CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 16, 2025

D-Link DIR-816 Access Control Vulnerability in AGL Service

An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the component form2alg.cgi. This vulnerability allows unauthenticated attackers to manipulate the AGL service of the device by sending a crafted POST request.

6.3
Jan 16, 2025

D-Link DIR-816 Access Control Vulnerability in form2PortriggerRule.cgi Allowing Unauthenticated Port Triggering

An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. The issue allows unauthenticated attackers to manipulate the port triggering settings of the device by sending a crafted POST request. This vulnerability arises from inadequate access controls in the affected CGI component, form2PortriggerRule.cgi.

6.7
Jan 16, 2025

D-Link DIR-816 Access Control Vulnerability in Repeater Service Configuration

An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability allows unauthenticated attackers to manipulate the 2.4G and 5G repeater services of the device by sending a crafted POST request.

5.8
Jan 16, 2025

D-Link DIR-816 Access Control Vulnerability in form2WlAc.cgi Allowing Unauthenticated MAC ACL Modification

An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability allows unauthenticated attackers to manipulate the MAC access control list for both the 2.4GHz and 5GHz bands. Exploitation is achieved by sending a crafted POST request to the device.

6.7
Jan 16, 2025

D-Link DIR-816 Access Control Vulnerability in form2Wan.cgi Allowing Unauthenticated WAN Service Modification

An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability allows unauthenticated attackers to manipulate the WAN service settings of the device by sending a crafted POST request. The issue arises in the form2Wan.cgi component, where inadequate access controls permit unauthorized modifications to critical network configurations.

6.7
Jan 16, 2025

D-Link DIR-816 Access Control Vulnerability in form2WlanBasicSetup.cgi Allowing Unauthenticated WLAN Service Modification

An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. The issue allows unauthenticated attackers to manipulate the 2.4G and 5G WLAN services of the device by sending a crafted POST request to the form2WlanBasicSetup.cgi component.

4.9
Jan 16, 2025

Gomatrixserverlib Server-Side Request Forgery Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in Gomatrixserverlib, a Go library for Matrix federation. This vulnerability allows the library to access and serve content from a private network, under certain conditions. The issue is present in versions of Gomatrixserverlib through dbd5f31fefc031633c3418165e4ef6d343e03999.

2.9
Jan 16, 2025

Mattermost Mobile Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in Mattermost Mobile versions through 2.22.0. The issue arises because the application fails to properly validate the style of proto provided to an action's style in post.props.attachments. This lack of validation allows an attacker to crash the mobile application by sending crafted malicious input.

1.0
Jan 16, 2025

JFinalOA Cross-Site Scripting Vulnerability in Edit Page Interface

A cross-site scripting (XSS) vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the apply/getEditPage?view interface, where attackers can execute arbitrary web scripts or HTML by injecting a crafted payload.

3.3
Jan 16, 2025

JFinalOA SQL Injection Vulnerability in Workflow History Component

A SQL injection vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the workflow history component, specifically through the 'getWorkFlowHis?insid' parameter.

3.9
Jan 16, 2025

JFinalOA Cross-Site Scripting Vulnerability in Business Upload List Interface

A cross-site scripting (XSS) vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the getBusinessUploadListPage?busid interface, where attackers can execute arbitrary web scripts or HTML by injecting a crafted payload.

3.3
Jan 16, 2025

JFinalOA Cross-Site Scripting Vulnerability in openSelectManyUserPage?orgid Interface

A cross-site scripting (XSS) vulnerability has been identified in JFinalOA versions prior to v2025.01.01. The issue arises in the openSelectManyUserPage?orgid interface, where attackers can execute arbitrary web scripts or HTML by injecting a crafted payload.

3.3
Jan 16, 2025

JFinalOA Cross-Site Scripting Vulnerability in Draft List Interface

A cross-site scripting (XSS) vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the '/bumph/getDraftListPage?type' interface, where attackers can execute arbitrary web scripts or HTML by injecting a crafted payload.

3.3
Jan 16, 2025

JFinalOA Cross-Site Scripting Vulnerability in Edit Page Interface

A cross-site scripting (XSS) vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the common/getEditPage?view interface, where attackers can execute arbitrary web scripts or HTML by injecting a crafted payload.

3.3
Jan 16, 2025

JFinalOA SQL Injection Vulnerability

A SQL injection vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the apply/save#oaContractApply.id component, allowing attackers to manipulate SQL queries and potentially access or modify database information.

