CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
MacPorts PortsCLI Remote Code Execution Vulnerability via Compromised Mirror
A vulnerability exists in the MacPorts package manager for macOS, specifically in the PortsCLI component. When a user runs 'port selfupdate' against a malicious or compromised MacPorts mirror, the mirror can execute arbitrary commands as root on the user's machine. This issue arises because the MacPorts client uses 'rsync' to download update files from the mirror. If the mirror serves a valid, signed archive along with additional crafted files, the client can be tricked into executing commands specified in those files, bypassing signature validation.
SourceCodester Home Clean Services Management System SQL Injection Vulnerability
A critical SQL injection vulnerability has been identified in SourceCodester Home Clean Services Management System version 1.0. The issue arises in the file '/public_html/admin/process.php', where the manipulation of the 'type', 'length', and 'business' arguments allows for SQL injection. This vulnerability can be exploited remotely, and the details of the exploit have been disclosed publicly.
IBM Security ReaQta Sensitive Information Disclosure Vulnerability
A vulnerability in IBM Security ReaQta version 3.12 has been identified, where the application improperly discloses sensitive information in HTTP responses. This information could potentially be exploited in further attacks against the system.
IBM Security ReaQta Denial-of-Service Vulnerability Allowing Privileged Users to Disrupt Service
A denial-of-service vulnerability has been identified in IBM Security ReaQta version 3.12. This issue could allow a privileged user to disrupt service by sending multiple administration requests, which could overwhelm the system due to improper resource allocation.
User Profile Builder Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the User Profile Builder plugin for WordPress, specifically in versions through 3.12.9. This vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into user meta parameters. The injected scripts are executed when a user accesses the affected page and clicks a link to view the user meta.
LibreOffice Environmental Variable and INI File Value Exfiltration Vulnerability
A vulnerability in LibreOffice prior to 24.8.4 allows for the exfiltration of potentially sensitive information by expanding environmental variables and INI file values in URLs. When a document containing such links is opened, the information could be sent to a remote server. This issue arises from the application's handling of URLs, which could be crafted to exploit the variable expansion feature.
WP Job Portal Insecure Direct Object Reference Vulnerability
A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the WP Job Portal plugin for WordPress, in all versions through 2.2.5. This vulnerability arises from inadequate validation of a user-controlled key, enabling authenticated attackers with Subscriber-level access or higher to submit resumes on behalf of other applicants when applying for jobs.
IBM Concert Software Sensitive Information Disclosure Vulnerability
A vulnerability in IBM Concert Software versions 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 allows remote attackers to access sensitive information through detailed technical error messages displayed in the browser. This information could be leveraged for further attacks against the system.
IBM Concert Software Log Injection and Information Disclosure Vulnerability
A vulnerability exists in IBM Concert Software versions 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3, allowing authenticated users to inject malicious information or extract data from log files. This issue arises from improper neutralization of log output, which could be exploited to manipulate log contents or retrieve sensitive information.
IBM Concert Software Sensitive Information Disclosure Vulnerability
A vulnerability in IBM Concert Software versions 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow an unauthorized actor to access sensitive system information. This information disclosure could be leveraged for further attacks against the system.
IBM Concert Software HTTP Strict Transport Security Vulnerability Allowing Sensitive Information Disclosure
A vulnerability exists in IBM Concert Software versions 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3, due to improper implementation of HTTP Strict Transport Security. This flaw could enable a remote attacker to intercept and access sensitive information through man-in-the-middle techniques.
WordPress RSVP and Event Management Plugin Missing Authorization Vulnerability
A vulnerability exists in the RSVP and Event Management plugin for WordPress, in all versions through 2.7.13. The issue arises from several AJAX functions lacking proper capability checks, which allows unauthorized access. This flaw enables unauthenticated attackers to delete questions and attendees, while authenticated users can modify question menu orders.
BWD Elementor Addons Sensitive Information Exposure Vulnerability
A vulnerability allowing sensitive information exposure exists in the BWD Elementor Addons plugin for WordPress, affecting all versions through 4.3.18. The issue is located in the 'widgets/bwdeb-content-switcher.php' file, where authenticated attackers with Contributor-level access and above can access private, pending, and draft template data.
LibreOffice Path Traversal Vulnerability Allowing Arbitrary .ttf File Write
A path traversal vulnerability has been identified in LibreOffice versions 24.8 prior to 24.8.4, allowing for absolute path traversal. This vulnerability enables an attacker to write to arbitrary locations, provided the locations are accessible for writing, by embedding a file in a format that supports embedded fonts. The written files are always suffixed with '.ttf'.
Jupiter X Core Missing Authorization Vulnerability in Popup Template Export
A vulnerability exists in the Jupiter X Core plugin for WordPress, allowing unauthorized access to popup template data. This issue arises from a lack of proper capability checks in the export_popup_action() function, affecting all versions up to and including 4.8.5. As a result, unauthenticated attackers can export popup templates without authorization.
Jupiter X Core Missing Authorization Vulnerability in Library Sync Function
A vulnerability exists in the Jupiter X Core plugin for WordPress, all versions through 4.8.5, due to a lack of proper capability checks in the sync_libraries() function. This flaw allows authenticated users with Subscriber-level access and higher to synchronize libraries without authorization.
