CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
WP Job Portal Insecure Direct Object Reference Vulnerability Allowing Unauthenticated Logo Deletion
A vulnerability exists in the WP Job Portal WordPress plugin, specifically in versions through 2.2.6. The issue is an Insecure Direct Object Reference (IDOR) that allows unauthenticated users to delete arbitrary company logos. This vulnerability arises from the deleteCompanyLogo() function, which lacks proper validation on user-controlled keys.
WP Job Portal Insecure Direct Object Reference Vulnerability Allowing Arbitrary Company Deletion
A vulnerability exists in the WP Job Portal WordPress plugin, specifically in versions through 2.2.6. This issue is an Insecure Direct Object Reference (IDOR) that arises from the enforcedelete() function, which lacks proper validation on a user-controlled key. As a result, authenticated attackers with Employer-level access or higher can delete companies belonging to other users.
WP Job Portal Insecure Direct Object Reference Vulnerability Allowing Unauthenticated Resume Downloads
A vulnerability exists in the WP Job Portal WordPress plugin, specifically in versions through 2.2.6. The issue is an Insecure Direct Object Reference (IDOR) that allows unauthenticated users to download resumes from other users without proper authorization. This vulnerability arises from missing validation on a user-controlled key in the 'getresumefiledownloadbyid()' and 'getallresumefiles()' functions.
WP Job Portal Missing Authorization Vulnerability Allowing Unauthenticated Arbitrary Email Sending
A vulnerability exists in the WP Job Portal WordPress plugin, specifically in versions through 2.2.6. The issue arises from a lack of proper capability checks in the sendEmailToJobSeeker() function, allowing unauthenticated users to send arbitrary emails with any content from the site's mail server.
Custom Related Posts WordPress Plugin Missing Authorization Vulnerability
A vulnerability exists in the Custom Related Posts plugin for WordPress, affecting all versions through 1.7.3. The issue arises from a lack of proper capability checks on three AJAX actions, allowing authenticated attackers with Subscriber-level access and above to unauthorized access and modification of data. Exploitation of this vulnerability enables these attackers to search private posts and manipulate related post relationships.
UniFi OS Improper Certificate Validation Vulnerability Allowing Man-in-the-Middle Attacks
A vulnerability exists in UniFi OS devices with Identity Enterprise configured, allowing improper certificate validation. This flaw could enable a malicious actor to perform a man-in-the-middle (MitM) attack during application updates.
MagicForm WordPress Plugin Missing Authorization Vulnerability
A vulnerability exists in the MagicForm plugin for WordPress, in all versions through 1.6.2, due to a lack of proper capability checks on the plugin's AJAX actions. This flaw allows authenticated attackers with Subscriber-level access and above to access and modify data by invoking these AJAX actions. Exploitation could lead to unauthorized deletion or viewing of logs, modification of forms, or changes to plugin settings.
MultiLoca WooCommerce Multi Locations Inventory Management SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress, affecting all versions through 4.1.11. The vulnerability arises from inadequate escaping of user-supplied data in the 'data-id' parameter, coupled with a lack of proper preparation in the SQL query. This flaw allows authenticated attackers with Subscriber-level access and above to inject additional SQL queries into existing ones, potentially leading to the extraction of sensitive information from the database.
The Plus Addons for Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in The Plus Addons for Elementor WordPress plugin, specifically in versions through 6.1.8. The issue arises in the Table Widget's 'searchable_label' parameter, where inadequate input sanitization and output escaping allow authenticated attackers with Contributor-level access or higher to inject arbitrary scripts. These scripts are executed when a user views the affected page.
Jupiter X Core WordPress Plugin Local File Inclusion Vulnerability Leading to Remote Code Execution
A vulnerability allowing local file inclusion (LFI) that can be exploited for remote code execution (RCE) has been identified in the Jupiter X Core plugin for WordPress. This issue affects all versions through 4.8.7 and arises in the get_svg() function. Authenticated attackers with Contributor-level access or higher can exploit this vulnerability by uploading an SVG file containing malicious content, which can then be executed on the server. This vulnerability could be used to bypass access controls, access sensitive information, or execute arbitrary code on the server.
Jupiter X Core Directory Traversal Vulnerability Allowing Arbitrary File Read
A directory traversal vulnerability has been identified in the Jupiter X Core plugin for WordPress, affecting all versions through 4.8.7. The vulnerability arises from the inline SVG feature, allowing authenticated attackers with Contributor-level access or higher to read arbitrary files on the server that may contain sensitive information.
