CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Betheme WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Betheme plugin for WordPress, affecting all versions through 27.6.1. The issue arises from inadequate input sanitization and output escaping on user-supplied attributes, allowing authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages. These scripts would execute when a user views the affected page.
Elastic Kibana Resource Exhaustion Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in Elastic Kibana versions prior to 7.17.23 and 8.14.2. The issue arises from an unlimited allocation of resources in response to certain requests, specifically to the '/api/log_entries/summary' endpoint. This vulnerability can be exploited by users with read access to the Observability-Logs feature, potentially leading to a crash of the Kibana instance.
Elasticsearch Resource Exhaustion Vulnerability Leading to Denial-of-Service
A resource allocation vulnerability without proper limits or throttling has been identified in Elasticsearch. This issue is present in versions prior to 7.17.21 and prior to 8.13.3. When exploited through a specially crafted query using an SQL function, the vulnerability can cause an OutOfMemoryError exception, leading to a crash.
Elastic Defend Improper Handling of Alternate Encoding Leading to Crash Vulnerability
A vulnerability exists in Elastic Defend on Windows systems, where improper handling of multibyte character encoding can lead to an uncaught exception. This exception causes Elastic Defend to crash, preventing the application from quarantining files or terminating processes as needed. The issue affects versions of Elastic Defend prior to 8.13.3.
wp-greet WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the wp-greet plugin for WordPress, affecting all versions through 6.2. The vulnerability arises from inadequate nonce validation, allowing unauthenticated attackers to manipulate settings and inject malicious scripts by tricking an administrator into clicking a link.
FireCask Like & Share Button Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the FireCask Like & Share Button plugin for WordPress, affecting all versions through 1.2. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts. These scripts are executed when users access the affected pages.
Apache CXF Denial-of-Service Vulnerability in Temporary File Handling
A denial-of-service vulnerability has been identified in Apache CXF versions prior to 3.5.10, 3.6.0 prior to 3.6.5, and 4.0.0 prior to 4.0.6. In certain edge cases, instances of CachedOutputStream may not be properly closed. If these instances are backed by temporary files, they can accumulate and potentially fill up the file system, affecting both server and client environments.
NEC WebSAM DeploymentManager X-Frame-Options Vulnerability Allowing Configuration Reset or Product Restart
A vulnerability in NEC Corporation's WebSAM DeploymentManager versions 6.0 through 6.80 allows an attacker to reset configurations or restart products over the network. This issue arises because the X-FRAME-OPTIONS header is not specified, potentially enabling clickjacking attacks.
WordPress Link Library Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Link Library plugin for WordPress, affecting all versions through 7.7.2. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the 'searchll' parameter. These injected scripts could be executed if a user is tricked into clicking a link.
Atarim WordPress Plugin Missing Authorization Vulnerability Allows Unauthenticated Data Deletion
A vulnerability in the Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress, in versions through 4.0.9, allows unauthenticated users to delete project pages and files. This issue arises from a missing capability check in the 'wpf_delete_file' functions, enabling unauthorized data deletion.
WP-BibTeX Plugin for WordPress Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP-BibTeX plugin for WordPress, affecting all versions through 3.0.1. The vulnerability arises from inadequate nonce validation in the wp_bibtex_option_page() function, allowing unauthenticated attackers to inject malicious scripts via a forged request, provided they can persuade a site administrator to click a link or perform a similar action.
JetElements WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the JetElements plugin for WordPress, affecting all versions through 2.7.2.1. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in several widgets. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.
String Locator WordPress Plugin Unauthenticated PHP Object Injection Vulnerability
A PHP Object Injection vulnerability has been identified in the String Locator plugin for WordPress, affecting all versions through 2.6.6. The issue arises from the deserialization of untrusted input in the 'recursive_unserialize_replace' function, allowing unauthenticated attackers to inject PHP objects. While the vulnerable plugin version does not have a known payload execution chain, such a chain could potentially be exploited if an additional vulnerable plugin or theme is installed, leading to arbitrary file deletion, sensitive data exposure, or code execution. The vulnerability is triggered when an administrator performs a search and replace action.
