CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 14, 2025

Siemens Industrial Edge Management OS Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in all versions of Siemens Industrial Edge Management OS (IEM-OS). This vulnerability allows attackers to extract sensitive information by deceiving users into clicking on malicious links.

2.0
Jan 14, 2025

Page Builder by SiteOrigin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Page Builder by SiteOrigin plugin for WordPress, affecting all versions through 2.31.0. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into pages. These scripts are executed when a user views the affected page.

5.3
Jan 14, 2025

Y'S Corporation STEALTHONE D220/D340 SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the STEALTHONE D220 and D340 models, both running firmware through version 6.03.02. This vulnerability allows an attacker with access to the device to retrieve the administrative password for the web management interface.

2.6
Jan 14, 2025

Y'S Corporation STEALTHONE D220/D340 OS Command Injection Vulnerability

An OS command injection vulnerability has been identified in the STEALTHONE D220 and D340 network storage servers, both of which are affected by firmware versions through 6.03.02. This vulnerability allows an attacker with access to the device to execute arbitrary operating system commands.

2.7
Jan 14, 2025

Y'S Corporation STEALTHONE D220/D340/D440 OS Command Injection Vulnerability

An OS command injection vulnerability has been identified in network storage servers STEALTHONE D220, D340, and D440, all provided by Y'S Corporation. This vulnerability affects users with administrative privileges who are logged into the web management interface. The flaw allows these users to execute arbitrary operating system commands.

1.7
Jan 14, 2025

Paid Memberships Subscriptions Authentication Bypass Vulnerability

An authentication bypass vulnerability has been identified in the Paid Membership Subscriptions plugin for WordPress, affecting all versions through 2.13.7. The issue arises in the 'pms_pb_payment_redirect_link' function, which improperly uses the 'pms_payment_id' parameter to authenticate users without adequate identity verification. This flaw allows unauthenticated attackers who know a valid payment ID to log in as any user who has made a purchase on the site.

5.6
Jan 14, 2025

Groundhogg WordPress Plugin Arbitrary File Upload Vulnerability

A vulnerability allowing arbitrary file uploads has been identified in the Groundhogg WordPress plugin, specifically in versions through 3.7.3.5. This issue arises from inadequate file type validation in the 'gh_big_file_upload' function. As a result, authenticated attackers with Author-level access or higher can upload arbitrary files to the server, potentially leading to remote code execution.

4.2
Jan 14, 2025

Royal Elementor Addons and Templates Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Royal Elementor Addons and Templates plugin for WordPress, affecting all versions through 1.7.1006. The vulnerability arises from inadequate nonce validation in the 'wpr_filter_grid_posts()' function, allowing unauthenticated attackers to inject malicious scripts by tricking a site administrator into clicking a link.

4.4
Jan 14, 2025

HTML5 Video Player WordPress Plugin DOM-Based Stored Cross-Site Scripting Vulnerability

A DOM-Based Stored Cross-Site Scripting vulnerability has been identified in the HTML5 Video Player – mp4 Video Player Plugin and Block for WordPress. This issue affects all versions through 2.5.35 and arises from inadequate input sanitization and output escaping. The vulnerability allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the compromised pages.

3.7
Jan 14, 2025

Keycloak Unrestricted Access to Environment Variables Vulnerability for Admin Users

A vulnerability in Keycloak allows admin users to access sensitive server environment variables and system properties through user-configurable URLs. This issue arises when admin users configure backchannel logout URLs or admin URLs, as they can include placeholders that the server replaces with actual values during URL processing. The vulnerability is present in Red Hat build of Keycloak 26.0.8, specifically within the Keycloak Quarkus server component.

3.6
Jan 14, 2025

Keycloak Denial-of-Service Vulnerability via Security Header Manipulation

A denial-of-service vulnerability exists in Keycloak that allows an administrative user with the authority to change realm settings to disrupt service. This is achieved by altering security headers and adding newlines, which causes the Keycloak server to process a request that has already been terminated, resulting in the failure of that request. Consequently, users may experience disruptions when accessing applications that rely on Keycloak or its administrative consoles within the affected realm.

