CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 19, 2025

Linux Kernel MPTCP Blackhole Timeout Vulnerability Leading to Null Pointer Dereference

A vulnerability in the Linux kernel's Multipath TCP (MPTCP) implementation has been addressed. The issue arose from the sysctl blackhole timeout feature, which improperly used the 'current' task's network namespace proxy. This approach could lead to inconsistencies and potential null pointer dereferences, particularly when the current task is exiting, as identified by syzbot. The vulnerability stemmed from relying on the 'net' structure through 'current', which can be NULL in certain situations.

5.7
Jan 19, 2025

Linux Kernel SCTP HMAC Algorithm Sysctl Vulnerability

A vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation has been addressed. The issue arose from the sysctl interface for the cookie HMAC algorithm, which improperly used the 'current' task's namespace proxy. This approach could lead to inconsistencies by mixing network namespace information from different tasks, and it also posed a risk of null pointer dereference errors when the current task was exiting. The vulnerability was identified by syzbot.

5.7
Jan 19, 2025

Linux Kernel SCTP Sysctl RTO Minimum/Maximum Vulnerability

A vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) sysctl interface for minimum and maximum retransmission timeouts has been addressed. The issue arose from using the 'net' structure via 'current', which can lead to inconsistencies and potential null pointer dereferences. This vulnerability was identified by syzbot while using the acct system call.

5.7
Jan 19, 2025

Linux Kernel SCTP Auth Enable Sysctl Vulnerability Leading to Null Pointer Dereference

A vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation has been addressed. The issue arose from the 'auth_enable' sysctl using 'current->nsproxy', which can lead to inconsistencies and potential null pointer dereferences. This vulnerability was identified by syzbot, particularly when the current task is exiting. The problem stems from accessing the 'net' structure through 'current', which is not advisable for various reasons, including the possibility of 'current->nsproxy' being NULL in certain situations.

5.7
Jan 19, 2025

Linux Kernel SCTP Sysctl UDP Port Vulnerability Leading to Null Pointer Dereference

A vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation has been addressed. The issue arose from the sysctl UDP port handling, which improperly used the 'current' context to access network namespace information. This approach could lead to inconsistencies and potential null pointer dereferences, particularly when the current task is exiting. The vulnerability was identified by syzbot while using the acct system call.

5.7
Jan 19, 2025

Linux Kernel SCTP Sysctl PLPMTUD Probe Interval Vulnerability

A vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation has been addressed. The issue arose from the sysctl parameter 'plpmtud_probe_interval', which improperly used 'current->nsproxy' to access the 'net' structure. This approach could lead to inconsistencies and potential null pointer dereferences, particularly when the current task is exiting. The vulnerability was identified by syzbot, highlighting the need for a more reliable method of obtaining network namespace information.

5.7
Jan 19, 2025

Linux Kernel RDS Subsystem Sysctl Vulnerability in TCP Buffer Management

A vulnerability in the Linux kernel's RDS subsystem has been addressed, specifically related to the sysctl parameters rds_tcp_rcvbuf and rds_tcp_sndbuf. The issue arose from using the 'current' task's network namespace, which can lead to inconsistencies and potential null pointer dereferences, particularly when the current task is exiting. This vulnerability was identified by syzbot.

5.3
Jan 19, 2025

Linux Kernel Cgroup/Cpuset Kernfs Active Break Removal Vulnerability

A vulnerability in the Linux kernel's cgroup cpuset management has been addressed. The issue arose from a warning related to the kernfs active protection mechanism. When the cpuset.cpus file was modified, the cgroup removal process could interfere, leading to a warning about active protection not being properly managed. This situation was caused by recent changes that made cpuset hotplug processing asynchronous, creating potential circular locking dependencies that could result in deadlocks. The vulnerability has been resolved by synchronizing cpuset hotplug processing, eliminating the need for manual intervention in the active protection, and preventing concurrent hotplug and cpuset operations from conflicting.

