CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Leiyuxi Cy-Fast SQL Injection Vulnerability in Menu Data Listing Function
A critical SQL injection vulnerability has been identified in Leiyuxi Cy-Fast version 1.0. The issue arises in the 'listData' function within the 'CommparaController.java' file, specifically at the '/sys/menu/listData' endpoint. The vulnerability allows remote attackers to manipulate the argument order, leading to the execution of arbitrary SQL statements. This exploitation is possible due to inadequate filtering of SQL inputs, enabling the concatenation and execution of unfiltered SQL functions.
Unlimited Elements For Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Unlimited Elements For Elementor plugin for WordPress, affecting all versions through 1.5.135. The vulnerability arises from inadequate input sanitization and output escaping on user-supplied attributes across multiple widgets. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages. To apply the patch, the impacted widgets must be manually deleted and reinstalled.
SonicWall SSL-VPN Multi-Factor Authentication Bypass Vulnerability
A vulnerability allowing bypass of multi-factor authentication (MFA) has been identified in SonicWall SSL-VPN. This issue arises from the different handling of User Principal Names (UPN) and Security Account Manager (SAM) account names when integrated with Microsoft Active Directory. This discrepancy allows MFA to be configured separately for each login method, potentially enabling attackers to exploit the alternative account name to bypass MFA.
Leiyuxi Cy-Fast SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Leiyuxi Cy-Fast version 1.0. The issue arises in the 'listData' function within the file '/commpara/listData', where improper handling of argument order allows for SQL injection. This vulnerability can be exploited remotely.
CampCodes Computer Laboratory Management System Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in CampCodes Computer Laboratory Management System version 1.0. The issue arises in the file '/class/edit/edit', where the 's_lname' argument is not properly sanitized, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely and requires user interaction.
CampCodes Computer Laboratory Management System Unrestricted File Upload Vulnerability Allowing Remote Code Execution
A critical vulnerability exists in CampCodes Computer Laboratory Management System version 1.0, specifically within the file '/class/edit/edit'. The issue arises from an unrestricted file upload feature, where the 'e_photo' argument can be manipulated to upload arbitrary files. This vulnerability can be exploited remotely, leading to unauthorized code execution on the server.
Iocharger Buffer Overflow Vulnerability in CGI Binaries of AC Model Chargers
A buffer overflow vulnerability has been identified in multiple CGI binaries of Iocharger AC model chargers, affecting firmware versions prior to 24120701. This vulnerability is likely to be exploited, as the buffer overflows are common and the web server provides clear error messages. While such overflows typically result in a segmentation fault and a 502 Bad Gateway error, a skilled attacker could potentially leverage them for remote code execution, despite the presence of Address Space Layout Randomization (ASLR) on the charging station.
Iocharger AC Models Authenticated Arbitrary File Upload Vulnerability
An authenticated vulnerability allowing arbitrary file uploads has been identified in Iocharger firmware for AC models prior to version 24120701. The issue arises from a CGI binary that can be accessed by any user, although the file upload interface is only available to the 'iocadmin' user. Exploitation of this vulnerability requires knowledge of the CGI binary and access to a low-privilege account, or the ability to persuade a user with such access to upload a file. The uploaded files can be placed in either '/tmp/upload/' or '/tmp/', but cannot be accessed or utilized without the presence of additional vulnerabilities.
Iocharger Buffer Overflow Vulnerability in OCPP Service CGI Scripts
A buffer overflow vulnerability has been identified in the Iocharger .so library used by Iocharger AC models prior to version 24120701. The vulnerability arises in the certificate deletion process, where a long file path can be provided to the .exe CGI binary or the .sh CGI script. This path is then written to a file that the vulnerable library reads, leading to a buffer overflow. Exploitation of this vulnerability causes the OCPP communication process to crash repeatedly, creating a denial-of-service condition that cannot be recovered by the user.
