CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
WordPress ReviewsTap Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress ReviewsTap plugin, specifically in versions through 1.1.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.
WordPress Subscription DNA Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Subscription DNA plugin, affecting versions through 2.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could lead to XSS vulnerabilities.
David de Boer Paytium WordPress Plugin Full Path Disclosure Vulnerability
A full path disclosure vulnerability has been identified in the David de Boer Paytium WordPress plugin, affecting versions through 4.4.11. This vulnerability allows the retrieval of embedded sensitive data by disclosing the full path of files or directories on the server.
Matthias Wagner Caching Compatible Cookie Opt-In and JavaScript Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress plugin 'Caching Compatible Cookie Opt-In and JavaScript' versions through 0.0.10. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that are executed when visitors access the affected site.
RSTheme Ultimate Coming Soon & Maintenance Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the RSTheme Ultimate Coming Soon & Maintenance plugin for WordPress, affecting versions through 1.0.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Ultimate Coming Soon and Maintenance Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Ultimate Coming Soon & Maintenance plugin, specifically in versions through 1.0.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Icegram WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Icegram WordPress plugin, affecting versions through 3.1.31. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
GitHub CodeQL Action Environment Variable Exposure Vulnerability
A vulnerability exists in the GitHub CodeQL Action that can lead to the unintentional exposure of environment variables, including sensitive secrets, in debug artifacts. This issue arises when specific conditions are met during a CodeQL analysis of Kotlin or Java repositories. The vulnerability is present in CodeQL Action versions prior to 3.28.3 and in CodeQL CLI versions 2.9.2 (May 2022) through 2.20.2. When a workflow fails before the CodeQL database is finalized, the debug artifact can include a valid GITHUB_TOKEN with repository access, creating a potential supply chain risk.
JoeyBling Bootplus Unrestricted File Upload Vulnerability
A critical vulnerability allowing unrestricted file uploads has been identified in JoeyBling Bootplus versions through commit 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. The issue arises in the SysFileController.java file, where the upload method fails to properly validate uploaded files. This flaw enables the upload of potentially malicious JSP and HTML files, which could be exploited to execute harmful scripts. The vulnerability can be exploited remotely.
One Identity Identity Manager Privilege Escalation Vulnerability
A privilege escalation vulnerability due to insecure direct object reference (IDOR) has been identified in One Identity Identity Manager versions 9.0.x prior to 9.2.1. This vulnerability affects only On-Premise installations, allowing unauthorized users to gain elevated privileges.
IBM i File-Level Local Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in IBM i versions 7.2, 7.3, 7.4, and 7.5. This vulnerability arises from an inadequate authority requirement, allowing a local non-privileged user to create a referential constraint using the privileges of another user who has been socially engineered to access the targeted file.
LibVNCServer Heap Buffer Overflow Vulnerability in HandleCursorShape Function Allowing Remote Code Execution
A heap buffer overflow vulnerability has been identified in LibVNCServer versions through 0.9.12. The issue arises in the HandleCursorShape() function within libvncclient/cursor.c, where an attacker can send cursor shapes with specially crafted dimensions. This exploitation can lead to remote code execution.
ASTEVAL Arbitrary Code Execution Vulnerability via Controlled Input
A vulnerability in the ASTEVAL library, prior to version 1.0.6, allows for arbitrary execution of Python code. This issue arises when an attacker can manipulate input to the library, bypassing its restrictions. The vulnerability is linked to how ASTEVAL handles 'FormattedValue' Abstract Syntax Tree (AST) nodes. Specifically, the 'on_formattedvalue' method utilizes the 'format' function of the str class, which can be exploited to access protected attributes by triggering an 'AttributeError' and capturing the exception to retrieve sensitive object properties.
Updatecli Private Maven Repository Credential Leak Vulnerability
A vulnerability in Updatecli prior to version 0.93.0 allows private Maven repository credentials to be leaked in application logs during unsuccessful retrieval operations. When an Updatecli pipeline includes a Maven source with basic authentication credentials, these credentials are exposed in the execution logs if the operation fails, such as due to incorrect coordinates or a non-existent artifact or version. In contrast, credentials are properly sanitized when the operation is successful.
Coolify Reflected Cross-Site Scripting Vulnerability in Tag Search
A reflected cross-site scripting vulnerability has been identified in Coolify versions prior to 4.0.0-beta.361. The issue arises on the tags page, where users can search for tags. If a search query returns no results, the entered query is reflected in an error modal, creating an opportunity for cross-site scripting.
