CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Codezips Gym Management System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Codezips Gym Management System version 1.0. The issue resides in the 'm_id' parameter of the '/dashboard/admin/submit_payments.php' file. This vulnerability allows remote attackers to inject arbitrary SQL code, potentially leading to unauthorized database access, data manipulation, and full system compromise.
Code-Projects Responsive Hotel Site SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Code-Projects Responsive Hotel Site version 1.0. The issue arises in an unknown function within the file /admin/print.php, where the 'pid' parameter is not properly sanitized or parameterized. This lack of input validation allows attackers to inject malicious SQL code, potentially manipulating database queries. The vulnerability can be exploited remotely, and the details of the exploit have been made public.
Code-Projects Travel Management System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Code-Projects Travel Management System version 1.0. The issue arises in the file 'enquiry.php', where the 'pid' parameter and several other parameters ('t1' through 't7') are processed without proper sanitization or parameterization. This lack of input validation allows attackers to inject malicious SQL code, potentially manipulating database queries to extract sensitive information. The vulnerability can be exploited remotely.
Code-Projects Local Storage Todo App Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been identified in the Local Storage Todo App version 1.0, created by Code-Projects. The issue arises in the file '/js-todo-app/index.html', where the 'Add' argument can be manipulated to execute malicious scripts. This vulnerability can be exploited remotely and has been publicly disclosed.
Provision-ISR Products Information Disclosure Vulnerability
A vulnerability allowing information disclosure has been identified in several Provision-ISR products, including the SH-4050A-2, SH-4100A-2L(MM), SH-8100A-2L(MM), SH-16200A-2(1U), SH-16200A-5(1U) models, and the NVR5-8200PX, all versions prior to December 20, 2024. The issue arises from an unknown functionality in the file '/server.js', which can be exploited remotely.
IObit Protected Folder Null Pointer Dereference Vulnerability in IOCTL Handler
A null pointer dereference vulnerability has been identified in IObit Protected Folder versions through 13.6.0.5. The issue arises in the IOCTL Handler component, specifically within the IURegistryFilter.sys library, and is triggered by certain function calls. This vulnerability requires local access to exploit and can lead to application crashes or unexpected exits.
IObit Protected Folder Null Pointer Dereference Vulnerability in IOCTL Handler
A null pointer dereference vulnerability has been identified in IObit Protected Folder versions prior to 13.6.0.5. The issue arises in the IOCTL Handler component, specifically within the IUProcessFilter.sys library, where certain function calls can be manipulated to cause a null pointer dereference. This vulnerability requires local exploitation.
IOBit Protected Folder Null Pointer Dereference Vulnerability in pffilter.sys IOCTL Handler
A null pointer dereference vulnerability has been identified in IOBit Protected Folder versions through 1.3.0. This issue arises in the IOCTL Handler component, specifically within the function 0x22200c of the pffilter.sys library. The vulnerability allows for a local denial-of-service condition. Although the vendor was notified about this issue, there has been no response.
osuuu LightPicture Stored Cross-Site Scripting Vulnerability in SVG File Upload Handler
A stored cross-site scripting vulnerability has been identified in osuuu LightPicture versions through 1.2.2. The issue resides in the SVG file upload feature of the API, where the application fails to properly sanitize uploaded SVG files. This lack of validation allows for the execution of embedded JavaScript in the context of the user's browser when the image is viewed. The vulnerability can be exploited remotely by uploading a maliciously crafted SVG file via the upload API.
Trimble SPS851 Cross-Site Scripting Vulnerability in Ethernet Configuration Menu
A cross-site scripting (XSS) vulnerability has been identified in the Trimble SPS851 device running version 488.01. The issue arises in the Ethernet Configuration Menu, where the Hostname field can be manipulated to inject a reflected XSS payload. This vulnerability can be exploited remotely. When the injected payload is submitted, it triggers a pop-up containing session information, indicating successful execution of the script.
Emlog Pro Cross-Site Scripting Vulnerability in Cover Upload Handler
A cross-site scripting (XSS) vulnerability has been identified in Emlog Pro versions through 2.4.3. The issue arises in the cover image upload feature within the file '/admin/article.php?action=upload_cover'. The vulnerability allows remote attackers to upload SVG files containing malicious XML, which is not properly sanitized before being processed.
Wangl1989 MySiteForMe Server-Side Request Forgery Vulnerability
A critical server-side request forgery (SSRF) vulnerability has been identified in Wangl1989 MySiteForMe version 1.0. The issue arises in the 'doContent' function of the 'FileController' Java file, where the 'content' argument is not properly validated. This lack of filtering allows remote attackers to manipulate requests, potentially leading to unauthorized access to internal resources or services.
