CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Juniper Networks Junos OS Improper Exception Handling Vulnerability on SRX1500, SRX4100, and SRX4200 Devices Leading to Denial-of-Service
A vulnerability has been identified in the command-line processing of Juniper Networks Junos OS, specifically on SRX1500, SRX4100, and SRX4200 devices. This vulnerability involves improper handling of exceptional conditions, allowing a local, low-privileged authenticated attacker to execute the 'show chassis environment pem' command and cause the chassis daemon (chassisd) to crash and restart. This disruption results in a temporary denial-of-service condition. However, if the command is executed repeatedly, the chassisd process may fail to restart, adversely affecting packet processing on the system.
Juniper Networks Junos OS and Junos OS Evolved Improper Resource Control Vulnerability in BGP Handling Leading to Denial-of-Service
A vulnerability has been identified in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved. This vulnerability allows an unauthenticated, network-based attacker to cause a denial-of-service (DoS) condition. On devices with Segment Routing over IPv6 (SRv6) enabled, an attacker can send a malformed BGP UPDATE packet that causes the rpd to crash and restart. Continued receipt of these malformed UPDATE packets can lead to a sustained DoS condition. This vulnerability affects both iBGP and eBGP, as well as IPv4 and IPv6. The issue is present in all versions of Junos OS and Junos OS Evolved prior to specific release patches, with certain version ranges also affected.
Juniper Networks Junos OS SRX Series Exposure of Sensitive Information Vulnerability
A vulnerability allowing exposure of sensitive information to unauthorized users has been identified in the command-line interface (CLI) of Juniper Networks Junos OS on SRX Series devices. This issue affects all versions prior to 21.4R3-S8, as well as certain versions in the 22.x and 23.x ranges. The vulnerability allows a local, low-privileged user with access to the Junos CLI to view the contents of sensitive files on the file system. By executing specific commands related to advanced anti-malware or security intelligence services, these users can access protected files containing sensitive information that could be used to further impact the system.
Joomag WP Joomag Plugin Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in the WP Joomag WordPress plugin, affecting versions through 2.5.2. This issue allows for DOM-based XSS, where a malicious actor could inject harmful scripts that are executed when users visit the affected site.
WordPress Sell Digital Downloads Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Sell Digital Downloads plugin, specifically in versions through 2.2.7. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Live Flight Radar Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Live Flight Radar plugin, affecting versions through 1.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Genesis Style Shortcodes Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress Genesis Style Shortcodes plugin, affecting versions through 1.0. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
Bishawjit Das WP Custom Countdown Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Bishawjit Das WP Custom Countdown plugin, affecting versions through 2.8. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress StorePress Theme DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress StorePress theme, affecting versions through 1.0.12. This issue arises from improper neutralization of input during web page generation, allowing malicious actors to inject and execute harmful scripts on the website.
Daniel Walmsley VR Views Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Daniel Walmsley VR Views WordPress plugin, affecting versions through 1.5.1. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
4wpbari Qr Code and Barcode Scanner Reader Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the 4wpbari Qr Code and Barcode Scanner Reader plugin for WordPress, affecting versions through 1.0.0. This vulnerability allows for the injection of malicious scripts that are executed when users visit the affected site.
S3Bubble S3Player WooCommerce and Elementor Integration Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the S3Bubble S3Player plugin, specifically in versions through 4.2.1, when integrated with WooCommerce and Elementor. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed on the website.
Venutius BP Profile Shortcodes Extra Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Venutius BP Profile Shortcodes Extra WordPress plugin, affecting versions through 2.6.0. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress Button Block Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Button Block plugin, affecting versions through 1.1.6. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.
WordPress Zephyr Admin Theme Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Zephyr Admin Theme plugin, specifically in versions through 1.4.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress ChatBot Conversational Forms Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the ChatBot for WordPress plugin, specifically in the Conversational Forms component, affecting versions through 1.4.2. This vulnerability allows users to inject malicious scripts that are executed when other users view the affected content.
FlickDevs News Ticker Widget for Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the FlickDevs News Ticker Widget for Elementor, affecting versions through 1.3.2. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.
Modeltheme MT Addons for Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Modeltheme MT Addons for Elementor plugin, affecting versions through 1.0.6. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
CBB Team Content Blocks Builder Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the CBB Team Content Blocks Builder plugin for WordPress, affecting versions through 2.7.6. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Gravity Master PDF Catalog WooCommerce DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the Gravity Master PDF Catalog WooCommerce plugin, affecting versions through 2.0. This issue arises from improper neutralization of input during web page generation, allowing malicious actors to inject harmful scripts that could be executed when guests visit the site.
Surbma Premium WP Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the Surbma Premium WP WordPress plugin, affecting versions through 9.0. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when visitors access the affected site.
WordPress Responsive Flickr Slideshow Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Responsive Flickr Slideshow plugin, affecting versions through 2.6.0. This issue allows attackers to inject malicious scripts that are executed when users view the slideshow.
Modernaweb Studio Black Widgets For Elementor DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the Black Widgets For Elementor plugin by Modernaweb Studio, affecting versions through 1.3.8. This issue arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
ThemePoints Skill Bar Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the ThemePoints Skill Bar WordPress plugin, affecting versions through 1.2. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Author Avatars List/Block Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Author Avatars List/Block plugin, affecting versions through 2.1.23. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.
