CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Octopus Server File Existence Information Disclosure Vulnerability
A vulnerability exists in certain versions of Octopus Server that allows the preview import feature to be used for file existence probing. This could enable an adversary to gather information about the presence of specific files on the server, potentially facilitating further attacks.
GNU Binutils Memory Corruption Vulnerability in the ELF Relocation Handling Function
A critical memory corruption vulnerability has been identified in GNU Binutils version 2.43. The issue arises in the linker component, specifically within the ELF relocation handling function. This vulnerability can be exploited remotely, although the attack's complexity is considered high, making exploitation difficult.
Octopus Deploy Active Directory Data Exposure Vulnerability
A vulnerability exists in Octopus Deploy versions 2020.3.x (after 2020.3.3), 2020.4.x, 2020.5.x, 2020.6.x, 2021.x, 2022.x, 2023.x, 2024.1.x, 2024.2.x, 2024.3.x (before 2024.3.13071), and 2024.4.x (before 2024.4.7065) when Active Directory is used for authentication. This vulnerability allows an unauthenticated user to make API requests to two endpoints that retrieve data from Active Directory. Depending on how the requests are crafted, this could include specific user profile information such as email addresses, UPNs, display names, or group details like group IDs and display names. Notably, this vulnerability does not expose any data within the Octopus Server product itself.
GNU Binutils Memory Corruption Vulnerability in ld Component
A critical memory corruption vulnerability has been identified in GNU Binutils versions through 2.43. This issue arises in the ld component, specifically within the _bfd_elf_gc_mark_rsec function in bfd/elflink.c. The vulnerability can be exploited remotely, although the attack's complexity is considered high, making successful exploitation difficult.
GNU Binutils Memory Corruption Vulnerability in ld Component
A memory corruption vulnerability has been identified in GNU Binutils version 2.43, specifically within the ld component's eh_frame handling. This issue arises from illegal read access in the _bfd_elf_write_section_eh_frame function, leading to a segmentation fault. The vulnerability can be exploited remotely, although the attack's complexity is considered high. When exploited, this issue causes the linker to crash, creating a denial-of-service condition. Furthermore, the illegal memory access could result in undefined behavior, potentially allowing for memory corruption that affects other processes on the system. In certain environments, this vulnerability might be leveraged to escalate privileges or execute arbitrary code.
SolarWinds Platform Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in SolarWinds Platform. This issue arises from inadequate sanitization of input parameters, allowing for the injection of malicious scripts. The vulnerability requires authentication by a high-privileged account to be exploited.
SolarWinds Platform Information Disclosure Vulnerability
An information disclosure vulnerability has been identified in the SolarWinds Platform. This vulnerability arises from an error message that, while not revealing sensitive data, could provide an attacker with information useful for conducting other malicious activities. The issue is present in multiple versions of the SolarWinds Platform.
SolarWinds Platform Server-Side Request Forgery Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in SolarWinds Platform. This vulnerability arises from inadequate input validation, which allows for the possibility of malicious web requests being sent. The issue is present in multiple versions of the platform.
SolarWinds Kiwi Syslog Server Sensitive Data Exposure Vulnerability
A vulnerability exists in SolarWinds Kiwi Syslog Server (KSS) NG versions through 1.3.1, allowing sensitive data to be exposed to non-privileged users via a configuration file. This issue requires local access to the computer with a low-privileged account to retrieve the file containing the sensitive information.
SolarWinds Web Help Desk Hardcoded Cryptographic Key Vulnerability
A vulnerability exists in SolarWinds Web Help Desk due to a hardcoded cryptographic key, which could lead to the unauthorized disclosure of sensitive information from the application. This issue affects Web Help Desk versions prior to 12.8.5.
Zox News WordPress Theme Missing Authorization Vulnerability Allows Privilege Escalation and Arbitrary Options Modification
A vulnerability exists in the Zox News - Professional WordPress News & Magazine Theme plugin, affecting all versions through 3.17.0. The issue arises from missing capability checks in the backup_options() and reset_options() functions, allowing authenticated attackers with Subscriber-level access and above to modify or delete arbitrary option values. This vulnerability could be exploited to escalate privileges by changing the default user role for new registrations to Administrator, thereby gaining administrative access. Additionally, attackers could remove critical options, potentially disrupting the site's functionality and causing denial-of-service conditions for legitimate users.
GNU Binutils Memory Corruption Vulnerability in ld Component
A critical memory corruption vulnerability has been identified in GNU Binutils version 2.43. The issue arises in the ld component, specifically within the bfd_putl64 function in bfd/libbfd.c. This vulnerability can be exploited remotely, although the attack's complexity is high and exploitation is known to be difficult.
