CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 7, 2025

ARS Affiliate Page Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the ARS Affiliate Page Plugin for WordPress, affecting all versions through 2.0.2. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the 'utm_keyword' parameter. These injected scripts could be executed on pages if a user is tricked into clicking a link.

2.0
Jan 7, 2025

Formaloo Form Maker and Customer Analytics for WordPress and WooCommerce Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce plugin, affecting all versions through 2.1.3.2. The vulnerability arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts. These scripts are executed when a user accesses the compromised page.

2.7
Jan 7, 2025

Slider Pro Lite Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Slider Pro Lite plugin for WordPress, affecting all versions through 1.4.1. The issue arises from inadequate input sanitization and output escaping on user-supplied attributes, particularly within the 'sliderpro' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected page.

2.7
Jan 7, 2025

Sell Media WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Sell Media plugin for WordPress, affecting all versions through 2.5.8.5. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'sell_media_search_form_gutenberg' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.4
Jan 7, 2025

Timeline Designer WordPress Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the Timeline Designer plugin for WordPress, affecting all versions through 1.4. The issue arises from inadequate escaping of user-supplied data in the 's' parameter, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information within the database.

2.6
Jan 7, 2025

Dell Update Package Framework Local Privilege Escalation Vulnerability

A local privilege escalation vulnerability has been identified in the Dell Update Package Framework, affecting versions prior to 22.01.02. This vulnerability allows a low-privileged local attacker to execute arbitrary remote scripts on the server, potentially leading to a denial-of-service condition.

1.3
Jan 6, 2025

Deno Cross-Origin Authorization Header Leak Vulnerability

A vulnerability exists in Deno's fetch() redirect handling, where the Authorization header is not properly managed during cross-origin redirects. When a request with an Authorization header is sent to one domain and the response redirects to a different domain, Deno retains the original Authorization header in the follow-up request. This behavior leaks the header's content to the second domain, contrary to the expected behavior of dropping the Authorization header in such scenarios. The issue arises because Deno does not adhere to the same-origin policy and lacks a cookie jar, leading to unintentional leakage of authenticated data across origins. This vulnerability affects Deno versions prior to 1.46.4 and 2.1.2, as well as deno_fetch versions 0.204.0 and through 0.0.1.

5.5
Jan 6, 2025

FRRouting RTR Buffer Overflow Vulnerability Leading to Performance Degradation

A vulnerability in FRRouting (FRR) versions 6.0 prior to 10.3 allows for route re-validation to be triggered when an update received via the RTR protocol exceeds the default socket buffer size of 4K. This can be exploited by causing a large number of updates to be sent during the update interval, which typically lasts 30 minutes. The issue can also occur organically, but when exploited, it forces continuous route validation. Routers with large routing tables may take longer than 30 minutes to complete this process, leading to potential performance impacts. Additionally, the re-validation increases BMP traffic to ingestors.

3.4
Jan 6, 2025

AVM FRITZ!Box 7530 AX Unauthenticated Information Disclosure Vulnerability

A vulnerability exists in the AVM FRITZ!Box 7530 AX router, specifically in version 7.59, allowing unauthorized access to sensitive information through the '/juis_boxinfo.xml' file. This issue arises from an access control flaw that permits remote attackers to retrieve data without authentication. However, the reported vulnerability is disputed by the supplier, who states it cannot be reproduced and attributes the issue to an unintended configuration with direct Internet exposure.

3.8
Jan 6, 2025

ipTIME A2004 Access Control Vulnerability in hostinfo2.cgi Allowing Unauthorized Information Disclosure

An access control vulnerability has been identified in the ipTIME A2004 router, specifically in the login component hostinfo2.cgi, version 12.17.0. This vulnerability allows attackers to access sensitive information without authentication.

2.5
Jan 6, 2025

Plane Profile Image Upload Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability exists in Plane versions prior to 0.23. This issue allows authenticated users to upload SVG files as profile images. These SVG files can contain malicious JavaScript that executes in the browsers of users viewing the profile image.

2.4
Jan 6, 2025

ipTIME A2004 Access Control Vulnerability in hostinfo.cgi Allowing Unauthorized Information Disclosure

An access control vulnerability has been identified in the ipTIME A2004 router, specifically in version 12.17.0. The issue resides in the '/login/hostinfo.cgi' component, where attackers can access sensitive information, including version details, without authentication. This vulnerability could be exploited by simply visiting the affected URL.