Deepin Dde-Api-Proxy Privilege Escalation Vulnerability
A vulnerability in Deepin dde-api-proxy versions through 1.0.19 allows unprivileged users to access D-Bus services as root. The proxy, which runs as root, forwards messages from local users to legacy D-Bus methods in services that are unaware of the proxying. This miscommunication can lead to unauthorized access to methods that should be restricted to root users. In cases involving Polkit, this could result in the caller being treated as an administrator, further escalating privileges.
Coolify Private Key Enumeration Vulnerability Leading to Remote Command Execution
A critical vulnerability in Coolify versions prior to 4.0.0-beta.374 allows authenticated users to access private keys in plain text. If the exposed keys are used in conjunction with matching server configurations—specifically the IP or domain, port (likely 22), and user (root)—an attacker can execute arbitrary commands on the remote server.
Coolify Privilege Escalation Vulnerability Allowing Remote Code Execution
A critical privilege escalation vulnerability has been identified in Coolify versions prior to 4.0.0-beta.361. The issue arises from missing authorization, which allows any authenticated user to elevate their privileges or those of team members to any role, including owner. This capability extends to removing any team member, such as admins or owners. Exploitation of this vulnerability enables access to the 'Terminal' feature, where remote commands can be executed.
Coolify OAuth Configuration Exposure Vulnerability
A vulnerability in Coolify versions prior to 4.0.0-beta.361 allows any authenticated user to access and modify the global OAuth configuration. This flaw arises from a lack of proper authorization, which enables the exposure of sensitive information such as the 'client id' and 'client secret' for all custom OAuth providers used in the Coolify instance.
Coolify Private Key Hijacking and Remote Code Execution Vulnerability
A critical vulnerability allowing private key hijacking and remote code execution has been identified in Coolify versions prior to 4.0.0-beta.361. The issue arises from a lack of proper authorization, which enables any authenticated user to attach an existing private key to their own server. If the server's IP/domain, port (likely 22), and user (root) align with those of the victim's server, the attacker can exploit the 'Terminal' feature to execute arbitrary commands on the victim's server.
JoeyBling Bootplus SQL Injection Vulnerability in User Management List
A critical SQL injection vulnerability has been identified in JoeyBling Bootplus versions up to commit 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. The issue arises in the user management list administration page, specifically within the sorting functionality. The vulnerability can be exploited remotely, allowing attackers to manipulate the sort parameter to inject malicious SQL, potentially leading to unauthorized data access or manipulation.
JoeyBling Bootplus SQL Injection Vulnerability in Log Management Functionality
A critical SQL injection vulnerability has been identified in JoeyBling Bootplus versions prior to commit 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. The issue arises in the log management feature, specifically within the file '/admin/sys/log/list'. The vulnerability allows for remote exploitation by manipulating the 'logId' parameter, which is not properly sanitized before being processed. This oversight enables attackers to inject malicious SQL commands, potentially leading to unauthorized data access or manipulation.
WordPress Product Size Charts Plugin for WooCommerce Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the Product Size Charts Plugin for WooCommerce, affecting versions through 2.4.5. This vulnerability allows unprivileged users to perform actions that require higher privileges, due to a lack of proper authorization checks.
Coolify GitHub/GitLab OAuth Secrets Leak Vulnerability
A vulnerability in Coolify prior to version 4.0.0-beta.361 allows any authenticated user to access the details page of any GitHub or GitLab configuration on a Coolify instance, simply by knowing the UUID of the model. This flaw arises from a lack of proper authorization, leading to the unintentional exposure of sensitive information, including the 'client id', 'client secret', and 'webhook secret'.
Coolify Command Injection Vulnerability in Project Management
A command injection vulnerability has been identified in Coolify version 4.0.0-beta.358 and possibly earlier. This issue arises when creating or updating a project, as unescaped characters in the project name can disrupt the command structure and allow the execution of arbitrary shell commands on the host system. Exploitation of this vulnerability could lead to full system compromise, unauthorized modification or deletion of sensitive files, and privilege escalation, depending on the permissions of the executed commands.
JoeyBling Bootplus SQL Injection Vulnerability in Role Management
A critical SQL injection vulnerability has been identified in JoeyBling Bootplus versions up to commit 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. The issue arises in the role management feature, specifically within the '/admin/sys/role/list' endpoint. The vulnerability is caused by the application not properly validating the 'sort' parameter, allowing remote attackers to manipulate the input and execute arbitrary SQL commands. This exploitation could potentially lead to unauthorized data access or modification.
