CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 13, 2025

Samsung Exynos Processors Information Leak Vulnerability via Malformed Uplink Scheduling Message

A vulnerability exists in several Samsung mobile processors, wearable processors, and modems, including the Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, and Modem 5300. The issue arises because the user equipment (UE) improperly processes a malformed uplink scheduling message, leading to an unintentional information leak from the UE.

4.5
Jan 13, 2025

Samsung Exynos Processors Stack Out-of-Bounds Write Vulnerability

A vulnerability exists in several Samsung mobile processors, including Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. The issue arises from a lack of proper length validation, leading to a stack out-of-bounds write in the function loadOutputBuffers.

4.1
Jan 13, 2025

Pega Platform Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting (XSS) vulnerability has been identified in Pega Platform, affecting versions 8.1 through 24.2.0. This vulnerability allows attackers to inject malicious scripts into the application, which can be executed in the context of the user.

2.8
Jan 13, 2025

Teedy Cross-Site Request Forgery Vulnerability Allowing Account Takeover

A cross-site request forgery (CSRF) vulnerability has been identified in Teedy versions through 1.11. This vulnerability allows for account takeover by sending a POST request to the /api/user/admin endpoint.

3.7
Jan 13, 2025

Post SMTP WordPress Plugin Broken Access Control Vulnerability

A broken access control vulnerability has been identified in the Post SMTP WordPress plugin, affecting versions through 2.9.11. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileged users.

4.3
Jan 13, 2025

GiveWP WordPress Plugin PHP Object Injection Vulnerability

A deserialization vulnerability allowing PHP object injection has been identified in the GiveWP WordPress plugin, affecting versions through 3.19.3. This vulnerability could potentially lead to various types of code injection, including SQL injection, path traversal, and denial-of-service, especially if a suitable object injection chain is exploited.

5.2
Jan 13, 2025

WordPress Scanventory Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Scanventory plugin, affecting versions through 1.1.3. This issue allows attackers to inject malicious scripts that are executed when users visit the affected page.

2.0
Jan 13, 2025

Detlef Stöver WPEX Replace DB Urls Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WPEX Replace DB Urls WordPress plugin, affecting versions through 0.4.0. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.

2.0
Jan 13, 2025

WordPress Scan External Links Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Scan External Links plugin, affecting versions through 1.0. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.

2.0
Jan 13, 2025

WordPress Site PIN Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Site PIN plugin, affecting versions through 1.3. This issue allows attackers to inject malicious scripts that could be executed when users visit the affected site.

2.0
Jan 13, 2025

WordPress Inline Tweets Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Inline Tweets plugin, affecting versions through 2.0. This issue allows attackers to inject malicious scripts that are executed when users view the affected content.

2.0
Jan 13, 2025

WordPress Featured Page Widget Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Featured Page Widget plugin, affecting versions through 2.2. This issue allows attackers to inject malicious scripts that are executed when users visit the affected page.

2.0
Jan 13, 2025

WordPress Post And Page Reactions Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Post And Page Reactions plugin, specifically in versions through 1.0.5. This issue allows attackers to inject malicious scripts that could be executed when users visit the affected page.

2.0
Jan 13, 2025

TRUSTist REVIEWer Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the TRUSTist REVIEWer WordPress plugin, affecting versions through 2.0. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.

2.0
Jan 13, 2025

Yamna KNR Author List Widget Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Yamna KNR Author List Widget, affecting versions through 3.1.1. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 13, 2025

SmartAgenda WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the SmartAgenda WordPress plugin, specifically in versions through 4.7. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 13, 2025

FAKTOR VIER F4 Post Tree Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the FAKTOR VIER F4 Post Tree WordPress plugin, affecting versions through 1.1.18. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected page.

2.0
Jan 13, 2025

New Normal LLC LucidLMS Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the New Normal LLC LucidLMS WordPress plugin, affecting versions through 1.0.5. This issue allows attackers to inject malicious scripts that are executed when users visit the affected page.

2.0
Jan 13, 2025

WordPress Media Category Library Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Media Category Library plugin, affecting versions through 2.7. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 13, 2025

Infosoft Consultant Order Audit Log for WooCommerce Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Infosoft Consultant Order Audit Log for WooCommerce plugin, affecting versions through 2.0. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.