Iocharger AC Model Chargers Arbitrary File Download Vulnerability
An authenticated vulnerability allowing arbitrary file downloads has been identified in Iocharger firmware for AC model chargers prior to version 24120701. The issue arises from a CGI script that can be exploited to download any file from the filesystem, including sensitive files such as '/etc/shadow', the CGI script source code, binaries, and configuration files. While the vulnerability has a high likelihood of exploitation, it requires authentication. The impact is critical, as it allows for the extraction of confidential files from the device.
Iocharger AC Models Plaintext Default Credentials Vulnerability
A vulnerability exists in Iocharger AC model EV chargers running firmware prior to 25010801, allowing default credentials to be extracted from the firmware. This issue arises because all chargers of this model initially shared the same password, and the lack of a mandatory password change in earlier firmware versions leaves many devices vulnerable. Once obtained, these credentials could enable unauthorized access to the charging stations, where attackers could execute arbitrary commands through the System → Custom page.
Iocharger AC Models Patch Traversal Vulnerability Allowing Arbitrary File Deletion
A patch traversal vulnerability has been identified in Iocharger Home firmware for AC models, prior to version 25010801. This vulnerability allows authenticated users to delete arbitrary files on the charging station, which could disrupt the integrity and availability of the device. Exploitation of this vulnerability could also remove essential binaries, further affecting the charging station's functionality.
Iocharger AC Model Chargers OS Command Injection Vulnerability Allowing Root Access
A command injection vulnerability has been identified in Iocharger firmware for AC model chargers, affecting versions prior to 24120701. This vulnerability allows authenticated users to execute arbitrary OS commands as root on the charging station. The issue arises when uploading firmware, as a crafted firmware file can execute a shell script during processing, leading to full control over the device. Exploitation requires access to the action.exe CGI binary, either directly or by convincing a user with the necessary privileges to upload the malicious firmware.
Iocharger AC Model Chargers Command Injection Vulnerability Allowing OS Command Execution as Root
A command injection vulnerability has been identified in Iocharger firmware for AC model chargers, affecting versions prior to 24120701. This vulnerability allows authenticated users to execute operating system commands as the root user on the charging station. The issue arises from improper neutralization of special elements used in commands, enabling manipulation of backup files to include malicious CGI scripts that can be executed remotely. The vulnerability has a moderate likelihood of exploitation, as it requires knowledge of the file structure and access to upload modified backup files. However, once exploited, it grants full control over the charging station, with potential safety implications due to the high power involved.
Iocharger Command Injection Vulnerability in AC Model Chargers
A command injection vulnerability has been identified in Iocharger firmware for AC model chargers, affecting versions prior to 24120701. This vulnerability allows authenticated users to execute operating system commands as the root user on the charging station. The issue arises from improper neutralization of special elements used in commands, enabling OS command injection. The vulnerability can be exploited by finding the name of a specific CGI script and using a low-privilege account to access it, or by convincing a user with the necessary access to execute a request.
Iocharger AC Models Command Injection Vulnerability Leading to Root Access
A command injection vulnerability has been identified in Iocharger firmware for AC models, all versions prior to 25010801. This vulnerability allows authenticated users to execute OS commands as root on the charging station. The issue arises from improper neutralization of special elements used in commands, enabling OS command injection. While the vulnerability is present in the web interface, it may be more challenging to exploit as it requires access to a specific binary, similar to one used in the Iocharger Pedestal charging station. An attacker would need a low-privilege account or to persuade a user with such access to send a crafted HTTP request.
Iocharger AC Model Chargers Command Injection Vulnerability Leading to Root Access
A command injection vulnerability has been identified in Iocharger firmware for AC model chargers, affecting versions prior to 24120701. This vulnerability allows authenticated users to execute operating system commands as the root user on the charging station. The issue arises from improper neutralization of special elements used in commands, enabling command injection via a specific binary. While the vulnerability is not directly exposed through the web interface, it can be exploited by convincing a user with low privileges to send a crafted HTTP request. The impact of this vulnerability is critical, as it allows full control over the charging station, including the ability to add, modify, and delete files and services. Additionally, compromised devices could potentially be used to access restricted networks. Given that this vulnerability involves an electric vehicle charger handling significant power, there are potential safety implications.
