CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 4, 2025

Code-Projects Online Shoe Store Improper Access Control Vulnerability

A critical vulnerability has been identified in Code-Projects Online Shoe Store version 1.0, specifically within the file '/admin/index.php'. This vulnerability arises from broken access controls, allowing any user, including those unauthenticated, to gain administrative privileges and access the admin panel. The issue can be exploited remotely without any authentication.

4.6
Jan 4, 2025

WP Multi Store Locator Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WP Multi Store Locator plugin for WordPress, affecting all versions through 2.4.1. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into pages. These scripts are executed when a user accesses the compromised page.

3.2
Jan 4, 2025

WP Social AutoConnect WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP Social AutoConnect plugin for WordPress, affecting all versions through 4.6.2. The vulnerability arises from inadequate nonce validation, allowing unauthenticated attackers to inject malicious scripts via a forged request, provided they can persuade a site administrator to click a link or perform a similar action.

4.9
Jan 4, 2025

WP Project Manager SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the WP Project Manager plugin for WordPress, specifically in versions prior to and including 2.6.16. The vulnerability arises in the '/wp-json/pm/v2/projects/2/task-lists' REST API endpoint, where the 'project_id' parameter is insufficiently sanitized. This flaw allows authenticated attackers with project access to inject additional SQL queries into the existing query, potentially leading to the extraction of sensitive database information.

4.1
Jan 4, 2025

Turnkey bbPress by WeaverTheme Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Turnkey bbPress by WeaverTheme plugin for WordPress, affecting all versions through 1.6.3. The vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the '_wpnonce' parameter. These injected scripts could be executed if a user is tricked into clicking a link or performing a similar action.

2.7
Jan 4, 2025

Code-Projects Online Shoe Store SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Code-Projects Online Shoe Store version 1.0. The issue arises in the file '/details2.php', where the 'id' parameter is manipulated, allowing for unauthorized database access. This vulnerability can be exploited remotely, and the public disclosure of the exploit suggests it may be actively used.

3.4
Jan 4, 2025

Dynamics 365 Integration WordPress Plugin Twig Server-Side Template Injection Vulnerability Allowing Remote Code Execution

A vulnerability allowing remote code execution and arbitrary file read has been identified in the Dynamics 365 Integration plugin for WordPress, affecting all versions through 1.3.23. The issue arises from Twig server-side template injection, caused by inadequate input validation and sanitization in the render function. This vulnerability enables authenticated attackers with Contributor-level access and above to execute code on the server.

2.5
Jan 4, 2025

Taskbuilder WordPress Project and Task Management Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Taskbuilder WordPress Project & Task Management plugin, affecting all versions through 3.0.6. The vulnerability arises from inadequate input sanitization and output escaping on user-supplied attributes in the wppm_tasks shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the compromised page.

2.7
Jan 4, 2025

Code-Projects Online Shoe Store SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Code-Projects Online Shoe Store version 1.0. The issue arises in the file '/details.php', where the 'id' parameter is processed without proper validation or sanitization, allowing remote attackers to manipulate the input and execute arbitrary SQL commands. This vulnerability could lead to unauthorized access to the application's database or even remote code execution.

3.5
Jan 4, 2025

WP Smart Import Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WP Smart Import: Import any XML File to WordPress plugin, affecting all versions through 1.1.2. The vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the 'page' parameter. These injected scripts can be executed if a user is tricked into clicking a link.

2.7
Jan 4, 2025

Scratch & Win WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Scratch & Win WordPress plugin, specifically in versions through 2.7.1. The issue arises from the reset_installation() function, which lacks proper nonce validation. This vulnerability allows unauthenticated attackers to reset the plugin's installation by sending a forged request, provided they can persuade a site administrator to click a link or perform a similar action.

3.0
Jan 4, 2025

Backup Migration WordPress Plugin PHP Object Injection Vulnerability

A PHP Object Injection vulnerability has been identified in the Backup Migration plugin for WordPress, affecting all versions up to and including 1.4.6. The issue arises from the deserialization of untrusted input in the 'recursive_unserialize_replace' function, allowing unauthenticated attackers to inject a PHP object. Exploitation is possible if an administrator creates a staging site, as the vulnerability requires this condition to be met.

3.2
Jan 4, 2025

Code-Projects Student Management System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Code-Projects Student Management System version 1.0. The issue resides in the 'showSubject1' function within '/config/DbFunction.php', where the 'sid' parameter is manipulated, allowing for SQL injection. This vulnerability can be exploited remotely, and other parameters may also be affected.

3.2
Jan 4, 2025

TCS BaNCS File Inclusion Vulnerability in REPORTS_SHOW_FILE.jsp

A file inclusion vulnerability has been identified in TCS BaNCS version 10. The issue arises in the REPORTS_SHOW_FILE.jsp file, where the FilePath argument can be manipulated to include unauthorized files. However, the existence of this vulnerability is currently under scrutiny.

1.7
Jan 4, 2025

Code-Projects Point of Sales and Inventory Management System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Code-Projects Point of Sales and Inventory Management System version 1.0. The issue resides in the file '/user/update_account.php', where the 'username' parameter is manipulated, allowing for SQL injection. This vulnerability can be exploited remotely, potentially leading to unauthorized access to sensitive information in the server's database.