Brave Browser Incorrectly Displays Download Origin on macOS
A vulnerability exists in Brave Browser for desktop, specifically in versions 1.70.x to 1.73.x, where the download origin is misrepresented in the file selector dialog. Instead of showing the actual source of the downloaded file, the browser displays the referrer header value. This issue can be exploited by combining it with an open redirect vulnerability on a trusted site, allowing a malicious site to initiate a download that appears to come from a reputable source.
1003 Mortgage Application WordPress Plugin Full Path Disclosure Vulnerability
A full path disclosure vulnerability has been identified in the 1003 Mortgage Application plugin for WordPress, affecting all versions through 1.87. The issue arises because the file '/inc/class/fnm/export.php' is publicly accessible with error logging enabled. This configuration allows unauthenticated attackers to retrieve the full path of the web application, potentially aiding in the exploitation of other vulnerabilities. However, the disclosed information is not harmful on its own and requires the presence of another vulnerability to cause damage to the affected website.
IBM UrbanCode Deploy Sensitive Information Logging Vulnerability
A vulnerability exists in IBM UrbanCode Deploy (UCD) versions 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13. The issue involves the improper logging of potentially sensitive information in a manner that could be accessed by a local user with permission to read HTTP request logs.
Vim Segmentation Fault Vulnerability in Silent Ex Mode
A segmentation fault vulnerability has been identified in Vim versions prior to 9.1.1043. In silent Ex mode, Vim operates without displaying a screen, but it is still possible to trigger the scrolling function of a GUI version by sending binary characters. This can cause a segmentation fault by accessing the ScreenLines pointer, which has not been allocated in silent mode. The vulnerability requires the user to intentionally feed binary data to Vim in Ex mode.
OpenVPN Easy-RSA Weak Encryption Vulnerability Allowing CA Key Brute Force
A vulnerability exists in OpenVPN Easy-RSA versions 3.0.5 through 3.1.7, where a weak encryption algorithm allows local attackers to more easily brute-force the private Certificate Authority (CA) key. This issue arises when the CA key is created using OpenSSL 3.
Cosmos Home Server User Existence Verification Vulnerability
A vulnerability in Cosmos Home Server versions prior to 0.17.7 allows for user existence verification through error code analysis during the login process. This issue arises because the application does not properly obscure whether a username is registered in the database, creating a potential vector for user enumeration. Although the vulnerability's impact is considered low due to rate limiting that hinders scanning attempts, it still poses a risk by allowing targeted checks for user accounts, except for the 'admin' username, which is explicitly blocked.
IBM DevOps and UrbanCode Velocity Local Storage Vulnerability Allowing Cross-User Access
A vulnerability exists in IBM DevOps Velocity version 5.0.0 and IBM UrbanCode Velocity versions 4.0.0 through 4.0.25, allowing web pages to be stored locally and accessed by other users on the same system. This issue arises from improper handling of local storage, which can lead to unauthorized access to stored data.
IBM UrbanCode Velocity and DevOps Velocity CORS Vulnerability Allowing Privileged Actions and Information Retrieval
A Cross-Origin Resource Sharing (CORS) vulnerability has been identified in IBM DevOps Velocity version 5.0.0 and IBM UrbanCode Velocity versions 4.0.0 through 4.0.15. The vulnerability arises because the CORS policy does not restrict domain names to trusted sources, potentially allowing attackers to perform privileged actions and access sensitive information.
IBM DevOps and UrbanCode Velocity Cryptographic Vulnerability Allowing Decryption of Sensitive Information
A vulnerability exists in IBM DevOps Velocity version 5.0.0 and IBM UrbanCode Velocity versions 4.0.0 through 4.0.15, due to the use of weaker than expected cryptographic algorithms. This flaw could enable an attacker to decrypt highly sensitive information.