3.8
Jan 14, 2025

W3 Total Cache Information Exposure Vulnerability

A vulnerability allowing information exposure has been identified in the W3 Total Cache plugin for WordPress, affecting all versions through 2.8.1. The issue arises from a publicly accessible debug log file that can reveal sensitive information, such as nonce values, which could be exploited in cross-site request forgery (CSRF) attacks. This vulnerability requires the debug feature to be enabled, which is off by default.

2.7
Jan 14, 2025

W3 Total Cache Missing Capability Check Vulnerability Allowing Unauthenticated Plugin Deactivation and Extensions Management

A vulnerability exists in the W3 Total Cache plugin for WordPress, affecting all versions through 2.8.1. The issue arises from a lack of proper capability checks in several functions, allowing unauthenticated users to deactivate the main plugin and manage its extensions by activating or deactivating them.

3.5
Jan 14, 2025

WP Booking Calendar Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WP Booking Calendar plugin for WordPress, affecting all versions through 10.9.2. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'booking' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected page.

4.8
Jan 14, 2025

Veeam Backup for Microsoft Azure Server-Side Request Forgery Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability has been identified in Veeam Backup for Microsoft Azure, specifically in version 7.1.0.22 and all earlier versions. This vulnerability allows an unauthenticated attacker to send unauthorized requests from the system, which could lead to network enumeration or facilitate other types of attacks.

2.5
Jan 14, 2025

Zyxel WBE530 and WBE660S Improper Privilege Management Vulnerability Allowing Privilege Escalation

A vulnerability has been identified in the web management interface of the Zyxel WBE530 and WBE660S access points. This vulnerability, present in WBE530 firmware versions through 7.00(ACLE.3) and WBE660S firmware versions through 6.70(ACGG.2), allows an authenticated user with limited privileges to escalate their privileges to that of an administrator. This privilege escalation could enable the user to upload configuration files to the affected device.

3.4
Jan 14, 2025

WeGIA Stored Cross-Site Scripting Vulnerability in remuneration.php

A stored cross-site scripting vulnerability has been identified in the WeGIA application, specifically within the 'remuneracao.php' endpoint. This issue allows attackers to inject malicious scripts into the 'descricao' parameter, which are then stored on the server. The injected scripts are executed automatically when the affected page is accessed by users, creating a significant security risk. The vulnerability arises from the application's failure to properly validate and sanitize user inputs, enabling the injection of harmful scripts that could compromise user data and systems.

2.8
Jan 14, 2025

WeGIA Stored Cross-Site Scripting Vulnerability in Control.php Endpoint

A stored cross-site scripting vulnerability has been identified in the WeGIA application, specifically within the control.php endpoint. This issue allows attackers to inject malicious scripts into the 'cargo' parameter, which are then stored on the server. The injected scripts are executed automatically when the affected page is accessed by users, creating a significant security risk. The vulnerability arises from the application's failure to properly validate and sanitize user inputs, enabling the injection of harmful scripts that can compromise user data and systems.

2.9
Jan 14, 2025

WeGIA Reflected Cross-Site Scripting Vulnerability in pre_cadastro_funcionario.php

A reflected cross-site scripting vulnerability has been identified in the WeGIA application, specifically within the 'pre_cadastro_funcionario.php' endpoint. This issue arises because the application does not properly validate or sanitize user inputs in the 'msg_e' parameter, allowing attackers to inject malicious scripts. These scripts are then executed in the context of the user's browser. The vulnerability affects WeGIA versions prior to 3.2.6.

2.9
Jan 14, 2025

WeGIA Stored Cross-Site Scripting Vulnerability in adicionar_tipo_quadro_horario.php Endpoint

A stored cross-site scripting vulnerability has been identified in the WeGIA application, specifically within the 'adicionar_tipo_quadro_horario.php' endpoint. This issue allows attackers to inject malicious scripts into the 'tipo' parameter, which are then stored on the server. The injected scripts are executed automatically when the affected page is accessed by users, creating a significant security risk. The vulnerability arises from the application's failure to properly validate and sanitize user inputs, enabling the injection of harmful scripts that can compromise user data and systems.