5.6
Jan 19, 2025

Linux Kernel Shadow Stack Register Handling Vulnerability

A vulnerability in the Linux kernel's x86 floating-point unit (FPU) handling of shadow stack registers has been addressed. The issue arises because the shadow stack, which is managed by XSAVE, contains supervisor state components that userspace cannot access. This limitation prevents the shadow stack registers from being available through the standard ptrace interface for XSAVE state. As a result, a new ptrace get/set interface was introduced, but the regset code did not properly verify if the shadow stack was active before allowing certain operations. This oversight could lead to warnings being triggered when the shadow stack is not enabled, causing potential disruptions in the kernel's operation.

6.0
Jan 19, 2025

Linux Kernel Block Subsystem Use-After-Free Vulnerability in BFQ I/O Scheduler

A use-after-free vulnerability has been identified in the Linux kernel's block subsystem, specifically within the BFQ I/O scheduler. This vulnerability, present in version 6.6, allows for a slab-use-after-free condition, where freed memory is accessed, potentially leading to memory corruption or arbitrary code execution. The issue arises in the 'bfq_init_rq' function when handling request queues, and can be triggered by certain I/O operations, such as those performed by the 'fsstress' workload.

5.6
Jan 19, 2025

Epic Games Launcher Untrusted Search Path Vulnerability in Installer Component

A vulnerability allowing for an untrusted search path has been identified in the Epic Games Launcher, affecting versions prior to 17.2.1. This issue arises in the library profapi.dll within the Installer component, where unknown code is manipulated. The vulnerability requires local access to exploit, and the complexity of the attack is considered high, making exploitation difficult.

4.2
Jan 19, 2025

Tenda AC15 Stack-Based Buffer Overflow Vulnerability in SetDevNetName Function

A critical stack-based buffer overflow vulnerability has been identified in the Tenda AC15 router, specifically in version 15.13.07.13. The issue arises in the function 'formSetDevNetName' within the file '/goform/SetDevNetName', where improper handling of the 'mac' argument allows for remote exploitation. This vulnerability has been publicly disclosed.

4.7
Jan 19, 2025

ZZCMS SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in ZZCMS 2023, specifically within the '/index.php' file. The issue arises from improper handling of the 'id' argument, allowing remote attackers to manipulate the input and execute malicious SQL queries. This vulnerability has been publicly disclosed and is available for exploitation.

4.7
Jan 19, 2025

WP All Import Pro Stored Cross-Site Scripting Vulnerability via SVG File Upload

A stored cross-site scripting vulnerability has been identified in the WP All Import Pro plugin for WordPress, in all versions through 4.9.7. This issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Administrator-level access to inject arbitrary web scripts into pages. The injected scripts execute when a user accesses the SVG file.

1.5
Jan 19, 2025

Code-Projects Fantasy-Cricket SQL Injection Vulnerability in authenticate.php

A critical SQL injection vulnerability has been identified in the Fantasy-Cricket project version 1.0. The issue resides in the authenticate.php file, where the uname parameter is manipulated to inject malicious SQL queries. This vulnerability can be exploited remotely, allowing attackers to gain unauthorized access to the database, leak sensitive information, tamper with data, and potentially disrupt services.

3.0
Jan 19, 2025

IBM Security ReaQta Unauthorized Actions Vulnerability Due to Untrusted Input

A vulnerability in IBM Security ReaQta version 3.12 could enable an authenticated user to execute unauthorized actions. This issue arises from the application's dependence on untrusted inputs.

1.7
Jan 19, 2025

IBM Sterling Connect:Direct Web Services Sensitive IP Address Disclosure Vulnerability

A vulnerability exists in IBM Sterling Connect:Direct Web Services versions 6.0, 6.1, 6.2, and 6.3, allowing authenticated users to access sensitive IP address information. This disclosure could be leveraged for further attacks against the system.