3.8
Jan 6, 2025

BG.Studio Color Phone Call Screen App Intent-Based Call Placing Vulnerability

A vulnerability in the Color Phone Call Screen App (com.asianmobile.callcolor) for Android, up to version 24, allows any application to place phone calls without user interaction. This is achieved by sending a crafted intent to the exported CallActivity component, bypassing normal permission requirements.

1.8
Jan 6, 2025

Call Screen Application Intent-Based Unattended Call Initiation Vulnerability

A vulnerability in the 'iCall OS17 - Color Phone Flash' application, specifically in versions through 4.3 for Android, allows any application to make phone calls without user interaction. This is achieved by sending a crafted intent to the 'com.callos14.callscreen.colorphone.DialerActivity' component, bypassing normal permission requirements.

3.4
Jan 6, 2025

Color Phone Call Screen Themes Intent-Based Unattended Call Initiation Vulnerability

A vulnerability in the Color Phone Call Screen Themes application for Android, specifically in versions through 1.1.2, allows any app to make phone calls without user interaction. This is achieved by sending a specially crafted intent to the 'com.frovis.androidbase.call.DialerActivity' component, bypassing normal permission requirements.

1.8
Jan 6, 2025

Color Call Theme & Call Screen Insecure Permission Vulnerability Allowing Unattended Outgoing Calls

A vulnerability in the Color Call Theme & Call Screen application, specifically in version 1.0.7 for Android, allows any app to make phone calls on behalf of the user without permission or interaction. This is achieved by sending a specially crafted intent to the exported DialerActivity component.

1.5
Jan 6, 2025

GeniusTools Color Phone Call Screen Theme Unintended Outgoing Call Vulnerability

A vulnerability in the Color Phone: Call Screen Theme application, specifically in version 21.1.9 for Android, allows any app to make phone calls without user interaction. This is achieved by sending a crafted intent to the exported DialerActivity component, bypassing normal permission requirements.

1.8
Jan 6, 2025

Glitter Caller Screen Insecure Permission Vulnerability Allowing Unauthorized Phone Calls

A vulnerability in the Glitter Caller Screen application (also known as iCaller, Caller Theme & Dialer) for Android, in versions through 1.1, allows any application to make phone calls on behalf of the user without permission or interaction. This is achieved by sending a specially crafted intent to the exported 'com.glitter.caller.screen.DialerActivity' component.

1.8
Jan 6, 2025

Redis Denial-of-Service Vulnerability Due to Malformed ACL Selectors

A denial-of-service vulnerability has been identified in Redis versions 7.0.0 and later. The issue arises when an authenticated user with sufficient privileges creates a malformed Access Control List (ACL) selector. When this malformed selector is accessed, it triggers a server panic, leading to a crash and subsequent denial-of-service condition.

3.2
Jan 6, 2025

Netis Routers Information Disclosure Vulnerability

A vulnerability allowing remote attackers to access sensitive information exists in multiple Netis router models, including the Wifi6 Router NX10 (versions 2.0.1.3643 and 2.0.1.3582), Wifi 11AC Router NC65 (version 3.0.0.3749), Wifi 11AC Router NC63 (versions 3.0.0.3327 and 3.0.0.3503), Wifi 11AC Router NC21 (versions 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329), and Wifi Router MW5360 (versions 1.0.1.3442 and 1.0.1.3031). The issue arises from the endpoint /cgi-bin/skk_set.cgi and the binary /bin/scripts/start_wifi.sh, which can be exploited to retrieve confidential information.

4.1
Jan 6, 2025

Netis Routers Sensitive Information Disclosure Vulnerability

A vulnerability exists in multiple Netis router models, including the Wifi6 Router NX10, Wifi 11AC Routers NC65, NC63, NC21, and the Wifi Router MW5360. This issue allows remote attackers to access sensitive information by exploiting the password parameter on the change admin password page of the router's web interface.