2.0
Jan 13, 2025

WP Scripts Food Store Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WP Scripts Food Store plugin for WordPress, specifically in versions through 1.5.3. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 13, 2025

Eniture Technology Distance Based Shipping Calculator Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Eniture Technology Distance Based Shipping Calculator plugin for WordPress, affecting versions through 2.0.21. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.

2.0
Jan 13, 2025

Saleswonder.biz WP2LEADS Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Saleswonder.biz WP2LEADS plugin, affecting versions through 3.4.2. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected page.

2.0
Jan 13, 2025

Apache CloudStack Access Validation Vulnerability Allowing Unauthorized Annotation Management

An access validation vulnerability has been identified in Apache CloudStack versions 4.16.0 and later. This issue allows users with knowledge of resource UUIDs to list and add comments (annotations) on resources they are authorized to access. While this vulnerability could lead to a loss of confidentiality if annotations contain privileged information, the overall impact is considered very low. CloudStack administrators can temporarily restrict access to the annotation management APIs for non-admin roles.

4.1
Jan 13, 2025

Imagination Technologies GPU Driver Out-of-Bounds Write Vulnerability in DDK Releases through 24.2 RTM2

A vulnerability exists in the GPU Device Driver Development Kit (DDK) within a Guest VM, where the kernel can send improper commands to the GPU firmware. This flaw can disrupt memory reconstruction processes, leading to unauthorized data writes outside the virtualized GPU memory of the Guest. The issue arises from unchecked block counts and reference count mismanagement, allowing exploitation of shared memory with the GPU firmware.

1.4
Jan 13, 2025

Imagination Technologies GPU Driver Out-of-Bounds Write Vulnerability Allowing Arbitrary Memory Access

A vulnerability exists in the GPU driver provided by Imagination Technologies, specifically in the Graphics Processing Unit (GPU) Driver Development Kit (DDK) version 24.2 RTM2 and prior. This vulnerability allows kernel software running inside a Guest Virtual Machine (VM) to exploit memory shared with the GPU firmware. The exploitation can lead to writing data outside the Guest's virtualized GPU memory, potentially causing unauthorized access to physical memory or corruption of memory used by the kernel and other drivers.

1.4
Jan 13, 2025

Imagination Technologies GPU Driver Out-of-Bounds Write Vulnerability Allowing Arbitrary Memory Access

A vulnerability exists in the GPU driver of Imagination Technologies, specifically within the Graphics Processing Unit (GPU) Driver Development Kit (DDK) version 24.2 RTM2 and prior releases. This vulnerability allows kernel software running inside a Guest Virtual Machine (VM) to send improper commands to the GPU firmware. As a result, it can write data outside the Guest's virtualized GPU memory, potentially leading to unauthorized access or corruption of memory.

1.3
Jan 13, 2025

Imagination Technologies GPU Driver Out-of-Bounds Write Vulnerability Allowing Arbitrary Memory Access

A vulnerability exists in the GPU driver provided by Imagination Technologies, specifically in the Graphics Processing Unit (GPU) Driver Development Kit (DDK) version 24.2 RTM2 and earlier. This vulnerability allows kernel software running inside a Guest Virtual Machine (VM) to exploit memory shared with the GPU firmware. The exploitation can lead to writing data outside the virtualized GPU memory of the guest, potentially causing unauthorized access to physical memory or corruption of memory used by the kernel and other drivers.

1.4
Jan 13, 2025

Imagination Technologies GPU Driver Out-of-Bounds Write Vulnerability Allowing Platform Instability

A vulnerability exists in the GPU driver from Imagination Technologies, specifically in the GPU DDK, that allows software running as a non-privileged user to perform improper GPU system calls. This mismanagement can lead to out-of-bounds writes in kernel memory, causing platform instability and unexpected reboots. The issue arises from integer overflows in memory management functions, which can be exploited to write outside the allocated memory boundaries, particularly in virtualized environments.

1.4
Jan 13, 2025

Imagination Technologies GPU Driver Out-of-Bounds Read Vulnerability Allowing Memory Access Outside Guest VM

A vulnerability exists in the GPU driver of Imagination Technologies that allows kernel software running in a Guest VM to send improper commands to the GPU firmware. This can result in reading or writing data outside the virtualized GPU memory allocated to the guest. The issue arises from mismanagement of memory access, particularly with physical memory pages that have been freed or are not properly synchronized.

