CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 25, 2025

IBM Maximo Application Suite Monitor Component Web Application Source Code Disclosure Vulnerability

A vulnerability exists in the Monitor Component of IBM Maximo Application Suite versions 8.10, 8.11, and 9.0. This vulnerability involves the improper storage of source code on the web server, which could be exploited to facilitate further attacks against the system.

2.5
Jan 25, 2025

IBM Analytics Content Hub Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

A buffer overflow vulnerability has been identified in IBM Analytics Content Hub version 2.0. This issue arises from improper return length checking, which could allow a remote authenticated attacker to overflow a buffer, potentially leading to arbitrary code execution on the system or causing the server to crash.

1.9
Jan 25, 2025

IBM Analytics Content Hub Improper Error Handling Vulnerability Allowing Information Disclosure

An improper error handling vulnerability has been identified in IBM Analytics Content Hub version 2.0. This vulnerability could allow a remote attacker to obtain sensitive information from the application. The issue arises when detailed technical error messages are returned in the browser, potentially exposing information that could be used in further attacks against the system.

4.0
Jan 25, 2025

IBM Control Center User Enumeration Vulnerability

A user enumeration vulnerability has been identified in IBM Control Center versions 6.2.1 and 6.3.1. This vulnerability allows remote attackers to enumerate usernames by exploiting an observable discrepancy in login attempt responses.

2.9
Jan 25, 2025

IBM Control Center Directory Listing Vulnerability Allowing Information Exposure

A directory listing vulnerability has been identified in IBM Control Center versions 6.2.1 and 6.3.1. This issue could enable an authenticated user to access sensitive information exposed through the directory listing.

2.2
Jan 25, 2025

IBM Control Center Improper Error Handling Vulnerability Allowing Information Disclosure

A vulnerability exists in IBM Control Center versions 6.2.1 and 6.3.1, where improper error handling could lead to sensitive information disclosure. When a detailed technical error message is returned in the browser, it may expose information that could be leveraged in subsequent attacks against the system.

2.1
Jan 25, 2025

IBM Control Center Sensitive Information Disclosure Vulnerability

A vulnerability in IBM Control Center versions 6.2.1 and 6.3.1 allows remote attackers to access sensitive information through detailed technical error messages displayed in the browser. This information could be leveraged for further attacks against the system.

3.0
Jan 25, 2025

IBM Cloud Pak System Information Disclosure Vulnerability

An information disclosure vulnerability has been identified in IBM Cloud Pak System versions 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0. This vulnerability could expose sensitive system information that might be leveraged for further attacks against the system.

3.0
Jan 25, 2025

IBM Cloud Pak System Sensitive Information Disclosure Vulnerability

A vulnerability exists in IBM Cloud Pak System versions 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1. This vulnerability could lead to the unintentional disclosure of sensitive system information, which might be exploited to conduct further attacks against the system.

3.0
Jan 25, 2025

IBM Cloud Pak System Sensitive Information Disclosure Vulnerability

A vulnerability exists in IBM Cloud Pak System versions 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1. This vulnerability could allow the disclosure of sensitive information in HTTP responses, which could be leveraged for further attacks against the system.

3.0
Jan 25, 2025

IBM Cloud Pak System Sensitive Information Disclosure Vulnerability

A vulnerability exists in IBM Cloud Pak System versions 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1. This vulnerability could allow an authenticated user to access sensitive information from log files, which may aid in further attacks against the system.

2.2
Jan 25, 2025

IBM Cloud Pak System Sensitive Information Disclosure Vulnerability

A vulnerability in IBM Cloud Pak System versions 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could lead to the unintentional disclosure of sensitive information in HTTP responses. This information could potentially be exploited to conduct further attacks against the system.

3.0
Jan 25, 2025

IBM Cloud Pak System Directory Traversal Vulnerability Allowing Arbitrary File Access

A directory traversal vulnerability has been identified in IBM Cloud Pak System versions 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0. This vulnerability could allow remote attackers to traverse directories on the system by sending specially crafted URL requests that include 'dot dot' sequences. Exploitation of this vulnerability could lead to unauthorized access to arbitrary files on the system.

3.0
Jan 25, 2025

Import WP WordPress Plugin Sensitive Information Exposure Vulnerability

A vulnerability allowing sensitive information exposure exists in the Import WP – Export and Import CSV and XML files to WordPress plugin, affecting all versions through 2.14.5. The vulnerability arises from unprotected files in the uploads directory, enabling unauthenticated attackers to access sensitive data, such as user information and imported files, stored insecurely in the wp-content/uploads directory.