GNU Binutils Memory Corruption Vulnerability in ld Component
A memory corruption vulnerability has been identified in GNU Binutils version 2.43, specifically within the ld component's bfd_putl64 function in libbfd.c. This vulnerability allows for illegal write access, leading to a segmentation fault and a crash of the linker. The issue can be exploited remotely, although the complexity of the attack is considered high.
WP Foodbakery Plugin Privilege Escalation Vulnerability
A privilege escalation vulnerability allowing account takeover has been identified in the WP Foodbakery plugin for WordPress, affecting all versions through 4.8. The issue arises because the plugin fails to properly validate a user's identity before assigning the current user and their authentication cookie. This vulnerability enables unauthenticated attackers to access the accounts of targeted users, such as administrators.
WP Foodbakery Privilege Escalation Vulnerability
A privilege escalation vulnerability has been identified in the WP Foodbakery plugin for WordPress, affecting all versions through 4.7. The issue arises because the plugin fails to properly restrict user meta updates during profile registration. This flaw allows unauthenticated attackers to register on the site as administrators.
dayrui XunRuiCMS Deserialization Vulnerability in Admin Linkage Function
A critical deserialization vulnerability has been identified in dayrui XunRuiCMS version 4.6.3. The issue arises in the import_add function within the file dayrui/Fcms/Control/Admin/Linkage.php. This vulnerability can be exploited remotely, allowing for potential manipulation of the application's data or behavior.
GNU Binutils Heap-Based Buffer Overflow Vulnerability
A critical heap-based buffer overflow vulnerability has been identified in GNU Binutils version 2.43. This issue arises in the linker component (ld), specifically within the '_bfd_elf_gc_mark_rsec' function of 'elflink.c'. The vulnerability can be exploited remotely, although the attack's complexity is high and exploitation is known to be difficult.
Stray Random Quotes WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Stray Random Quotes WordPress plugin, affecting versions through 1.9.9. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
Zarinpal Paid Download WordPress Plugin Arbitrary File Upload Vulnerability
A vulnerability exists in the Zarinpal Paid Download WordPress plugin, affecting versions through 2.3, due to improper validation of uploaded files. This flaw allows high-privilege users, such as administrators, to upload arbitrary files to the server, even in scenarios where such actions should be restricted, like in a multisite setup.
Zarinpal Paid Download WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Zarinpal Paid Download WordPress plugin, versions through 2.3. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
Hackney Server-Side Request Forgery Vulnerability
A Server-side Request Forgery (SSRF) vulnerability has been identified in the Hackney package, versions prior to 1.21.0. This vulnerability arises from improper URL parsing by the built-in URI module and Hackney itself. When the URL 'http://127.0.0.1?@127.2.2.2/' is processed, the URI module correctly identifies the host as '127.0.0.1', but Hackney mistakenly refers to the host as '127.2.2.2/'. This misinterpretation can be exploited in scenarios where users depend on the URI parsing for host validation.
1000 Projects Bookstore Management System Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Bookstore Management System version 1.0. The issue resides in the file process_book_add.php, within the Add Book Page component. The vulnerability is triggered by manipulating the 'Book Name' argument, allowing for the injection of malicious scripts that are executed when the book is viewed. This vulnerability can be exploited remotely and has been disclosed publicly.
1000 Projects Bookstore Management System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in the Bookstore Management System version 1.0. The issue arises in the file process_users_del.php, where the 'id' parameter is not properly sanitized before being included in SQL queries. This flaw allows remote attackers to manipulate the 'id' argument and execute arbitrary SQL commands, potentially leading to unauthorized data access or modification.
HT Mega – Absolute Addons For Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the HT Mega – Absolute Addons For Elementor plugin for WordPress, affecting all versions through 2.8.1. The issue arises in the Countdown widget, where inadequate input sanitization and output escaping on user-supplied attributes allow authenticated attackers with contributor-level access or higher to inject arbitrary web scripts. These scripts execute when a user accesses the affected page.
1000 Projects Bookstore Management System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in the Bookstore Management System version 1.0, developed by 1000 Projects. The issue arises in the 'addtocart.php' file, where the 'bcid' parameter is not properly sanitized before being included in the SQL query. This flaw allows for remote exploitation of the application.
Code-Projects Real Estate Property Management System Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Code-Projects Real Estate Property Management System version 1.0. The issue arises in the file /Admin/CustomerReport.php, where the Address parameter is not properly sanitized, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely and requires user interaction.