3.9
Jan 16, 2025

JFinalOA SQL Injection Vulnerability in borrowmoney Component

A SQL injection vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the borrowmoney component, specifically within the listData?applyUser endpoint.

3.9
Jan 16, 2025

JFinalOA SQL Injection Vulnerability in validRoleKey Component

A SQL injection vulnerability has been identified in JFinalOA versions prior to 2025.01.01. The issue arises in the validRoleKey component, specifically through the sysRole.key parameter.

3.9
Jan 16, 2025

Indico Broken Object Level Authorization Vulnerability

A Broken Object Level Authorization (BOLA) vulnerability exists in Indico versions through 3.3.5. This vulnerability allows attackers to read information by sending a crafted POST request to the /api/principals endpoint. The issue arises because the application design intentionally permits all users to access certain information about other user accounts, without restricting this functionality to privileged roles such as event organizers.

4.9
Jan 16, 2025

IBM CICS TX Stored Cross-Site Scripting Vulnerability Allowing JavaScript Injection

A stored cross-site scripting vulnerability has been identified in IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1. This issue allows users to inject arbitrary JavaScript into the Web UI, potentially altering functionality and leading to credential disclosure within a trusted session.

3.0
Jan 16, 2025

Intel Neural Compressor Time-of-Check Time-of-Use Race Condition Vulnerability Allowing Information Disclosure

A time-of-check time-of-use race condition vulnerability has been identified in Intel Neural Compressor software versions prior to 3.0. This vulnerability may allow an authenticated user to disclose information through adjacent access.

1.1
Jan 16, 2025

FFmpeg Unchecked Return Value, Out-of-bounds Read Vulnerability in libavfilter af_pan Allowing Read of Sensitive Constants

A vulnerability in FFmpeg's libavfilter component, specifically in the af_pan audio filter, has been identified. This issue involves an unchecked return value leading to an out-of-bounds read, which allows the reading of sensitive constants within an executable. The vulnerability was present in FFmpeg version 7.1 and has been fixed in a subsequent update.

5.1
Jan 16, 2025

07FLYCMS Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in 07FLYCMS version 1.3.9. The issue arises in the admin/doAdminAction.php file, specifically when the 'act' parameter is set to 'editShop' and the 'shopId' parameter is included.

3.9
Jan 16, 2025

Campcodes Cybercafe Management System SQL Injection Vulnerability

A SQL injection vulnerability has been identified in Campcodes Cybercafe Management System version 1.0. The issue resides in the 'view-user-detail.php' file, where user input is not properly sanitized, allowing attackers to manipulate SQL queries and potentially access or modify database information.

4.7
Jan 16, 2025

07FLYCMS Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in 07FLYCMS version 1.3.9. The issue arises in the OaWorkReport edit page, allowing attackers to perform actions on behalf of users without their consent.

3.8
Jan 16, 2025

07FLYCMS Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in 07FLYCMS version 1.3.9. The issue resides in the OaTask editing component, accessible through the erp.07fly.net domain.

3.8
Jan 16, 2025

07FLYCMS Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in 07FLYCMS version 1.3.9. The issue resides in the OaWorkReport component, specifically within the add.html page. This vulnerability allows an attacker to trick a user into submitting a request that could potentially manipulate data or perform actions on their behalf.

3.8
Jan 16, 2025

PMB Platform Temporary File Persistence Vulnerability

A vulnerability exists in the PMB platform in versions 4.0.10 and above, allowing attackers to persist temporary files on the server. This issue arises in the file upload functionality at the '/pmb/authorities/import/iimport_authorities' endpoint. When a file is uploaded, the server creates a temporary file that is normally deleted after a POST request is sent to the same endpoint. However, an attacker can intercept and delay this POST request, preventing the temporary file from being removed.

2.2
Jan 16, 2025

PMB Platform Information Exposure Vulnerability

A vulnerability allowing information exposure has been identified in the PMB platform, affecting versions 4.2.13 and earlier. This issue enables an attacker to upload a file to the environment and enumerate internal files on a machine by analyzing the response to the upload request.

2.8
Jan 16, 2025

PMB Platform Unrestricted File Upload Vulnerability Allowing Remote Access

A vulnerability allowing unrestricted file uploads has been identified in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could enable an attacker to upload a file that facilitates remote access to the machine, allowing unrestricted access to modify files and execute commands.

