CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 13, 2025

Pat Infinite Solutions HelpdeskAdvanced Directory Traversal Vulnerability via WSCView/Save Function

A directory traversal vulnerability has been identified in Pat Infinite Solutions HelpdeskAdvanced versions through 11.0.33. This vulnerability can be exploited via the WSCView/Save function, allowing attackers to traverse directories and potentially access restricted files.

1.7
Jan 13, 2025

Pat Infinite Solutions HelpdeskAdvanced Directory Traversal Vulnerability via Email/SaveAttachment Function

A directory traversal vulnerability has been identified in Pat Infinite Solutions HelpdeskAdvanced versions through 11.0.33. This vulnerability arises in the Email/SaveAttachment function, allowing attackers to traverse directories and potentially access unauthorized files.

2.5
Jan 13, 2025

Pat Infinite Solutions HelpdeskAdvanced Directory Traversal Vulnerability

A directory traversal vulnerability has been identified in Pat Infinite Solutions HelpdeskAdvanced versions through 11.0.33. The issue arises in the Attachment/DownloadTempFile function, allowing unauthorized access to files outside the intended directory.

2.5
Jan 13, 2025

WeGIA Reflected Cross-Site Scripting Vulnerability in editar_permissoes.php

A reflected cross-site scripting vulnerability has been identified in the WeGIA application, specifically within the 'editar_permissoes.php' endpoint. This issue arises because the application does not properly validate and sanitize user inputs in the 'msg_c' parameter, allowing attackers to inject malicious scripts. These scripts are then executed in the context of the user's browser. The vulnerability affects WeGIA versions prior to 3.2.6.

2.8
Jan 13, 2025

WeGIA Stored Cross-Site Scripting Vulnerability in 'adicionar_cargo.php' Endpoint

A stored cross-site scripting vulnerability has been identified in the WeGIA application, specifically within the 'adicionar_cargo.php' endpoint. This issue allows attackers to inject malicious scripts into the 'cargo' parameter, which are then stored on the server. The injected scripts are executed automatically when the affected page is accessed by users, creating a significant security risk. The vulnerability arises from the application's failure to properly validate and sanitize user inputs, enabling the injection of harmful scripts that can compromise user data and systems.

2.9
Jan 13, 2025

WeGIA Reflected Cross-Site Scripting Vulnerability in editar_socio.php Endpoint

A reflected cross-site scripting vulnerability has been identified in the WeGIA application, specifically within the 'editar_socio.php' endpoint. This issue allows attackers to inject malicious scripts through the 'socio' parameter. The vulnerability arises because the application does not properly validate and sanitize user inputs, enabling the injection of harmful payloads that are executed in the context of the user's browser.

2.8
Jan 13, 2025

WeGIA Stored Cross-Site Scripting Vulnerability in 'dependente_parentesco_adicionar.php' Endpoint

A stored cross-site scripting vulnerability has been identified in the WeGIA application, specifically within the 'dependente_parentesco_adicionar.php' endpoint. This issue allows attackers to inject malicious scripts into the 'descricao' parameter, which are then stored on the server. The injected scripts are executed automatically when the affected page is accessed by users, creating a significant security risk. The vulnerability arises from inadequate validation and sanitization of user inputs, enabling the injection of harmful scripts that can compromise user data and systems.

2.8
Jan 13, 2025

WeGIA Reflected Cross-Site Scripting Vulnerability in Cadastro_Atendido.php Endpoint

A reflected cross-site scripting vulnerability has been identified in the WeGIA application, specifically within the Cadastro_Atendido.php endpoint. This issue arises because the application does not properly validate or sanitize user inputs in the cpf parameter, allowing attackers to inject malicious scripts. These scripts are then executed in the context of the user's browser. The vulnerability affects WeGIA versions prior to 3.2.6.

2.8
Jan 13, 2025

WeGIA Stored Cross-Site Scripting Vulnerability in Personal Information Editing Endpoint

A stored cross-site scripting vulnerability has been identified in the WeGIA application, specifically within the 'dependente_editarInfoPessoal.php' endpoint. This issue allows attackers to inject malicious scripts into the 'nome' and 'SobrenomeForm' parameters. The injected scripts are stored on the server and executed automatically when the affected page is accessed by users, creating a significant security risk. The vulnerability arises from the application's failure to properly validate and sanitize user inputs, enabling the injection of harmful scripts that could be executed in the context of the user's browser, potentially compromising their data and system.

