CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
WordPress Show Notice or Message on Admin Area Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Show Notice or Message on Admin Area plugin, affecting versions through 2.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to, potentially leading to Stored Cross-Site Scripting (XSS) issues.
WP Social Stream Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP Social Stream plugin by Nirmal Kumar Ram, affecting versions through 1.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser session.
WordPress Easy WP Tiles Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Easy WP Tiles plugin, affecting versions through 1. This issue arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.
WordPress WP Admin Custom Page Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress WP Admin Custom Page plugin, specifically in versions through 1.5.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could introduce malicious scripts that are stored and executed later.
WordPress Vignette Ads Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Vignette Ads plugin, specifically in versions through 0.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.
OpenHarmony LiteOS_A Kernel Use-After-Free Vulnerability Allowing Privilege Escalation
A use-after-free vulnerability has been identified in the OpenHarmony LiteOS_A kernel, in versions through 4.1.2. This vulnerability allows a local attacker to escalate privileges by upgrading common permissions to root, and it also leads to the leakage of sensitive information.
OpenHarmony Buffer Overflow Vulnerability Leading to Root Privilege Escalation and Information Leak
A buffer overflow vulnerability has been identified in OpenHarmony versions through 4.1.2. This vulnerability allows a local attacker to escalate privileges by upgrading common permissions to root, and it also facilitates the leakage of sensitive information.
OpenHarmony Denial-of-Service Vulnerability Due to Integer Overflow
A denial-of-service vulnerability has been identified in OpenHarmony versions through 4.1.2. This issue allows a local attacker to cause a system crash or unresponsiveness by exploiting an integer overflow condition.
IBL Software Engineering Visual Weather Product Delivery Service Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in IBL Software Engineering Visual Weather and its derived products, including NAMIS, Aero Weather, and Satellite Weather. The issue arises in the Product Delivery Service (PDS) component when specific server configurations enable the PDS pipeline to use the IPDS pipeline with Message Editor Output Filters activated. In these scenarios, an unauthenticated attacker can send requests that execute the IPDS pipeline with specially crafted Form Properties, allowing for the remote execution of arbitrary Python code. This vulnerability could lead to a complete system compromise, especially if Visual Weather services are running under a privileged user account, contrary to the recommended installation best practices.
Delta Electronics CNCSoft-G2 Heap-Based Buffer Overflow Remote Code Execution Vulnerability
A heap-based buffer overflow vulnerability has been identified in Delta Electronics CNCSoft-G2, specifically in versions through 2.1.0.10. The issue arises from improper validation of user-supplied data length before it is copied to a fixed-length heap-based buffer. This vulnerability can be exploited to execute code in the context of the current process, potentially leading to unauthorized actions or access.
Node.js Memory Leak Vulnerability in HTTP/2 Server
A memory leak vulnerability has been identified in Node.js versions 18.x, 20.x, 22.x, and 23.x, specifically within the HTTP/2 Server implementation. The issue arises when a remote peer abruptly closes the socket without sending a GOAWAY notification, or when an invalid header is detected by nghttp2, leading to connection termination. This flaw can cause increased memory consumption and potentially result in a denial-of-service condition under certain circumstances.
Builder Shortcode Extras WordPress Plugin Information Exposure Vulnerability
A vulnerability allowing information exposure exists in the Builder Shortcode Extras WordPress plugin, specifically in versions through 1.0.0. The issue arises within the 'bse-elementor-template' shortcode, where inadequate restrictions allow authenticated attackers with Contributor-level access and above to access data from private and draft Elementor posts that should be off-limits.
Guten Free Options WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Guten Free Options WordPress plugin, affecting versions through 0.9.5. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
Legull WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Legull WordPress plugin, affecting versions through 1.2.2. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
GitLab CE/EE Denial-of-Service Vulnerability via Fogbugz Importer
A denial-of-service vulnerability has been identified in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2. The issue arises when maliciously crafted content is imported using the Fogbugz importer, leading to a denial-of-service condition.