Widget4Call WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Widget4Call WordPress plugin, affecting versions through 1.0.7. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
WordPress Email Newsletter Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress Email Newsletter plugin, affecting versions through 1.1. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
WP Finance WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WP Finance WordPress plugin, affecting versions through 1.3.6. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
WP Finance WordPress Plugin Stored Cross-Site Scripting Vulnerability via CSRF
A stored cross-site scripting vulnerability has been identified in the WP Finance WordPress plugin, affecting versions through 1.3.6. The issue arises from the plugin's lack of proper cross-site request forgery (CSRF) checks in certain areas, combined with inadequate data sanitization and escaping. This vulnerability could enable attackers to exploit logged-in administrators by injecting malicious scripts that are stored and executed later.
Responsive Iframe WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Responsive Iframe WordPress plugin, affecting versions through 1.2.0. The issue arises because the plugin fails to properly validate and escape certain block options before rendering them on pages or posts. This flaw enables users with a contributor role or higher to inject malicious scripts that are stored and executed later.
Directorist WordPress Plugin Information Exposure Vulnerability
A vulnerability allowing information exposure has been identified in the Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings, affecting all versions through 8.0.12. The vulnerability exists in the '/wp-json/directorist/v1/users/' endpoint, where unauthenticated attackers can access sensitive user data such as usernames, email addresses, names, and additional user information.
Dell PowerProtect DD Improper Access Control Vulnerability Allowing Privilege Escalation
A vulnerability has been identified in Dell PowerProtect DD versions prior to 8.3.0.0, 7.10.1.50, and 7.13.1.20. This vulnerability involves improper access control, which could be exploited by a local user with low privileges to escalate privileges on the system.
Dell PowerProtect DD Stack-Based Buffer Overflow Vulnerability in RestAPI Allowing Denial-of-Service
A stack-based buffer overflow vulnerability has been identified in the RestAPI of Dell PowerProtect DD. This vulnerability affects versions prior to 7.10.1.50 and 7.13.1.20. A high-privileged attacker with remote access could exploit this vulnerability, leading to a denial-of-service condition.
Dell PowerProtect DD Path Traversal Vulnerability Allowing Unauthorized File Overwrite
A path traversal vulnerability has been identified in Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20. This vulnerability allows a local user with low privileges to exploit the issue and gain unauthorized access to overwrite operating system files on the server's filesystem. Such exploitation could result in a denial-of-service condition.
RapidLoad WordPress Plugin Missing Authorization Vulnerability Allows Unauthorized Setting Resets
A vulnerability exists in the RapidLoad – Optimize Web Vitals Automatically plugin for WordPress, in all versions through 2.4.4. The issue arises from a missing capability check in the ajax_deactivate() function, allowing authenticated attackers with Subscriber-level access or higher to unauthorizedly modify data by resetting certain plugin settings.
aThemes Addons for Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the aThemes Addons for Elementor plugin for WordPress, affecting all versions through 1.0.12. The issue arises in the Image Accordion widget, where inadequate input sanitization and output escaping allow authenticated attackers with Contributor-level access or higher to inject arbitrary scripts. These scripts are executed when a user views the affected page.
WooCommerce Customers Manager Privilege Escalation Vulnerability
A privilege escalation vulnerability has been identified in the WooCommerce Customers Manager plugin for WordPress, affecting all versions through 31.3. The issue arises from a missing capability check in the ajax_assign_new_roles() function, allowing authenticated attackers with Subscriber-level access or higher to elevate their privileges to that of an administrator.
AnimateGL WordPress Plugin Missing Authorization Vulnerability in Settings Update
A vulnerability exists in the AnimateGL Animations for WordPress plugin, specifically in the Elementor and Gutenberg Blocks Animations versions through 1.4.23. The issue arises from a lack of proper capability checks on the 'agl_json' AJAX action, allowing unauthorized users to modify the plugin's settings. This vulnerability could be exploited by unauthenticated attackers to make unauthorized changes to the plugin's configuration.
WordPress Contact Forms by Cimatti Missing Authorization Vulnerability in File Download Function
A vulnerability exists in the WordPress Contact Forms by Cimatti plugin, affecting all versions through 1.9.4. The issue arises from a missing capability check in the 'accua_forms_download_submitted_file()' function, allowing unauthenticated users to download files submitted by other users via the contact forms.