VillaTheme Advanced Product Information for WooCommerce Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the VillaTheme Advanced Product Information for WooCommerce plugin, affecting versions through 1.1.4. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected page.
WordPress Email Templates Customizer YeeMail Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Email Templates Customizer for WordPress, specifically in the Drag And Drop Email Templates Builder – YeeMail, versions prior to and including 2.1.4. This vulnerability allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when guests visit the site.
HasThemes Free WooCommerce Theme 99fy Extension Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the HasThemes Free WooCommerce Theme 99fy Extension, affecting versions through 1.2.8. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress Mailing Group Listserv Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress Mailing Group Listserv plugin, affecting versions through 2.0.9. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Better User Shortcodes Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress Better User Shortcodes plugin, specifically in versions through 1.0. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.
WordPress Title Experiments Free Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the WordPress Title Experiments Free plugin, specifically in versions through 9.0.4. This vulnerability allows exploitation of improperly configured access control security levels, potentially leading to unauthorized actions by users with lower privileges.
WordPress Virtual Bot Plugin SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in the WordPress Virtual Bot plugin, affecting versions through 1.0.0. This vulnerability allows attackers to manipulate SQL queries, potentially leading to unauthorized data access or modification.
WordPress Emailing Subscription Plugin SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in the WordPress Emailing Subscription plugin, affecting versions through 1.4.1. This vulnerability allows attackers to manipulate SQL queries, potentially leading to unauthorized data access or modification.
WordPress Custom Database Tables Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress Custom Database Tables plugin, affecting versions through 2.1.34. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.
WordPress Google Maps Travel Route Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WordPress Google Maps Travel Route plugin, affecting versions through 1.3.1. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially enabling attackers to manipulate database queries and interact with the database in unauthorized ways.
WPListCal SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WPListCal WordPress plugin, affecting versions through 1.3.5. This vulnerability allows attackers to manipulate SQL queries, potentially leading to unauthorized database access or data manipulation.
WordPress Mailing Group Listserv SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WordPress Mailing Group Listserv plugin, affecting versions through 2.0.9. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially enabling malicious actors to interact with the database and steal information.
Scott Farrell WP Hosting Performance Check Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Scott Farrell WP Hosting Performance Check plugin, affecting versions through 2.18.8. This issue allows attackers to inject malicious scripts that are executed when users visit the affected page.
WordPress WC Price History for Omnibus PHP Object Injection Vulnerability
A deserialization vulnerability allowing object injection has been identified in the WordPress WC Price History for Omnibus plugin, affecting versions through 2.1.4. This vulnerability could potentially lead to various types of code injection, including SQL injection, path traversal, and denial-of-service, especially if a suitable property-oriented programming chain is available.
Roninwp FAT Event Lite Local File Inclusion Vulnerability
A local file inclusion vulnerability has been identified in the Roninwp FAT Event Lite plugin, affecting versions through 1.1. This vulnerability arises from improper control of filenames in include or require statements, allowing for PHP remote file inclusion. Exploitation of this issue could enable a malicious actor to include local files from the target website and display their contents, potentially leading to a complete takeover of the database if sensitive information is accessed.
Nabaraj Chapagain NC Wishlist for WooCommerce SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the NC Wishlist for WooCommerce plugin, affecting versions through 1.0.1. This vulnerability allows attackers to improperly manipulate SQL commands, potentially leading to unauthorized database access or data manipulation.
WordPress 4ECPS Web Forms Plugin Arbitrary File Upload Vulnerability
A vulnerability allowing unrestricted upload of files with dangerous types has been identified in the WordPress 4ECPS Web Forms Plugin, affecting versions through 0.2.18. This vulnerability could be exploited to upload a web shell to the server, potentially leading to further unauthorized access or actions on the website.
Opentracker Analytics Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Opentracker Analytics WordPress plugin, affecting versions through 1.3. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Tobias Spiess TS Comfort DB Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Tobias Spiess TS Comfort DB WordPress plugin, affecting versions through 2.0.7. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Cf7Save Extension Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress Cf7Save Extension plugin, affecting versions through 1. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.
Mahesh Waghmare MG Parallax Slider Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Mahesh Waghmare MG Parallax Slider WordPress plugin, affecting versions through 1.0. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
OTWthemes Widgetize Pages Light Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the OTWthemes Widgetize Pages Light plugin for WordPress, affecting versions through 3.0. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected page.
CodeAstrology Product Table for WooCommerce Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the CodeAstrology Product Table for WooCommerce plugin, affecting versions through 4.0.3. This vulnerability allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.
Tripetto WordPress Plugin Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Tripetto WordPress form builder plugin, which is used for creating contact forms, surveys, and quizzes. This vulnerability affects versions of the plugin through 8.0.5.
Silicon Labs Simplicity SDK Buffer Overflow Vulnerability in Packet Handoff Plugin
A buffer overflow vulnerability has been identified in the packet handoff plugin of Silicon Labs' Simplicity SDK. This vulnerability allows an attacker to overwrite memory outside the plugin's designated buffer, potentially leading to arbitrary code execution or other malicious outcomes. The issue is present in several components of the Simplicity SDK, including the Bluetooth SDK, Bluetooth Mesh SDK, Gecko Platform, OpenThread SDK, Proprietary Flex SDK, USB Device Stack, Wi-SUN SDK, Z-Wave and Z-Wave Long Range 800 SDK, and Zigbee EmberZNet SDK.