2.9
Jan 19, 2025

IBM Maximo Directory Traversal Vulnerability in MXAPIASSET API

A directory traversal vulnerability has been identified in the IBM Maximo MXAPIASSET API version 7.6.1.3. This vulnerability could allow a remote attacker to traverse directories on the system by sending a specially crafted URL request that includes "dot dot" sequences. Exploitation of this vulnerability could enable the attacker to view arbitrary files on the system.

1.7
Jan 19, 2025

Fantasy-Cricket SQL Injection Vulnerability in Update.php

A critical SQL injection vulnerability has been identified in the Fantasy-Cricket project version 1.0. The issue resides in the update.php file, where the uname parameter is manipulated to inject malicious SQL queries. This vulnerability can be exploited remotely, allowing attackers to gain unauthorized access to the database, leak sensitive information, tamper with data, and potentially disrupt services.

3.0
Jan 19, 2025

Codezips Gym Management System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Codezips Gym Management System version 1.0. The issue arises in the file '/dashboard/admin/health_status_entry.php', where the 'usrid' parameter can be manipulated to inject arbitrary SQL commands. This vulnerability can be exploited remotely, potentially leading to unauthorized database access, data manipulation, and system compromise.

4.7
Jan 19, 2025

Itsourcecode Farm Management System SQL Injection Vulnerability in add-pig.php

A critical SQL injection vulnerability has been identified in the Itsourcecode Farm Management System version 1.0. The issue resides in the add-pig.php file, where the pigno parameter is manipulated to inject malicious SQL queries. This vulnerability allows remote attackers to interfere with database operations, potentially leading to unauthorized data access, data manipulation, and in some cases, executing arbitrary code on the server.

3.2
Jan 18, 2025

IBM Safer Payments Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in IBM Safer Payments versions 6.4.0.00 through 6.4.2.07, 6.5.0.00 through 6.5.0.05, and 6.6.0.00 through 6.6.0.03. This vulnerability allows remote attackers to cause a denial of service by exploiting improper resource allocation, which can lead to buffer overflow and uncontrolled memory allocation errors. These issues can occur when remote systems send arbitrarily large requests to the Message Command Interface (MCI).

2.5
Jan 18, 2025

IBM Robotic Process Automation Privilege Escalation Vulnerability

A vulnerability in IBM Robotic Process Automation versions 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18, as well as in IBM Robotic Process Automation for Cloud Pak within the same version ranges, could enable an authenticated user to execute unauthorized actions with privileged user rights. This issue arises from inadequate validation of client-side security measures.

2.2
Jan 18, 2025

IBM Concert Sensitive Information Disclosure Vulnerability

A vulnerability in IBM Concert versions 1.0.0, 1.0.1, and 1.0.2 allows for sensitive information disclosure through specially crafted API calls. This issue arises from incompatible policies that expose sensitive data.

2.5
Jan 18, 2025

IBM ICP Voice Gateway XML Injection Vulnerability

A vulnerability allowing XML injection has been identified in multiple versions of IBM ICP - Voice Gateway, specifically in versions 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.7.1, and 1.0.8. This vulnerability could enable a remote attacker to send specially crafted XML statements, potentially allowing them to view or modify information within the XML document.

1.8
Jan 18, 2025

IBM Jazz for Service Management Information Disclosure Vulnerability

An information disclosure vulnerability has been identified in IBM Jazz for Service Management versions 1.1.3 through 1.1.3.22. The issue arises from inadequate access controls, which could enable a remote attacker to access sensitive information. This information could potentially be used to facilitate further attacks against the system.

2.5
Jan 18, 2025

CampCodes School Management Software Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in CampCodes School Management Software version 1.0. The issue arises in an unknown function of the file '/photo-gallery' within the Photo Gallery Page component. The vulnerability allows for remote exploitation by manipulating the 'Description' argument.

2.8
Jan 18, 2025

IBM Robotic Process Automation Privilege Escalation Vulnerability

A privilege escalation vulnerability has been identified in IBM Robotic Process Automation versions 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18. The issue arises because all files in the installation inherit the file permissions of the parent directory. This allows a non-privileged user to replace any executable for the nssm.exe service. When the service or server is restarted, the substituted executable is executed with administrator privileges.