ELEX WordPress HelpDesk and Customer Ticketing System Privilege Escalation Vulnerability
A privilege escalation vulnerability has been identified in the ELEX WordPress HelpDesk & Customer Ticketing System plugin, affecting all versions through 3.2.6. The vulnerability arises from a missing capability check on the 'eh_crm_agent_add_user' AJAX action, allowing authenticated attackers with Subscriber-level access and above to create new administrative user accounts.
Site Search 360 Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Site Search 360 plugin for WordPress, affecting all versions through 2.1.6. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'ss360-resultblock' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when a user accesses the affected page.
Dumb Drop Path Traversal Vulnerability Allowing Arbitrary File Overwrite and Root Access
A path traversal vulnerability has been identified in Dumb Drop, a file upload application. This vulnerability allows users with upload permissions to overwrite arbitrary system files. The issue arises because the application does not properly sanitize file names before saving them, enabling the manipulation of file paths. Since the application runs in a Docker container as root by default, there are no restrictions on which files can be overwritten. Exploiting this vulnerability could involve injecting malicious payloads into files executed on a schedule or triggered by specific service actions. Additionally, the absence of required authentication for the service could grant unprivileged users root access, or allow access to those with a PIN.
EasyVirt DCScope and CO2Scope SQL Injection Vulnerability
A vulnerability allowing SQL injection has been identified in EasyVirt DCScope versions through 8.6.0 and CO2Scope versions through 1.3.0. This vulnerability allows remote unauthenticated attackers to execute arbitrary SQL commands by manipulating the username or password parameters in the login API.
Macrozheng Mall-Tiny Null Pointer Dereference Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in Macrozheng Mall-Tiny version 1.0.1. The issue arises when an attacker sends null data through the resource creation interface, causing a null pointer dereference. This dereference occurs in all subsequent operations that require authentication, effectively launching a denial-of-service attack and causing a failure in service restart.
macrozheng Mall-Tiny Incorrect Access Control Vulnerability Allowing Unauthorized Super Administrator Access
A vulnerability has been identified in macrozheng mall-tiny version 1.0.1, related to incorrect access control. By default, the application imports users, and the test user is granted super administrator privileges.
macrozheng Mall-Tiny Incorrect Access Control Vulnerability in Logout Function
A vulnerability exists in macrozheng mall-tiny version 1.0.1, related to improper access control in the logout function. After a user logs out, their token remains active and can still retrieve information as if the user were logged in.
EasyVirt DCScope and CO2Scope Code Injection Vulnerability
A code injection vulnerability has been identified in EasyVirt DCScope versions through 8.6.0 and CO2Scope versions through 1.3.0. This vulnerability allows remote, unauthenticated attackers to execute arbitrary code by sending a request to the /api/license/sendlicense/ endpoint.
EasyVirt DCScope and CO2Scope SQL Injection Vulnerability Allowing User and Role Management
Multiple SQL injection vulnerabilities have been identified in EasyVirt DCScope versions through 8.6.0 and CO2Scope versions through 1.3.0. These vulnerabilities allow remote authenticated attackers with low privileges to manipulate user and role data through various API endpoints. Exploitation could lead to unauthorized user creation, modification, deletion, and role management.
EasyVirt DCScope and CO2Scope Weak JWT Secret Vulnerability Allowing Privilege Escalation
A vulnerability exists in EasyVirt DCScope versions through 8.6.0 and CO2Scope versions through 1.3.0, due to a weak JSON Web Token (JWT) secret. The HMAC secret for generating tokens is hardcoded as 'somerandomaccesstoken', which is predictable and allows remote attackers to create valid JWTs. This could be exploited for privilege escalation by impersonating users with elevated rights.
EasyVirt DCScope and CO2Scope Access Control Vulnerability Allowing Privilege Escalation
A vulnerability exists in EasyVirt DCScope versions through 8.6.0 and CO2Scope versions through 1.3.0, where multiple incorrect access control issues allow remote authenticated attackers with low privileges to manipulate user and group data. Exploitation of this vulnerability could lead to unauthorized privilege escalation.
EasyVirt DCScope and CO2Scope SQL Injection Vulnerability
Multiple SQL injection vulnerabilities have been identified in EasyVirt DCScope versions through 8.6.0 and CO2Scope versions through 1.3.0. These vulnerabilities allow remote authenticated attackers to execute arbitrary SQL commands by exploiting various parameters in specific API endpoints.
Code-Projects Job Recruitment SQL Injection Vulnerability
A SQL injection vulnerability has been identified in Code-Projects Job Recruitment version 1.0. The issue resides in the file '/parse/_call_job_search_ajax.php', where the 'n' argument can be manipulated to execute unauthorized SQL commands. This vulnerability can be exploited remotely, potentially allowing attackers to access sensitive information from the application's database.
