another identified issue, CVE-2024-57258.
Kasuganosoras Pigeon Server-Side Request Forgery Vulnerability
A critical server-side request forgery (SSRF) vulnerability has been identified in Kasuganosoras Pigeon version 1.0.177. The issue resides in the file '/pigeon/imgproxy/index.php', where the 'url' parameter can be manipulated to send unauthorized requests to internal network resources. This vulnerability can be exploited remotely, potentially leading to unauthorized access to sensitive information or services within the affected network.
Booking Package WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Booking Package plugin for WordPress, affecting all versions through 1.6.72. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages. These scripts could execute if a user is tricked into clicking a link.
Libxml2 NULL Pointer Dereference Vulnerability in Pattern Matching Component
A NULL pointer dereference vulnerability has been identified in Libxml2 versions prior to 2.12.10 and 2.13.0 prior to 2.13.6. The issue occurs in the 'xmlPatMatch' function within 'pattern.c', where the pattern compiler incorrectly handles explicit 'child' axes, leading to a runtime error. This vulnerability can be exploited to cause a Denial of Service (DoS).
Rufus DLL Hijacking Vulnerability Allowing Privilege Escalation
A DLL hijacking vulnerability has been identified in Rufus versions through 4.6.2208. This vulnerability allows an attacker to load and execute a malicious DLL with elevated privileges. The issue arises from the application's behavior of loading 'cfgmgr32.dll' from the same directory as the executable, a process that can be exploited by placing a malicious DLL in that location. Once injected, the DLL is automatically loaded, taking advantage of the higher privileges granted to Rufus at launch.
FFmpeg NULL Pointer Dereference Vulnerability in MOV Format Handling
A NULL pointer dereference vulnerability has been identified in FFmpeg git master versions prior to the commit c08d30. The issue arises in the MOV format handling component of the libavformat library.
FFmpeg NULL Pointer Dereference Vulnerability in MOV Format Handling
A NULL pointer dereference vulnerability has been identified in FFmpeg git master versions prior to the commit fd1772. This issue arises in the libavformat component, specifically within the MOV file format handling.
Libxml2 Stack-Based Buffer Overflow Vulnerability in DTD Validation
A stack-based buffer overflow vulnerability has been identified in Libxml2 versions prior to 2.12.10 and 2.13.x prior to 2.13.6. The issue arises in the 'xmlSnprintfElements' function within 'valid.c', and can be exploited when DTD validation is performed on an untrusted document or DTD.
FFmpeg Heap Buffer Overflow Vulnerability in avformat Tile Grid Group Stream Processing
A heap buffer overflow vulnerability has been identified in FFmpeg versions prior to the commit 4bf784c. This vulnerability allows attackers to cause memory corruption by supplying a crafted media file that exploits the tile grid group stream processing in the avformat component. The exploitation of this vulnerability can lead to a denial-of-service condition.
FFmpeg Reachable Assertion Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in FFmpeg git-master commit N-113007-g8d24a28d06. This issue arises from a reachable assertion that allows attackers to cause a crash by opening a specially crafted AAC file.
Das U-Boot Heap Corruption Vulnerability in SquashFS Directory Listing
A heap memory corruption vulnerability has been identified in Das U-Boot versions prior to 2025.01-rc1. This issue arises in the 'sqfs_search_dir' function, which handles SquashFS directory listings. The vulnerability is caused by an off-by-one error that leads to improper size calculations, as the path separator is not adequately considered. An attacker capable of modifying SquashFS filesystem data structures can exploit this vulnerability.
Das U-Boot Integer Overflow Vulnerability in Memory Allocation
A vulnerability allowing multiple integer overflows in the memory allocation process has been identified in Das U-Boot versions prior to 2025.01-rc1. This issue arises when handling a crafted SquashFS filesystem, particularly through the sbrk function, the request2size function, or due to improper management of ptrdiff_t on x86_64 architectures.
Das U-Boot Stack Consumption Vulnerability via Deeply Nested Symlinks in SquashFS Filesystems
A stack consumption vulnerability has been identified in Das U-Boot bootloader versions through 2024.10. The issue arises in the 'sqfs_size' function, where the bootloader improperly handles deeply nested symlinks within a crafted SquashFS filesystem. This flaw can lead to excessive stack usage, potentially causing a stack overflow.
Das U-Boot Integer Overflow Vulnerability in ext4 Filesystem Symlink Handling
A vulnerability allowing for memory corruption has been identified in Das U-Boot bootloader versions through 2024.10. This issue arises from an integer overflow in the 'ext4fs_read_symlink' function, where a crafted ext4 filesystem with an inode size of 0xffffffff causes an improper allocation of memory. The overflow occurs by adding one to a little-endian 32-bit variable, leading to a zero allocation and subsequent memory overwrite.
