CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 17, 2025

Code-Projects Car Rental Management System Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Code-Projects Car Rental Management System version 1.0. The issue arises in the '/admin/manage-pages.php' file, where the 'pgdetails' parameter is processed without proper sanitization. This allows authenticated attackers to inject malicious scripts that are executed when other users view the 'FAQs' page, potentially leading to data theft, redirection to malicious sites, or account compromise.

3.4
Jan 17, 2025

1000 Projects Attendance Tracking Management System SQL Injection Vulnerability

A critical SQL injection vulnerability exists in version 1.0 of the 1000 Projects Attendance Tracking Management System. The issue is located in the file '/admin/edit_action.php', where the 'attendance_id' parameter is not properly validated, allowing attackers to inject malicious SQL queries that could be executed by the database. This vulnerability can be exploited remotely, leading to unauthorized database access, data leakage, data tampering, potential system control, and service interruptions.

3.9
Jan 17, 2025

InformationPush Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability exists in InformationPush master version. This issue allows remote attackers to inject malicious scripts or HTML into the webpage, potentially leading to the theft of sensitive information. The vulnerability arises because user-supplied data in the 'title', 'time', and 'msg' parameters is directly embedded into the HTML without any sanitization or validation.

3.4
Jan 17, 2025

Sunnygkp10 Online Exam System Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability exists in the sunnygkp10 Online Exam System in the master version. This issue allows remote attackers to inject malicious scripts that can be executed in the context of the user's browser. The vulnerability is triggered through the 'w' parameter in the URL, where the injected script can be used to steal sensitive information, such as cookies.

3.4
Jan 17, 2025

Typecho Clickjacking Vulnerability in v1.2.1

A clickjacking vulnerability has been identified in Typecho version 1.2.1. This issue occurs on the '/install.php' page, where an attacker can manipulate user interactions by overlaying transparent layers, leading users to unintentionally click on elements of the underlying page.

4.8
Jan 17, 2025

WeGIA SQL Injection Vulnerability in query_geracao_auto.php

A SQL injection vulnerability exists in WeGIA versions prior to 3.2.0, specifically in the query_geracao_auto.php file. The vulnerability allows attackers to manipulate the query parameter and execute arbitrary SQL commands, potentially compromising the database's confidentiality, integrity, and availability.

2.9
Jan 17, 2025

WeGIA Password Change Vulnerability Due to Incorrect Access Control

A vulnerability exists in WeGIA versions prior to 3.2.0, specifically in the controle/control.php file, where the application fails to properly validate the old password during password change requests. This flaw allows users to reset their passwords by entering any value in the 'senha_antiga' field, bypassing authentication requirements. The issue enables unauthorized password changes for any user, including administrators.

2.9
Jan 17, 2025

WeGIA SQL Injection Vulnerability in Remuneracao.php

A SQL injection vulnerability has been identified in WeGIA versions prior to 3.2.0. The issue resides in the 'id_funcionario' parameter of the 'remuneracao.php' file within the 'funcionario' directory. This vulnerability allows attackers to execute arbitrary SQL commands, potentially compromising the confidentiality, integrity, and availability of the application's data.

3.0
Jan 17, 2025

WeGIA Cross-Site Scripting Vulnerability in Documentos Funcionario PHP

A stored cross-site scripting (XSS) vulnerability exists in WeGIA versions prior to 3.2.0. The issue is located in the 'documentos_funcionario.php' file, specifically within the 'id' parameter. This vulnerability allows unauthorized scripts to be executed in the user's browser, with the malicious code being permanently stored on the server and executed whenever the compromised page is accessed.

2.8
Jan 17, 2025

Teradata Vantage Editor Desktop Unrestricted Web Browsing Vulnerability

A vulnerability in Teradata Vantage Editor Desktop version 1.0.1 and earlier allows users to bypass intended restrictions and access arbitrary remote websites. This issue arises from the application's unintentional exposure of Chromium Developer Tools, which can be used to manipulate the embedded browser's behavior. While Vantage Editor is primarily designed for SQL database access, the vulnerability could be exploited by convincing a user to execute JavaScript code in the developer console, effectively turning the application into an unrestricted web browser. This could lead to unauthorized access to websites or, potentially, to other security exploits, such as injecting malicious code into SQL query results or phishing for Teradata database credentials.