3.6
Jan 25, 2025

Divi Carousel Maker Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Divi Carousel Maker plugin for WordPress, specifically in versions through 2.0.4. The issue arises in the Image Carousel and Logo Carousel features, where inadequate input sanitization and output escaping allow authenticated attackers with contributor-level access or higher to inject arbitrary scripts. These scripts are executed when a user views the affected page.

2.4
Jan 25, 2025

Boom Fest WordPress Plugin Missing Authorization Vulnerability in Settings Update

A vulnerability exists in the Boom Fest WordPress plugin, all versions through 2.2.1, allowing unauthorized data modification. The issue arises from a lack of capability checks in the 'bf_admin_action' function. This flaw enables authenticated attackers with Subscriber-level access or higher to alter plugin settings that affect the website's appearance.

2.7
Jan 25, 2025

LearnPress WordPress LMS Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the LearnPress WordPress LMS Plugin, affecting all versions through 4.2.7.5. The issue arises from inadequate input sanitization and output escaping of lesson names, allowing authenticated attackers with LP Instructor-level access or higher to inject arbitrary scripts. These scripts are executed when users access the compromised pages.

4.8
Jan 25, 2025

Masy Gallery WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Masy Gallery plugin for WordPress, affecting all versions through 1.7. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'justified-gallery' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the compromised page.

2.3
Jan 25, 2025

ABC Notation WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the ABC Notation plugin for WordPress, affecting all versions through 6.1.3. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'abcjs' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.9
Jan 25, 2025

ABC Notation WordPress Plugin Path Traversal Vulnerability Allowing Arbitrary File Read

A path traversal vulnerability has been identified in the ABC Notation plugin for WordPress, affecting all versions through 6.1.3. The vulnerability arises in the 'file' attribute of the 'abcjs' shortcode, allowing authenticated attackers with Contributor-level access and above to read arbitrary files on the server. This could lead to the exposure of sensitive information.

3.0
Jan 25, 2025

Power Ups for Elementor Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Power Ups for Elementor plugin for WordPress, affecting all versions through 1.2.2. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'magic-button' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.

2.3
Jan 25, 2025

WP Contact Form7 Email Spam Blocker Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WP Contact Form7 Email Spam Blocker plugin for WordPress, affecting all versions through 1.0.0. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link.

2.0
Jan 25, 2025

WordPress SEO Friendly Accordion FAQ Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress SEO Friendly Accordion FAQ with AI assisted content generation plugin, affecting all versions through 2.2.1. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'noticefaq' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.

2.3
Jan 25, 2025

Bilingual Linker WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Bilingual Linker plugin for WordPress, affecting all versions through 2.4. This vulnerability arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts. These scripts are executed when users access the affected pages.

2.8
Jan 25, 2025

Youzify BuddyPress Plugin Missing Authorization Vulnerability in WordPress

A vulnerability exists in the Youzify BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress, in all versions through 1.3.3. The issue arises from a missing capability check in the save_addon_key_license() function, allowing authenticated attackers with Subscriber-level access and above to update arbitrary options with a valid license key. This unauthorized access could be exploited to manipulate license-related settings, potentially leading to unauthorized premium features or updates.

2.8
Jan 25, 2025

Youzify BuddyPress Plugin Missing Authorization Vulnerability in WordPress

A vulnerability exists in the Youzify - BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress, in all versions through 1.3.4. The issue arises from a missing capability check in the youzify_offer_banner() function, allowing authenticated attackers with Subscriber-level access and above to update arbitrary site options to a value of one.

2.8
Jan 25, 2025

Connections Business Directory WordPress Plugin Arbitrary Directory Deletion Vulnerability

A vulnerability allowing arbitrary directory deletion has been identified in the Connections Business Directory plugin for WordPress, affecting all versions through 10.4.66. The issue arises from inadequate file path validation when deleting a connections image directory. This flaw enables authenticated attackers with Administrator-level access and above to delete any folder on the server along with its contents.

1.5
Jan 25, 2025

GoHero Store Customizer for WooCommerce Missing Authorization Vulnerability in WordPress

A vulnerability exists in the GoHero Store Customizer for WooCommerce plugin for WordPress, all versions through 3.5. The issue arises from a missing capability check in the wooh_action_settings_save_frontend() function, allowing unauthorized users to modify certain plugin settings. This vulnerability could be exploited by unauthenticated attackers to make unauthorized changes to plugin data.