Iocharger AC Model Chargers Command Injection Vulnerability Leading to Root Access
A command injection vulnerability has been identified in Iocharger firmware for AC model chargers, affecting versions prior to 24120701. This vulnerability allows authenticated users to execute operating system commands as the root user on the charging station. The issue arises from improper neutralization of special elements used in commands, enabling unauthorized command execution. While the vulnerability is not directly exposed through the web interface, it can be exploited by users with low-privilege accounts who can send crafted HTTP requests or by manipulating the Iocharger Pedestal charging station binary.
Iocharger Command Injection Vulnerability in AC Models Allowing Root Access
A command injection vulnerability has been identified in Iocharger firmware for AC models prior to version 241207101. This vulnerability allows authenticated users to execute operating system commands as the root user on the affected charging station. The issue arises from improper handling of special elements in commands, which could be exploited by convincing a user with low privileges to send a crafted HTTP request. Once exploited, the attacker could gain full control over the charging station, including the ability to add, modify, or delete files and services. Additionally, because this is an electric vehicle charger managing significant power, there are potential safety implications.
Iocharger Command Injection Vulnerability in AC Models Allows Root OS Command Execution
A command injection vulnerability has been identified in Iocharger firmware for AC models, affecting versions prior to 24120701. This vulnerability allows authenticated users to execute operating system commands as root on the charging station. The issue arises from improper neutralization of special elements used in commands, enabling command injection via a specific binary. While the vulnerability requires a low-privilege account to access the binary, it can potentially be exploited by convincing a user with the necessary access to send a crafted HTTP request.
Iocharger Command Injection Vulnerability in AC Models Allowing Remote Code Execution
A command injection vulnerability has been identified in Iocharger firmware for AC models prior to version 24120701. This vulnerability allows authenticated users to inject commands through a specific parameter in a <redacted>.exe request, leading to remote code execution as the root user. The issue arises because the injection point is not a typical location for such vulnerabilities, making it likely that an attacker would need to reverse-engineer the firmware or experiment with various <redacted> fields to discover it. Additionally, the attacker must have a low-privilege account to access the <redacted> binary or persuade a user with the necessary privileges to execute a malicious payload.
Iocharger Command Injection Vulnerability in AC Models Prior to Version 24120701 Allowing Remote Code Execution
A command injection vulnerability has been identified in the Iocharger firmware for AC models prior to version 24120701. This vulnerability allows authenticated users to execute arbitrary commands via a specific parameter in a <redacted>.exe request, leading to remote code execution as the root user. The vulnerability is not commonly found in this context, making it likely that an attacker would need to reverse-engineer the firmware or test various <redacted> fields to discover it. Access to the <redacted> binary is required, either by having a low-privilege account or by persuading a user with such access to execute a malicious payload.
SonicWall SonicOS Integer-Based Buffer Overflow Vulnerability via IPSec Allowing Denial-of-Service and Potential Arbitrary Code Execution
A buffer overflow vulnerability has been identified in SonicWall SonicOS through IPSec, specifically in versions 6.5.4.4-44v-21-2395 and earlier, as well as in several Gen7 models. This vulnerability allows remote attackers, under certain conditions, to cause a denial-of-service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload. The issue arises from an integer-based buffer overflow, which can be exploited to manipulate memory and execute unauthorized code.
SonicWall SonicOS Post-authentication Absolute Path Traversal Vulnerability Allowing Arbitrary File Read
A post-authentication absolute path traversal vulnerability has been identified in SonicWall SonicOS management. This vulnerability allows remote attackers to read arbitrary files on the system. It affects multiple generations of SonicWall firewalls and certain versions of the SonicWall NSv product.