4.2
Jan 6, 2025

Netis Routers Information Disclosure Vulnerability in skk_get.cgi Component

A vulnerability allowing remote attackers to access sensitive information exists in several Netis router models, including the Wifi6 Router NX10 (versions 2.0.1.3643 and 2.0.1.3582), Wifi 11AC Router NC65 (version 3.0.0.3749), Wifi 11AC Router NC63 (versions 3.0.0.3327 and 3.0.0.3503), Wifi 11AC Router NC21 (versions 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329), and Wifi Router MW5360 (versions 1.0.1.3442 and 1.0.1.3031). The issue arises from the skk_get.cgi component, where the mode_name and wl_link parameters can be exploited to retrieve sensitive information.

4.1
Jan 6, 2025

Redis Remote Code Execution Vulnerability via Lua Scripting

A remote code execution vulnerability has been identified in Redis versions prior to 6.2.17, 7.2.7, and 7.4.2. This issue allows an authenticated user to execute a specially crafted Lua script that manipulates the garbage collector, potentially leading to arbitrary code execution. The vulnerability exists in all versions of Redis that support Lua scripting.

5.3
Jan 6, 2025

Inspur ClusterEngine Privilege Escalation Vulnerability in getJobsByShell Component

A privilege escalation vulnerability has been identified in Inspur ClusterEngine version 4.0. This issue arises from an improper SUID configuration in the component '/opt/tsce4/torque6/bin/getJobsByShell', allowing non-administrative users to gain root access by exploiting the SUID mechanism. The vulnerability enables these users to execute arbitrary commands with elevated privileges.

3.7
Jan 6, 2025

Grocy CSRF Vulnerability Allowing Password Change for Administrators

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Grocy versions through 4.3.0. The application lacks CSRF protection, as the session token does not have security flags and no countermeasures are implemented. This vulnerability allows users to change the password of the administrator by exploiting the absence of CSRF safeguards.

3.7
Jan 6, 2025

Grocy Information Disclosure Vulnerability

An information disclosure vulnerability exists in Grocy versions through 4.3.0. It allows remote attackers to access sensitive data by directly requesting pages that are not visible in the user interface, such as the calendar and recipes. This issue is a result of broken access control, where unauthorized users can bypass restrictions by accessing certain URLs or API endpoints directly.

4.5
Jan 6, 2025

Guzzle OAuth Subscriber Insufficient Nonce Entropy Vulnerability Allowing Replay Attacks

A vulnerability exists in Guzzle OAuth Subscriber versions prior to 0.8.1, where the OAuth 1.0 nonce generation lacks adequate entropy and does not utilize a cryptographically secure pseudorandom source. This deficiency can expose servers to replay attacks, particularly when TLS is not implemented.

3.1
Jan 6, 2025

Grocy Stored Cross-Site Scripting Vulnerability Leading to Privilege Escalation

A stored cross-site scripting vulnerability has been identified in Grocy versions through 4.3.0. This issue allows for privilege escalation by uploading a malicious HTML or SVG file, which is not properly validated, to the edit profile section. When the file is accessed by an administrator, the embedded script is executed, potentially leading to unauthorized actions such as changing an admin password.

3.3
Jan 6, 2025

ASUS System Analysis IO Improper Access Control Vulnerability in AsusSAIO.sys Driver

A vulnerability has been identified in the AsusSAIO.sys driver associated with ASUS System Analysis IO version 1.0.0. This vulnerability allows low-privileged users to bypass access controls and misuse driver functionalities by sending specially crafted IOCTL requests. The exploitation of this vulnerability could lead to privilege escalation, unauthorized code execution with elevated rights, and information disclosure. Additionally, because these drivers are signed, they could potentially be used to circumvent Microsoft's driver-signing policy to execute malicious code.

2.6
Jan 6, 2025

ITE Tech ITE IO Access Arbitrary Port Read and Write Vulnerability

A vulnerability in the DeviceloControl function of ITE Tech, Inc. ITE IO Access version 1.0.0.0, allows attackers to execute arbitrary read and write operations on ports by sending crafted IOCTL requests.

2.9
Jan 6, 2025

REDAXO CMS Stored Cross-Site Scripting Vulnerability Allowing Arbitrary Code Execution

A stored cross-site scripting vulnerability has been identified in REDAXO CMS version 5.17.1. This vulnerability allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the password parameter of the /media/test.html component. Additionally, this vulnerability can lead to authenticated arbitrary code execution, according to the vulnerability's author.