2.9
Jan 13, 2025

WeGIA Stored Cross-Site Scripting Vulnerability in informacao_adicional.php

A stored cross-site scripting vulnerability has been identified in the WeGIA application, specifically within the 'informacao_adicional.php' endpoint. This issue allows attackers to inject malicious scripts into the 'descricao' parameter, which are then stored on the server. The injected scripts are executed automatically when the affected page is accessed by users, creating a significant security risk. The vulnerability arises from the application's failure to properly validate and sanitize user inputs, enabling the injection of harmful scripts that can compromise user data and systems.

2.8
Jan 13, 2025

Codidact QPixel Suggested Edit Visibility Vulnerability in Private Categories

A vulnerability exists in Codidact QPixel, a community knowledge-sharing software, where suggested edits in private or limited-visibility categories can be accessed by unprivileged or anonymous users through the suggested edit queue. This issue affects all versions of QPixel and has not been patched yet. Users are advised not to rely on private categories for sensitive information.

2.0
Jan 13, 2025

Vim Heap-Buffer Overflow Vulnerability in Visual Mode

A heap-buffer overflow vulnerability has been identified in Vim versions prior to 9.1.1003. The issue arises when visual mode is active and the ':all' command is executed, causing Vim to improperly manage the visual selection. This mismanagement can lead to accessing memory beyond the intended buffer line, creating a heap-buffer overflow. The vulnerability requires user interaction, as visual mode must be enabled when the ':all' command is used.

5.0
Jan 13, 2025

Next.js Next-Forge BASEHUB_TOKEN Exposure Vulnerability

A vulnerability exists in the Next.js project boilerplate 'next-forge' due to the inclusion of a sensitive token, BASEHUB_TOKEN, in the file 'apps/web/.env.example'. This token should not be used and any access it may have granted should be revoked.

3.2
Jan 13, 2025

Jte Template Engine Cross-Site Scripting Vulnerability in HTML Templates with Script Tags

A cross-site scripting (XSS) vulnerability exists in the Jte (Java Template Engine) HTML templates rendered with 'OwaspHtmlTemplateOutput' in versions through 3.1.15. The issue arises when templates include 'script' tags or script attributes containing JavaScript template strings (backticks). The 'javaScriptBlock' and 'javaScriptAttribute' methods in the 'Escape' class fail to properly escape backticks and dollar signs, which are crucial for JavaScript template string interpolation. As a result, malicious JavaScript can be injected and executed.

3.4
Jan 13, 2025

NamelessMC Password Reset Vulnerability Leading to Account Takeover

A vulnerability in NamelessMC versions through 2.1.2 allows for password resets and subsequent account takeovers. This issue arises when a user with 'admincp.core.emails' or 'admincp.users.edit' permissions manually validates another user. Unlike accounts validated via email, which receive a NULL reset code, manually validated accounts are assigned an empty reset code. An attacker can exploit this by requesting a password reset with the empty code, effectively taking over the account.

3.8
Jan 13, 2025

NamelessMC Cross-Site Scripting Vulnerability Allowing JavaScript Execution on Staff Panel

A cross-site scripting (XSS) vulnerability has been identified in NamelessMC versions through 2.1.2. This issue allows users to inject JavaScript into an additional field, which is executed when a staff member views the user's profile in the staff panel. Consequently, an attacker could run JavaScript on the staff member's computer.

3.3
Jan 13, 2025

Venki Supravizio BPM Open Redirect Vulnerability Leading to Reflected Cross-Site Scripting

A vulnerability allowing open redirect has been identified in Venki Supravizio BPM versions through 18.1.1. This open redirect can be exploited to perform reflected cross-site scripting (XSS) attacks.

2.3
Jan 13, 2025

Venki Supravizio BPM NTLM Hash Leak Vulnerability Allowing Privilege Escalation

A vulnerability in Venki Supravizio BPM versions through 18.0.1 allows authenticated attackers with Application Administrator access to leak NTLM hashes, potentially leading to privilege escalation on the underlying host system.