Fedify Webfinger Mechanism Vulnerability Leading to Denial-of-Service and Blind Server-Side Request Forgery
A vulnerability in the Fedify TypeScript library allows manipulation of the Webfinger mechanism to send GET requests to any internal resource on any host, port, or URL, bypassing existing security measures. This exploitation forces the victim's server into an infinite loop, causing a denial-of-service condition. Additionally, the vulnerability can be exploited to perform a blind server-side request forgery attack. The issue arises in versions 1.0.13, 1.1.10, 1.2.10, and 1.3.3, and has been patched in 1.0.14, 1.1.11, 1.2.11, and 1.3.4.
CodeIgniter 4 Header Validation Vulnerability Leading to Potential Denial-of-Service
A vulnerability exists in CodeIgniter 4 versions prior to 4.5.8 due to improper validation of HTTP header names and values. This flaw allows attackers to create malformed headers using the Header class, which can disrupt application functionality by causing errors or generating invalid HTTP requests. Such malformed requests may be interpreted as malicious by a remote service's web application firewall, potentially leading to a denial-of-service scenario by blocking further communication with the application.
Vite Cross-Site WebSocket Hijacking and CORS Vulnerability
A vulnerability in Vite, a frontend tooling framework for JavaScript, allows any website to send requests to the Vite development server and read the responses. This issue arises from default Cross-Origin Resource Sharing (CORS) settings that permit all origins and a lack of validation on the Origin header for WebSocket connections. The vulnerability affects Vite versions 6.0.0 through 6.0.8, 5.0.0 through 5.4.11, and 4.0.0 through 4.5.5. It is important to note that this vulnerability can be exploited even when the Vite development server is running locally and not exposed to the network.
WeGIA SQL Injection Vulnerability in adicionar_raca.php Endpoint
A SQL injection vulnerability has been identified in the WeGIA application, specifically within the adicionar_raca.php endpoint. This flaw allows attackers to execute arbitrary SQL commands, leading to unauthorized access to sensitive information. Exploitation of this vulnerability enabled a complete dump of the application's database, underscoring its severity. The issue arises from inadequate validation and sanitization of the 'raca' parameter, allowing direct manipulation of SQL queries. This vulnerability affects WeGIA versions prior to 3.2.9 and has been patched in version 3.2.10.
WeGIA SQL Injection Vulnerability in adicionar_cor.php Endpoint Allows Database Access
A SQL injection vulnerability has been identified in the WeGIA application, specifically within the adicionar_cor.php endpoint. This flaw allows attackers to execute arbitrary SQL commands, leading to unauthorized access to sensitive information. Exploitation of this vulnerability enabled a complete dump of the application's database, underscoring its severity. The issue arises because the application fails to properly validate or sanitize the 'cor' parameter, allowing direct manipulation of SQL queries. This vulnerability affects WeGIA versions prior to 3.2.9.
WeGIA SQL Injection Vulnerability in adicionar_especie.php Endpoint
A SQL injection vulnerability has been identified in the WeGIA application, specifically within the adicionar_especie.php endpoint. This flaw allows attackers to execute arbitrary SQL commands, leading to unauthorized access to sensitive information. Exploitation of this vulnerability enabled a complete dump of the application's database, underscoring its severity. The issue arises because the application fails to properly validate or sanitize the 'especie' parameter, allowing direct manipulation of SQL queries. This vulnerability affects WeGIA versions prior to 3.2.9 and has been patched in version 3.2.10.
PwnDoc Cross-Site Request Forgery Vulnerability Allowing Unauthorized Actions
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PwnDoc, a penetration test report generator. The issue arises from the lack of CSRF protection, enabling attackers to send requests on behalf of logged-in users. This vulnerability affects both GET and POST requests, due to the absence of the SameSite attribute on cookies and the ability to refresh cookies. Exploitation can lead to unauthorized actions, such as creating admin accounts.
