CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
WordPress Scroll Top Advanced Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Scroll Top Advanced plugin, affecting versions through 2.5. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that are executed when users visit the site.
WordPress Shockingly Big IE6 Warning Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Shockingly Big IE6 Warning plugin, affecting versions through 1.6.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where a malicious actor could trick users with higher privileges into performing actions that could lead to the execution of harmful scripts.
MarvinLabs WP PT-Viewer Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the MarvinLabs WP PT-Viewer WordPress plugin, affecting versions through 2.0.2. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.
Capa Wp-Scribd-List Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Capa Wp-Scribd-List plugin for WordPress, specifically in versions through 1.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.
David Marcucci Password Protect WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Password Protect Plugin for WordPress, specifically in versions through 0.8.1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where a malicious actor could exploit the CSRF to inject harmful scripts that are then executed when a user accesses the affected content.
WordPress Easy EU Cookie Law Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Easy EU Cookie Law plugin, affecting versions through 1.3.3.1. This vulnerability arises from improper input handling during web page generation, allowing malicious actors to inject scripts that are executed when users visit the affected site.
WordPress AlTi5 AlT Report Plugin Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress AlTi5 AlT Report plugin, affecting versions through 1.12.0. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Mass Custom Fields Manager Cross-Site Request Forgery Vulnerability Allowing Reflected Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Mass Custom Fields Manager plugin, specifically in versions through 1.5. This vulnerability allows for Reflected Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could lead to XSS vulnerabilities.
Altima Lookbook Free for WooCommerce Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Altima Lookbook Free for WooCommerce plugin, affecting versions through 1.1.0. This vulnerability allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.
Wizcrew Technologies Go Social WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Wizcrew Technologies Go Social WordPress plugin, specifically in versions through 1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.
WordPress Marquee Style RSS News Ticker Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Marquee Style RSS News Ticker plugin, affecting versions through 3.2.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Smackcoders SendGrid for WordPress Missing Authorization Vulnerability
A broken access control vulnerability has been identified in the Smackcoders SendGrid for WordPress plugin, affecting versions through 1.4. This vulnerability arises from improperly configured access control security levels, which can be exploited to perform actions without the necessary authorization.
Matrix Media Repo Untrusted File Format Thumbnailing Vulnerability Invoking External Decoders
A vulnerability exists in Matrix Media Repo (MMR) versions prior to 1.3.8, allowing users to upload files that falsely claim to be SVG or JPEGXL. When these files are processed for thumbnails, they can trigger different decoders in ImageMagick. In certain ImageMagick installations, this could enable the execution of Ghostscript to decode the file, potentially leading to the execution of malicious code. Similarly, if MP4 thumbnailers are enabled, the issue could arise with the ffmpeg installation, exploiting the same flaw by uploading a file that pretends to be an MP4.
Zulip Server Information Disclosure Vulnerability
An information disclosure vulnerability has been identified in Zulip Server versions 7.0 and above. When a server hosts multiple organizations, an unauthenticated user can send a request to the '/api/v1/fetch_api_key' endpoint and determine if a specific email address is associated with a user account. This issue arises because the server responds with an 'invalid subdomain' error when an email address does not exist on the requested subdomain, but does on another, allowing the attacker to infer the existence of the account.
OpenObserve Improper Authorization Vulnerability in User Management Endpoint Allows Admin to Remove Root User
A vulnerability exists in OpenObserve versions prior to 0.14.1, specifically in the user management endpoint '/api/{org_id}/users/{email_id}'. This vulnerability allows an 'Admin' role user to remove a 'Root' user from the organization, violating the intended privilege hierarchy. The issue arises from insufficient role checks in the 'remove_user_from_org' function, which fails to prevent an 'Admin' user from targeting a 'Root' user for removal. Consequently, an 'Admin' user can eliminate critical 'Root' accounts, potentially gaining full control by removing the highest-privileged users.
Matrix Media Repo Denial-of-Service Vulnerability via Memory Exhaustion
A denial-of-service vulnerability has been identified in Matrix Media Repo (MMR) versions prior to 1.3.8. This issue arises because MMR can parse large amounts of JSON data returned from other servers, leading to excessive memory consumption and exhaustion of available resources. The vulnerability can be exploited during normal operation when MMR processes requests to resource owners that return substantial JSON payloads.
Matrix Media Repo Server-Side Request Forgery Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in Matrix Media Repo (MMR) versions prior to 1.3.8. This vulnerability allows MMR to access and serve content from internal networks under certain conditions. The issue arises when MMR is manipulated to make requests to internal resources, potentially exposing sensitive data or services.