1.9
Jan 18, 2025

IBM App Connect Enterprise Privileged User JMS Credentials Disclosure Vulnerability

A vulnerability exists in IBM App Connect Enterprise versions 12.0.1.0 through 12.0.7.0 and 13.0.1.0, which under certain configurations, could allow a privileged user to obtain Java Message Service (JMS) credentials. This issue is related to improper management of sensitive trace data.

2.7
Jan 18, 2025

Campcodes School Management Software Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Campcodes School Management Software version 1.0. The issue arises in the Create Id Card Page component, specifically within the file '/create-id-card'. The vulnerability is triggered by manipulating the 'ID Card Title' argument, allowing for the injection of malicious scripts. This issue can be exploited remotely.

3.3
Jan 18, 2025

TDuckCloud tduck-platform SQL Injection Vulnerability in QueryProThemeRequest Function

A critical SQL injection vulnerability has been identified in TDuckCloud tduck-platform versions prior to 4.0. The issue arises in the QueryProThemeRequest function within the file src/main/java/com/tduck/cloud/form/request/QueryProThemeRequest.java. The vulnerability allows remote attackers to manipulate the color parameter, leading to unauthorized access to sensitive information. This exploitation is made easier by the lack of proper input sanitization, allowing attackers to inject malicious SQL commands that could be executed by the application's database.

2.5
Jan 18, 2025

Hyland Alfresco Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Hyland Alfresco Community Edition and Alfresco Enterprise Edition versions through 6.2.2. The issue resides in the URL Handler component, specifically within the /share/s/ endpoint. This vulnerability allows remote attackers to inject malicious scripts that are executed in the context of the victim's browser, potentially compromising data integrity and confidentiality.

3.4
Jan 18, 2025

Adifier System WordPress Plugin Privilege Escalation Vulnerability Allowing Unauthenticated Password Reset

A vulnerability in the Adifier System plugin for WordPress, present in all versions through 3.1.7, allows for privilege escalation via account takeover. The issue arises because the plugin fails to properly validate a user's identity before updating account details, such as passwords, through the adifier_recover() function. This flaw enables unauthenticated attackers to reset passwords for any user, including administrators, and gain access to their accounts.

2.6
Jan 18, 2025

The Ultimate WordPress Toolkit WP Extended Unauthenticated SQL Injection Vulnerability

A time-based SQL injection vulnerability has been identified in The Ultimate WordPress Toolkit - WP Extended plugin, affecting all versions through 3.0.12. The vulnerability arises in the Login Attempts module, where insufficient escaping of user-supplied data allows unauthenticated attackers to inject additional SQL queries. This exploitation could lead to the extraction of sensitive information from the database.

4.4
Jan 18, 2025

Rate Star Review Vote WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings plugin for WordPress, affecting all versions through 1.6.3. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'videowhisper_reviews' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected page.

2.7
Jan 18, 2025

Buzz Club WordPress Theme Missing Authorization Vulnerability Allowing Arbitrary Option Updates

A vulnerability exists in the Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme, in all versions through 2.0.4. The issue arises from a missing capability check in the 'cmsmasters_hide_admin_notice' function, allowing authenticated attackers with Subscriber-level access and above to unauthorizedly modify option values. This could lead to a denial-of-service condition by causing errors on the site or by manipulating options related to user registration.

1.7
Jan 18, 2025

Crocoblock JetEngine Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the JetEngine plugin for WordPress, affecting all versions through 3.6.2. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts. These scripts are executed when users access the affected pages.

1.7
Jan 18, 2025

MarketKing WooCommerce Multivendor Marketplace Solution Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the MarketKing - Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress, affecting all versions through 1.9.80. The vulnerability arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Shop Manager-level permissions or higher to inject arbitrary scripts. These scripts are executed when a user accesses the affected page. This issue is present in multi-site installations where unfiltered_html has been disabled.

