CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 23, 2025

Uyumsoft ERP Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in Uyumsoft ERP versions prior to Erp4.2109.166p45. This issue arises from improper neutralization of input during web page generation, allowing attackers to inject invalid characters that could be executed in the user's browser.

1.6
Jan 23, 2025

SonicWall SMA1000 Pre-Authentication Remote Command Execution Vulnerability

A pre-authentication vulnerability allowing deserialization of untrusted data has been identified in the SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC). Under specific conditions, this vulnerability could enable a remote, unauthenticated attacker to execute arbitrary operating system commands. The issue affects SMA1000 versions through 12.4.3-02804 (platform-hotfix).

4.9
Jan 23, 2025

SEO Blogger to WordPress Migration Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the SEO Blogger to WordPress Migration using 301 Redirection plugin, affecting all versions through 0.4.8. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the 'url' parameter. These scripts could be executed if a user is tricked into clicking a link.

2.7
Jan 23, 2025

Cliptakes WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Cliptakes WordPress plugin, affecting all versions through 1.3.4. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'cliptakes_input_email' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.

3.2
Jan 23, 2025

MDTF WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the MDTF – Meta Data and Taxonomies Filter plugin for WordPress, affecting all versions through 1.3.3.6. The vulnerability arises from inadequate input sanitization and output escaping on user-supplied attributes within the 'mdf_results_by_ajax' shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the injected pages.

3.6
Jan 23, 2025

Tainacan WordPress Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the Tainacan plugin for WordPress, affecting all versions through 0.21.12. The issue arises from inadequate escaping of user-supplied data in the 'collection_id' parameter, coupled with a lack of proper preparation in the SQL query. This vulnerability allows authenticated attackers with Subscriber-level access or higher to inject additional SQL commands into existing queries, potentially leading to the extraction of sensitive information from the database.

3.2
Jan 23, 2025

Broadcast Live Video WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Broadcast Live Video WordPress plugin, specifically in the Live Streaming: HTML5, WebRTC, HLS, RTSP, RTMP version 6.1.9 and prior. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'videowhisper_hls' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when a user accesses the affected page.

2.7
Jan 23, 2025

The Events Calendar WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the The Events Calendar WordPress plugin, affecting all versions through 6.9.0. The issue arises in the Event Calendar Link Widget, specifically through the html_tag attribute, due to inadequate input sanitization and output escaping. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary scripts into pages, which are executed when users access the affected pages.

4.8
Jan 23, 2025

M-Files Server Denial-of-Service Vulnerability via Database Driver Configuration Change

A denial-of-service vulnerability has been identified in M-Files Server versions prior to 25.1.14445.5 and before 24.8 LTS SR3. This issue arises from an unexpected server crash in the database driver, which can be triggered by a highly privileged attacker through configuration changes. The vulnerability requires a vault admin level user to add or modify External Object Types.

1.4
Jan 23, 2025

M-Files Server Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in M-Files Server versions prior to 25.1.14445.5. This vulnerability allows an unauthenticated user to exhaust system resources under certain conditions, leading to slowed processing times. While the denial-of-service condition causes noticeable delays, it does not completely disrupt the server's functionality.

2.0
Jan 23, 2025

M-Files Server Password Recovery Vulnerability for External Connectors

A vulnerability in M-Files Server versions prior to 25.1.14445.5 allows highly privileged users, such as system or vault administrators, to recover passwords for external connectors. This issue arises from an unsafe password recovery mechanism in the server's configuration. While these administrators can already set the passwords, the recovery feature is not typically allowed. It's important to note that this vulnerability does not impact other user types or administrative passwords. The issue is particularly relevant in environments with multiple admin users who have different levels of access to external systems connected via EOT connectors, which are not enabled by default.