SonicWall SonicOS Post-authentication Format String Vulnerability Allowing Firewall Crash and Potential Code Execution
A post-authentication format string vulnerability has been identified in the management interface of SonicWall SonicOS. This vulnerability allows remote attackers to cause a crash of the firewall and potentially execute arbitrary code. It affects multiple generations of SonicWall firewalls and certain versions of the SonicWall NSv product.
SonicWall SonicOS Post-authentication Stack-based Buffer Overflow Vulnerability
A post-authentication stack-based buffer overflow vulnerability has been identified in SonicWall SonicOS management. This vulnerability allows remote attackers to crash the firewall and potentially execute arbitrary code. It affects multiple generations of SonicWall firewalls and management services, with the vulnerable versions being 6.5.4.15-117n and older, 7.0.1-5161 and older, 7.1.2-7019 and older, and 8.0.0-8035.
pgAdmin LDAP Authentication Session Fixation Vulnerability
A vulnerability exists in pgAdmin when it is running in server mode with LDAP authentication. If multiple users log in simultaneously, there is a risk that one user may be inadvertently attached to another user's session.
Mattermost Invite Permission Vulnerability in Team Privacy Settings
A vulnerability exists in Mattermost versions 9.11.x prior to 9.11.5, allowing team admins without invitation permissions to invite users. This is achieved by changing the 'allow_open_invite' field after making their team public, thereby bypassing permission restrictions.
Mattermost Calls Configuration Reporting Vulnerability in Versions 10.x through 10.2
A vulnerability exists in Mattermost versions 10.x through 10.2, where the application fails to accurately represent missing settings. This discrepancy can lead to confusion for administrators regarding the security-sensitive configuration of Calls, due to misleading information in the user interface.
Mattermost Denial-of-Service Vulnerability via Improper Post Type Validation
A denial-of-service vulnerability has been identified in Mattermost versions 10.2.0, 9.11.x through 9.11.5, 10.0.x through 10.0.3, and 10.1.x through 10.1.3. The issue arises from the application's failure to properly validate post types, allowing attackers to disrupt service for users with the 'sysconsole_read_plugins' permission. This is achieved by creating a post with the 'custom_pl_notification' type and specific properties.
Cinema Seat Reservation System SQL Injection Vulnerability in deleteBooking.php
A critical SQL injection vulnerability has been identified in the Cinema Seat Reservation System version 1.0. The issue arises in the file deleteBooking.php, where improper handling of the 'id' argument allows for SQL injection. This vulnerability can be exploited remotely.
Online Bike Rental Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been identified in the Online Bike Rental application, version 1.0. The issue arises in an unknown function within the file 'vehical-details.php', specifically related to the HTTP GET request handling. This vulnerability can be exploited remotely.
Codezips Project Management System SQL Injection Vulnerability
A critical SQL injection vulnerability exists in Codezips Project Management System version 1.0, specifically within the file '/pages/forms/teacher.php'. This vulnerability allows remote attackers to manipulate the 'name' parameter, injecting malicious SQL queries that could be executed by the database. The lack of proper input validation and sanitization in the application is the root cause, enabling exploitation of the vulnerability.
SonicWall Gen7 SonicOS Cloud NSv Privilege Escalation Vulnerability
A vulnerability exists in the Gen7 SonicOS Cloud platform NSv, specifically in the AWS and Azure editions. It allows a remote authenticated local low-privileged attacker to elevate privileges to root, potentially leading to code execution.
SonicWall SonicOS SSH Management Server-Side Request Forgery Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in the SonicOS SSH management interface. This vulnerability allows remote attackers to establish TCP connections to any IP address and port while the user is logged into the firewall. The issue affects multiple SonicWall firewall products across different generations and versions.
SonicWall SSLVPN Authentication Bypass Vulnerability
A vulnerability allowing authentication bypass in the SSLVPN authentication mechanism has been identified in SonicWall products. This improper authentication issue allows remote attackers to bypass authentication requirements. The vulnerability is present in several SonicWall firewall products, specifically in certain versions of SonicOS. The issue arises from the SSLVPN authentication mechanism, which can be exploited to gain unauthorized access.