2.3
Jan 18, 2025

Easy Digital Downloads Stored Cross-Site Scripting Vulnerability in WordPress

A stored cross-site scripting vulnerability has been identified in the Easy Digital Downloads plugin for WordPress, specifically in the eCommerce Payments and Subscriptions made easy version 3.3.2 and prior. This vulnerability arises from inadequate input sanitization and output escaping, allowing authenticated attackers with administrator-level access to inject arbitrary web scripts into pages. The injected scripts are executed when a user accesses the compromised page. This issue is present only in multi-site installations where unfiltered_html has been disabled.

3.6
Jan 18, 2025

Utilities for MTG WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Utilities for MTG WordPress plugin, affecting all versions through 1.4.1. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'mtglink' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users view the affected page.

1.6
Jan 18, 2025

Webcamconsult WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Webcamconsult plugin for WordPress, affecting all versions through 1.5.0. The vulnerability arises from inadequate nonce validation, allowing unauthenticated attackers to manipulate settings and inject harmful scripts by tricking an administrator into clicking a link.

2.7
Jan 18, 2025

Video Share VOD WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Video Share VOD WordPress plugin, specifically in versions through 2.6.31. This issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'videowhisper_videos' shortcode. As a result, authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages, which will execute when a user accesses the compromised page.

2.3
Jan 18, 2025

MicroPayments WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the MicroPayments WordPress plugin, specifically in the 'videowhisper_content_upload_guest' shortcode. This issue affects all versions of the plugin up to and including 2.9.29. The vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes, allowing authenticated attackers with contributor-level access or higher to inject arbitrary web scripts. These scripts are executed when a user accesses the compromised page.

2.3
Jan 18, 2025

JSM Screenshot Machine Shortcode WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the JSM Screenshot Machine Shortcode plugin for WordPress, affecting all versions through 2.3.0. The vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'ssm' shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the compromised pages.

2.4
Jan 18, 2025

ShipWorks Connector for WooCommerce Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the ShipWorks Connector for WooCommerce plugin for WordPress, affecting all versions through 5.2.5. The vulnerability arises from inadequate nonce validation on the 'shipworks-wordpress' page, allowing unauthenticated attackers to manipulate service usernames and passwords. Exploitation requires tricking a site administrator into clicking a link that initiates the forged request.

2.7
Jan 18, 2025

WordPress Picture Gallery Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress, affecting all versions through 1.5.22. The issue arises from inadequate input sanitization and output escaping on user-supplied attributes, particularly within the videowhisper_picture_upload_guest shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected page.

3.3
Jan 18, 2025

WP Abstracts WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP Abstracts plugin for WordPress, affecting all versions through 2.7.2. The vulnerability arises from inadequate nonce validation in the 'wpabstracts_load_status()' and 'wpabstracts_delete_abstracts()' functions. This flaw allows unauthenticated attackers to inject malicious scripts via a forged request, provided they can persuade a site administrator to click a link or perform a similar action.

3.5
Jan 18, 2025

Podlove Podcast Publisher Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Podlove Podcast Publisher plugin for WordPress, affecting versions through 4.1.25. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with administrator-level access to inject arbitrary web scripts into pages. These scripts execute when users access the injected pages. This vulnerability is specific to multi-site installations where unfiltered_html has been disabled.

3.6
Jan 18, 2025

Ultimate Member WordPress Plugin Information Exposure Vulnerability

A vulnerability allowing information exposure has been identified in the Ultimate Member WordPress plugin, specifically in versions through 2.9.1. The issue arises from the plugin's error handling, which inadvertently reveals sensitive information through various error messages. This flaw enables unauthenticated attackers to extract data from the WordPress usermeta database table.

5.7
Jan 18, 2025

Ultimate Member WordPress Plugin Time-Based SQL Injection Vulnerability

A time-based SQL injection vulnerability has been identified in the Ultimate Member WordPress plugin, specifically in versions through 2.9.1. The vulnerability arises from inadequate escaping of user-supplied data in the search parameter, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to the extraction of sensitive information from the database.

6.5