2.1
Jan 13, 2025

Samsung Exynos Modem and Processor Denial-of-Service Vulnerability via RRC Setup Procedure

A denial-of-service vulnerability has been identified in Samsung mobile processors and modems, specifically in the Exynos 5G modem and processor series, including Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W1000, Modem 5123, Modem 5300, and Modem 5400. The issue arises because the User Equipment (UE) does not limit the number of attempts for the Radio Resource Control (RRC) Setup procedure in 5G Standalone (SA) mode. This oversight can be exploited to create a battery-drain attack, causing unnecessary power consumption and potentially leading to premature device shutdown.

5.9
Jan 13, 2025

Cfx.re FXServer Incorrect Access Control Vulnerability Allowing Unauthenticated User Data Modification and Access

A vulnerability exists in Cfx.re FXServer versions through 9601, allowing unauthenticated users to read and modify arbitrary user data via an exposed API endpoint. This issue arises from incorrect access control, enabling unauthorized data manipulation and retrieval.

3.9
Jan 13, 2025

BigID PrivacyPortal Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in BigID PrivacyPortal version 179. This issue allows authenticated users to inject JavaScript into report templates via the 'Label' field. The injected script is executed in the context of all users viewing the report, potentially leading to session hijacking and unauthorized actions on behalf of the user.

3.4
Jan 13, 2025

EveHome Eve Play Password Hash Vulnerability Leading to Arbitrary Code Execution

A vulnerability allowing arbitrary code execution has been identified in EveHome Eve Play versions through 1.1.42. This issue arises from the use of password hashes that require insufficient computational effort, which an attacker could exploit.

2.6
Jan 13, 2025

Samsung Exynos Mobile Processors Stack Out-of-Bounds Write Vulnerability

A stack out-of-bounds write vulnerability has been identified in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. The issue arises from a lack of length validation, which leads to the out-of-bounds write at the function loadInputBuffers.

4.1
Jan 13, 2025

Venki Supravizio BPM Arbitrary File Upload Vulnerability Leading to Remote Code Execution

An arbitrary file upload vulnerability has been identified in Venki Supravizio BPM versions through 18.0.1. This vulnerability allows authenticated attackers to upload malicious files, which can lead to remote code execution on the server.

2.2
Jan 13, 2025

Silicon Labs Ember ZNet Stack Zigbee Buffer Overflow Vulnerability in APS Layer

A buffer overflow vulnerability has been identified in the APS layer of the Ember ZNet stack within the Silicon Labs Zigbee SDK. This issue arises from the processing of malformed packets, which can lead to an assertion failure. The vulnerability is present in several different versions of the Zigbee EmberZNet SDK.

5.6
Jan 13, 2025

Code-Projects Online Car Rental System Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in Code-Projects Online Car Rental System version 1.0. The issue arises in the admin panel, specifically within the edit-vehicle.php file. Authenticated attackers can exploit this vulnerability by injecting malicious JavaScript into the vehicalorcview parameter, which is then executed when the page is viewed.

2.4
Jan 13, 2025

Code-Projects Online Car Rental System File Upload Vulnerability Allowing Remote Code Execution

A remote code execution vulnerability has been identified in Code-Projects Online Car Rental System version 1.0. The issue arises from the file upload feature, which fails to properly validate file extensions or MIME types. This lack of validation allows attackers to upload PHP shells without any restrictions and execute commands on the server.

2.7
Jan 13, 2025

MonicaHQ Client-Side Injection Vulnerability Leading to Stored Cross-Site Scripting

A client-side injection vulnerability has been identified in MonicaHQ version 4.1.2. This issue allows authenticated attackers to inject malicious code into the 'last_name' parameter of the General Information module, located within the settings section. The vulnerability arises from improper handling of user input, which can be exploited to execute scripts that are stored and potentially executed in the context of the user.

3.2
Jan 13, 2025

Samsung Exynos Processors Information Leak Vulnerability via Malformed Uplink Scheduling Message

A vulnerability exists in several Samsung mobile processors, wearable processors, and modems, including the Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, and Modem 5300. The issue arises because the user equipment (UE) improperly processes a malformed uplink scheduling message, leading to an unintentional information leak from the UE.