2.9
Jan 14, 2025

WeGIA Reflected Cross-Site Scripting Vulnerability in tags.php Endpoint

A reflected cross-site scripting vulnerability has been identified in the WeGIA application, specifically within the tags.php endpoint. This issue arises because the application does not properly validate or sanitize user inputs in the msg_e parameter, allowing attackers to inject malicious scripts. These scripts are then executed in the context of the user's browser. The vulnerability affects WeGIA versions prior to 3.2.6 and has been addressed in version 3.2.8. Users are advised to upgrade.

2.8
Jan 14, 2025

WeGIA Stored Cross-Site Scripting Vulnerability in adicionar_situacao.php Endpoint

A stored cross-site scripting vulnerability has been identified in the WeGIA application, specifically within the adicionar_situacao.php endpoint. This issue allows attackers to inject malicious scripts into the situacao parameter, which are then stored on the server. The injected scripts are executed automatically when the affected page is accessed by users, creating a significant security risk. The vulnerability arises from inadequate validation and sanitization of user inputs, enabling the injection of harmful scripts that can compromise user data and systems.

2.9
Jan 14, 2025

WeGIA Stored Cross-Site Scripting Vulnerability in adicionar_escala.php Endpoint

A stored cross-site scripting vulnerability has been identified in the WeGIA application, specifically within the adicionar_escala.php endpoint. This issue allows attackers to inject malicious scripts into the escala parameter, which are then stored on the server. The injected scripts are executed automatically when the affected page is accessed by users, creating a significant security risk. The vulnerability arises from the application's failure to properly validate and sanitize user inputs, enabling the injection of harmful scripts that can compromise user data and systems.

2.9
Jan 14, 2025

WeGIA Stored Cross-Site Scripting Vulnerability in adicionar_alergia.php

A stored cross-site scripting vulnerability has been identified in the WeGIA application, specifically within the adicionar_alergia.php endpoint. This issue allows attackers to inject malicious scripts into the nome parameter, which are then stored on the server. The injected scripts are executed automatically when the affected page is accessed by users, creating a significant security risk. The vulnerability arises from the application's failure to properly validate and sanitize user inputs, enabling the injection of harmful scripts that can compromise user data and systems.

2.8
Jan 14, 2025

WeGIA Reflected Cross-Site Scripting Vulnerability in 'cadastro_funcionario.php' Endpoint

A reflected cross-site scripting vulnerability has been identified in the WeGIA application, specifically within the 'cadastro_funcionario.php' endpoint. This issue arises because the application does not properly validate and sanitize user inputs in the 'cpf' parameter, allowing attackers to inject malicious scripts. These scripts are then executed in the context of the user's browser. The vulnerability affects WeGIA versions prior to 3.2.6.

2.8
Jan 14, 2025

SAP NetWeaver Application Server for ABAP Improper Authentication Vulnerability Allowing Privilege Escalation

A vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform allows authenticated attackers to exploit improper authentication checks, leading to unauthorized access and privilege escalation. This exploitation can cause significant security issues, with a high impact on confidentiality, integrity, and availability.

3.9
Jan 14, 2025

SAP SAPSetup Privilege Escalation Vulnerability via DLL Injection

A DLL injection vulnerability in SAPSetup allows an attacker with local user privileges or access to a compromised corporate user's Windows account to gain elevated privileges. This exploitation could facilitate lateral movement within the network and further compromise the company's Active Directory, significantly impacting the confidentiality, integrity, and availability of the Windows server.

3.3
Jan 14, 2025

SAP NetWeaver Application Server ABAP Authorization Check Vulnerability

A vulnerability exists in SAP NetWeaver Application Server ABAP due to an outdated feature that failed to implement necessary authorization checks. This flaw allows authenticated attackers to access information that is normally restricted. The vulnerability does not affect the application's integrity or availability.