Matrix Media Repo Unbounded Disk Consumption Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in Matrix Media Repo (MMR) versions prior to 1.3.5. This issue allows an unauthenticated attacker to cause excessive disk usage by inducing the application to download and store large quantities of remote media files. The vulnerability primarily affects instances using a file-backed storage option or those that self-host an S3 storage system, leading to a disk fill attack. When the disk becomes full, authenticated users are unable to upload new media, causing a denial-of-service condition. In cases where cloud-based S3 storage is used, the vulnerability could result in significant service charges instead of a denial-of-service impact.
Matrix Media Repo Unauthenticated Content Injection Vulnerability
A vulnerability in Matrix Media Repo (MMR) versions prior to 1.3.5 allows unauthenticated remote participants to download and cache media from a remote homeserver to the local media repository. This content can then be accessed from the local homeserver without authentication. As a result, unauthenticated remote adversaries can exploit this feature to introduce undesirable content into the media repository.
Mattermost Mobile Attachment Processing Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in Mattermost Mobile versions through 2.22.0. The issue arises because the application fails to properly manage posts with attachments that include fields not convertible to a string. This flaw allows an attacker to create and send such a post to a channel, causing the mobile application to crash.
Mattermost Denial-of-Service Vulnerability in Post Attachments
A denial-of-service vulnerability has been identified in Mattermost versions 10.2.x through 10.2.0, 9.11.x through 9.11.5, 10.0.x through 10.0.3, and 10.1.x through 10.1.3. The issue arises because the application fails to properly process posts with attachments that include fields unable to be converted to a string. This flaw allows an attacker to crash the web application by creating and sending such a post to a channel.
D-Link DIR-816 Access Control Vulnerability in formDMZ.cgi Allowing Unauthenticated DMZ Configuration
An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability allows unauthenticated attackers to manipulate the DMZ service settings of the device by sending a crafted POST request. The issue arises in the component formDMZ.cgi, where inadequate access controls permit unauthorized modifications to the DMZ configuration.
D-Link DIR-816 Access Control Vulnerability in URL Filter Component
An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability allows unauthenticated attackers to manipulate the device's URL filter settings by sending a crafted POST request.
D-Link DIR-816 Information Disclosure Vulnerability in d_status.asp Component
A vulnerability allowing information disclosure has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability arises in the d_status.asp component, where unauthenticated attackers can access sensitive information by sending a crafted POST request.
D-Link DIR-816 Access Control Vulnerability in AGL Service
An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the component form2alg.cgi. This vulnerability allows unauthenticated attackers to manipulate the AGL service of the device by sending a crafted POST request.
D-Link DIR-816 Access Control Vulnerability in form2PortriggerRule.cgi Allowing Unauthenticated Port Triggering
An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. The issue allows unauthenticated attackers to manipulate the port triggering settings of the device by sending a crafted POST request. This vulnerability arises from inadequate access controls in the affected CGI component, form2PortriggerRule.cgi.
D-Link DIR-816 Access Control Vulnerability in Repeater Service Configuration
An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability allows unauthenticated attackers to manipulate the 2.4G and 5G repeater services of the device by sending a crafted POST request.
D-Link DIR-816 Access Control Vulnerability in form2WlAc.cgi Allowing Unauthenticated MAC ACL Modification
An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability allows unauthenticated attackers to manipulate the MAC access control list for both the 2.4GHz and 5GHz bands. Exploitation is achieved by sending a crafted POST request to the device.
D-Link DIR-816 Access Control Vulnerability in form2Wan.cgi Allowing Unauthenticated WAN Service Modification
An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability allows unauthenticated attackers to manipulate the WAN service settings of the device by sending a crafted POST request. The issue arises in the form2Wan.cgi component, where inadequate access controls permit unauthorized modifications to critical network configurations.
D-Link DIR-816 Access Control Vulnerability in form2WlanBasicSetup.cgi Allowing Unauthenticated WLAN Service Modification
An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. The issue allows unauthenticated attackers to manipulate the 2.4G and 5G WLAN services of the device by sending a crafted POST request to the form2WlanBasicSetup.cgi component.
Gomatrixserverlib Server-Side Request Forgery Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in Gomatrixserverlib, a Go library for Matrix federation. This vulnerability allows the library to access and serve content from a private network, under certain conditions. The issue is present in versions of Gomatrixserverlib through dbd5f31fefc031633c3418165e4ef6d343e03999.
Mattermost Mobile Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Mattermost Mobile versions through 2.22.0. The issue arises because the application fails to properly validate the style of proto provided to an action's style in post.props.attachments. This lack of validation allows an attacker to crash the mobile application by sending crafted malicious input.