1.3
Jan 13, 2025

Imagination Technologies GPU Driver Out-of-Bounds Read Vulnerability in Guest VMs

A vulnerability exists in the GPU driver that can be exploited by kernel software running in a Guest VM. The issue arises because the software may send improper commands to the GPU firmware, allowing it to read data from outside the Guest's virtualized GPU memory. This vulnerability affects several different DDK releases, up to and including 24.3.

1.4
Jan 13, 2025

Email Subscribers by Icegram Express Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Email Subscribers by Icegram Express WordPress plugin, affecting versions prior to 5.7.45. The issue arises because the plugin fails to properly sanitize and escape certain Workflow settings. This flaw enables high-privilege users, such as administrators, to execute stored cross-site scripting attacks, even in environments where the unfiltered_html capability is restricted, such as multisite setups.

4.2
Jan 13, 2025

Email Subscribers by Icegram Express Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Email Subscribers by Icegram Express WordPress plugin, affecting versions prior to 5.7.45. The issue arises because the plugin fails to properly sanitize and escape certain form settings. This flaw enables high-privilege users, such as administrators, to execute stored cross-site scripting attacks, even in environments where the unfiltered_html capability is restricted, such as multisite setups.

4.3
Jan 13, 2025

Email Subscribers by Icegram Express Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Email Subscribers by Icegram Express WordPress plugin, affecting versions prior to 5.7.45. The issue arises because the plugin fails to properly sanitize and escape certain form settings. This flaw enables high-privilege users, such as administrators, to execute stored cross-site scripting attacks, even in environments where the unfiltered_html capability is restricted, such as multisite setups.

2.8
Jan 13, 2025

WordPress Appointment Booking Calendar and Scheduling Plugin Unauthenticated Export Vulnerability

A vulnerability exists in the Appointment Booking Calendar and Scheduling WordPress plugins, prior to version 1.1.23, allowing unauthenticated attackers to access exported settings files. The plugins export data to a public directory using an easily guessable file name, potentially exposing sensitive information if the exported files are present.

3.9
Jan 13, 2025

Email Subscribers by Icegram Express Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Email Subscribers by Icegram Express WordPress plugin, affecting versions prior to 5.7.45. The issue arises because the plugin fails to properly sanitize and escape certain Text Block options. This flaw enables high-privilege users, such as administrators, to execute stored cross-site scripting attacks, even in environments where the unfiltered_html capability is restricted, such as multisite setups.

4.2
Jan 13, 2025

Luxion KeyShot Viewer Memory Corruption Vulnerability Leading to Remote Code Execution

A remote code execution vulnerability has been identified in Luxion KeyShot Viewer, all versions prior to 2023.3. This issue arises from improper validation of user-supplied data in the processing of KSP files, leading to memory corruption. Exploitation of this vulnerability requires user interaction, such as opening a malicious KSP file.

3.7
Jan 13, 2025

Liujianview Gymxmjpa SQL Injection Vulnerability in Menber Controller

A critical SQL injection vulnerability has been identified in Liujianview Gymxmjpa version 1.0. The issue arises in the MenberDaoInpl function within the MenberController.java file. The vulnerability is triggered by unfiltered input in the hyname parameter, allowing for blind SQL injection. This vulnerability can be exploited remotely.

3.0
Jan 13, 2025

Liujianview Gymxmjpa SQL Injection Vulnerability in Membertype Controller

A critical SQL injection vulnerability has been identified in Liujianview Gymxmjpa version 1.0. The issue resides in the MembertypeController, specifically within the MembertypeDaoImpl function. The vulnerability arises because the typeName parameter is not properly sanitized, allowing for malicious SQL code to be injected and executed. This flaw can be exploited remotely, and details of the exploitation have been made public.

3.1
Jan 13, 2025

liujianview gymxmjpa SQL Injection Vulnerability in LoosController

A critical SQL injection vulnerability has been identified in liujianview gymxmjpa version 1.0. The issue arises in the LoosController.java file, specifically within the LoosDaoImpl function. The vulnerability allows for remote exploitation by manipulating the loosName parameter, which is not properly sanitized before being used in SQL queries.

