CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 2, 2025

WordPress DX Delete Attached Media Plugin Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the WordPress DX Delete Attached Media plugin, specifically in versions through 2.0.5.1. This vulnerability allows unprivileged users to perform actions that require higher privileges, due to incorrectly configured access control security levels.

1.5
Jan 2, 2025

RumbleTalk Live Group Chat Missing Authorization Vulnerability Allowing Broken Access Control

A broken access control vulnerability has been identified in the RumbleTalk Live Group Chat plugin for WordPress, affecting versions through 6.2.5. This vulnerability arises from missing authorization checks, which can be exploited to manipulate access control security levels incorrectly.

1.8
Jan 2, 2025

WordPress Poll Maker Plugin Broken Access Control Vulnerability

A broken access control vulnerability has been identified in the WordPress Poll Maker plugin, affecting versions through 4.7.1. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.

3.0
Jan 2, 2025

weDevs WP ERP Missing Authorization Vulnerability in Access Control

A broken access control vulnerability has been identified in the weDevs WP ERP plugin, affecting versions through 1.12.6. This vulnerability arises from missing authorization checks, allowing users with lower privileges to perform actions reserved for higher privileged users.

3.8
Jan 2, 2025

gVectors wpDiscuz Broken Access Control Vulnerability

A broken access control vulnerability has been identified in the gVectors wpDiscuz WordPress plugin, affecting versions through 7.6.3. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.

3.1
Jan 2, 2025

CodePeople Appointment Hour Booking Missing Authorization Vulnerability Allowing Broken Access Control

A broken access control vulnerability has been identified in the CodePeople Appointment Hour Booking WordPress plugin, affecting versions through 1.4.23. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.

2.6
Jan 2, 2025

WebToffee WordPress Backup and Migration Missing Authorization Vulnerability

A broken access control vulnerability has been identified in the WebToffee WordPress Backup & Migration plugin, affecting versions through 1.4.1. This vulnerability arises from missing authorization checks, which can be exploited by users with lower privileges to perform actions reserved for higher privileged users.

3.1
Jan 2, 2025

WordPress WPDevArt Responsive Image Gallery and Gallery Album Missing Authorization Vulnerability

A missing authorization vulnerability has been identified in the WPDevArt Responsive Image Gallery, Gallery Album plugin for WordPress, affecting versions through 2.0.3. This vulnerability arises from broken access control, allowing unprivileged users to perform actions reserved for higher privileges.

1.8
Jan 2, 2025

Kali Forms WordPress Plugin Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the Kali Forms WordPress plugin, specifically in the Contact Form builder with drag-and-drop functionality. This issue affects versions through 2.3.28 and allows unprivileged users to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions.

3.1
Jan 2, 2025

WowStore ProductX Gutenberg WooCommerce Blocks Missing Authorization Vulnerability

A missing authorization vulnerability has been identified in the WowStore ProductX Gutenberg WooCommerce Blocks plugin, affecting versions through 2.7.8. This vulnerability arises from incorrectly configured access control, which can be exploited to perform actions that require higher privileges.

1.8
Jan 2, 2025

BoldThemes Bold Timeline Lite Missing Authorization Vulnerability Allowing Broken Access Control

A missing authorization vulnerability has been identified in the BoldThemes Bold Timeline Lite WordPress plugin, affecting versions through 1.1.9. This vulnerability allows exploitation of improperly configured access control, enabling unprivileged users to perform actions reserved for higher privileges.

1.8
Jan 2, 2025

WPDeveloper BetterLinks Plugin Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the WPDeveloper BetterLinks plugin, affecting versions through 1.6.0. This vulnerability allows exploitation of improperly configured access control levels, potentially leading to unauthorized actions by users with lower privileges.

4.0
Jan 2, 2025

CusRev Customer Reviews for WooCommerce Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the CusRev Customer Reviews for WooCommerce plugin, affecting versions through 5.36.0. This vulnerability arises from incorrectly configured access control levels, which can be exploited to perform actions reserved for higher privileged users.

3.1
Jan 2, 2025

AWSM Innovations WP Job Openings Missing Authorization Vulnerability Allowing Broken Access Control

A missing authorization vulnerability has been identified in the AWSM Innovations WP Job Openings plugin, specifically in versions through 3.4.1. This vulnerability allows exploitation of incorrectly configured access control security levels, potentially leading to unauthorized actions by users with lower privileges.

4.0
Jan 2, 2025

WordPress WP Custom Widget Area Plugin Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the WordPress WP Custom Widget Area plugin, specifically in versions through 1.2.5. This vulnerability allows unprivileged users to exploit improperly configured access control, potentially leading to unauthorized actions that require higher privileges.

2.2
Jan 2, 2025

weDevs WP User Frontend Missing Authorization Vulnerability Allowing Broken Access Control

A missing authorization vulnerability has been identified in the weDevs WP User Frontend plugin, specifically in versions through 3.6.8. This vulnerability allows exploitation of improperly configured access control security levels, potentially leading to unauthorized actions by users with lower privileges.