1.4
Jan 23, 2025

Elastic Kibana Resource Exhaustion Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability has been identified in Elastic Kibana, specifically in versions through 7.17.22 and 8.0.0 up to and including 8.14.3. The issue arises from an allocation of resources without proper limits or throttling, allowing users with read access to certain features, such as Observability Metrics or Logs, to send specially crafted requests that can crash the application.

3.8
Jan 23, 2025

Product Table by WBW WordPress Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the Product Table by WBW plugin for WordPress, affecting all versions through 2.1.2. The vulnerability arises from inadequate escaping of user-supplied data in the 'additionalCondition' parameter, coupled with a lack of proper preparation of the SQL query. This flaw allows unauthenticated attackers to inject additional SQL commands into existing queries, potentially leading to the extraction of sensitive information from the database.

3.6
Jan 23, 2025

Prime Slider Addons for Elementor Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Prime Slider Addons for Elementor plugin, specifically in versions through 3.16.5. The issue arises in the 'blog' widget, where the 'social_link_title' parameter lacks proper input sanitization and output escaping. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access those pages.

3.1
Jan 23, 2025

BMLT Meeting Map WordPress Plugin Local File Inclusion Vulnerability

A local file inclusion vulnerability has been identified in the BMLT Meeting Map plugin for WordPress, affecting all versions through 2.6.0. The vulnerability arises in the 'bmlt_meeting_map' shortcode, allowing authenticated attackers with Contributor-level access and above to include and execute arbitrary files on the server. This exploitation could bypass access controls, access sensitive data, or execute PHP code from included files, particularly if the site allows uploading of images or other 'safe' file types.

3.7
Jan 23, 2025

Variation Swatches for WooCommerce Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Variation Swatches for WooCommerce plugin, affecting versions 1.0.8 prior to 1.3.2. The vulnerability arises from inadequate nonce verification in the plugin's settings reset feature. Specifically, the issue is located in the settings_init() function, which handles reset actions based on certain query parameters in the URL. The associated delete_settings() function fails to properly validate nonces, rendering the reset process insecure and open to unauthorized access.

5.1
Jan 23, 2025

ASUS Armoury Crate Arbitrary File Deletion Vulnerability

A vulnerability in file handling commands within certain versions of ASUS Armoury Crate may lead to arbitrary file deletion. This issue is addressed in the January 23, 2025, security update for the Armoury Crate app.

4.1
Jan 23, 2025

Apache Wicket Denial-of-Service Vulnerability via Request Handling

A denial-of-service vulnerability has been identified in Apache Wicket versions 7.0.0 through 7.18.*, 8.0.0-M1 through 8.16.*, 9.0.0-M1 through 9.18.*, and 10.0.0-M1 through 10.2.*. The issue arises in the core request handling, where an attacker can cause a memory leak by sending multiple requests to server resources, leading to a denial-of-service condition.

3.2
Jan 23, 2025

Elastic Fleet Server Sensitive Information Exposure in Logs Vulnerability

A vulnerability exists in Elastic Fleet Server versions 8.13.0 prior to 8.15.0, where Fleet policies containing sensitive information could be inadvertently logged at INFO and ERROR levels. The type of sensitive information exposed varies based on the enabled integrations.

3.6
Jan 23, 2025

Elastic Kibana Resource Exhaustion Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability has been identified in Elastic Kibana, specifically in versions through 7.17.22 and 8.0.0 up to 8.14.3. The issue arises from an allocation of resources without proper limits or throttling, which can lead to a crash. This vulnerability can be exploited by users with read access to the Observability Metrics or Logs features in Kibana, through a specially crafted request to the '/api/metrics/snapshot' endpoint.

3.8
Jan 23, 2025

phpMyAdmin Cross-Site Scripting Vulnerability in Check Tables Feature

A cross-site scripting (XSS) vulnerability exists in phpMyAdmin versions 5.x prior to 5.2.2. The issue arises in the 'Check tables' feature, where a crafted table or database name can be used to execute an XSS attack.

