CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 16, 2025

Tenda AC18 Stack Overflow Vulnerability in PPTP Server Configuration

A stack overflow vulnerability has been identified in the Tenda AC18 router, specifically in version V15.03.05.19. The issue arises in the formSetPPTPServer function, where the startIP parameter is improperly handled, leading to the overflow.

5.9
Jan 16, 2025

Tenda AC18 Stack-Based Buffer Overflow Vulnerability in Firewall Configuration

A stack-based buffer overflow vulnerability has been identified in the Tenda AC18 router, specifically in the V15.03.05.19 firmware. The issue arises in the formSetFirewallCfg function, where the firewallEn parameter is processed without adequate validation. The vulnerability allows an attacker to send a crafted firewallEn parameter that exceeds the buffer size, leading to a stack overflow. This exploitation can overwrite critical stack memory, potentially causing a denial-of-service condition by crashing the router.

5.1
Jan 16, 2025

Tenda AC18 Stack Overflow Vulnerability in Device Name Setting Function

A stack overflow vulnerability has been identified in the Tenda AC18 router, specifically in the V15.03.05.19 firmware. The issue arises in the 'formSetDeviceName' function, where the 'devName' parameter from a POST request is processed. The vulnerability allows an attacker to send a 'devName' value that exceeds the buffer capacity, leading to a stack overflow. This vulnerability can be exploited remotely by an unauthenticated attacker, potentially causing a denial-of-service condition by crashing the router.

6.3
Jan 16, 2025

Tenda AC18 Stack Overflow Vulnerability in formSetClientState Function

A stack overflow vulnerability has been identified in the Tenda AC18 router, specifically in the V15.03.05.19 firmware. The issue arises in the formSetClientState function, where the limitSpeedUp parameter is extracted from a POST request without proper input validation. This parameter is then passed to a sprintf function, which writes the formatted string into a local stack-based buffer. If the limitSpeedUp value exceeds the buffer's capacity, it can overwrite the function's return address, causing a stack overflow. This vulnerability could be exploited by an unauthenticated attacker to create a denial-of-service condition or potentially execute arbitrary code on the device, undermining its security and functionality.

5.1
Jan 16, 2025

Tenda AC18 Stack Overflow Vulnerability in funcSetCfm Function

A stack overflow vulnerability has been identified in the Tenda AC18 router, specifically in version V15.03.05.19. The issue arises in the formSetCfm function, where the funcpara1 parameter is improperly handled, leading to the overflow.

6.4
Jan 16, 2025

Tenda AC18 Stack Overflow Vulnerability in formSetSpeedWan Function

A stack overflow vulnerability has been identified in the Tenda AC18 router, specifically in the V15.03.05.19 firmware. The issue arises in the formSetSpeedWan function, where the speed_dir parameter is extracted from a POST request without adequate validation. This unvalidated input is then used in a sprintf function, allowing an attacker to craft a specific speed_dir value that overflows the stack buffer. The exploitation of this vulnerability can lead to a crash of the affected function or the entire device, causing a denial-of-service condition. Notably, this vulnerability can be exploited remotely by an unauthenticated attacker.

5.0
Jan 16, 2025

Tenda AC18 Stack-Based Buffer Overflow Vulnerability in WiFi Settings Function

A stack-based buffer overflow vulnerability has been identified in the Tenda AC18 router, specifically in version V15.03.05.19. The issue arises in the 'form_fast_setting_wifi_set' function, where the 'ssid' parameter is processed. The function lacks proper size validation, allowing an attacker to send a crafted 'ssid' parameter that exceeds the capacity of two stack buffers, each 64 bytes. This overflow can disrupt normal service or, potentially, enable remote code execution by overwriting critical stack memory with maliciously controlled data.

5.1
Jan 16, 2025

Carrotbits Greek Namedays Widget Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Carrotbits Greek Namedays Widget, available through Eortologio.Net, affecting versions prior to 20191113. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.7
Jan 16, 2025

Revolutionart Marmoset Viewer Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Revolutionart Marmoset Viewer plugin for WordPress, affecting versions through 1.9.3. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.5
Jan 16, 2025

WordPress mybb Last Topics Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress mybb Last Topics plugin, specifically in versions through 1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could introduce malicious scripts that are stored and executed later.

2.0
Jan 16, 2025

WordPress Call Me Now Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Call Me Now plugin, specifically in versions through 1.0.5. This vulnerability allows for Stored Cross-Site Scripting, where an attacker could trick users with higher privileges into performing actions that could inject malicious scripts, which are then stored and potentially executed later.

2.0
Jan 16, 2025

WordPress Social Analytics Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Social Analytics plugin, specifically in versions through 0.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the application.

2.0
Jan 16, 2025

Mozilla Web Push Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Mozilla Web Push plugin for WordPress, affecting versions through 1.4.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed.

2.0
Jan 16, 2025

ITMOOTI WordPress Theme 'My Ontraport Smartform' Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the ITMOOTI WordPress theme 'My Ontraport Smartform', affecting versions through 1.2.11. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Jan 16, 2025

RaymondDesign Post & Page Notes Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the RaymondDesign Post & Page Notes WordPress plugin, affecting versions through 0.1.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed in the context of the user.

2.0
Jan 16, 2025

WordPress Hack Me If You Can Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress plugin 'Hack Me If You Can' versions through 1.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could lead to the injection of malicious scripts.

2.0
Jan 16, 2025

WordPress Kapost Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Kapost plugin, specifically in versions through 2.2.9. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Jan 16, 2025

WordPress Flying Twitter Birds Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Flying Twitter Birds plugin, specifically in versions through 1.8. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Jan 16, 2025

Dominic Fallows DF Draggable Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Dominic Fallows DF Draggable WordPress plugin, affecting versions through 1.13.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.