2.5
Jan 25, 2025

Etsy Importer Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Etsy Importer plugin for WordPress, affecting all versions through 1.4.2. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'product_link' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.3
Jan 25, 2025

WordPress Notice Board by Towkir Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Notice Board by Towkir plugin, affecting all versions through 3.1. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'notice-board' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.

2.6
Jan 25, 2025

Brodos.net Onlineshop Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the brodos.net Onlineshop Plugin for WordPress, affecting all versions through 2.0.2. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'BrodosCategory' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.3
Jan 25, 2025

WordPress Ask Me Anything (Anonymously) Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Ask Me Anything (Anonymously) plugin for WordPress, affecting all versions up to and including 1.6. The vulnerability arises from inadequate input sanitization and output escaping on user-supplied attributes, particularly within the 'askmeanythingpeople' shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the compromised page.

1.6
Jan 25, 2025

Youzify BuddyPress Community Plugin for WordPress Missing Authorization Vulnerability Allowing Review Deletion

A vulnerability exists in the Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress, in all versions through 1.3.2. The issue arises from a lack of proper capability checks in the delete_user_review() and delete_review() functions. This flaw enables authenticated users with Subscriber-level access and above to delete reviews written by other users, leading to unauthorized data loss.

2.1
Jan 25, 2025

WordPress Target Video Easy Publish Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Target Video Easy Publish plugin for WordPress, affecting all versions up to and including 3.8.3. The vulnerability arises from inadequate nonce validation in several functions, allowing unauthenticated attackers to inject malicious scripts through forged requests, provided they can persuade a site administrator to click a link or perform a similar action.

3.1
Jan 25, 2025

Broadstreet WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Broadstreet plugin for WordPress, affecting all versions through 1.51.0. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into pages. These scripts are executed when a user accesses the compromised page.

2.4
Jan 25, 2025

Custom Product Tabs Lite for WooCommerce PHP Object Injection Vulnerability

A PHP Object Injection vulnerability has been identified in the Custom Product Tabs Lite for WooCommerce plugin for WordPress, affecting all versions through 1.9.0. The vulnerability arises from the deserialization of untrusted input in the 'frs_woo_product_tabs' parameter. This issue allows authenticated attackers with Shop Manager-level access or higher to inject a PHP object. While the vulnerable software does not have a known object injection chain, such a chain could potentially be exploited if an additional plugin or theme on the target system facilitates it, possibly leading to arbitrary file deletion, sensitive data exposure, or code execution.

2.7
Jan 25, 2025

Flexmls IDX Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Flexmls IDX Plugin for WordPress, affecting all versions through 3.14.26. The issue arises from inadequate input sanitization and output escaping in the 'api_key' and 'api_secret' parameters. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.

2.4
Jan 25, 2025

ThemeREX Addons WordPress Plugin Local File Inclusion Vulnerability

A local file inclusion vulnerability has been identified in the ThemeREX Addons plugin for WordPress, affecting all versions through 2.33.0. The vulnerability arises in the 'trx_sc_reviews' shortcode, specifically through the 'type' attribute. This issue allows authenticated attackers with contributor-level or higher permissions to include and execute arbitrary files on the server. Exploitation of this vulnerability could lead to the execution of PHP code contained in the included files, potentially bypassing access controls, accessing sensitive data, or executing code in scenarios where PHP files can be uploaded and included.

3.5
Jan 25, 2025

Plethora Plugins Tabs + Accordions Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Plethora Plugins Tabs + Accordions for WordPress, affecting all versions through 1.1.8. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into pages. These scripts are executed when users access the compromised pages.

2.3
Jan 25, 2025

7-Zip Mark-of-the-Web Bypass Vulnerability

A vulnerability in 7-Zip allows remote attackers to bypass the Mark-of-the-Web (MOTW) protection mechanism on Windows installations. This issue arises in versions prior to 24.09 and requires user interaction, such as visiting a malicious page or opening a harmful file. The flaw occurs when extracting files from a crafted archive that bears the MOTW; 7-Zip fails to propagate the MOTW to the extracted files. Consequently, an attacker could exploit this vulnerability to execute arbitrary code in the context of the current user.

6.7
Jan 25, 2025

WordPress Linear Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Linear plugin for WordPress, affecting all versions up to and including 2.8.1. The issue arises from inadequate nonce validation on the 'linear-debug' page, allowing unauthenticated attackers to reset the plugin's cache by sending a forged request, provided they can persuade a site administrator to click a link or perform a similar action.