JFinalOA Cross-Site Scripting Vulnerability in Edit Page Interface
A cross-site scripting (XSS) vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the apply/getEditPage?view interface, where attackers can execute arbitrary web scripts or HTML by injecting a crafted payload.
JFinalOA SQL Injection Vulnerability in Workflow History Component
A SQL injection vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the workflow history component, specifically through the 'getWorkFlowHis?insid' parameter.
JFinalOA Cross-Site Scripting Vulnerability in Business Upload List Interface
A cross-site scripting (XSS) vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the getBusinessUploadListPage?busid interface, where attackers can execute arbitrary web scripts or HTML by injecting a crafted payload.
JFinalOA Cross-Site Scripting Vulnerability in openSelectManyUserPage?orgid Interface
A cross-site scripting (XSS) vulnerability has been identified in JFinalOA versions prior to v2025.01.01. The issue arises in the openSelectManyUserPage?orgid interface, where attackers can execute arbitrary web scripts or HTML by injecting a crafted payload.
JFinalOA Cross-Site Scripting Vulnerability in Draft List Interface
A cross-site scripting (XSS) vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the '/bumph/getDraftListPage?type' interface, where attackers can execute arbitrary web scripts or HTML by injecting a crafted payload.
JFinalOA Cross-Site Scripting Vulnerability in Edit Page Interface
A cross-site scripting (XSS) vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the common/getEditPage?view interface, where attackers can execute arbitrary web scripts or HTML by injecting a crafted payload.
JFinalOA SQL Injection Vulnerability
A SQL injection vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the apply/save#oaContractApply.id component, allowing attackers to manipulate SQL queries and potentially access or modify database information.
JFinalOA SQL Injection Vulnerability in borrowmoney Component
A SQL injection vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the borrowmoney component, specifically within the listData?applyUser endpoint.
JFinalOA SQL Injection Vulnerability in validRoleKey Component
A SQL injection vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the validRoleKey component, specifically through the sysRole.key parameter.
Indico Broken Object Level Authorization Vulnerability
A Broken Object Level Authorization (BOLA) vulnerability exists in Indico versions through 3.3.5. This vulnerability allows attackers to read information by sending a crafted POST request to the /api/principals endpoint. The issue arises because the application design intentionally permits all users to access certain information about other user accounts, without restricting this functionality to privileged roles such as event organizers.
IBM CICS TX Stored Cross-Site Scripting Vulnerability Allowing JavaScript Injection
A stored cross-site scripting vulnerability has been identified in IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1. This issue allows users to inject arbitrary JavaScript into the Web UI, potentially altering functionality and leading to credential disclosure within a trusted session.
Intel Neural Compressor Time-of-Check Time-of-Use Race Condition Vulnerability Allowing Information Disclosure
A time-of-check time-of-use race condition vulnerability has been identified in Intel Neural Compressor software versions prior to 3.0. This vulnerability may allow an authenticated user to disclose information through adjacent access.
FFmpeg Unchecked Return Value, Out-of-bounds Read Vulnerability in libavfilter af_pan Allowing Read of Sensitive Constants
A vulnerability in FFmpeg's libavfilter component, specifically in the af_pan audio filter, has been identified. This issue involves an unchecked return value leading to an out-of-bounds read, which allows the reading of sensitive constants within an executable. The vulnerability was present in FFmpeg version 7.1 and has been fixed in a subsequent update.
07FLYCMS Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in 07FLYCMS version 1.3.9. The issue arises in the admin/doAdminAction.php file, specifically when the 'act' parameter is set to 'editShop' and the 'shopId' parameter is included.
Campcodes Cybercafe Management System SQL Injection Vulnerability
A SQL injection vulnerability has been identified in Campcodes Cybercafe Management System version 1.0. The issue resides in the 'view-user-detail.php' file, where user input is not properly sanitized, allowing attackers to manipulate SQL queries and potentially access or modify database information.
07FLYCMS Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in 07FLYCMS version 1.3.9. The issue arises in the OaWorkReport edit page, allowing attackers to perform actions on behalf of users without their consent.
07FLYCMS Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in 07FLYCMS version 1.3.9. The issue resides in the OaTask editing component, accessible through the erp.07fly.net domain.
07FLYCMS Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in 07FLYCMS version 1.3.9. The issue resides in the OaWorkReport component, specifically within the add.html page. This vulnerability allows an attacker to trick a user into submitting a request that could potentially manipulate data or perform actions on their behalf.