NetVision Information ISOinsight Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in NetVision Information ISOinsight versions 2.9.0.x and 3.0.0.x. This vulnerability allows unauthenticated remote attackers to execute arbitrary JavaScript in the user's browser, potentially through phishing methods.
Quanxun School Affairs System Sensitive Information Exposure Vulnerability
A vulnerability allowing the exposure of sensitive information has been identified in the Quanxun School Affairs System. This issue enables unauthenticated attackers to access specific pages, retrieve database information, and obtain plaintext credentials for administrators.
Billion Electric Routers Hard-Coded Credentials Vulnerability Allowing Root Access via SSH
A vulnerability exists in certain Billion Electric router models, including the M100, M150, M120N, and M500. These routers have hard-coded Linux credentials that can be used to log in through the SSH service, granting root privileges on the system.
Code-Projects Real Estate Property Management System Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Code-Projects Real Estate Property Management System version 1.0. The issue arises in an unknown function within the file /Admin/Category.php, where the argument 'Desc' can be manipulated to inject malicious scripts. This vulnerability can be exploited remotely.
SourceCodester Image Compressor Tool Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in SourceCodester Image Compressor Tool version 1.0. The issue arises from an unknown processing of the file '/image-compressor/compressor.php', where the 'image' argument can be manipulated to inject malicious scripts. This vulnerability can be exploited remotely.
SourceCodester Contact Manager SQL Injection Vulnerability in Export to VCF Feature
A critical SQL injection vulnerability has been identified in SourceCodester Contact Manager version 1.0, specifically within the export to VCF feature. The issue arises in the file '/endpoint/delete-contact.php', where the 'contact' parameter is manipulated, allowing attackers to inject SQL payloads. This vulnerability can be exploited remotely, with public knowledge of the exploit available.
Mayuri K Employee Management System SQL Injection Vulnerability in Update_User.php
A critical SQL injection vulnerability has been identified in the Mayuri K Employee Management System, affecting versions up to 192.168.70.3. The issue arises in the file '/hr_soft/admin/Update_User.php', where the 'id' parameter can be manipulated to execute arbitrary SQL commands. This vulnerability can be exploited remotely, potentially allowing attackers to access or modify sensitive database information.
SourceCodester Food Menu Manager Unrestricted File Upload Vulnerability
A critical unrestricted file upload vulnerability has been identified in SourceCodester Food Menu Manager version 1.0. The issue resides in the file endpoint/update.php, where the upload logic fails to properly validate file types. This flaw allows attackers to bypass image type detection using a crafted GIF file and upload malicious PHP scripts, such as Trojans, that can execute arbitrary code on the server.
SAP Supplier Relationship Management File Download Vulnerability in Master Data Management Catalog
A vulnerability in SAP Supplier Relationship Management's Master Data Management Catalog allows an unauthenticated attacker to download arbitrary files over the network using a publicly available servlet. This issue can be exploited without user interaction, potentially exposing highly sensitive information while not affecting the integrity or availability of the system.
SAP Applications Missing Authorization Check Vulnerability in Overtime Requests Management
A vulnerability exists in certain SAP applications due to a missing authorization check. This flaw allows logged-in attackers to view or delete 'My Overtime Requests', potentially accessing sensitive employee information. The issue arises from inadequate authorization controls, leading to a low impact on the application's confidentiality and integrity, with no effect on availability.
SAP Approuter Node.js Package Authentication Bypass Vulnerability
An authentication bypass vulnerability has been identified in the SAP Approuter Node.js package, specifically in version 16.7.1 and earlier. This vulnerability allows an attacker to steal a victim's session by injecting malicious payloads while exchanging an authorization code. The issue arises from a flaw in the authorization code handling process, leading to a high impact on the application's confidentiality and integrity.
SAP Commerce SameSite Cookie Vulnerability in Authentication Cookies
A vulnerability exists in SAP Commerce due to certain cookies, including authentication cookies used in SAP Commerce Backoffice, being set with the SameSite attribute configured to None. This default setting weakens protection against Cross-Site Request Forgery (CSRF) attacks and may cause compatibility issues in the future.
SAP Commerce Clickjacking Vulnerability via Deprecated X-FRAME-OPTIONS Header
A vulnerability exists in SAP Commerce (Backoffice) due to the use of the outdated X-FRAME-OPTIONS header for clickjacking protection. While this method is currently effective, it may become inadequate in the future as browsers could phase out support for this header in favor of the frame-ancestors Content Security Policy directive. If that occurs, clickjacking could be feasible, potentially leading to the exposure and unauthorized modification of sensitive information.