Dell Update Manager Plugin Basic Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been identified in the Dell Update Manager Plugin, affecting versions 1.5.0 through 1.6.0. This vulnerability arises from improper sanitization of script-related HTML tags, allowing low-privileged attackers with remote access to potentially exploit the issue, leading to information exposure.
Safetytest Cloud-Master Server Path Traversal Vulnerability
A critical path traversal vulnerability has been identified in Safetytest Cloud-Master Server versions through 1.1.1. The issue resides in an unknown part of the code within the file '/static/', allowing remote attackers to manipulate file paths and potentially access unauthorized files by exploiting the traversal sequence '../filedir'.
Nextend Social Login Pro Authentication Bypass Vulnerability via Apple OAuth
A vulnerability allowing authentication bypass has been identified in the Nextend Social Login Pro plugin for WordPress, affecting versions through 3.1.16. The issue arises from inadequate verification of the user information provided during the Apple OAuth authentication process. This flaw enables unauthenticated attackers to log in as any existing user on the site, including administrators, if they have access to the user's email address.
Animati PACS Cross-Site Scripting Vulnerability in Login File
A cross-site scripting vulnerability has been identified in Animati PACS versions prior to 1.24.12.09.03. The issue arises in the login file, where the manipulation of the 'p' argument allows for the injection of malicious scripts. This vulnerability can be exploited remotely.
Mindskipe XZS-MySQL Cross-Site Request Forgery Vulnerability
A cross-site request forgery (CSRF) vulnerability has been identified in Mindskip XZS-MySQL version 3.9.0. The application lacks proper CSRF protections, allowing attackers to manipulate authenticated users into performing unintended actions, such as submitting exam answers without consent. This vulnerability affects multiple endpoints, including the answer submission endpoint for exam papers.
Elber Communications Equipment Unauthenticated Configuration and Hidden Functionality Disclosure Vulnerability
A vulnerability exists in multiple Elber communications products, allowing for unauthenticated access to device configuration and the disclosure of client-side hidden functionalities. This issue affects the Signum DVB-S/S2 IRD (versions 1.999 and prior), Cleber/3 Broadcast Multi-Purpose Platform (version 1.0), Reble610 M/ODU XPIC IP-ASI-SDH (version 0.01), ESE DVB-S/S2 Satellite Receiver (versions 1.5.179 and prior), and Wayber Analog/Digital Audio STL (version 4).
Elber Communications Equipment Authentication Bypass Vulnerability Allowing Unauthorized Administrative Access
An authentication bypass vulnerability has been identified in multiple Elber communications products, including the Signum DVB-S/S2 IRD, Cleber/3 Broadcast Multi-Purpose Platform, Reble610 M/ODU XPIC IP-ASI-SDH, ESE DVB-S/S2 Satellite Receiver, and Wayber Analog/Digital Audio STL. This vulnerability allows attackers to gain unauthorized access to the password management functionality by manipulating the endpoint to overwrite any user's password. Exploitation of this vulnerability grants unauthorized administrative access to protected areas of the application, compromising the device's system security.
Microsoft Edge Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in the Chromium-based version of Microsoft Edge. This issue allows an attacker to execute arbitrary code on the affected system.
Microsoft Edge Spoofing Vulnerability
A spoofing vulnerability has been identified in the Chromium-based version of Microsoft Edge. This vulnerability allows for the manipulation of web content, potentially leading to deceptive representations of information or user interactions.
Microsoft Edge Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in the Chromium-based version of Microsoft Edge. This issue arises from a type confusion flaw, allowing attackers to execute arbitrary code in the context of the user.
Microsoft Edge Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in the Chromium-based version of Microsoft Edge. This issue allows an attacker to execute arbitrary code on the affected system.
Microsoft Edge Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in Microsoft Edge (Chromium-based).
Microsoft Edge Spoofing Vulnerability
A spoofing vulnerability has been identified in Microsoft Edge (Chromium-based) version 133.0.3065.51. This vulnerability allows an attacker to manipulate user interactions or perceptions, potentially leading to unauthorized actions or information disclosure. Exploitation requires local access to the system and could involve convincing a user to open a malicious file.