2.2
Jan 16, 2025

WAGO 750-8xx Controller Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in WAGO 750-8xx controllers, including the 750-8100, 750-831, 750-880, and 750-889 models, all running versions through their respective maximums. The vulnerability allows an unauthenticated remote attacker to disrupt normal device operation by causing uncontrolled resource consumption, particularly high network load, which can interfere with the device's CPU performance and cycle timing. This network packet flood can be especially problematic, as it may temporarily degrade the device's functionality, although it typically resumes normal operation once the network load decreases.

2.5
Jan 16, 2025

Fortinet FortiManager and FortiAnalyzer Weak Authentication Vulnerability Allowing Unauthorized Code Execution

A weak authentication vulnerability has been identified in Fortinet FortiManager Cloud, FortiAnalyzer, FortiManager, and FortiManager Cloud. This vulnerability affects several different versions and ranges, specifically FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, and FortiAnalyzer Cloud versions 7.4.1 through 7.4.3. The vulnerability allows attackers to execute unauthorized code or commands by leveraging a brute-force attack.

1.6
Jan 16, 2025

WP Responsive Tabs Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WP Responsive Tabs plugin for WordPress, affecting all versions through 1.2.9. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'wprtabs' shortcode. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary scripts into pages, which are executed when users access the affected pages.

2.3
Jan 16, 2025

Admin and Customer Messages After Order for WooCommerce Limited File Upload Vulnerability

A vulnerability exists in the Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress, in all versions through 13.2. The issue arises from inadequate validation of file types in the upload_file() function, allowing authenticated attackers with Subscriber-level access and above to upload files to the server. This vulnerability could potentially lead to remote code execution and has been confirmed to allow Cross-Site Scripting.

2.5
Jan 16, 2025

Passwords Manager WordPress Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the Passwords Manager plugin for WordPress, affecting all versions through 1.4.8. The vulnerability arises from inadequate escaping of user-supplied data in several AJAX actions, allowing authenticated attackers with Subscriber-level access or higher to inject additional SQL queries. This could be exploited to extract sensitive information from the database.

2.7
Jan 16, 2025

Passwords Manager WordPress Plugin Missing Capability Check Vulnerability

A vulnerability exists in the Passwords Manager plugin for WordPress, in all versions through 1.4.8. The issue stems from a lack of proper capability checks on the 'pms_save_setting' and 'post_new_pass' AJAX actions. This flaw allows authenticated attackers with Subscriber-level access and above to unauthorizedly modify plugin settings, add passwords, and update the encryption key used for password management.

2.7
Jan 16, 2025

Passwords Manager WordPress Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the Passwords Manager plugin for WordPress, affecting all versions through 1.4.8. The vulnerability arises from inadequate escaping of user-supplied parameters in several AJAX functions, allowing unauthenticated attackers to inject additional SQL queries. Exploitation of this vulnerability could lead to the extraction of sensitive information from the database.

3.5
Jan 16, 2025

WordPress Multi Step Form Plugin Unauthorized File Upload Vulnerability

A vulnerability exists in the Multi Step Form plugin for WordPress, allowing unauthorized file uploads. This issue arises from a lack of proper capability checks on the 'fw_upload_file' AJAX action, affecting all versions up to and including 1.7.23. As a result, unauthenticated attackers can upload certain file types, such as images.

3.4
Jan 16, 2025

Fortinet FortiRecorder, FortiWeb, and FortiVoice Path Traversal Vulnerability Allowing Privilege Escalation

A path traversal vulnerability has been identified in Fortinet FortiRecorder versions 7.2.0 through 7.2.1 and 7.0.0 through 7.0.4, as well as FortiWeb versions 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.10, and 6.4.0 through 6.4.3. Additionally, FortiVoice versions 7.0.0 through 7.0.4, 6.4.0 through 6.4.9, and 6.0.0 through 6.0.12 are affected. This vulnerability allows attackers to escalate privileges by sending specially crafted packets, taking advantage of improper restrictions on file paths that could lead to accessing unauthorized directories.