3.8
Jan 2, 2025

WordPress WP Custom Admin Interface Missing Authorization Vulnerability Allowing Broken Access Control

A missing authorization vulnerability has been identified in the WordPress WP Custom Admin Interface plugin, versions through 7.32. This vulnerability allows exploitation of improperly configured access control security levels, potentially enabling unprivileged users to perform actions reserved for higher privileges.

2.2
Jan 2, 2025

Schema App Structured Data Plugin Missing Authorization Vulnerability Allowing Exploitation of Access Control Security Levels

A missing authorization vulnerability has been identified in the Schema App Structured Data WordPress plugin, affecting versions through 1.23.1. This vulnerability allows exploitation of incorrectly configured access control security levels, potentially enabling unauthorized users to perform actions reserved for higher privileges.

2.1
Jan 2, 2025

D-Link DIR-816 A2 DHCP Improper Access Control Vulnerability

A critical vulnerability has been identified in the D-Link DIR-816 A2 router, specifically in version 1.10CNB05_R1B011D88210. The issue arises in the DHCPD Setting Handler, within the file '/goform/form2Dhcpd.cgi'. This vulnerability allows for improper access controls, enabling remote exploitation.

6.4
Jan 2, 2025

D-Link DIR-816 A2 WiFi Settings Improper Access Control Vulnerability

A critical vulnerability has been identified in the D-Link DIR-816 A2 router, specifically in version 1.10CNB05_R1B011D88210. The issue arises in the WiFi Settings Handler, within the file '/goform/form2AdvanceSetup.cgi'. This vulnerability allows for improper access controls, enabling unauthorized users to manipulate settings or access restricted features. The vulnerability can be exploited remotely, without any authentication requirements.

6.3
Jan 2, 2025

Azzaroco WP SuperBackup Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Azzaroco WP SuperBackup plugin for WordPress, affecting versions through 2.3.3. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.

2.0
Jan 2, 2025

WordPress HTML Forms Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress HTML Forms plugin, affecting versions through 1.4.1. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 2, 2025

WordPress SendSMS Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress SendSMS plugin, affecting versions through 1.2.9. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 2, 2025

WordPress User Referral Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress User Referral plugin, affecting versions through 8.0. This issue allows attackers to inject malicious scripts that could be executed when users visit the affected site.

2.0
Jan 2, 2025

WordPress odPhotogallery Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress odPhotogallery plugin, affecting versions through 0.5.3. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 2, 2025

WordPress Upload Scanner Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Upload Scanner plugin, affecting versions through 1.2. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 2, 2025

Irshad Services WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Irshad Services WordPress plugin, specifically in the 'Services updates for customers' component, affecting versions through 1.0. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected page.

2.0
Jan 2, 2025

WordPress FAQs Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress FAQs plugin, affecting versions through 1.0.2. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the site.

2.0
Jan 2, 2025

Foliovision FV Descriptions Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Foliovision FV Descriptions WordPress plugin, affecting versions through 1.4. This issue allows attackers to inject malicious scripts that are executed when users visit the affected page.

2.0
Jan 2, 2025

10CentMail WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the 10CentMail WordPress plugin, affecting versions through 2.1.50. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 2, 2025

Dreamwinner Easy Language Switcher Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Dreamwinner Easy Language Switcher WordPress plugin, affecting versions through 1.0. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.

2.0
Jan 2, 2025

Lemonade Coding Studio Lemonade Social Networks Autoposter Pinterest Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Lemonade Social Networks Autoposter Pinterest plugin for WordPress, affecting versions through 2.0. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.

2.0
Jan 2, 2025

BizSwoop Leads CRM Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the BizSwoop Leads CRM plugin, affecting versions through 2.0.13. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.

2.0
Jan 2, 2025

WordPress Inline Footnotes Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Inline Footnotes plugin, affecting versions through 2.3.0. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.7
Jan 2, 2025

D-Link DIR-816 A2 Access Control Vulnerability in Virtual Service Handler

A critical access control vulnerability has been identified in the D-Link DIR-816 A2 router, specifically in version 1.10CNB05_R1B011D88210. The issue arises from improper access controls in the Virtual Service Handler component, particularly within the file '/goform/form2AddVrtsrv.cgi'. This vulnerability allows unauthorized users to manipulate the service handler, potentially leading to unauthorized access or actions.

6.4
Jan 2, 2025

D-Link DIR-816 A2 Improper Access Control Vulnerability in DDNS Service

A critical vulnerability has been identified in the D-Link DIR-816 A2 router, specifically in version 1.10CNB05_R1B011D88210. The issue resides within the DDNS service component, particularly in the '/goform/DDNS' file. This vulnerability allows for improper access control, enabling unauthorized users to manipulate DDNS settings remotely without authentication.