4.5
Jan 13, 2025

Samsung Exynos Processors Stack Out-of-Bounds Write Vulnerability

A vulnerability exists in several Samsung mobile processors, including Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. The issue arises from a lack of proper length validation, leading to a stack out-of-bounds write in the function loadOutputBuffers.

4.1
Jan 13, 2025

Pega Platform Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting (XSS) vulnerability has been identified in Pega Platform, affecting versions 8.1 through 24.2.0. This vulnerability allows attackers to inject malicious scripts into the application, which can be executed in the context of the user.

2.8
Jan 13, 2025

Teedy Cross-Site Request Forgery Vulnerability Allowing Account Takeover

A cross-site request forgery (CSRF) vulnerability has been identified in Teedy versions through 1.11. This vulnerability allows for account takeover by sending a POST request to the /api/user/admin endpoint.

3.7
Jan 13, 2025

Post SMTP WordPress Plugin Broken Access Control Vulnerability

A broken access control vulnerability has been identified in the Post SMTP WordPress plugin, affecting versions through 2.9.11. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileged users.

4.3
Jan 13, 2025

GiveWP WordPress Plugin PHP Object Injection Vulnerability

A deserialization vulnerability allowing PHP object injection has been identified in the GiveWP WordPress plugin, affecting versions through 3.19.3. This vulnerability could potentially lead to various types of code injection, including SQL injection, path traversal, and denial-of-service, especially if a suitable object injection chain is exploited.

5.2
Jan 13, 2025

WordPress Scanventory Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Scanventory plugin, affecting versions through 1.1.3. This issue allows attackers to inject malicious scripts that are executed when users visit the affected page.

2.0
Jan 13, 2025

Detlef Stöver WPEX Replace DB Urls Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WPEX Replace DB Urls WordPress plugin, affecting versions through 0.4.0. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.

2.0
Jan 13, 2025

WordPress Scan External Links Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Scan External Links plugin, affecting versions through 1.0. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.

2.0
Jan 13, 2025

WordPress Site PIN Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Site PIN plugin, affecting versions through 1.3. This issue allows attackers to inject malicious scripts that could be executed when users visit the affected site.

2.0
Jan 13, 2025

WordPress Inline Tweets Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Inline Tweets plugin, affecting versions through 2.0. This issue allows attackers to inject malicious scripts that are executed when users view the affected content.

2.0
Jan 13, 2025

WordPress Featured Page Widget Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Featured Page Widget plugin, affecting versions through 2.2. This issue allows attackers to inject malicious scripts that are executed when users visit the affected page.

2.0
Jan 13, 2025

WordPress Post And Page Reactions Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Post And Page Reactions plugin, specifically in versions through 1.0.5. This issue allows attackers to inject malicious scripts that could be executed when users visit the affected page.

2.0
Jan 13, 2025

TRUSTist REVIEWer Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the TRUSTist REVIEWer WordPress plugin, affecting versions through 2.0. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.

2.0
Jan 13, 2025

Yamna KNR Author List Widget Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Yamna KNR Author List Widget, affecting versions through 3.1.1. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 13, 2025

SmartAgenda WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the SmartAgenda WordPress plugin, specifically in versions through 4.7. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 13, 2025

FAKTOR VIER F4 Post Tree Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the FAKTOR VIER F4 Post Tree WordPress plugin, affecting versions through 1.1.18. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected page.

2.0
Jan 13, 2025

New Normal LLC LucidLMS Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the New Normal LLC LucidLMS WordPress plugin, affecting versions through 1.0.5. This issue allows attackers to inject malicious scripts that are executed when users visit the affected page.

2.0
Jan 13, 2025

WordPress Media Category Library Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Media Category Library plugin, affecting versions through 2.7. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 13, 2025

Infosoft Consultant Order Audit Log for WooCommerce Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Infosoft Consultant Order Audit Log for WooCommerce plugin, affecting versions through 2.0. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.

2.0
Jan 13, 2025

WP Scripts Food Store Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WP Scripts Food Store plugin for WordPress, specifically in versions through 1.5.3. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 13, 2025

Eniture Technology Distance Based Shipping Calculator Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Eniture Technology Distance Based Shipping Calculator plugin for WordPress, affecting versions through 2.0.21. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.

2.0