3.4
Jan 25, 2025

WPBookit WordPress Plugin Unauthenticated Arbitrary File Upload Vulnerability

A vulnerability allowing arbitrary file uploads has been identified in the WPBookit plugin for WordPress, affecting versions through 1.6.9. The issue arises from inadequate file type validation in the 'WPB_Profile_controller::handle_image_upload' function. This vulnerability enables unauthenticated attackers to upload arbitrary files to the affected site's server, potentially leading to remote code execution.

2.7
Jan 25, 2025

Nuxt Webpack and Rspack Builder Source Code Theft Vulnerability

A vulnerability in Nuxt's webpack and rspack builders allows for source code theft during development. This issue affects Nuxt versions 3.0.0 through 3.15.12 for webpack and versions 3.12.2 through 3.152 for rspack. The vulnerability arises because script requests are not restricted by the same origin policy, enabling attackers to inject malicious scripts that can be executed in the context of the victim's application. By exploiting this flaw, an attacker can access the application's source code through the injected script.

4.4
Jan 25, 2025

Nuxt Development Server CORS Vulnerability Allowing Code Access

A CORS vulnerability has been identified in Nuxt versions 3.8.1 prior to 3.15.3, allowing any website to send requests to the Nuxt development server and read the responses. This issue arises from default CORS settings that permit all origins to access the server. As a result, malicious websites could potentially steal source code from applications running on the affected Nuxt version.

5.0
Jan 24, 2025

Sungrow WiNet-S Heap-Based Buffer Overflow Vulnerability Allowing Denial-of-Service and Remote Code Execution

A heap-based buffer overflow vulnerability has been identified in the Sungrow WiNet-SV200.001.00.P027 firmware and earlier versions. This vulnerability arises from inadequate bounds checking of the MQTT message content, which could be exploited to cause a buffer overflow. Such an overflow could lead to a denial-of-service condition or allow for remote code execution on the affected device.

2.6
Jan 24, 2025

Sungrow WiNet-S Buffer Overflow Vulnerability in MQTT Message Decryption Allowing Denial-of-Service and Remote Code Execution

A stack-based buffer overflow vulnerability has been identified in the SunGrow WiNet-SV200.001.00.P027 firmware and earlier versions. The issue arises during the decryption of MQTT messages, where the code responsible for parsing certain TLV fields lacks adequate bounds checks. This vulnerability could be exploited to cause a denial-of-service condition or to execute arbitrary code remotely.

2.5
Jan 24, 2025

Sungrow WiNet-S Buffer Overflow Vulnerability in MQTT Message Parsing Allowing Denial-of-Service and Remote Code Execution

A stack-based buffer overflow vulnerability has been identified in Sungrow WiNet-S version WINET-SV200.001.00.P027 and earlier. This vulnerability arises from inadequate bounds checking of MQTT topics, which can be exploited when the device processes MQTT messages. The flaw could lead to a denial-of-service condition or allow for remote code execution on the affected device.

2.6
Jan 24, 2025

Sungrow WiNet-S Buffer Overflow Vulnerability Allowing Denial-of-Service and Remote Code Execution

A stack-based buffer overflow vulnerability has been identified in Sungrow WiNet-SV200.001.00.P027 and earlier versions. The issue arises when the firmware copies timestamps from MQTT messages without properly checking the buffer size, potentially leading to memory corruption.

2.6
Jan 24, 2025

Sungrow WiNet-S Hardcoded MQTT Credentials Vulnerability Allowing Arbitrary Command Execution on Inverters

A vulnerability exists in Sungrow WiNet-S version WINET-SV200.001.00.P027 and earlier, due to hardcoded MQTT credentials that enable attackers to send arbitrary commands to any connected inverter. Additionally, the absence of TLS for broker verification allows for impersonation of the MQTT broker, exposing communications to potential man-in-the-middle attacks at the TCP/IP level.

2.2
Jan 24, 2025

Sungrow WiNet-S Hardcoded Password Vulnerability Allowing Firmware Decryption

A vulnerability exists in Sungrow WiNet-S version WINET-SV200.001.00.P027 and earlier, due to a hardcoded password in the WiNet WebUI. This password can be used to decrypt firmware update files, which are otherwise encrypted. The presence of this hardcoded password could potentially be exploited to manipulate the firmware update process.

2.5