SonicWall SonicOS SSLVPN Cryptographically Weak PRNG Vulnerability Allowing Authentication Bypass
A vulnerability exists in the SonicOS SSLVPN authentication token generator due to the use of a cryptographically weak pseudo-random number generator (PRNG). In certain cases, this weakness allows an attacker to predict the generated tokens, potentially leading to authentication bypass. This issue affects multiple versions of SonicWall SonicOS on both Gen6 and Gen7 firewalls, as well as the Gen7 Cloud platform NSv (AWS and Azure editions only)
GitLab CE/EE SAML External Provider Configuration Vulnerability
A vulnerability exists in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 16.4 prior to 17.5.5, 17.6 prior to 17.6.3, and 17.7 prior to 17.7.1. The issue arises when users are created through the SAML provider; the external groups setting can override the external provider configuration. Consequently, users may not be designated as external, granting them access to internal projects or groups.
Online Bike Rental System Change Image Handler Unrestricted File Upload Vulnerability
A critical vulnerability allowing unrestricted file uploads has been identified in the Change Image Handler component of the Online Bike Rental System version 1.0. This issue could be exploited remotely, potentially affecting other endpoints as well.
Leiyuxi Cy-Fast SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Leiyuxi Cy-Fast version 1.0. The issue arises in the 'listData' function within the file '/sys/user/listData', where the manipulation of argument order can be exploited. This vulnerability can be exploited remotely.
GitLab CE/EE Denial-of-Service Vulnerability Due to Cyclic Epic References
A denial-of-service vulnerability has been identified in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 15.7 prior to 17.5.5, 17.6 prior to 17.6.3, and 17.7 prior to 17.7.1. The issue arises from the ability to create cyclic references between epics, leading to resource exhaustion. This can be exploited by authenticated users on the affected GitLab instance.
BU Section Editing WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the BU Section Editing WordPress plugin, affecting versions through 0.9.9. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against high-privilege users, such as administrators.
Aklamator INfeed WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Aklamator INfeed WordPress plugin, affecting versions through 2.0.0. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
Aklamator INfeed WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Aklamator INfeed WordPress plugin, affecting versions through 2.0.0. The issue arises because the plugin fails to properly sanitize and escape certain settings. This flaw enables high-privilege users, such as administrators, to execute stored cross-site scripting attacks, even in environments where the unfiltered_html capability is restricted, such as multisite setups.
Asgard Security Scanner WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Asgard Security Scanner WordPress plugin, affecting versions through 0.7. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against high-privilege users, such as administrators.
Backlink Monitoring Manager WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Backlink Monitoring Manager WordPress plugin, affecting versions through 0.1.3. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
PostLists WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the PostLists WordPress plugin, affecting versions through 2.0.2. The issue arises because the plugin does not properly escape the 'REQUEST_URI' parameter from the server before outputting it in an attribute. This flaw could be exploited in older web browsers.
Leiyuxi Cy-Fast SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Leiyuxi Cy-Fast version 1.0. The issue arises in the 'listData' function within the file '/sys/role/listData', where the manipulation of argument order allows for SQL injection. This vulnerability can be exploited remotely.
YunzMall Password Recovery Vulnerability in ResetpwdController.php
A critical vulnerability exists in YunzMall versions through 2.4.2, specifically in the password recovery function of the ResetpwdController.php file. This issue arises from the HTTP POST request handling, where improper manipulation of the password argument enables weak password recovery. The vulnerability can be exploited remotely.
KaiYuanTong ECT Platform Command Injection Vulnerability in HTTP POST Request Handler
A critical command injection vulnerability has been identified in KaiYuanTong ECT Platform versions through 2.0.0. The issue resides in the file '/public/server/runCode.php', within the HTTP POST Request Handler component. The vulnerability allows remote attackers to inject commands by manipulating the 'code' argument, exploiting improper handling of input that could alter command execution.