Microsoft Edge Spoofing Vulnerability on iOS and Android
A spoofing vulnerability has been identified in Microsoft Edge for iOS and Android. This issue allows an attacker to misrepresent information in a way that could be misleading to users.
Microsoft Dynamics 365 Sales Server-Side Request Forgery Vulnerability Allowing Privilege Escalation
A Server-Side Request Forgery (SSRF) vulnerability has been identified in Microsoft Dynamics 365 Sales. This vulnerability allows an authorized attacker to manipulate requests sent from the server, potentially leading to unauthorized access or actions within the network. The issue arises from insufficient validation of server-side requests, enabling attackers to exploit the application's request handling capabilities.
Mindskip xzs-mysql CORS Misconfiguration Vulnerability
A vulnerability exists in Mindskip xzs-mysql 学之思开源考试系统 version 3.9.0, specifically within the CORS Handler component. This vulnerability allows for a permissive cross-domain policy that can be exploited by untrusted domains. The issue can be exploited remotely, but the complexity of the attack is high, requiring some form of user interaction. While the vulnerability has been publicly disclosed and a proof-of-concept exploit is available, technical details on the exploitation are not specified.
Mindskip XZS-MySQL Exam Edit Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Mindskip XZS-MySQL 学之思开源考试系统 version 3.9.0. The issue arises in the Exam Edit Handler component, specifically within the API endpoint /api/admin/question/edit. The vulnerability is triggered by manipulating the title or content arguments, allowing for the injection of malicious scripts. This issue can be exploited remotely and requires user interaction.
Kanaries Pygwalker Open Redirect Vulnerability Allowing Sensitive Information Disclosure and Arbitrary Code Execution
A vulnerability in Kanaries Inc Pygwalker versions prior to 0.4.9.9 allows remote attackers to access sensitive information and execute arbitrary code. This is achieved through the redirect_path parameter in the login redirection function, which can be manipulated to redirect users to malicious sites or potentially execute harmful code.
ProFTPD Buffer Overflow Vulnerability Allowing Arbitrary Code Execution and Denial-of-Service
A buffer overflow vulnerability has been identified in ProFTPD version 1.3.7a+dfsg-12+deb11u5. This vulnerability allows remote attackers to execute arbitrary code and can lead to a denial-of-service condition on the FTP service. The issue arises when a maliciously crafted message is sent to the ProFTPD service port, causing the FTP service to crash.
CodeAstro Complaint Management System Privilege Escalation Vulnerability Allowing Unauthorized Deletion of Complaints
A vulnerability in CodeAstro Complaint Management System version 1.0 allows unauthorized deletion of complaints through improper access control in the /admin/m_delete.php endpoint. Attackers can exploit this issue by manipulating the id parameter, enabling arbitrary deletion of complaints without the need for a valid session or privileges.
Deep-Diver LLM-As-Chatbot Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in deep-diver LLM-As-Chatbot versions prior to commit 99c2c03. The issue arises in the modelsbyom.py component, where a remote attacker can execute arbitrary code.
GoldPanKit Eva-Server Arbitrary File Download Vulnerability
An arbitrary file download vulnerability has been identified in GoldPanKit Eva-Server version 4.1.0. The issue arises in the '/api/resource/local/download' endpoint, where the 'path' parameter can be manipulated to download arbitrary files from the server.
WebFileSys Directory Traversal Vulnerability in relPath Parameter
A directory traversal vulnerability has been identified in WebFileSys version 2.31.0. The issue arises in the relPath parameter, where attackers can inject traversal payloads through crafted HTTP requests. This manipulation of file paths may lead to unauthorized access to sensitive files, potentially exposing data outside the intended directory.
Gilnei Moraes phpABook Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Gilnei Moraes phpABook version 0.9. The issue allows remote attackers to execute arbitrary code by injecting malicious scripts into the 'rol' parameter of 'index.php'. This vulnerability stems from inadequate validation and sanitization of user input, enabling the execution of scripts in the context of the user's browser.