3.8
Jan 14, 2025

SAP NetWeaver Application Server Java Missing Authorization Check Vulnerability Allowing JCo Connection Entry Creation

A vulnerability exists in SAP NetWeaver Application Server Java due to a missing authorization check on service endpoints. This flaw allows an attacker with a standard user role to create JCo connection entries, facilitating remote function calls to or from the application server. The vulnerability could result in a low impact on the application's confidentiality, integrity, and availability.

4.1
Jan 14, 2025

SAP NetWeaver AS for ABAP and ABAP Platform Access Control Vulnerability

A vulnerability exists in SAP NetWeaver AS for ABAP and ABAP Platform, specifically within the Internet Communication Framework. Under certain conditions, weak access controls allow an attacker to access restricted information. This vulnerability could significantly impact the confidentiality, integrity, and availability of affected applications.

4.1
Jan 14, 2025

SAP NetWeaver AS ABAP Authorization Bypass Vulnerability in RFC Function Modules

A vulnerability exists in SAP NetWeaver AS ABAP and ABAP Platform, where authorization checks are not properly enforced for certain Remote Function Call (RFC) function modules. This flaw allows an attacker with basic user privileges to manipulate data in the Informix database, potentially leading to a complete compromise of confidentiality, integrity, and availability.

4.2
Jan 14, 2025

SAP BusinessObjects Business Intelligence Platform Session Hijacking Vulnerability

An information disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to hijack sessions over the network without user interaction. This vulnerability enables the attacker to access and modify all application data.

4.5
Jan 14, 2025

SAP BusinessObjects Business Intelligence Platform Cross-Site Scripting Vulnerability Allowing Data Theft and Impersonation

A cross-site scripting vulnerability has been identified in SAP BusinessObjects Business Intelligence Platform. This issue allows an authenticated user with limited access to inject malicious JavaScript that can read sensitive information from the server and send it to the attacker. The attacker could then use this information to impersonate a high-privileged user, significantly impacting the application's confidentiality and integrity.

3.6
Jan 14, 2025

SAP NetWeaver AS ABAP SAP GUI for HTML Local Storage Data Exposure Vulnerability

A vulnerability exists in applications using SAP GUI for HTML on SAP NetWeaver Application Server ABAP, where user input is stored in the local browser storage. This storage is accessible to attackers with administrative privileges or those who can access the victim's user directory at the operating system level. The exposed data, depending on the user input in transactions, could range from non-critical to highly sensitive, significantly impacting the application's confidentiality.

3.9
Jan 14, 2025

SAP Business Workflow and Flexible Workflow Sensitive Information Disclosure Vulnerability

A vulnerability exists in SAP Business Workflow and SAP Flexible Workflow, allowing authenticated attackers to manipulate parameters in legitimate resource requests. This manipulation can lead to unauthorized access to sensitive information that is normally restricted. However, the attackers cannot modify or disrupt the availability of the information.

1.7
Jan 14, 2025

SAP NetWeaver AS JAVA Stored Cross-Site Scripting Vulnerability in User Admin Application

A stored cross-site scripting vulnerability has been identified in the User Admin Application of SAP NetWeaver AS JAVA. This issue allows an attacker, impersonating an admin, to upload a photo containing malicious JavaScript. When a victim accesses the affected component, the injected script can be executed, potentially leading to unauthorized reading and modification of information within the victim's web browser.

3.9
Jan 14, 2025

SAP GUI for Java User Input Data Disclosure Vulnerability

A vulnerability exists in SAP GUI for Java that allows for the unauthorized reading of user input data saved on the client PC. This issue can be exploited by an attacker with administrative privileges or access to the victim's user directory at the Operating System level. The disclosed data, which could range from non-critical to highly sensitive depending on the user input in transactions, poses a significant risk to the application's confidentiality.

0.9
Jan 14, 2025

SAP GUI for Windows User Input Data Disclosure Vulnerability

A vulnerability exists in SAP GUI for Windows that allows for the unauthorized reading of user input data stored on the client PC. This issue arises under specific conditions, where an attacker with administrative privileges or access to the victim's user directory at the Operating System level could access the data. The impact of this vulnerability varies depending on the nature of the user input, potentially leading to the disclosure of either non-critical or highly sensitive information, thereby significantly compromising the application's confidentiality.