JoeyBling Bootplus SQL Injection Vulnerability in Admin Menu List
A critical SQL injection vulnerability has been identified in JoeyBling Bootplus versions prior to the commit 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. The issue arises in the admin/sys/menu/list endpoint, where the sort and order parameters are not properly sanitized, allowing attackers to inject malicious SQL commands. This vulnerability can be exploited remotely, with known technical details and a public proof-of-concept exploit available.
IBM Maximo Asset Management Unrestricted File Upload Vulnerability
A vulnerability allowing unrestricted file uploads has been identified in the IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API. This issue allows authenticated users with low privileges to upload restricted file types by simply adding a dot at the end of the file name, but only when Maximo is installed on a Windows operating system.
IBM Concert Software HTTP Strict Transport Security Vulnerability Allowing Information Disclosure
A vulnerability exists in IBM Concert Software versions 1.0.0 and 1.0.1, where the application fails to properly implement HTTP Strict Transport Security (HSTS). This oversight could enable remote attackers to intercept sensitive information through man-in-the-middle techniques.
IBM InfoSphere Information Server Information Disclosure Vulnerability
An information disclosure vulnerability exists in IBM InfoSphere Information Server version 11.7. This vulnerability could allow a remote user to access sensitive version information, potentially facilitating further attacks against the system.
IBM Planning Analytics Malicious File Upload Vulnerability
A malicious file upload vulnerability has been identified in IBM Planning Analytics versions 2.0 and 2.1. The issue arises because the application does not properly validate the content of files uploaded through the web interface. This lack of validation allows attackers to upload harmful executable files into the system, which can then be sent to victims to facilitate further attacks.
IBM Planning Analytics Malicious File Upload Vulnerability
A vulnerability allowing malicious file uploads has been identified in IBM Planning Analytics versions 2.0 and 2.1. This issue arises because the File Manager T1 process does not properly validate file types, enabling attackers to upload harmful executable files that could be sent to victims for further exploitation.
Jobify WordPress Theme Missing Authorization Vulnerability Allowing Unauthenticated Image Upload and AI Image Generation
A vulnerability exists in the Jobify - Job Board WordPress Theme, in all versions through 4.2.7, due to a lack of proper capability checks in the 'download_image_via_ai' and 'generate_image_via_ai' functions. This flaw enables unauthenticated attackers to send web requests from the application to upload image files and to generate AI images using the site's OpenAI key.
Coolify Command Injection Vulnerability Allowing Arbitrary Code Execution
A command injection vulnerability has been identified in Coolify, an open-source tool for managing servers, applications, and databases. This vulnerability exists in versions 4.0.0-beta.18 prior to 4.0.0-beta.253. It allows authenticated users to execute arbitrary code on the local Coolify container via SSH command injection. Exploitation of this vulnerability could lead to unauthorized access to sensitive data, including private keys and tokens of other users or teams. Additionally, it could allow attackers to modify the behavior of the application or its deployed services.
Telstra Smart Modem Gen 2 HTTP Response Header Injection Vulnerability
A vulnerability exists in the Telstra Smart Modem Gen 2, in versions prior to 20250115, allowing for HTTP response header injection. This issue arises from user-supplied data being improperly validated and sanitized before being inserted into the Content-Disposition header. The vulnerability can be exploited remotely without authentication, potentially enabling attackers to manipulate HTTP headers and inject malicious payloads into server responses.
Silicon Labs USBXpress Win 98SE Dev Kit DLL Hijacking Vulnerability Allowing Privilege Escalation and Arbitrary Code Execution
A DLL hijacking vulnerability has been identified in the USBXpress Win 98SE Dev Kit installer. This vulnerability arises from an uncontrolled search path in the installer, which can be exploited to escalate privileges and execute arbitrary code when the affected installer is run.
Silicon Labs USBXpress SDK DLL Hijacking Vulnerability Allowing Privilege Escalation and Arbitrary Code Execution
A DLL hijacking vulnerability has been identified in the USBXpress SDK installer, stemming from an uncontrolled search path. This vulnerability can lead to privilege escalation and arbitrary code execution when the affected installer is run.
Silicon Labs USBXpress 4 SDK Installer DLL Hijacking Vulnerability Allowing Privilege Escalation and Arbitrary Code Execution
A DLL hijacking vulnerability has been identified in the USBXpress 4 SDK installer, stemming from an uncontrolled search path. This vulnerability can lead to privilege escalation and arbitrary code execution when the affected installer is run.