3.1
Jan 6, 2025

Grav Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability exists in Grav version 1.7.45. This issue allows users with limited page creation rights to inject malicious JavaScript into their pages, which could be executed by anyone viewing the page, including administrators. The vulnerability arises from inadequate input validation and content filtering, enabling the execution of unauthorized scripts.

5.0
Jan 6, 2025

ChestnutCMS File Upload Vulnerability Allowing Unrestricted File Types

A file upload vulnerability has been identified in ChestnutCMS versions through 1.5.0. The issue arises in the /api/member/avatar API endpoint, which accepts a base64-encoded image string. This string is processed by the memberService.uploadAvatarByBase64 method, where the image is decoded and saved to a file without proper validation of the file extension. This vulnerability is particularly concerning because it is exposed to the frontend, allowing for potentially harmful files to be uploaded.

3.6
Jan 6, 2025

Suricata TCP Urgent Data Handling Evasion Vulnerability

A vulnerability in Suricata's TCP stream processing prior to version 7.0.8 allows TCP urgent data to be mismanaged, potentially leading to evasion of detection. This issue arises because Suricata may analyze traffic differently than applications at the TCP endpoints, creating a disconnect in how data is processed. In versions prior to 7.0.8, urgent data was ignored, but many applications rely on this data being processed out-of-band. The vulnerability can be exploited by sending TCP packets with the urgent flag set, which Suricata will handle according to its default or configured policies, creating gaps or inconsistencies in the data analysis.

3.5
Jan 6, 2025

Suricata DNS Resource Name Compression Vulnerability Leading to Log Resource Starvation

A vulnerability in Suricata's DNS handling prior to version 7.0.8 allows DNS resource name compression to create small DNS messages with excessively large hostnames. This can be expensive to decode and result in oversized DNS log entries. Although there are limits to prevent this, they were not stringent enough. The issue has been fixed in Suricata version 7.0.8.

3.5
Jan 6, 2025

Suricata Buffer Overflow Vulnerability in TCP Stream Handling

A buffer overflow vulnerability has been identified in Suricata versions prior to 7.0.8. This issue arises from an unsigned integer underflow, which allows a specially crafted TCP stream to cause a significant buffer overflow. The vulnerability occurs because the buffer is initialized with zeroes using memset, creating an opportunity for the overflow to be exploited.

3.5
Jan 6, 2025

Suricata Buffer Overflow Vulnerability in BPF Filter Handling

A buffer overflow vulnerability has been identified in Suricata, a network intrusion detection and prevention system, prior to version 7.0.8. The issue arises when a large Berkeley Packet Filter (BPF) file is provided to Suricata at startup, leading to a buffer overflow condition. This vulnerability requires user interaction, as it involves the use of untrusted files with the 'suricata -F' command line option.

3.1
Jan 6, 2025

Z-BlogPHP Arbitrary Code Execution Vulnerability

An arbitrary code execution vulnerability exists in Z-BlogPHP versions through 1.7.3. The issue arises from a file upload vulnerability in the Z-Blog admin panel, where the system fails to properly validate theme files before allowing them to be uploaded. This lack of scrutiny enables attackers to inject malicious code into a theme file, which is then executed by the server. Exploitation of this vulnerability allows attackers to execute arbitrary code on the host machine, potentially leading to full control over the compromised system.

3.6
Jan 6, 2025

SeaCMS Incorrect Access Control Vulnerability Allowing Bulk Account Registration

A logic flaw in SeaCMS version 13.1 has been identified, allowing any user to register accounts in bulk. This vulnerability arises from incorrect access control, which can be exploited by attackers to bypass normal registration limits.

4.7
Jan 6, 2025

SeaCMS Incorrect Access Control Vulnerability Allowing Unlimited Member Recharges

A vulnerability in SeaCMS version 13.1 has been identified, allowing incorrect access control that can be exploited to enable any user to recharge membership for an indefinite period. This logic flaw could lead to unauthorized benefits or privileges within the application.

4.7
Jan 6, 2025

SecureAge Security Suite Privilege Escalation Vulnerability Allowing Arbitrary File Manipulation

A privilege escalation vulnerability exists in SecureAge Security Suite versions 7.0.x prior to 7.0.38, 7.1.x prior to 7.1.11, 8.0.x prior to 8.0.18, and 8.1.x prior to 8.1.18. This vulnerability allows unauthorized users to create, modify, and delete files arbitrarily.