3.0
Jan 13, 2025

liujianview gymxmjpa SQL Injection Vulnerability in Equipment Controller

A critical SQL injection vulnerability has been identified in liujianview gymxmjpa version 1.0. The issue resides in the EquipmentDaoImpl function within the EquipmentController.java file. The vulnerability allows for remote exploitation by manipulating the hyname parameter, which is not properly sanitized before being used in SQL queries.

3.0
Jan 13, 2025

Liujianview Gymxmjpa SQL Injection Vulnerability in Subject Controller

A critical SQL injection vulnerability has been identified in Liujianview Gymxmjpa version 1.0. The issue arises in the SubjectDaoImpl function within the SubjectController.java file, where the subname parameter is not properly sanitized. This flaw allows for blind SQL injection attacks that can be executed remotely.

3.0
Jan 13, 2025

Liujianview Gymxmjpa SQL Injection Vulnerability in GoodsController

A critical SQL injection vulnerability has been identified in Liujianview Gymxmjpa version 1.0. The issue arises in the GoodsDaoImpl function within the GoodsController.java file, where the goodsName parameter is not properly sanitized. This flaw allows for remote exploitation by injecting malicious SQL that could be executed by the database.

3.0
Jan 13, 2025

Liujianview Gymxmjpa SQL Injection Vulnerability in CoachController

A critical SQL injection vulnerability has been identified in Liujianview Gymxmjpa version 1.0. The issue resides in the CoachController, specifically within the count method, where the coachName parameter is not properly sanitized. This oversight allows for blind SQL injection attacks, which can be executed remotely.

3.5
Jan 13, 2025

Reggie Phone Number Validation Handler Information Disclosure Vulnerability

An information disclosure vulnerability has been identified in Reggie version 1.0, specifically within the Phone Number Validation Handler component. The issue arises in the '/user/sendMsg' file, where the 'code' argument can be manipulated, leading to unauthorized access to sensitive information. This vulnerability can be exploited remotely, and the details have been made public.

3.3
Jan 13, 2025

Reggie Unrestricted File Upload Vulnerability

A critical vulnerability in Reggie version 1.0 allows for unrestricted file uploads. The issue arises in the upload function of the CommonController.java file, where only front-end validation of file extensions is performed. This flaw enables attackers to upload any type of file, potentially leading to further exploitation. The vulnerability can be exploited remotely, and details of the exploit have been made public.

4.0
Jan 13, 2025

Reggie Path Traversal Vulnerability in CommonController Download Function

A critical path traversal vulnerability has been identified in the Reggie application, version 1.0. The issue arises in the CommonController's download method, located in src/main/java/com/itheima/reggie/controller/CommonController.java. The vulnerability allows remote attackers to manipulate the name parameter, enabling them to download arbitrary files without authentication. The default file upload and download paths are set to D:\img\, as specified in the application.yml configuration file.

3.9
Jan 12, 2025

StarSea99 Starsea-Mall Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in StarSea99's Starsea-Mall version 1.0. The issue arises in the admin categories update interface, where the categoryName parameter is not properly sanitized. This lack of filtering allows attackers to inject malicious JavaScript, potentially leading to the execution of harmful scripts in the user's browser. The vulnerability can be exploited remotely.

2.8
Jan 12, 2025

StarSea99 Starsea-Mall Unrestricted File Upload Vulnerability in UploadController

A critical vulnerability exists in StarSea99's starsea-mall version 1.0, specifically within the UploadController function of the file src/main/java/com/siro/mall/controller/common/uploadController.java. This vulnerability allows for unrestricted file uploads, as the upload method does not properly validate the types of files being uploaded. Attackers can exploit this issue remotely by uploading JSP and HTML files, potentially leading to further exploitation.

4.0
Jan 12, 2025

HCL MyXalytics Cleartext Transmission of Sensitive Information Vulnerability

A vulnerability exists in HCL MyXalytics version 6.3, allowing the cleartext transmission of sensitive information. The application sends security-critical data over a communication channel that can be intercepted by unauthorized parties.

2.3