2.0
Jan 16, 2025

WordPress Free MailClient FMC Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Free MailClient FMC plugin, specifically in versions through 1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the application.

2.0
Jan 16, 2025

WordPress Anonymize Links Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Anonymize Links plugin, affecting versions through 1.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Jan 16, 2025

TechMix Event Countdown Timer Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Event Countdown Timer Plugin by TechMix, affecting versions through 1.4. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed in the context of the user's browser.

2.0
Jan 16, 2025

WP Custom Google Search Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP Custom Google Search WordPress plugin, specifically in versions through 1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Jan 16, 2025

Shabbos Commerce WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Shabbos Commerce WordPress plugin, specifically in versions through 1.9. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Jan 16, 2025

WordPress Secure CAPTCHA Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Secure CAPTCHA plugin, specifically in versions through 1.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Jan 16, 2025

WordPress Slider for Writers Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Slider for Writers plugin, affecting versions through 1.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser session.

2.0
Jan 16, 2025

WordPress Send to Twitter Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Send to Twitter plugin, specifically in versions through 1.7.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where a malicious actor could trick users with higher privileges into performing actions that could lead to the execution of harmful scripts.

2.0
Jan 16, 2025

WordPress Book a Place Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Book a Place plugin, specifically in versions through 0.7.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed.

2.0
Jan 16, 2025

Poco Blogger Image Import Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Poco Blogger Image Import plugin, specifically in version 2.1. This issue arises from improper input neutralization during web page generation, allowing malicious users to inject harmful scripts that are executed when the affected page is viewed.

2.0
Jan 16, 2025

WordPress HTTP to HTTPS Link Changer by Eyga.net Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress plugin 'HTTP to HTTPS Link Changer' by Eyga.net, affecting versions through 0.2.4. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser session.

2.0
Jan 16, 2025

WordPress Import Users to MailChimp Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Import Users to MailChimp plugin, specifically in versions through 1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts, which are then stored and executed later.

2.0
Jan 16, 2025

WordPress Email on Publish Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Email on Publish plugin, affecting versions through 1.5. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could introduce malicious scripts that are permanently stored and executed later.

2.0
Jan 16, 2025

WordPress RSV GMaps Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress RSV GMaps plugin, specifically in versions through 1.5. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Jan 16, 2025

WordPress Real Seguro Viagem Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Real Seguro Viagem WordPress plugin, specifically in versions through 2.0.5. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.

2.0
Jan 16, 2025

WordPress WP Panoramio Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress WP Panoramio plugin, specifically in versions through 1.5.0. This vulnerability allows for Stored Cross-Site Scripting, where an attacker can inject malicious scripts that are executed by users.

2.0
Jan 16, 2025

WordPress NV Slider Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress NV Slider plugin, affecting versions through 1.6. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's insufficient protection against CSRF, enabling attackers to manipulate users with higher privileges into performing actions that could lead to the execution of malicious scripts.

2.0
Jan 16, 2025

Walter Cerrudo MFPlugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Walter Cerrudo MFPlugin for WordPress, affecting versions through 1.3. This vulnerability allows for Stored Cross-Site Scripting, where an attacker can inject malicious scripts that are executed by users.

2.0
Jan 16, 2025

WordPress MercadoLibre Integration Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress MercadoLibre Integration plugin, affecting versions through 1.1. This vulnerability allows for Stored Cross-Site Scripting, where an attacker can inject malicious scripts that are executed by users.

2.0
Jan 16, 2025

WordPress Twitter Post Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Twitter Post plugin, specifically in versions through 0.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Jan 16, 2025

Kreg Steppe Auphonic Importer Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Kreg Steppe Auphonic Importer WordPress plugin, affecting versions through 1.5.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser session.

2.0
Jan 16, 2025

WordPress QuoteMedia Tools Plugin DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the QuoteMedia Tools WordPress plugin, affecting versions through 1.0. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

1.6
Jan 16, 2025

WordPress Sidebar-Content from Shortcode Plugin DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the WordPress Sidebar-Content from Shortcode plugin, affecting versions through 2.0. This issue arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

1.6
Jan 16, 2025

WordPress Powie's pLinks PagePeeker Plugin DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in WordPress Powie's pLinks PagePeeker Plugin versions through 1.0.2. This issue arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

1.6
Jan 16, 2025

WordPress Rename Author Slug Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Rename Author Slug plugin, specifically in versions through 1.2.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.

2.0
Jan 16, 2025

MDC YouTube Downloader Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the MDC YouTube Downloader WordPress plugin, affecting versions through 3.0.0. This vulnerability allows for Stored Cross-Site Scripting, where an attacker could trick users with higher privileges into performing actions that introduce malicious scripts, which are then stored and potentially executed later.

2.5
Jan 16, 2025

WordPress Comment-Emailer Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Comment-Emailer plugin, specifically in versions through 1.0.5. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed.

2.0
Jan 16, 2025

WordPress Contact Form 7 – CCAvenue Add-on Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Contact Form 7 – CCAvenue Add-on, affecting versions through 1.0. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.

2.0
Jan 16, 2025

WordPress Captchelfie Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Captchelfie – Captcha by Selfie plugin, affecting versions through 1.0.7. This vulnerability allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.

2.0
Jan 16, 2025

WordPress Twitter Shortcode Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Twitter Shortcode plugin, affecting versions through 0.9. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed.

2.0
Jan 16, 2025

Oliver Schaal Floatbox Plus Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Oliver Schaal Floatbox Plus WordPress plugin, specifically in versions through 1.4.4. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0