2.7
Jan 17, 2025

Roche Algo Edge Authentication Vulnerability in navify Algorithm Suite

A vulnerability exists in Roche Algo Edge versions prior to 2.1.2, which is a legacy component of the navify Algorithm Suite. This vulnerability affects the authentication mechanism, potentially allowing an attacker with adjacent access to the laboratory network and the Algo Edge system to create valid authentication tokens and access the component. Other components of the navify Algorithm Suite are not impacted.

1.5
Jan 17, 2025

Codezips Gym Management System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Codezips Gym Management System version 1.0. The issue resides in the 'uid' parameter of the '/dashboard/admin/edit_mem_submit.php' file. This vulnerability allows remote attackers to inject arbitrary SQL commands, potentially leading to unauthorized database access, data manipulation, and full system compromise.

4.7
Jan 17, 2025

1000 Projects Campaign Management System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in the 1000 Projects Campaign Management System Platform for Women, version 1.0. The issue resides in the '/Code/loginnew.php' file, where the 'Username' parameter is manipulated to inject malicious SQL queries. This vulnerability can be exploited remotely, without any authentication, allowing attackers to gain unauthorized access to the database, leak sensitive information, tamper with data, and potentially disrupt services.

4.2
Jan 17, 2025

1000 Projects Campaign Management System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in the 1000 Projects Campaign Management System Platform for Women, version 1.0. The issue resides in the '/Code/sc_login.php' file, where the 'uname' parameter is manipulated, allowing attackers to inject malicious SQL queries. This vulnerability can be exploited remotely, without any authentication or authorization.

4.3
Jan 17, 2025

Codezips Gym Management System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Codezips Gym Management System version 1.0. The issue resides in the 'm_id' parameter of the '/dashboard/admin/new_submit.php' file. This vulnerability allows remote attackers to inject arbitrary SQL commands, potentially leading to unauthorized database access, data manipulation, and system compromise.

4.7
Jan 17, 2025

Belledonne Communications Linphone-Desktop NULL Pointer Dereference Vulnerability Leading to Denial-of-Service

A NULL pointer dereference vulnerability has been identified in Belledonne Communications Linphone-Desktop version 5.2.6. This vulnerability allows remote attackers to cause a denial-of-service condition on affected devices.

2.5
Jan 17, 2025

Nedap Librix Ecoreader Missing Authentication Vulnerability Allowing Remote Code Execution

A vulnerability exists in Nedap Librix Ecoreader due to missing authentication for critical functions, potentially allowing an unauthenticated attacker to execute malicious code. This issue affects all versions of Ecoreader.

2.6
Jan 17, 2025

Ossur Mobile Logic Application Command Injection Vulnerability

A command injection vulnerability has been identified in the Ossur Mobile Logic Application, specifically in versions prior to 1.5.5. The issue arises from multiple bash files being present in the application's private directory. An attacker with full access to the mobile platform could exploit this vulnerability to manipulate the application's translation files, disrupting normal functionality.

0.9
Jan 17, 2025

Ossur Mobile Logic Application Exposure of Sensitive Information and Command Injection Vulnerabilities

A vulnerability in the Ossur Mobile Logic Application, affecting versions prior to 1.5.5, allows for the exposure of hard-coded credentials and static tokens. These were extracted from a decompiled IPA file and could be used to disrupt the application's normal functioning by altering translation files, thereby compromising the application's integrity. Additionally, the presence of multiple bash files in the application's private directory could be exploited by an attacker with full access to the mobile platform, further manipulating the application's translation files.