6.3
Jan 2, 2025

ASUS Routers Unintended Entry Point Vulnerability Allowing Arbitrary Command Execution

A vulnerability has been identified in certain ASUS router models that creates an unintended entry point, potentially allowing arbitrary command execution. This issue is detailed in the '01/02/2025 ASUS Router AiCloud vulnerability' section of the ASUS Security Advisory.

1.6
Jan 2, 2025

Code-Projects Job Recruitment SQL Injection Vulnerability in Seeker Profile Handler

A critical SQL injection vulnerability has been identified in Code-Projects Job Recruitment version 1.0. The issue resides in the Seeker Profile Handler component, specifically within the file '_parse/_call_main_search_ajax.php'. The vulnerability is triggered by manipulating the 's1' parameter, allowing remote attackers to execute arbitrary SQL commands. This exploitation could lead to unauthorized access to sensitive information in the server's database.

2.9
Jan 2, 2025

Code-Projects Job Recruitment SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in the Job Recruitment application, version 1.0. The issue arises in the Job Post Handler component, specifically within the file '/_parse/_call_job/search_ajax.php'. The vulnerability allows remote attackers to manipulate the 'n' argument, leading to unauthorized database access or manipulation.

2.5
Jan 2, 2025

ASUS Routers AiCloud Improper Input Insertion Vulnerability Leading to Arbitrary Command Execution

A vulnerability allowing arbitrary command execution has been identified in the AiCloud feature of certain ASUS router models. This issue arises from improper input insertion and affects several different router models. Users can refer to the ASUS Security Advisory for detailed information about the specific models impacted.

1.6
Jan 2, 2025

AHAthat WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the AHAthat WordPress plugin, affecting versions through 1.6. The issue arises because the plugin does not properly escape the 'REQUEST_URI' parameter from the server before outputting it in an attribute. This flaw could be exploited in older web browsers.

3.4
Jan 2, 2025

Goodlayers Core WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Goodlayers Core WordPress plugin, affecting versions prior to 2.0.10. The issue arises because the plugin fails to properly sanitize and escape certain settings, potentially allowing users with contributor roles and above to execute XSS attacks that are stored and could be triggered later.

2.9
Jan 2, 2025

wp-enable-svg WordPress Plugin SVG Upload Vulnerability Allowing Cross-Site Scripting

A stored cross-site scripting vulnerability has been identified in the wp-enable-svg WordPress plugin, affecting versions through 0.7. The issue arises because the plugin does not properly sanitize SVG files upon upload, allowing users with author roles and above to upload SVGs that contain malicious scripts.

3.0
Jan 2, 2025

Net::EasyTCP Perl Package Random Number Generation Vulnerability

A vulnerability exists in the Net::EasyTCP package for Perl, specifically in versions 0.15 through 0.26. The issue arises because the package relies on Perl's built-in random number generator, rand(), which is not secure, unless a stronger randomization module is available. This vulnerability can lead to predictable random number generation, potentially compromising cryptographic operations.

2.9
Jan 2, 2025

Net::EasyTCP Cryptographic Weakness Vulnerability

A vulnerability exists in the Net::EasyTCP package for Perl, specifically in versions prior to 0.15. The issue arises because the package relies on Perl's built-in random number generator, rand(), which is not suitable for cryptographic purposes, to create cryptographic keys. This could lead to predictable key generation and potential security risks in applications using this module.

3.5
Jan 2, 2025

Landray EIS SQL Injection Vulnerability

A SQL injection vulnerability has been identified in Landray EIS versions 2001 through 2006. The issue arises in the 'Message/fi_message_receiver.aspx' page, where the 'replyid' parameter is vulnerable to injection attacks.

3.0
Jan 2, 2025

Huang Yaoshi Pharmaceutical Management Software Arbitrary File Upload Vulnerability

An arbitrary file upload vulnerability has been identified in Huang Yaoshi Pharmaceutical Management Software versions through 16.0. The issue arises in the UploadFile function within the XSDService.asmx file, where the fileName element can be manipulated to upload files with .asp extensions. This vulnerability allows attackers to upload arbitrary files and potentially execute them on the server.

4.0
Jan 1, 2025

Code-Projects Job Recruitment SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Code-Projects Job Recruitment version 1.0. The issue resides in the file '/_parse/_feedback_system.php', where the 'person' parameter is manipulated, allowing for remote exploitation. This vulnerability enables attackers to execute arbitrary SQL commands, potentially leading to unauthorized access or manipulation of database information.

2.9
Jan 1, 2025

Travel Tour Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Travel Tour WordPress theme, versions prior to 5.2.4. The issue arises because the theme fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.

2.0
Jan 1, 2025

WordPress Category Post Shortcode Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Category Post Shortcode plugin, affecting versions through 2.4. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.7