Wangl1989 MySiteForMe Unrestricted File Upload Vulnerability in LocalUploadServiceImpl
A critical vulnerability allowing arbitrary file upload has been identified in Wangl1989 MySiteForMe version 1.0. The issue resides in the LocalUploadServiceImpl file, where the upload function fails to properly validate file types. This flaw enables remote attackers to upload malicious JSP or HTML files, potentially leading to the execution of harmful scripts on the server.
Wangl1989 MySiteForMe Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Wangl1989 MySiteForMe version 1.0. The issue arises in the RestResponse function of the SiteController file, where incoming data is not properly sanitized, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely.
Wangl1989 MySiteForMe Remote Command Execution Vulnerability
A critical vulnerability allowing remote command execution has been identified in Wangl1989 MySiteForMe version 1.0. The issue arises in the 'rememberMeManager' function within 'src/main/java/com/mysiteforme/admin/config/ShiroConfig.java', where improper handling of data leads to deserialization vulnerabilities.
Emlog Pro Cross-Site Scripting Vulnerability in Twitter Subpage Handler
A reflected cross-site scripting vulnerability has been identified in Emlog Pro version 2.4.3. The issue resides in the admin/twitter.php file, within the Subpage Handler component. This vulnerability allows remote attackers to inject malicious JavaScript into the URL, which is then executed in the context of the user's browser.
ZeroWdd Studentmanager Unrestricted File Upload Vulnerability in TeacherController
A critical vulnerability allowing unrestricted file uploads has been identified in ZeroWdd Studentmanager version 1.0. The issue resides in the TeacherController, specifically within the addTeacher and editTeacher functions. This vulnerability allows the upload of files with dangerous extensions, such as JSP and HTML, which can be processed by the application. Although the uploaded files are initially inaccessible and require a system restart to be accessed, this flaw could still be exploited remotely.
Trimble SPS851 Receiver Status Identity Tab Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been identified in the Trimble SPS851 receiver, specifically in version 488.01. The issue arises within the Receiver Status Identity Tab, where the 'System Name' argument can be manipulated to execute malicious scripts. This vulnerability can be exploited remotely.
ZeroWdd Studentmanager Unrestricted File Upload Vulnerability
A critical vulnerability allowing unrestricted file uploads has been identified in ZeroWdd Studentmanager version 1.0. This issue arises in the StudentController and TeacherController files, where the addStudent, editStudent, addTeacher, and editTeacher methods fail to properly restrict file extensions and content. As a result, malicious JSP and HTML files can be uploaded. However, uploaded JSP files cannot be accessed until the application is restarted.
Emlog Pro Cross-Site Scripting Vulnerability in Article Management Component
A reflected cross-site scripting vulnerability has been identified in Emlog Pro versions through 2.4.3. The issue resides in the admin/article.php file within the Subpage Handler component. This vulnerability allows remote attackers to inject malicious scripts that are executed in the context of the user's browser.
Dahua IPC Cameras Path Traversal Vulnerability in Web Interface
A critical path traversal vulnerability has been identified in several Dahua IPC camera models, including the IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z, and IPC-HDW1200S, all versions prior to 20241222. This vulnerability allows remote attackers to bypass directory restrictions and access sensitive files, such as ../mtd/Config/Sha1Account1, which contains hashed credentials and other configuration data. The issue arises from the web interface's improper handling of file paths, enabling exploitation by manipulating input to traverse directories and access restricted files.
TMD Custom Header Menu OpenCart Module SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the TMD Custom Header Menu OpenCart module, version 4.0.0.1. This vulnerability exists in the admin index.php file, where the headermenu_id parameter is improperly processed, allowing authenticated attackers to manipulate SQL queries. Exploitation of this vulnerability could lead to unauthorized access to database contents, including admin session details, Personally Identifiable Information (PII), and payment information. The vulnerability requires a valid session cookie and user_token for exploitation.
CampCodes Project Management System Unrestricted File Upload Vulnerability Allowing Remote Code Execution
A critical vulnerability exists in CampCodes Project Management System version 1.0, specifically within the file '/forms/update_forms.php?action=change_pic2&id=4'. This vulnerability allows for unrestricted file uploads by manipulating the 'file' argument, enabling the upload of malicious PHP scripts. The issue can be exploited remotely, leading to arbitrary code execution on the server.
Campcodes Student Grading System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Campcodes Student Grading System version 1.0. The issue resides in the 'view_students.php' file, where the 'id' parameter is improperly sanitized, allowing remote attackers to manipulate SQL queries and potentially access or modify database information.