Das U-Boot Integer Overflow Vulnerability in SquashFS Symlink Resolution
A vulnerability exists in Das U-Boot bootloader versions prior to 2025.01-rc1, due to an integer overflow in the 'sqfs_resolve_symlink' function. This vulnerability can be triggered by a crafted SquashFS filesystem that includes an inode size of 0xffffffff. The resulting memory corruption occurs because the overflow leads to a memory allocation of zero, which is then overwritten, creating potential for exploitation.
Das U-Boot Integer Overflow Vulnerability in SquashFS Symlink Size Calculation
A vulnerability allowing for integer overflow has been identified in Das U-Boot versions prior to 2025.01-rc1. This issue occurs in the symlink size calculation within the 'sqfs_inode_size' function, when processing a crafted SquashFS filesystem. The integer overflow can lead to memory corruption vulnerabilities, which may be exploited to bypass verified boot and execute arbitrary code, according to the vendor.
Wonder Video Embed Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Wonder Video Embed plugin for WordPress, affecting all versions through 2.2. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's wonderplugin_video shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the compromised page.
D-Link DSL-3782 Buffer Overflow Vulnerability Leading to Denial-of-Service
A buffer overflow vulnerability has been identified in the D-Link DSL-3782 router, specifically in version 1.01. The issue arises in the web interface, where the destination, netmask, and gateway parameters can be manipulated. This vulnerability allows attackers to send crafted packets that cause a denial-of-service condition, disrupting normal operation of the device.
D-Link DSL-3782 OS Command Injection Vulnerability
An OS command injection vulnerability exists in the D-Link DSL-3782 router, specifically in version 1.01. The issue arises in the public_type parameter, allowing attackers to execute arbitrary operating system commands by sending a crafted packet.
D-Link DSL-3782 OS Command Injection Vulnerability
An OS command injection vulnerability exists in the D-Link DSL-3782 router, specifically in version 1.01. The issue arises in the samba_wg and samba_nbn parameters, allowing attackers to execute arbitrary operating system commands by sending a crafted packet.
D-Link DSL-3782 OS Command Injection Vulnerability
An OS command injection vulnerability exists in the D-Link DSL-3782 router, version 1.01. The issue arises in the web interface, where certain parameters can be manipulated to execute arbitrary operating system commands. This vulnerability can be exploited by sending a crafted packet that includes the inIP, insPort, inePort, exsPort, exePort, and protocol parameters.
D-Link DSL-3782 Buffer Overflow Vulnerability Leading to Denial-of-Service
A buffer overflow vulnerability has been identified in the D-Link DSL-3782 router, specifically in version 1.01. The issue arises in the sstartip, sendip, dstartip, and dendip parameters, allowing attackers to send crafted packets that cause a denial-of-service condition.
D-Link DSL-3782 Buffer Overflow Vulnerability Leading to Denial-of-Service
A buffer overflow vulnerability has been identified in the D-Link DSL-3782 router, specifically in version 1.01. This vulnerability is triggered by the destination, netmask, and gateway parameters, allowing attackers to send crafted packets that cause a denial-of-service condition.
FFmpeg Memory Leak Vulnerability in libavutil/iamf Component
A memory leak vulnerability has been identified in FFmpeg git-master versions prior to commit d5873b, specifically within the libavutil/iamf.c component. This vulnerability can lead to increased memory usage over time, potentially causing performance degradation or exhaustion of system resources.
FFmpeg Memory Leak Vulnerability in libavutil/mem Component
A memory leak vulnerability has been identified in FFmpeg git-master versions prior to the commit d5873b. This issue occurs in the libavutil/mem.c component, where improper memory management can lead to resource exhaustion.
libx264 Memory Leak Vulnerability Allowing Arbitrary Code Execution
A vulnerability in libx264 git master has been identified, stemming from inadequate management of allocated memory. This flaw can be exploited by creating a specially crafted AAC file, leading to arbitrary code execution. The issue arises when libx264 is used with FFmpeg, specifically with the 'libx264' and 'gpl' options enabled. The vulnerability has been confirmed to be a memory leak, where duplicated strings are not properly freed, allowing for potential exploitation.
FFmpeg Segmentation Violation Vulnerability in JPEG2000 Decoder Component
A segmentation violation vulnerability has been identified in FFmpeg git-master, N-113007-g8d24a28d06, within the JPEG2000 decoding component. This issue can lead to a crash or unexpected behavior in the application.