Silicon Labs USBXpress Dev Kit Installer DLL Hijacking Vulnerability Allowing Privilege Escalation and Arbitrary Code Execution
A DLL hijacking vulnerability has been identified in the USBXpress Dev Kit installer, stemming from an uncontrolled search path. This vulnerability can lead to privilege escalation and arbitrary code execution when the affected installer is run.
Silicon Labs CP210x VCP Windows Installer DLL Hijacking Vulnerability Allowing Privilege Escalation and Arbitrary Code Execution
A DLL hijacking vulnerability has been identified in the CP210x VCP Windows installer. This vulnerability arises from an uncontrolled search path, which can lead to privilege escalation and arbitrary code execution when the affected installer is run.
Silicon Labs CP210 VCP Windows Installer DLL Hijacking Vulnerability Allowing Privilege Escalation and Arbitrary Code Execution
A DLL hijacking vulnerability has been identified in the CP210 VCP Windows 2000 installer. This vulnerability arises from an uncontrolled search path, which can lead to privilege escalation and arbitrary code execution when the affected installer is run.
Silicon Labs ToolStick Installer DLL Hijacking Vulnerability Allowing Privilege Escalation and Arbitrary Code Execution
A DLL hijacking vulnerability has been identified in the Silicon Labs ToolStick installer, stemming from an uncontrolled search path. This vulnerability can lead to privilege escalation and arbitrary code execution when the affected installer is run.
Silicon Labs Flash Programming Utility DLL Hijacking Vulnerability Allowing Privilege Escalation and Arbitrary Code Execution
A DLL hijacking vulnerability has been identified in the Flash Programming Utility installer, stemming from an uncontrolled search path. This vulnerability can lead to privilege escalation and arbitrary code execution when the affected installer is run.
Silicon Labs Configuration Wizard 2 DLL Hijacking Vulnerability Allowing Privilege Escalation and Arbitrary Code Execution
A DLL hijacking vulnerability has been identified in the Configuration Wizard 2 installer, stemming from an uncontrolled search path. This vulnerability can lead to privilege escalation and arbitrary code execution when the affected installer is run.
Silicon Labs 8-Bit IDE Installer DLL Hijacking Vulnerability Allowing Privilege Escalation and Arbitrary Code Execution
A DLL hijacking vulnerability has been identified in the Silicon Labs 8-bit IDE installer, stemming from an uncontrolled search path. This vulnerability can lead to privilege escalation and arbitrary code execution when the affected installer is run.
GPAC Heap-Based Buffer Overflow Vulnerability in MPEG-2 Transport Stream Processing
A heap-based buffer overflow vulnerability has been identified in GPAC version 0.8.0, specifically within the MP4Box application. The issue arises in the function 'gf_m2ts_process_pmt' located in 'media_tools/mpegts.c' at line 2163. This vulnerability can be exploited to cause a denial-of-service (DoS) condition by using a crafted MP4 file.
IBM Cognos Dashboards Dependency Confusion Vulnerability Allowing Unauthorized Actions
A dependency confusion vulnerability has been identified in IBM Cognos Dashboards versions 4.0.7 and 5.0.0 on Cloud Pak for Data. This vulnerability could enable a remote attacker to perform unauthorized actions.
Activity Plus Reloaded for BuddyPress Blind Server-Side Request Forgery Vulnerability
A Blind Server-Side Request Forgery (SSRF) vulnerability has been identified in the Activity Plus Reloaded for BuddyPress plugin for WordPress, affecting all versions through 1.1.1. This vulnerability allows authenticated attackers with Subscriber-level access and above to make web requests to arbitrary locations from the web application, potentially querying and modifying information from internal services.
RomethemeKit For Elementor Sensitive Information Exposure Vulnerability
A vulnerability allowing sensitive information exposure has been identified in the RomethemeKit For Elementor plugin for WordPress, affecting all versions through 1.5.2. The issue arises in the register_controls function within widgets/offcanvas-rometheme.php, where authenticated attackers with Contributor-level access or higher can access private, pending, and draft template data.
GPAC MP4Box Buffer Overflow Vulnerability in VVC PPS Parsing Function
A buffer overflow vulnerability has been identified in GPAC MP4Box version 2.1-DEV-rev574-g9d5bb184b. The issue arises in the 'gf_vvc_read_pps_bs_internal' function within 'media_tools/av_parsers.c', where improper validation of the 'num_exp_tile_columns' parameter can lead to memory corruption.