Campcodes School Faculty Scheduling System File Inclusion Vulnerability
A critical file inclusion vulnerability has been identified in Campcodes School Faculty Scheduling System version 1.0. The issue arises in the admin index.php file, where the page argument can be manipulated to include files. This vulnerability can be exploited remotely.
IBM Engineering Lifecycle Optimization - Publishing Unhandled SSL Exception Vulnerability
A vulnerability exists in IBM Engineering Lifecycle Optimization - Publishing versions 7.0.2 and 7.0.3, allowing remote attackers to trigger an unhandled SSL exception. This could result in the connection being left in an unexpected or insecure state.
IBM Engineering Lifecycle Optimization - Publishing SQL Injection Vulnerability
A SQL injection vulnerability has been identified in IBM Engineering Lifecycle Optimization - Publishing versions 7.0.2 and 7.0.3. This vulnerability allows remote attackers to send specially crafted SQL statements that could be used to view, add, modify, or delete information in the back-end database.
IBM Engineering Lifecycle Optimization - Publishing Denial-of-Service Vulnerability via Complex Regular Expressions
A denial-of-service vulnerability has been identified in IBM Engineering Lifecycle Optimization - Publishing versions 7.0.2 and 7.0.3. This issue allows remote attackers to disrupt service by exploiting inefficient regular expression processing, which can lead to catastrophic backtracking and event loop blocking in server-side environments like Node.js.
IBM Engineering Lifecycle Optimization - Publishing Directory Traversal Vulnerability
A directory traversal vulnerability has been identified in IBM Engineering Lifecycle Optimization - Publishing versions 7.0.2 and 7.0.3. This vulnerability could allow a remote attacker to traverse directories on the system by sending a specially crafted URL request that includes 'dot dot' sequences. Exploitation of this vulnerability could enable the attacker to view arbitrary files on the system.
IBM Engineering Lifecycle Optimization - Publishing Cryptographic Weakness Allowing Decryption of Sensitive Information
A vulnerability exists in IBM Engineering Lifecycle Optimization - Publishing versions 7.0.2 and 7.0.3, where weaker than expected cryptographic algorithms could enable an attacker to decrypt highly sensitive information.
Campcodes School Faculty Scheduling System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Campcodes School Faculty Scheduling System version 1.0. The issue arises in the file /admin/ajax.php, specifically within the login action. The vulnerability allows for remote exploitation by manipulating the username parameter, which is not properly sanitized before being used in a database query. This flaw could be exploited to execute arbitrary SQL commands, potentially leading to unauthorized data access or manipulation.
UpdraftPlus WordPress Plugin PHP Object Injection Vulnerability
A PHP Object Injection vulnerability has been identified in the UpdraftPlus: WP Backup & Migration Plugin for WordPress, affecting versions 1.23.8 prior to 1.24.11. The vulnerability arises from the deserialization of untrusted input in the 'recursive_unserialized_replace' function, allowing unauthenticated attackers to inject PHP objects. While the vulnerable plugin itself does not have a known Payload Execution Chain (POP chain), the vulnerability could be exploited if another plugin or theme with a POP chain is installed on the same site. In such cases, the attacker might be able to delete arbitrary files, access sensitive data, or execute code, depending on the specific POP chain available. To trigger the exploit, an administrator must perform a search and replace action.
Code-Projects Online Shoe Store SQL Injection Vulnerability in summary.php
A critical SQL injection vulnerability has been identified in Code-Projects Online Shoe Store version 1.0. The issue resides in the summary.php file, where the tid parameter is manipulated, allowing attackers to inject malicious SQL queries. This vulnerability can be exploited remotely, potentially leading to unauthorized access to the application's database or even remote code execution.
Code-Projects Online Shoe Store SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Code-Projects Online Shoe Store version 1.0. The issue resides in the file '/function/login.php', where user-supplied email and password parameters are directly inserted into an SQL query without proper validation or sanitization. This vulnerability can be exploited remotely, potentially leading to unauthorized access to the application's database or even remote code execution.
Code-Projects Online Shoe Store Improper Access Control Vulnerability
A critical vulnerability has been identified in Code-Projects Online Shoe Store version 1.0, specifically within the file '/admin/index.php'. This vulnerability arises from broken access controls, allowing any user, including those unauthenticated, to gain administrative privileges and access the admin panel. The issue can be exploited remotely without any authentication.
WP Multi Store Locator Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WP Multi Store Locator plugin for WordPress, affecting all versions through 2.4.1. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into pages. These scripts are executed when a user accesses the compromised page.