1.0
Jan 17, 2025

Ossur Mobile Logic Application Hard-Coded Credentials Vulnerability

A vulnerability exists in the Ossur Mobile Logic Application, specifically in versions prior to 1.5.5, due to the inclusion of hard-coded credentials in the application binary. These credentials are used in the authentication process and communication with the mobile application, potentially allowing an attacker to access unauthorized information. The vulnerability could be exploited by decompiling the application to retrieve the credentials, which could then be used to disrupt normal application use by altering translation files, thereby undermining the application's integrity.

1.4
Jan 17, 2025

ETIC Telecom Remote Access Server Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in all versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0. The issue arises in the 'get view' method, specifically under the 'view' parameter. This vulnerability allows attackers to inject malicious scripts that are then executed in the context of the user's browser. The ETIC RAS web server generates dynamic pages that incorporate client-side input, which is reflected back to the client, creating an opportunity for XSS attacks.

2.5
Jan 17, 2025

ETIC Telecom Remote Access Server Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in all versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0. This vulnerability allows attackers to inject malicious scripts into web pages viewed by users. The issue arises because the ETIC RAS web server dynamically generates pages that reflect client-side input without proper validation, particularly in the method parameter.

2.5
Jan 17, 2025

ETIC Telecom Remote Access Server Cleartext Credentials Exposure Vulnerability

A vulnerability exists in all versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0, where cleartext credentials are exposed in the web portal. This allows an attacker to access the ETIC RAS web portal, view hidden HTML code, and connect to the ETIC RAS SSH server, potentially enabling actions on the device.

3.0
Jan 17, 2025

ETIC Telecom Remote Access Server Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in all versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0. The issue arises in the appliance site name, which is saved by the ETIC RAS web server and then reflected back to administrators on various pages. This vulnerability allows an attacker to inject malicious scripts that could be executed in the context of the user's browser.

2.5
Jan 17, 2025

ETIC Telecom Remote Access Server Cross-Site Request Forgery Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in ETIC Telecom Remote Access Server (RAS) versions prior to 4.9.19. This vulnerability allows an external attacker to manipulate an end user into sending a 'setconf' method request without the need for a CSRF token, potentially causing a denial-of-service condition on the device.

2.5
Jan 17, 2025

Code-Projects Chat System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Code-Projects Chat System version 1.0. The issue arises from an unknown processing flaw in the file '/user/leaveroom.php', where the 'id' argument can be manipulated to execute unauthorized SQL commands. This vulnerability can be exploited remotely.

3.5
Jan 17, 2025

Code-Projects Job Recruitment Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Code-Projects Job Recruitment version 1.0. The issue resides in the file '/_parse/_feedback_system.php', where the 'type' parameter is echoed without proper sanitization, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely, and has been publicly disclosed along with a proof-of-concept exploit.

2.8
Jan 17, 2025

Code-Projects Train Ticket Reservation System Buffer Overflow Vulnerability

A critical stack-based buffer overflow vulnerability has been identified in Code-Projects Train Ticket Reservation System version 1.0. The issue arises in the Login Form component, where the 'username' input is not properly validated, allowing for excessively long strings to be entered. This lack of input size control leads to a stack overflow, causing the program to crash with a segmentation fault. The vulnerability must be exploited locally.

2.5
Jan 17, 2025

Tenda AC8, AC10, and AC18 Command Injection Vulnerability via Telnet HTTP Request

A critical command injection vulnerability has been identified in Tenda AC8, AC10, and AC18 routers running firmware version 16.03.10.20. The issue arises in the HTTP request handler for the '/goform/telnet' route, where an unknown functionality allows for the execution of arbitrary commands. This vulnerability can be exploited remotely, but requires authentication as an admin user.

5.1
Jan 17, 2025

Becon DATAGerry Incorrect Access Control Vulnerability in REST API Endpoint

A broken access control vulnerability has been identified in the Becon DATAGerry platform, affecting all versions through 2.2.0. The vulnerability resides in the '/rest/rights/' REST API endpoint, which can be accessed remotely without authentication. This flaw allows unauthorized users to gain access to sensitive information.