Gitoxide gix-worktree-state World-Writable File Permission Vulnerability
A vulnerability in Gitoxide's gix-worktree-state component, prior to version 0.17.0, allows executable files to be checked out with world-writable permissions. This issue arises because one of the methods used to set file permissions does not respect the umask, leading to insecure permissions in certain scenarios. The vulnerability is present on Unix-like systems, where it can expose files to unauthorized access and modification.
PhpSpreadsheet Cross-Site Scripting Vulnerability
A Cross-Site Scripting (XSS) vulnerability has been identified in PhpSpreadsheet versions 3.0.0 prior to 3.8.0, 1.29.8 prior to 2.1.7, and 2.2.0 prior to 2.3.6. The vulnerability arises in the HTML generation process from XLSX files, where sheet titles are not properly sanitized before being displayed. This flaw allows attackers to inject and execute JavaScript code by crafting an XLSX file with a malicious title.
Sunshine Game Stream Host Pairing Protocol Vulnerability Allowing MITM Attack and Denial-of-Service
A vulnerability in Sunshine, a self-hosted game stream host for Moonlight, has been identified in versions through 0.23.1. The issue arises because the pairing protocol does not properly validate the order of requests, leaving it susceptible to a man-in-the-middle (MITM) attack. This flaw could enable an unauthenticated attacker to hijack a legitimate pairing attempt and pair a client maliciously. Additionally, this vulnerability can be exploited by a remote attacker to crash the Sunshine application.
IBM Security Verify Access Password Change Vulnerability for Expired Users
A vulnerability exists in IBM Security Verify Access versions 10.0.0 to 10.0.8, as well as in IBM Security Verify Access Docker versions 10.0.0 to 10.0.8. This vulnerability could allow an unverified user to change the password of an expired user without knowing the previous password.
WriteFreely MySQL Database Credential Exposure Vulnerability
A vulnerability in WriteFreely versions through 0.15.1 allows local users to access MySQL database credentials stored in plaintext within a world-readable config.ini file. This issue arises when WriteFreely is set up to use a MySQL database, following the standard installation instructions. The vulnerability is present on any Linux-based platform, and potentially others, affecting instances on shared hosting environments.
Linux Kernel io_uring Use-After-Free Vulnerability in Eventfd Handling
A use-after-free vulnerability has been identified in the Linux kernel's io_uring implementation, specifically in how eventfd signals are managed. The issue arises because the function io_eventfd_do_signal() frees a reference-counted object immediately when its reference count drops to zero, without waiting for the necessary RCU grace period. This behavior can lead to a race condition, allowing a user-space thread to access a freed object, potentially causing memory corruption or other unintended consequences.
OpenSSL Timing Side-Channel Vulnerability in ECDSA Signature Computation
A timing side-channel vulnerability has been identified in the ECDSA signature computation of OpenSSL. This issue allows for the potential recovery of private keys. The vulnerability is present in OpenSSL versions 3.4, 3.3, 3.2, 3.1, 3.0, 1.1.1, and 1.0.2. The timing leak occurs when the top word of the inverted ECDSA nonce value is zero, which can happen with significant probability on certain elliptic curves, particularly the NIST P-521 curve. To exploit this vulnerability, an attacker must have local access to the signing application or a very fast, low-latency network connection.
CP Plus Router Cookie Flag Mismanagement Vulnerability Allowing Session Hijacking
A vulnerability in the CP Plus CP-XR-DE21-S Router, specifically in firmware version DE21_S_india_hx806_1.057.043_0023, has been identified. This issue arises from the insecure handling of cookie flags in the router's web interface, which could enable a remote attacker to intercept data during an HTTP session. Successful exploitation may lead to the acquisition of sensitive information and compromise the affected system.
Linux Kernel Netfilter nf_tables Garbage Collection Vulnerability
A vulnerability in the Linux kernel's netfilter component, specifically within the nf_tables backend, has been addressed. This issue involved the garbage collection (GC) process, where elements were improperly managed, leading to potential visibility during lookups. The vulnerability arose because the asynchronous GC could enqueue transaction work that might be aborted and retried, causing inconsistencies. Additionally, certain backend types did not properly synchronize GC operations, leaving elements in a state that could interfere with normal processing.