RSD Incorrectly Updates Mstatus Register, Leading to Processing Errors
A vulnerability exists in RSD that causes the mstatus register to update incorrectly, resulting in processing errors. This issue arises in RSD commit 3d13a when the FS field is set to 11, as the SD bit does not reflect the expected value. The incorrect handling of the mstatus register can lead to various processing errors, particularly in the context of the RISC-V privilege specification.
Egavilan Media Resumes Management and Job Application Website Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in Egavilan Media Resumes Management and Job Application Website version 1.0. This vulnerability allows remote attackers to inject arbitrary code into the application. The issue arises in the 'Apply For This Job' form, where injected scripts in the First and Last Name fields are executed when the application is accessed by an admin user.
Mitel OpenScape Command Injection Vulnerability in Platform Component
A command injection vulnerability has been identified in the Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager. This vulnerability affects versions V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 through V10 R1.54.1, and V10 R1.42.6 and earlier. The issue arises from insufficient parameter sanitization, allowing an unauthenticated attacker to execute arbitrary commands at the same privilege level as the web access process.
Bharti Airtel Xstream Fiber WiFi Weak Password Vulnerability
A vulnerability exists in Bharti Airtel Xstream Fiber WiFi routers, affecting versions through January 23, 2025. The issue arises from the WiFi Password Handler component, which implements a weak password scheme that can be easily brute-forced. The initial WiFi password consists of five random digits, prefixed by 'air', creating a predictable pattern. This vulnerability can be exploited by capturing the WiFi handshake and offline cracking the password, potentially leading to unauthorized access to the WiFi network and subsequent attacks, such as Man-in-the-Middle (MiTM) attacks.
IBM EntireX Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in IBM EntireX version 11.1. This issue arises from an unhandled error and fault isolation, which could allow a local user to disrupt service.
IBM EntireX Sensitive Information Disclosure Vulnerability
A vulnerability in IBM EntireX version 11.1 could allow a local user to access sensitive information through detailed technical error messages. This information might be leveraged for further attacks against the system.
IBM EntireX XML External Entity Injection Vulnerability
A vulnerability allowing XML external entity (XXE) injection has been identified in IBM EntireX version 11.1. This issue arises when the application processes XML data, creating an opportunity for authenticated attackers to exploit it. The exploitation of this vulnerability could lead to the exposure of sensitive information or excessive memory consumption.
Mitel OpenScape 4000 Privilege Escalation Vulnerability
A privilege escalation vulnerability has been identified in the Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager, affecting versions V10 R1.54.0 through V10 R1.54.1, V11 R0.22.0 through V11 R0.22.1, and V10 R1.42.6 and earlier. This vulnerability could allow an authenticated attacker to execute arbitrary commands with elevated privileges by exploiting a resource that is granted unnecessary privileges. The successful exploitation of this vulnerability could lead to unauthorized access and control over the system, potentially allowing a non-administrative user to gain full administrative rights.
Smartcom Ralink CPE/WiFi Routers Weak Default WiFi Password Vulnerability
A vulnerability exists in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi routers, specifically the SAM-4G1G-TT-W-VC and SAM-4F1F-TT-W-A1 models. The issue arises from a weak default WiFi password generation algorithm, which allows remote attackers to obtain sensitive information. The vulnerability exploits the fact that the serial number, used in password generation, can be easily derived from the router's BSSID.
Floodlight Denial-of-Service Vulnerability via Topology Manager and Link Discovery Modules
A denial-of-service vulnerability has been identified in Floodlight version 1.2. This issue allows a local attacker to cause link flooding by exploiting the Topology Manager and Link Discovery modules. The vulnerability arises because the Floodlight controller broadcasts BDDP packets with Controller TLV values greater than its own Controller ID. If no corresponding controller with a larger ID exists in the SDN system, this behavior leads to persistent link flooding.
Floodlight Denial-of-Service Vulnerability via Topology and Routing Modules
A denial-of-service vulnerability has been identified in Floodlight version 1.2. This issue allows a local attacker to disrupt network topology management by exploiting the Topology Manager, Topology Instance, and Routing modules. The vulnerability arises when a malicious host connected to a legacy switch manipulates network packets to remove external links from the SDN topology, causing data streams to be improperly forwarded.