2.9
Jan 17, 2025

Code-Projects Admission Management System SQL Injection Vulnerability in Signup Confirmation File

A critical SQL injection vulnerability has been identified in version 1.0 of the Code-Projects Admission Management System. The issue resides in the 'signupconfirm.php' file, where the 'in_eml' parameter is manipulated to inject malicious SQL queries. This vulnerability can be exploited remotely without any authentication, potentially leading to unauthorized database access, data modification or deletion, and exposure of sensitive information.

4.0
Jan 17, 2025

Newtec NTC2218, NTC2250, and NTC2299 Buffer Overflow Vulnerability Allowing Code Execution

A buffer overflow vulnerability has been identified in Newtec NTC2218, NTC2250, and NTC2299 modems running Linux on PowerPC and ARM architectures. This vulnerability, which allows local execution of code and remote code inclusion, arises from the 'swdownload' binary module's 'parse_INFO' function. The function employs an unrestricted 'sscanf' to read data from incoming network packets into a statically sized buffer, creating a stack buffer overflow. The issue affects versions 1.0.1.1 through 2.2.6.19.

2.6
Jan 17, 2025

Newtec/iDirect OS Command Injection Vulnerability Allowing Local Code Inclusion

A vulnerability allowing improper neutralization of special elements used in OS command execution has been identified in Newtec/iDirect models NTC2218, NTC2250, and NTC2299, running Linux on PowerPC and ARM architectures. This vulnerability, present in versions 1.0.1.1 through 2.2.6.19, arises from the `commit_multicast` page in the modem's web administration interface. The page improperly parses incoming data before passing it to an `eval` statement in a bash script, enabling attackers to inject arbitrary shell commands. Exploitation of this vulnerability could lead to unauthorized code execution on the affected device.

2.3
Jan 17, 2025

Schneider Electric RemoteConnect and SCADAPack x70 Utilities Deserialization Vulnerability Leading to Remote Code Execution

A deserialization vulnerability has been identified in all versions of Schneider Electric's RemoteConnect and SCADAPack x70 Utilities. This vulnerability allows for the potential loss of confidentiality and integrity, and could lead to remote code execution on the workstation of a non-admin authenticated user who opens a malicious project file.

1.6
Jan 17, 2025

Schneider Electric Web Applications Sensitive Information Disclosure Vulnerability

A vulnerability allowing the exposure of sensitive information to unauthorized users has been identified in certain web applications by Schneider Electric. This issue could lead to the unauthorized disclosure of restricted web pages, unauthorized modification of web content, and denial-of-service conditions when modified pages invoke restricted functions.

2.6
Jan 17, 2025

Schneider Electric PowerLogic HDPM6000 Improper Buffer Operation Vulnerability Allowing Unauthorized Configuration Modification

A vulnerability exists in the Schneider Electric PowerLogic HDPM6000 High-Density Metering System, specifically in versions through v0.62.7. This vulnerability, categorized as CWE-119, allows an unauthorized attacker to modify configuration values beyond the normal range. The issue arises when specific Modbus write packets are sent to the device, potentially leading to invalid data, corruption of the web interface, or a denial-of-service condition on the interface.

4.1
Jan 17, 2025

Schneider Electric PowerLogic HDPM6000 Authorization Bypass Vulnerability Allowing Privilege Escalation

An authorization bypass vulnerability has been identified in the Schneider Electric PowerLogic HDPM6000 High-Density Metering System, specifically in version v0.62.7. This vulnerability could allow an authorized attacker to elevate privileges by modifying values beyond their assigned rights. The issue arises when altered HTTPS requests are sent to the device.

3.4
Jan 17, 2025

Gravity Forms Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Gravity Forms plugin for WordPress, affecting versions 2.9.0.1 prior to 2.9.1.3. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts execute when a user accesses the compromised page. Notably, this vulnerability only affects users of the Chrome web browser and requires direct access to the media file through the attachment post.

4.1
Jan 17, 2025

Gravity Forms Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Gravity Forms plugin for WordPress, affecting all versions through 2.9.1.3. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the 'alt' parameter. These scripts execute when a user accesses the compromised page.