1.1
Jan 6, 2025

IceHRM Reflected Cross-Site Scripting Vulnerability in Login Page

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in the login page of IceHRM version 32.4.0.OS. This vulnerability arises from inadequate sanitization of the 'next' parameter, which is returned in the application's response without proper escaping. As a result, an attacker can exploit this issue by persuading a user to click on a specially crafted URL, leading to the execution of arbitrary JavaScript code in the context of the user's browser. This vulnerability exists despite the application having some sanitization measures in place.

2.6
Jan 6, 2025

NiceGUI Authentication Vulnerability Allowing Session Hijacking Across Browsers

A vulnerability in NiceGUI versions prior to 2.9.1 allows for session hijacking across different browsers, including incognito mode. When a user logs in on one browser, the session is shared with all other browsers without requiring a password. This issue has been addressed in NiceGUI version 2.9.1.

3.5
Jan 6, 2025

AAT Data Exfiltration Vulnerability

A data exfiltration vulnerability has been identified in AAT (Another Activity Tracker) versions prior to 1.26. This vulnerability allows malicious apps installed on the same device to access and read data from AAT, including sensitive geolocation information.

1.4
Jan 6, 2025

go-git Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in go-git versions prior to 5.13. This issue allows an attacker to cause resource exhaustion in go-git clients by sending specially crafted responses from a Git server. This vulnerability does not affect the upstream Git command-line interface.

3.6
Jan 6, 2025

go-git Argument Injection Vulnerability Allowing Arbitrary git-upload-pack Flag Modification

An argument injection vulnerability has been identified in go-git, a Git implementation library written in Go, affecting versions 4.0.0 prior to 5.13.0. The vulnerability arises when the file transport protocol is used, as this is the only protocol that interacts with Git binaries. Exploitation could allow an attacker to inject arbitrary values into git-upload-pack flags.

3.6
Jan 6, 2025

Linux Kernel Uninitialized Value Vulnerability in DVB Frontend DIB3000MB

A vulnerability has been identified in the Linux kernel's DVB frontend component, specifically in the DIB3000MB driver. This issue involves the use of an uninitialized value in the 'DIB3000_READ_REG' function, which can lead to undefined behavior. The problem arises because a local buffer is used in an I2C transfer as a read buffer; if the transfer fails, the buffer may contain unpredictable values. The 'DIB3000_WRITE_REG' function lacks proper error handling for this scenario, creating a potential risk. The vulnerability has been addressed by initializing the read buffer to zero before use.

5.6
Jan 6, 2025

Linux Kernel BPF Processor ID Function Vulnerability in Non-SMP Configurations

A vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) subsystem has been addressed. The issue arose on x86-64 architectures when calling the function 'bpf_get_smp_processor_id()' in a kernel with 'CONFIG_SMP' disabled. This situation can lead to a page fault error because 'pcpu_hot' is unavailable, causing a supervisor read access violation in kernel mode. The vulnerability has been fixed by modifying the function to return 0 when 'CONFIG_SMP' is not enabled.

5.3
Jan 6, 2025

Linux Kernel DMA Engine Null Pointer Dereference Vulnerability in AT XDMAC Component

A null pointer dereference vulnerability has been identified in the Linux kernel's DMA engine, specifically within the AT XDMAC component. The issue arises in the 'at_xdmac_memset_create_desc' function, which may return a NULL value. This can lead to a null pointer dereference if, for instance, the 'len' input is erroneous, or if the 'atchan->free_descs_list' is empty and memory resources are depleted. The vulnerability has been addressed by adding a check to prevent the null pointer dereference.

5.7
Jan 6, 2025

Linux Kernel Double Free Vulnerability in MTD Raw NAND Subsystem

A double free vulnerability has been identified in the Linux kernel's MTD raw NAND subsystem, specifically within the Atmel PMECC (Error Correction Code) handling function. The issue arises because the 'user' pointer, which was originally allocated using kzalloc(), was changed to be allocated by devm_kzalloc(). This modification creates a scenario where calling kfree(user) results in a double free condition, potentially leading to memory corruption or other unintended consequences.

5.7