Quill Forms WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Quill Forms WordPress plugin, specifically in versions through 3.10.0. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'quillforms-popup' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
WordPress Ach Invoice App Local File Inclusion Vulnerability
A local file inclusion vulnerability has been identified in the WordPress Ach Invoice App plugin, affecting versions through 1.0.1. This vulnerability arises from improper control of filenames in include or require statements, allowing PHP remote file inclusion that could be exploited to include local files from the server.
WordPress WPAchievements Free Plugin Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress WPAchievements Free plugin, affecting versions through 1.2.0. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress SyncFields Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress SyncFields plugin, affecting versions through 2.1. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress WP Advertising Management Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress WP Advertising Management plugin, affecting versions through 1.0.3. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Target Notifications Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress Target Notifications plugin, specifically in versions through 1.1.1. This issue arises from improper input neutralization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.
Kikx Simple Post Author Filter Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Kikx Simple Post Author Filter plugin for WordPress, affecting versions through 1.0. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected page.
Balcom-Vetillo Design BVD Easy Gallery Manager Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the BVD Easy Gallery Manager plugin by Balcom-Vetillo Design, Inc. This issue affects versions of the plugin through 1.0.6. The vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.
ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in the ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin, affecting versions through 1.4.9. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing for direct manipulation of the database. Such exploitation could lead to unauthorized data access or modification.
WordPress Contact Form 7 Database CFDB7 SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WordPress plugin Contact Form 7 Database – CFDB7, affecting versions through 1.0.0. This vulnerability allows for improper neutralization of special elements used in SQL commands, enabling malicious actors to manipulate database queries.
WordPress Auction Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WordPress Auction Plugin, affecting versions through 3.7. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing attackers to manipulate database queries and potentially access or modify database information.
RTO DynamicTags WordPress Plugin SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in the RTO GmbH DynamicTags WordPress plugin, affecting versions through 1.4.0. This vulnerability allows for improper neutralization of special elements used in SQL commands, enabling direct interaction with the database, such as unauthorized data access or manipulation.
WordPress BSK Forms Blacklist Plugin Cross-Site Request Forgery Vulnerability Allowing Blind SQL Injection
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress BSK Forms Blacklist plugin, specifically in versions through 3.9. This vulnerability allows for Blind SQL Injection. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could manipulate the database.
WordPress wpSOL Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress wpSOL plugin, specifically in versions through 1.2.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where a malicious actor could trick users with higher privileges into performing actions that could lead to the execution of harmful scripts.
WordPress WP Simple Sitemap Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP Simple Sitemap plugin for WordPress, specifically in versions through 0.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.
WordPress Store Commerce Theme DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress Store Commerce theme, affecting versions through 1.2.3. This issue arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
WordPress Wizhi Multi Filters by Wenprise Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Wizhi Multi Filters by Wenprise plugin, affecting versions through 1.8.6. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.
Piotnet Addons For Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Piotnet Addons For Elementor WordPress plugin, affecting versions through 2.4.31. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
Elevio WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Elevio WordPress plugin, affecting versions through 4.4.1. This vulnerability allows for Stored Cross-Site Scripting, where an attacker could trick users with higher privileges into performing actions that could lead to the injection of malicious scripts.
WordPress EO4WP Plugin Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress EO4WP plugin, affecting versions through 1.0.8.1. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
5centsCDN WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the 5centsCDN WordPress plugin, affecting versions through 25.4.15. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Autocompleter Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Autocompleter plugin, specifically in versions through 1.3.5.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed.
Andon Ivanov OZ Canonical WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Andon Ivanov OZ Canonical WordPress plugin, affecting versions through 0.5. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Jewel Theme Image Hover Effects for Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Jewel Theme Image Hover Effects plugin for Elementor, affecting versions through 1.0.2.3. This vulnerability allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.
TheInnovs ElementsCSS Addons for Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in TheInnovs ElementsCSS Addons for Elementor, affecting versions through 1.0.8.7. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
ProductDyno WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the ProductDyno WordPress plugin, specifically in versions through 1.0.24. This issue allows attackers to inject malicious scripts that could be executed when users visit the affected site.
WPBits WPBITS Addons For Elementor Page Builder Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in WPBits WPBITS Addons For Elementor Page Builder, affecting versions through 1.5.1. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WPDeveloper Typing Text Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WPDeveloper Typing Text plugin, affecting versions through 1.2.7. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
ThimPress Thim Elementor Kit DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the Thim Elementor Kit WordPress plugin, affecting versions through 1.2.8. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
TemplatesNext WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the TemplatesNext WordPress plugin, specifically in versions through 3.2.9. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject harmful scripts that are executed when users visit the affected site.
WordPress SpeakOut! Email Petitions Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress SpeakOut! Email Petitions plugin, affecting versions through 4.4.2. This vulnerability arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute harmful scripts on the website.
WordPress Smart Custom Fields Plugin Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Smart Custom Fields plugin, affecting versions through 5.0.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WP OnlineSupport Hero Banner Ultimate Local File Inclusion Vulnerability
A local file inclusion vulnerability has been identified in the WP OnlineSupport Hero Banner Ultimate plugin, affecting versions through 1.4.4. This vulnerability arises from improper control of filename parameters in PHP include or require statements, allowing potentially malicious actors to include and execute local files on the server.
WordPress WP Visitor Statistics Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the WP Visitor Statistics (Real Time Traffic) plugin for WordPress, affecting versions through 7.5. This vulnerability allows unprivileged users to exploit improperly configured access control levels, potentially leading to unauthorized actions.