4.1
Jan 17, 2025

Schneider Electric Web Designer XML External Entity Vulnerability Allowing Information Disclosure and Remote Code Execution

A vulnerability allowing improper restriction of XML external entity references has been identified in the Web Designer configuration tool for certain Modicon communication modules. This vulnerability could lead to information disclosure, impact workstation integrity, and allow remote code execution on the compromised computer when a specifically crafted XML file is imported. The issue affects all versions of the Web Designer tool for the following products: BMXNOR0200H, BMXNOE0110(H), BMENOC0311(C), and BMENOC0321(C).

3.4
Jan 17, 2025

Schneider Electric Pro-face GP-Pro EX and Remote HMI Improper Message Integrity Enforcement Vulnerability

A vulnerability exists in Schneider Electric's Pro-face GP-Pro EX and Remote HMI products, all versions, due to improper enforcement of message integrity during transmission. This vulnerability could lead to a man-in-the-middle attack, allowing an attacker to intercept communication and cause a partial loss of confidentiality, integrity, and availability of the Human Machine Interface (HMI).

3.0
Jan 17, 2025

WP Hotel Booking Plugin Missing Authorization Vulnerability Allowing Unauthenticated Room Additions

A vulnerability exists in the WP Hotel Booking plugin for WordPress, in all versions through 2.1.5. The issue arises from a lack of proper capability checks, which allows unauthorized users to add rooms with custom prices. This vulnerability could be exploited by unauthenticated attackers to manipulate room data.

4.5
Jan 17, 2025

Schneider Electric Products Denial-of-Service Vulnerability via Crafted HTTPS Packets

A vulnerability allowing for denial-of-service has been identified in certain Schneider Electric products. This issue arises from an incorrect calculation of buffer size, which could be exploited by an unauthenticated user sending a specially crafted HTTPS packet to the web server.

2.5
Jan 17, 2025

Schneider Electric EcoStruxure Power Build Rapsody Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

A buffer overflow vulnerability has been identified in Schneider Electric's EcoStruxure Power Build Rapsody software, specifically in versions through 2.6.4 INT, 2.7.5 ES, 2.7.1 FR, and 2.5.2 NL. This vulnerability, categorized as CWE-119, allows local attackers to exploit memory corruption issues, potentially leading to arbitrary code execution when a malicious project file is opened.

3.3
Jan 17, 2025

WordPress Quote Post Type Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Quote Post Type Plugin for WordPress, affecting all versions through 1.2.2. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into pages. These scripts would execute when a user views the affected page.

1.6
Jan 17, 2025

WordPress Sandbox Plugin Missing Authorization Vulnerability in Export Download Action

A vulnerability exists in the Sandbox plugin for WordPress, all versions through 0.4, due to a lack of proper capability checks on the export_download action. This flaw allows authenticated users with Subscriber-level access and higher to download a complete copy of a sandbox environment, which may include sensitive information such as the wp-config.php file.

2.4
Jan 17, 2025

WordPress Sandbox Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Sandbox plugin for WordPress, affecting all versions through 0.4. This issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. The injected scripts can execute on pages if a user is tricked into clicking a link or performing a similar action.

2.0
Jan 17, 2025

Moving Users WordPress Plugin Sensitive Information Exposure Vulnerability

A vulnerability allowing sensitive information exposure exists in the Moving Users plugin for WordPress, affecting all versions through 1.05. The issue arises from the export functionality, where JSON files containing user data are saved in predictable locations with easily guessable file names. This flaw could enable unauthenticated attackers to access sensitive information such as email addresses, hashed passwords, and IP addresses.

2.5
Jan 17, 2025

MyBookProgress WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the MyBookProgress by Stormhill Media plugin for WordPress, affecting all versions through 1.0.8. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into pages. These scripts are executed when a user accesses the compromised page.

1.6
Jan 17, 2025

Glofox Shortcodes WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Glofox Shortcodes plugin for WordPress, affecting all versions up to and including 2.6. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'glofox' and 'glofox_lead_capture' shortcodes. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

1.6