4.5
Jan 23, 2025

phpMyAdmin XSS Vulnerability in Insert Tab

A cross-site scripting (XSS) vulnerability has been identified in phpMyAdmin versions 5.x prior to 5.2.2. This issue occurs in the 'Insert' tab, allowing for the injection of malicious scripts.

4.5
Jan 23, 2025

Elastic Kibana Server-Side Request Forgery Vulnerability in Fleet Health Check API

A server-side request forgery (SSRF) vulnerability has been identified in Elastic Kibana. This issue allows users with read access to Fleet to exploit the /api/fleet/health_check API to send requests to internal endpoints. The vulnerability is limited to endpoints that are accessible over HTTPS and return JSON.

3.8
Jan 23, 2025

Kibana Exposure of Sensitive Information to Unauthorized Users Vulnerability

A vulnerability exists in Kibana versions 8.0.0 prior to 8.15.0, allowing users without access to Fleet to view Elastic Agent policies that may contain sensitive information. This exposure depends on the integrations enabled for the Elastic Agent and their respective versions.

3.8
Jan 23, 2025

Envoy Gateway Path Traversal Vulnerability Allowing Unauthorized Access to Admin Interface Commands

A path traversal vulnerability has been identified in Envoy Gateway versions prior to 1.2.6. This vulnerability allows users with access to the Kubernetes cluster to execute commands from the Envoy Admin interface on proxies managed by Envoy Gateway. The Admin interface can be used to terminate the Envoy process and extract the Envoy configuration, which may contain sensitive data.

2.6
Jan 23, 2025

HCL BigFix Patch Download Plug-ins Path Traversal Vulnerability

A path traversal vulnerability has been identified in the BigFix Patch Download Plug-ins. This issue allows operators to download files from a local repository that is susceptible to path traversal attacks.

1.6
Jan 23, 2025

HCL BigFix Patch Download Plug-ins Insecure Protocol Support Vulnerability Allowing Improper SSL Certificate Validation

A vulnerability exists in HCL BigFix Patch Download Plug-ins due to insecure protocol support, which can lead to improper handling of SSL certificate validation. This issue may allow for man-in-the-middle attacks or other security risks related to SSL/TLS communication.

1.6
Jan 23, 2025

HCL BigFix Patch Download Plug-ins XML Injection Vulnerability Allowing Denial-of-Service and Unauthorized Access

A vulnerability exists in the BigFix Patch Download Plug-ins due to an insecure package that allows for XML injection attacks. This flaw enables an attacker to inject malicious XML content, potentially leading to denial-of-service conditions and unauthorized access.

1.8
Jan 23, 2025

HCL BigFix Patch Download Plug-ins Insecure Support for File URI Scheme Vulnerability

A vulnerability exists in HCL BigFix Patch Download Plug-ins due to insecure handling of the file URI scheme. This flaw could enable a malicious operator to download files from arbitrary locations using the file:// URI scheme. The vulnerability affects several different versions and/or ranges of the BigFix Patch Download Plug-ins.

1.7
Jan 23, 2025

IBM Sterling B2B Integrator Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in IBM Sterling B2B Integrator Standard Edition versions 6.0.0.0 prior to 6.1.2.5 and 6.2.0.0. This vulnerability allows users to inject arbitrary JavaScript into the Web UI, potentially altering functionality and leading to credential disclosure within a trusted session.

2.6
Jan 23, 2025

IBM Sterling B2B Integrator Cross-Site Scripting Vulnerability

A cross-site scripting vulnerability has been identified in IBM Sterling B2B Integrator versions 6.0.0.0 through 6.1.2.5 and 6.2.0.0. This issue allows users to inject arbitrary JavaScript into the Web UI, potentially altering functionality and leading to credential disclosure within a trusted session.

2.6
Jan 23, 2025

HCL BigFix Patch Download Plug-ins Arbitrary File Download Vulnerability

An arbitrary file download vulnerability has been identified in HCL BigFix Patch Download Plug-ins, specifically in versions prior to 1177. This vulnerability allows a malicious operator to download files from any URL without proper validation or allowlist controls.