3.5
Jan 14, 2025

SAP NetWeaver Application Server for ABAP Unauthorized Access to System Information Vulnerability

A vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform allows unauthorized access to system information, including details like system configuration. This issue arises from a specific URL parameter that can be exploited by an unauthenticated attacker. While the vulnerability has a limited impact on confidentiality, it could be used to facilitate further attacks or exploits.

4.6
Jan 14, 2025

OpenLink Virtuoso Denial-of-Service Vulnerability in sqlg_group_node Component

A denial-of-service vulnerability has been identified in the sqlg_group_node component of OpenLink Virtuoso Open Source version 7.2.11. This issue allows attackers to disrupt service by executing crafted SQL statements that cause the application to crash.

4.1
Jan 14, 2025

OpenLink Virtuoso Denial-of-Service Vulnerability in sqlg_place_dpipes Component

A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the sqlg_place_dpipes component, where attackers can cause a service disruption by sending crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image.

4.1
Jan 14, 2025

OpenLink Virtuoso-Opensource Denial-of-Service Vulnerability in SQLG Hash Source Component

A denial-of-service vulnerability has been identified in OpenLink Virtuoso-Opensource version 7.2.11. The issue arises in the SQLG hash source component, where attackers can cause a crash by sending crafted SQL statements. This vulnerability can be reproduced using the database management system's fuzzer, and it is also present in the beta Docker image of Virtuoso.

4.1
Jan 14, 2025

OpenLink Virtuoso SQL Injection Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability has been identified in the OpenLink Virtuoso open-source version 7.2.11. The issue arises in the 'sqlo_df' component, where attackers can cause a service crash by sending specially crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image by executing the malicious SQL through the isql command-line interface.

4.1
Jan 14, 2025

OpenLink Virtuoso SQL Injection Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the 'sqlo_expand_jts' component, where attackers can cause a crash by sending specially crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image.

4.1
Jan 14, 2025

OpenLink Virtuoso Parallel SQL Component Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11, specifically within the 'sqlg_parallel_ts_seq' component. This issue allows attackers to disrupt service by executing crafted SQL statements that exploit the vulnerability.

4.1
Jan 14, 2025

OpenLink Virtuoso-Opensource Denial-of-Service Vulnerability in SQL Tree Hash Component

A denial-of-service vulnerability has been identified in OpenLink Virtuoso-Opensource version 7.2.11. The issue arises in the SQL tree hash component, where attackers can cause a service disruption by sending crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image.

4.1
Jan 14, 2025

OpenLink Virtuoso-OpenSource Denial-of-Service Vulnerability in SQL Vector Update Component

A denial-of-service vulnerability has been identified in OpenLink Virtuoso-OpenSource version 7.2.11. The issue arises in the 'sqlg_vec_upd' component, where attackers can cause a crash by sending specially crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image by executing the proof-of-concept SQL payload through the isql command-line interface.

4.1
Jan 14, 2025

OpenLink Virtuoso-OpenSource Denial-of-Service Vulnerability in SQL Distinct Node Component

A denial-of-service vulnerability has been identified in OpenLink Virtuoso-OpenSource version 7.2.11. The issue arises in the 'sqlc_add_distinct_node' component, where attackers can cause a crash by sending specially crafted SQL statements. This vulnerability can be reproduced using the beta Docker image of Virtuoso.

4.1
Jan 14, 2025

OpenLink Virtuoso Denial-of-Service Vulnerability in dfe_n_in_order Component

A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the dfe_n_in_order component, where attackers can cause a crash by sending specially crafted SQL statements. This vulnerability can be reproduced using the beta Docker image of Virtuoso 7.2.11.

4.1
Jan 14, 2025

Openlink Virtuoso-Opensource Denial-of-Service Vulnerability in QST_VEC_GET_INT64 Component

A denial-of-service vulnerability has been identified in Openlink Virtuoso-Opensource version 7.2.11. The issue arises in the 'qst_vec_get_int64' component, where attackers can cause a crash by executing crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image.

4.1