TECNO Carlcare App Information Leakage Vulnerability
A vulnerability has been identified in the TECNO Carlcare mobile application, version 6.2.8.1, due to improper permission settings. This vulnerability may lead to a risk of information leakage.
aEnrich Technology a+HRD Insecure Deserialization Vulnerability Leading to Arbitrary Code Execution
An insecure deserialization vulnerability has been identified in a+HRD by aEnrich Technology, affecting versions through 7.5. This vulnerability allows remote attackers with database modification privileges and standard system privileges to execute arbitrary code.
aEnrich Technology a+HRD SQL Injection Vulnerability
A SQL injection vulnerability has been identified in a+HRD by aEnrich Technology, affecting versions through 7.5. This vulnerability allows unauthenticated remote attackers to inject arbitrary SQL commands, potentially leading to unauthorized reading, modification, or deletion of database contents.
aEnrich Technology a+HRD Server-Side Request Forgery Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in a+HRD versions 7.5 and earlier, developed by aEnrich Technology. This vulnerability allows unauthenticated remote attackers to probe internal networks, potentially leading to unauthorized access or information disclosure.
itsourcecode Farm Management System Code Injection Vulnerability in add-pig.php
A critical code injection vulnerability has been identified in the itsourcecode Farm Management System, specifically in version 1.0. The issue resides in the add-pig.php file, where the pigphoto parameter allows for unrestricted file uploads. This vulnerability arises from inadequate validation and sanitization of uploaded files, enabling attackers to upload malicious code that could be executed on the server.
CampCodes School Management Software Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in CampCodes School Management Software version 1.0. The issue resides in the chat history component, specifically within the '/chat/group/send' file. The vulnerability is triggered by manipulating the 'message' argument, allowing for the injection of malicious scripts. This issue can be exploited remotely, and there is a potential for account takeover, particularly targeting admin users.
Shiprocket OpenCart Module REST API Access Bypass Vulnerability
An access bypass vulnerability has been identified in the Shiprocket OpenCart Module version 3, specifically within the REST API component. The issue arises in the file 'index.php' when the 'route=extension/module/rest_api&action=getOrders' endpoint is accessed. The vulnerability allows for incorrect authorization by manipulating the 'contentHash' argument, enabling unauthorized access to Personally Identifiable Information (PII) and other sensitive data stored in the site's database. Additionally, this flaw could be exploited to make unauthorized changes to the database.
Shiprocket OpenCart Module SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in the Shiprocket module for OpenCart, specifically in versions 3 and 4. The issue arises in the REST API module's endpoint, where the 'x-username' header can be manipulated to execute arbitrary SQL commands. This vulnerability allows remote attackers to access and exfiltrate sensitive database information, including admin credentials and personally identifiable information.
OBS Studio Untrusted Search Path Vulnerability Allowing DLL Injection
A vulnerability exists in OBS Studio versions up to 30.0.2 on Windows, related to how the application loads dynamic link library (DLL) files. The issue arises from an untrusted search path that can be exploited to inject malicious code into DLLs, potentially leading to remote code execution. This vulnerability requires local access to the affected system.
aEnrich Technology a+HRD Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in a+HRD by aEnrich Technology, affecting versions through 7.5. This vulnerability allows unauthenticated remote attackers to execute arbitrary JavaScript in the user's browser, potentially through phishing attacks.
Facile Sistemas Cloud Apps Password Reset Handler Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Facile Sistemas Cloud Apps versions prior to 20250107. The issue arises in an unknown function within the Password Reset Handler component, specifically in the file '/account/forgotpassword'. The vulnerability is triggered by manipulating the 'reterros' argument, allowing remote attackers to inject malicious scripts. This exploit has been publicly disclosed.
Mobotix M15 Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been identified in the Mobotix M15 camera running firmware version 4.3.4.83. The issue arises from the file '/control/player' when certain parameters are manipulated, specifically 'p_qual'. This vulnerability can be exploited remotely.