1.7
Jan 23, 2025

lunasvg Segmentation Fault Vulnerability in Version 3.0.0

A segmentation fault vulnerability has been identified in lunasvg version 3.0.0. This issue arises in the gray_record_cell component, where improper handling of memory access leads to a crash. The vulnerability can be reproduced using the 'svg2png' command-line tool included with lunasvg, which is available on GitHub.

2.8
Jan 23, 2025

lunasvg Segmentation Fault Vulnerability in Version 3.0.0

A segmentation fault vulnerability has been identified in lunasvg version 3.0.0. This issue arises in the 'composition_source_over' component, where improper handling of memory access leads to a crash. The vulnerability can be reproduced using the 'svg2png' tool included with lunasvg, by processing a specially crafted SVG file that triggers the segmentation violation.

2.9
Jan 23, 2025

lunasvg Memory Corruption Vulnerability in Version 3.0.0

A vulnerability has been identified in lunasvg version 3.0.0, related to improper memory allocation handling in the 'plutovg_surface_create' component. This flaw can lead to a memory corruption issue, specifically a segmentation fault, by allowing excessively large allocation requests that exceed the maximum supported size. The vulnerability can be reproduced using the 'svg2png' tool included with lunasvg, which is available on GitHub.

2.8
Jan 23, 2025

lunasvg Segmentation Fault Vulnerability in Version 3.0.0

A segmentation fault vulnerability has been identified in lunasvg version 3.0.0. This issue arises from a null pointer dereference in the 'plutovg_path_add_path' function, leading to a read memory access violation. The vulnerability can be triggered by specific SVG files that cause the application to attempt to read from an invalid memory address, resulting in a crash.

2.8
Jan 23, 2025

lunasvg Segmentation Fault Vulnerability in Component plutovg_blend

A segmentation fault vulnerability has been identified in lunasvg version 3.0.0. The issue arises in the component plutovg_blend, where improper handling of memory access leads to a crash. This vulnerability can be triggered by specific SVG input that causes the application to attempt to read from an invalid memory address, resulting in a segmentation violation.

2.9
Jan 23, 2025

lunasvg Segmentation Fault Vulnerability in Version 3.0.0

A segmentation fault vulnerability has been identified in lunasvg version 3.0.0. This issue arises in the 'blend_transformed_tiled_argb.isra.0' component, where improper handling of memory access leads to a crash. The vulnerability is triggered by a read memory access violation, specifically referencing an address in the zero page, which is not permissible.

2.8
Jan 23, 2025

HCL BigFix Patch Download Plug-ins Server-Side Request Forgery Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability has been identified in HCL BigFix Patch Download Plug-ins. This vulnerability allows the application to download files from an internally hosted server on localhost. It affects BigFix Patch and Patching Support, site versions prior to 1177.

1.8
Jan 22, 2025

Avada Builder Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Avada Builder plugin for WordPress, affecting all versions through 3.11.11. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's shortcodes. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users view the affected pages.

3.7
Jan 22, 2025

Code Astro Internet Banking System Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in Code Astro Internet Banking System version 2.0.0. This vulnerability allows remote attackers to execute arbitrary JavaScript on the admin account page. The issue arises from inadequate validation of user requests, enabling attackers to manipulate admin users into executing harmful scripts. Exploitation could lead to unauthorized changes in account settings or the theft of sensitive user information.

3.8
Jan 22, 2025

Silverpeas Core Stored Cross-Site Scripting Vulnerability in My Subscriptions Functionality

A stored cross-site scripting vulnerability has been identified in Silverpeas Core versions 6.3.1 through 6.4.1. This vulnerability allows remote attackers to execute arbitrary JavaScript by injecting malicious payloads into the Name field of subscriptions. The issue arises in the My Subscriptions feature, specifically within the Categorization option. When an admin user views the affected subscription, the injected script can execute, potentially leading to session hijacking, data theft, or unauthorized actions.