SAP ABAP Platform Unauthorized Access Vulnerability in ABAP Build Framework
A vulnerability in the ABAP Build Framework of SAP ABAP Platform allows authenticated attackers to gain unauthorized access to specific transactions. By using the add-on build functionality within the framework, attackers can invoke transactions and view their details. This vulnerability has a limited impact on application confidentiality, with no effects on integrity or availability.
SAP GUI for Windows Privilege Escalation Vulnerability via Insecure Credential Storage
A vulnerability exists in SAP GUI for Windows, where RFC service credentials are improperly stored in the program's memory. This flaw allows an unauthenticated attacker to access sensitive information within systems, potentially leading to privilege escalation. The issue does not affect the integrity or availability of the system.
SAP NetWeaver Application Server Java Information Disclosure Vulnerability
An information disclosure vulnerability has been identified in SAP NetWeaver Application Server Java. This vulnerability allows an attacker to access an endpoint that reveals details about deployed server components, including their XML definitions. Ideally, this information should be restricted to customer administrators. The exposed XML files, while not entirely internal to SAP, are deployed with the server. As a result, sensitive information could be leaked without compromising its integrity or availability.
SAP HANA XS Advanced Model User Account and Authentication Service Open Redirect Vulnerability
A vulnerability in the User Account and Authentication service for SAP HANA extended application services, advanced model, allows an unauthenticated attacker to create a malicious link that, when clicked by a victim, redirects the browser to a harmful site. This exploitation takes advantage of inadequate validation of redirect URLs. Successful exploitation could lead to a limited impact on the system's confidentiality, integrity, and availability.
SAP BusinessObjects Platform Cross-Site Scripting Vulnerability in BI Launchpad
A cross-site scripting (XSS) vulnerability has been identified in SAP BusinessObjects Platform, specifically within the BI Launchpad component. This issue arises because the application does not adequately sanitize user input, allowing an unauthenticated attacker to create a URL that includes a malicious script embedded in an unprotected parameter. When a user clicks on the link, the script is executed in their browser, potentially enabling the attacker to access or modify information related to the web client, without impacting the application's availability.
SAP NetWeaver Server ABAP User-Based Information Disclosure Vulnerability
An information disclosure vulnerability has been identified in SAP NetWeaver Server ABAP. This issue allows an unauthenticated attacker to exploit the server's response behavior based on the presence of a specific user, potentially leading to the revelation of sensitive information. The vulnerability does not permit data modification and does not affect server availability.
SAP Fiori for SAP ERP Host Header Injection Vulnerability Allowing OData Cache Poisoning
A vulnerability exists in the SAP OData endpoint within SAP Fiori for SAP ERP, where cached values can be poisoned by altering the Host header in an HTTP GET request. This manipulation could redirect the 'atom:link' values in the metadata response from the SAP server to a malicious link specified by the attacker. Exploitation of this vulnerability could lead to a low integrity impact on the application.
SAP Missing Authorization Check Vulnerability Allowing Unauthorized Data Access
A vulnerability exists in certain SAP products due to a lack of proper authorization checks. This flaw enables an authenticated attacker to invoke a remote-enabled function module, potentially accessing data that should be restricted. However, the attacker cannot alter data or affect system availability.
SAP RFC Authorization Bypass Vulnerability in Transaction SDCCN Allowing Integrity Impact
A vulnerability exists in an RFC-enabled function module within transaction SDCCN due to a lack of proper authorization checks. This flaw allows authenticated attackers to generate technical metadata, potentially leading to a low impact on data integrity. The vulnerability does not affect confidentiality or availability.
SAP NetWeaver Missing Authorization Check in RFC Function Module Vulnerability in Transaction SDCCN
A vulnerability exists in an RFC-enabled function module within the SAP NetWeaver platform, specifically in transaction SDCCN. The issue arises from a missing authorization check, allowing an unauthenticated attacker to generate technical metadata. This vulnerability has a low impact on integrity, with no effects on confidentiality or availability.
Lumsoft ERP Unrestricted File Upload Vulnerability
A critical unrestricted file upload vulnerability has been identified in Lumsoft ERP version 8. The issue resides in the DoUpload/DoWebUpload function of the FileUploadApi.ashx file. This vulnerability allows for remote exploitation by manipulating the file upload argument, potentially leading to unauthorized file uploads on the server.