2.6
Jan 16, 2025

Fortinet FortiAnalyzer, FortiManager, and FortiAnalyzer Cloud Privilege Escalation Vulnerability

A vulnerability allowing privilege escalation has been identified in Fortinet FortiAnalyzer, FortiManager, and FortiAnalyzer Cloud. This issue arises from incorrect privilege assignments and affects multiple versions across these products. Specifically, it impacts FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, and 6.4.0 through 6.4.15. FortiManager versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, and 6.4.0 through 6.4.15 are also affected. Additionally, FortiAnalyzer Cloud versions 7.4.1 through 7.4.2, 7.2.1 through 7.2.6, 7.0.1 through 7.0.13, and 6.4.1 through 6.4.7 are vulnerable. The vulnerability allows attackers to escalate privileges by using specific shell commands.

3.7
Jan 16, 2025

Octopus Deploy Kubernetes Worker and Agent Sensitive Variable Logging Vulnerability

A vulnerability exists in Octopus Deploy Kubernetes worker and agent versions 1.x prior to 1.19.0 and 2.x prior to 2.8.0, allowing sensitive variables to be logged in clear text in the Kubernetes script pod logs. This issue was initially identified in version 2 but was later found to affect version 1 as well.

1.7
Jan 16, 2025

Chamber Dashboard Business Directory Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Chamber Dashboard Business Directory plugin for WordPress, affecting all versions through 3.3.8. The issue arises from inadequate input sanitization and output escaping on user-supplied attributes within the 'business_categories' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.8
Jan 16, 2025

WP User Profile Avatar Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP User Profile Avatar plugin for WordPress, affecting all versions through 1.0.5. The issue arises from inadequate nonce validation in the wpupa_user_admin() function, allowing unauthenticated attackers to manipulate plugin settings. Exploitation requires tricking a site administrator into clicking a link that generates a forged request.

2.7
Jan 16, 2025

RE11S Stack Overflow Vulnerability in PPPoE Setup Function

A stack overflow vulnerability has been identified in RE11S version 1.11. The issue arises in the formPPPoESetup function, where the pppUserName parameter can be manipulated to cause a buffer overflow. This vulnerability was discovered during an internship at Qi An Xin Tiangong Lab, while analyzing the router's web interface.

3.9
Jan 16, 2025

Edimax RE11S Stack Overflow Vulnerability in FormStaDrvSetup Function

A stack overflow vulnerability has been identified in the Edimax RE11S router, specifically in version 1.11. The issue arises in the formStaDrvSetup function, where the rootAPmac parameter can be manipulated to cause a buffer overflow. This vulnerability allows for a sprintf-based stack overflow, potentially leading to arbitrary code execution.

4.2
Jan 16, 2025

Edimax RE11S Command Injection Vulnerability

A command injection vulnerability has been identified in the Edimax RE11S router, specifically in version 1.11. The issue arises in the component '/goform/formAccept', where user-supplied data can be manipulated to execute arbitrary system commands.

4.0
Jan 16, 2025

Edimax RE11S Stack Overflow Vulnerability in formWlSiteSurvey Function

A stack overflow vulnerability has been identified in the Edimax RE11S router, specifically in version 1.11. The issue arises in the formWlSiteSurvey function, where the selSSID parameter can be manipulated to cause a buffer overflow. This vulnerability exploits a strncpy function, leading to a potential overflow of the stack.

3.9
Jan 16, 2025

RE11S Command Injection Vulnerability in Router via L2TPUserName Parameter

A command injection vulnerability has been identified in the RE11S router, specifically in version 1.11. The issue arises in the setWAN function, where the L2TPUserName parameter can be manipulated to execute arbitrary system commands.

4.0
Jan 16, 2025

Edimax RE11S Command Injection Vulnerability

A command injection vulnerability has been identified in the Edimax RE11S router, specifically in version 1.11. The issue arises in the '/goform/mp' endpoint, where user-supplied command parameters are not properly sanitized, allowing for arbitrary command execution on the system.

4.0
Jan 16, 2025

Edimax RE11S Stack Overflow Vulnerability in setWAN Function

A stack overflow vulnerability has been identified in the Edimax RE11S router, specifically in version 1.11. The issue arises in the setWAN function, where the pptpUserName parameter can be manipulated to cause a buffer overflow. This vulnerability allows for a sprintf-based stack overflow, potentially leading to arbitrary code execution.

3.0
Jan 16, 2025

NetVision Information airPASS OS Command Injection Vulnerability

A command injection vulnerability has been identified in the airPASS application by NetVision Information, specifically in versions 2.9.0.x and 3.0.0.x. This vulnerability allows remote attackers with normal user privileges to inject and execute arbitrary operating system commands.

1.9