3.1
Jan 22, 2025

Google Chrome V8 Out-of-Bounds Memory Access Vulnerability Allowing Heap Corruption

A high-severity out-of-bounds memory access vulnerability has been identified in the V8 JavaScript engine of Google Chrome. This issue affects Chrome versions prior to 132.0.6834.110 and has been linked to improper handling of function arguments, which can lead to memory corruption. The vulnerability can be exploited by a remote attacker through a crafted HTML page, potentially causing heap corruption that could be exploited.

6.3
Jan 22, 2025

Google Chrome V8 Object Corruption Vulnerability Allowing Heap Corruption Exploitation

A high-severity object corruption vulnerability has been identified in the V8 JavaScript engine used by Google Chrome. This issue affects Chrome versions prior to 132.0.6834.110. The vulnerability allows remote attackers to potentially exploit heap corruption by delivering a crafted HTML page.

6.0
Jan 22, 2025

D-Link DSL-3782 Buffer Overflow Vulnerability in Parental Control Interface

A buffer overflow vulnerability has been identified in the D-Link DSL-3782 router, specifically in version 1.01. The issue arises within the Parental Control section of the router's web interface.

4.6
Jan 22, 2025

Traffic Alert and Collision Avoidance System II Spoofing Vulnerability

A vulnerability exists in the Traffic Alert and Collision Avoidance System (TCAS) II) standard, specifically in versions 7.1 and prior. This vulnerability allows for the transmission of radio frequency signals with fake location data to aircraft, creating the illusion of non-existent aircraft on radar displays. Such spoofing can disrupt normal operations by triggering false Resolution Advisories, which are critical for maintaining safe distances between aircraft.

1.5
Jan 22, 2025

TCAS II Impersonation Vulnerability Leading to Denial-of-Service

A vulnerability exists in TCAS II systems with transponders compliant with MOPS prior to RTCA DO-181F. An attacker can impersonate a ground station and send a Comm-A Identity Request, which can lower the Sensitivity Level Control (SLC) and disable the Resolution Advisory (RA). This manipulation creates a denial-of-service condition by disrupting normal collision avoidance operations.

1.6
Jan 22, 2025

Cilium Hubble UI Cross-Origin Resource Sharing Misconfiguration Vulnerability

A vulnerability exists in Cilium Hubble UI deployments due to an insecure default 'Access-Control-Allow-Origin' header. This issue affects Cilium versions 1.14.0 through 1.14.7, 1.15.0 through 1.15.11, and 1.16.0 through 1.16.4. The misconfiguration could lead to unauthorized exposure of sensitive Kubernetes cluster data, including node names, IP addresses, and metadata about workloads and networking configurations. Exploitation requires a user to visit a malicious webpage.

4.3
Jan 22, 2025

Cloudflare WARP Improper Privilege Management Vulnerability on Windows Allowing File Manipulation

A vulnerability in Cloudflare WARP for Windows, prior to version 2024.12.492.0, involves improper privilege management that enables file manipulation. Users with low system privileges can create symlinks in the C:\ProgramData\Cloudflare\warp-diag-partials directory. When the 'Reset all settings' option is activated, the WARP service deletes the files linked by the symlinks. Since the WARP service runs with system privileges, this could result in the unintentional deletion of files owned by the System user.

3.7
Jan 22, 2025

Thermo Fisher Scientific Xcalibur and Foundation Local Privilege Escalation Vulnerability

A local privilege escalation vulnerability has been identified in Thermo Fisher Scientific Xcalibur versions prior to 4.7 SP1 and in Thermo Foundation Instrument Control Software (ICSW) versions prior to 3.1 SP10. This vulnerability arises from improper access control permissions on Windows systems, allowing unauthorized users to escalate privileges.

1.2