Python urllib Square Bracket Handling Vulnerability in Domain Names
A vulnerability exists in the Python standard library's urllib module, specifically in the urlsplit and urlparse functions. These functions improperly accept domain names that include square brackets, which is not compliant with RFC 3986. Square brackets should only be used to delimit IPv6 and IPvFuture addresses in URLs. This flaw can lead to inconsistent URL parsing between Python's parser and other parsers that adhere to the specification.
CTFd Host Header Injection Vulnerability Allowing Phishing and Password Reset
A host header injection vulnerability has been identified in CTFd version 3.7.5. This vulnerability arises because the application does not properly validate or sanitize the host header in HTTP requests. As a result, an attacker can manipulate the host header, potentially leading to phishing attacks, unauthorized password resets, or cache poisoning. The vulnerability was confirmed through manual analysis and exploitation in a real-world environment.
ZZCMS SQL Injection Vulnerability in Front-End
A SQL injection vulnerability has been identified in the front-end of ZZCMS versions through 2023. This vulnerability can be exploited without authentication, potentially allowing attackers to gain unauthorized access to the database and extract sensitive information.
macrozheng Mall-Tiny Insecure Permissions Vulnerability Allowing JWT Forgery and Authentication Bypass
A vulnerability exists in macrozheng mall-tiny version 1.0.1 due to insecure permissions related to JSON Web Token (JWT) handling. The application hardcodes JWT signing keys, which remain static, and embeds user information directly into the JWT. This information is subsequently used for privilege management. As a result, it is possible to forge JWTs for any user, bypassing authentication mechanisms.
OpenPanel OS Command Injection Vulnerability in the Timezone Parameter
A command injection vulnerability has been identified in OpenPanel version 0.3.4. This vulnerability allows remote execution of operating system commands through the timezone parameter.
IBM Financial Transaction Manager for SWIFT Services Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in IBM Financial Transaction Manager for SWIFT Services for Multiplatforms, specifically in versions 3.2.4.0 through 3.2.4.1. This vulnerability allows authenticated users to inject arbitrary JavaScript into the Web UI, potentially altering functionality and leading to credential disclosure within a trusted session.
IBM Financial Transaction Manager for SWIFT Services Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in IBM Financial Transaction Manager for SWIFT Services for Multiplatforms, versions 3.2.4.0 through 3.2.4.1. This vulnerability allows authenticated users to inject arbitrary JavaScript into the Web UI, potentially altering functionality and leading to credential disclosure within a trusted session.
SSH Communication Security PrivX User Impersonation Vulnerability
A user impersonation vulnerability has been identified in SSH Communication Security PrivX versions 18.0 prior to 36.0. The issue arises from inadequate validation of public key signatures in native SSH connections through a proxy port. This flaw enables a PrivX user (account A) to impersonate another user (account B) and access SSH target hosts available to account B.
Slabiak Appointment Scheduler Host Header Poisoning Open Redirect Vulnerability
A host header poisoning vulnerability leading to open redirect has been identified in Slabiak Appointment Scheduler version 1.0.5. This vulnerability allows remote attackers to manipulate the host header of an HTTP request, redirecting users to malicious websites. Such actions could result in credential theft, malware distribution, or other harmful activities.
PMD and PMD Designer GPG Key Passphrase Exposure Vulnerability
A vulnerability exists in PMD and PMD Designer due to the release signing key passphrase being exposed in a JAR file published to Maven Central. While the private key has not been compromised, the availability of its passphrase raises concerns about potential compromise. This issue affects PMD versions 6.21.0 through 7.9.0 and PMD Designer version 7.0.0, with the latest PMD Eclipse Plugin release also impacted. As a mitigation, the compromised keys have been revoked, and future releases will use a new signing key.
O2OA Cross-Site Scripting Vulnerability in Meetings Settings
A cross-site scripting (XSS) vulnerability has been identified in O2OA version 9.1.3, specifically within the Meetings - Settings section. This vulnerability allows attackers to inject payloads that execute arbitrary web scripts and HTML, exploiting a storage-based XSS flaw.
OpenPanel Directory Traversal Vulnerability in File Manager Component
A directory traversal vulnerability has been identified in the File Manager component of OpenPanel version 0.3.4. This issue arises in the Copy and View functions, allowing attackers to manipulate HTTP requests and access restricted directories.