WP Social AutoConnect WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP Social AutoConnect plugin for WordPress, affecting all versions through 4.6.2. The vulnerability arises from inadequate nonce validation, allowing unauthenticated attackers to inject malicious scripts via a forged request, provided they can persuade a site administrator to click a link or perform a similar action.
WP Project Manager SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WP Project Manager plugin for WordPress, specifically in versions prior to and including 2.6.16. The vulnerability arises in the '/wp-json/pm/v2/projects/2/task-lists' REST API endpoint, where the 'project_id' parameter is insufficiently sanitized. This flaw allows authenticated attackers with project access to inject additional SQL queries into the existing query, potentially leading to the extraction of sensitive database information.
Turnkey bbPress by WeaverTheme Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Turnkey bbPress by WeaverTheme plugin for WordPress, affecting all versions through 1.6.3. The vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the '_wpnonce' parameter. These injected scripts could be executed if a user is tricked into clicking a link or performing a similar action.
Code-Projects Online Shoe Store SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Code-Projects Online Shoe Store version 1.0. The issue arises in the file '/details2.php', where the 'id' parameter is manipulated, allowing for unauthorized database access. This vulnerability can be exploited remotely, and the public disclosure of the exploit suggests it may be actively used.
Dynamics 365 Integration WordPress Plugin Twig Server-Side Template Injection Vulnerability Allowing Remote Code Execution
A vulnerability allowing remote code execution and arbitrary file read has been identified in the Dynamics 365 Integration plugin for WordPress, affecting all versions through 1.3.23. The issue arises from Twig server-side template injection, caused by inadequate input validation and sanitization in the render function. This vulnerability enables authenticated attackers with Contributor-level access and above to execute code on the server.
Taskbuilder WordPress Project and Task Management Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Taskbuilder WordPress Project & Task Management plugin, affecting all versions through 3.0.6. The vulnerability arises from inadequate input sanitization and output escaping on user-supplied attributes in the wppm_tasks shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the compromised page.
Code-Projects Online Shoe Store SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Code-Projects Online Shoe Store version 1.0. The issue arises in the file '/details.php', where the 'id' parameter is processed without proper validation or sanitization, allowing remote attackers to manipulate the input and execute arbitrary SQL commands. This vulnerability could lead to unauthorized access to the application's database or even remote code execution.
WP Smart Import Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WP Smart Import: Import any XML File to WordPress plugin, affecting all versions through 1.1.2. The vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the 'page' parameter. These injected scripts can be executed if a user is tricked into clicking a link.
Scratch & Win WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Scratch & Win WordPress plugin, specifically in versions through 2.7.1. The issue arises from the reset_installation() function, which lacks proper nonce validation. This vulnerability allows unauthenticated attackers to reset the plugin's installation by sending a forged request, provided they can persuade a site administrator to click a link or perform a similar action.
Backup Migration WordPress Plugin PHP Object Injection Vulnerability
A PHP Object Injection vulnerability has been identified in the Backup Migration plugin for WordPress, affecting all versions up to and including 1.4.6. The issue arises from the deserialization of untrusted input in the 'recursive_unserialize_replace' function, allowing unauthenticated attackers to inject a PHP object. Exploitation is possible if an administrator creates a staging site, as the vulnerability requires this condition to be met.
Code-Projects Student Management System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Code-Projects Student Management System version 1.0. The issue resides in the 'showSubject1' function within '/config/DbFunction.php', where the 'sid' parameter is manipulated, allowing for SQL injection. This vulnerability can be exploited remotely, and other parameters may also be affected.
TCS BaNCS File Inclusion Vulnerability in REPORTS_SHOW_FILE.jsp
A file inclusion vulnerability has been identified in TCS BaNCS version 10. The issue arises in the REPORTS_SHOW_FILE.jsp file, where the FilePath argument can be manipulated to include unauthorized files. However, the existence of this vulnerability is currently under scrutiny.
Code-Projects Point of Sales and Inventory Management System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Code-Projects Point of Sales and Inventory Management System version 1.0. The issue resides in the file '/user/update_account.php', where the 'username' parameter is manipulated, allowing for SQL injection. This vulnerability can be exploited remotely, potentially leading to unauthorized access to sensitive information in the server's database.
Code-Projects Point of Sales and Inventory Management System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in Code-Projects Point of Sales and Inventory Management System version 1.0. The issue resides in the file '/user/search_num.php', where the 'search' parameter is manipulated to execute arbitrary SQL commands. This vulnerability can be exploited remotely, potentially allowing attackers to access sensitive information from the application's database.