2.9
Jan 4, 2025

Code-Projects Point of Sales and Inventory Management System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Code-Projects Point of Sales and Inventory Management System version 1.0. The issue resides in the file '/user/search_num.php', where the 'search' parameter is manipulated to execute arbitrary SQL commands. This vulnerability can be exploited remotely, potentially allowing attackers to access sensitive information from the application's database.

2.5
Jan 4, 2025

Optimizely EPiServer CMS Password Complexity Vulnerability

A medium-severity vulnerability exists in Optimizely EPiServer.CMS.Core versions prior to 12.32.0, due to inadequate enforcement of password complexity requirements. The application allows users to create passwords with a minimum length of 6 characters, but these passwords lack the necessary complexity to withstand contemporary attack methods such as password spraying or offline cracking.

2.6
Jan 4, 2025

Optimizely EPiServer CMS File Upload Validation Vulnerability Allowing Malicious File Execution

A medium-severity vulnerability exists in Optimizely EPiServer.CMS.Core versions prior to 12.32.0. The issue arises because the application fails to properly validate uploaded files, allowing potentially harmful file types, such as .docm and .html, to be uploaded. When these files are accessed by application users, they can execute malicious actions or compromise users' systems.

2.0
Jan 4, 2025

Optimizely EPiServer.CMS.Core Stored Cross-Site Scripting Vulnerability

A high-severity stored cross-site scripting vulnerability has been identified in Optimizely EPiServer.CMS.Core versions prior to 12.22.0. This vulnerability allows malicious actors to inject and execute arbitrary JavaScript code within the CMS. The issue could lead to the compromise of user data, unauthorized privilege escalation, or execution of unauthorized actions. The vulnerability is present in several areas of the CMS, including content editing, link management, and file uploads.

2.1
Jan 4, 2025

Optimizely Configured Commerce Session Hijacking Vulnerability

A medium-severity session hijacking vulnerability has been identified in Optimizely Configured Commerce versions prior to 5.2.2408. The issue arises when session tokens are transmitted as URL parameters, exposing sensitive information about the authenticated session.

2.6
Jan 4, 2025

Optimizely Configured Commerce Session Token Vulnerability in B2B Application

A medium-severity vulnerability has been identified in Optimizely Configured Commerce versions prior to 5.2.2408. This issue affects the B2B application and relates to session management in the storefront. The vulnerability allows session tokens from logged-out sessions to remain active and usable, potentially leading to unauthorized access.

2.5
Jan 4, 2025

Optimizely Configured Commerce Account Creation Vulnerability in B2B Application

A vulnerability exists in Optimizely Configured Commerce versions prior to 5.2.2408, where the B2B application does not require email confirmation for newly created accounts. This issue allows for the mass creation of accounts, potentially impacting database storage and leading to the creation of unsolicited storefront accounts on behalf of visitors.

2.5
Jan 4, 2025

Optimizely Configured Commerce Business Logic Vulnerability Allowing Purchase of Discontinued Products

A medium-severity business logic vulnerability has been identified in Optimizely Configured Commerce versions prior to 5.2.2408. This issue exists within the Commerce B2B application and allows storefront visitors to purchase discontinued products under certain conditions where requests are modified before reaching the server.

2.0
Jan 4, 2025

Optimizely Configured Commerce Input Validation Vulnerability in B2B Contact Us Functionality

A medium-severity input validation vulnerability has been identified in Optimizely Configured Commerce versions prior to 5.2.2408. This issue affects the Commerce B2B application, specifically the Contact Us feature, by allowing visitors to send email messages that could include unfiltered HTML markup under certain conditions.

2.5
Jan 3, 2025

Code-Projects Point of Sales and Inventory Management System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Code-Projects Point of Sales and Inventory Management System version 1.0. The issue resides in an unknown function of the file '/user/minus_cart.php', where the 'id' parameter is manipulated to execute unauthorized SQL commands. This vulnerability can be exploited remotely, potentially allowing attackers to access sensitive information from the server's database.

2.5
Jan 3, 2025

IBM PowerHA SystemMirror for i Session Cookie Vulnerability

A vulnerability exists in IBM PowerHA SystemMirror for i versions 7.4 and 7.5, where the secure attribute is not applied to authorization tokens or session cookies. This oversight allows attackers to intercept cookie values by sending a non-secure link to a user or embedding it in a site the user visits. The cookies would then be transmitted over the insecure link, enabling the attacker to snoop on the traffic and capture the cookie values.

2.8
Jan 3, 2025

IBM PowerHA SystemMirror for i Improper Access Vulnerability via iFrame Content Rendering

A vulnerability exists in IBM PowerHA SystemMirror for i versions 7.4 and 7.5, due to improper restrictions when rendering content through iFrames. This issue could enable an attacker to gain unauthorized access and perform actions on the system.

2.6
Jan 3, 2025

Photo Gallery Slideshow & Masonry Tiled Gallery WordPress Plugin Server-Side Request Forgery Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress, affecting all versions through 1.0.15. The vulnerability arises in the rjg_get_youtube_info_justified_gallery_callback function, allowing authenticated attackers with Subscriber-level access and above to make web requests to arbitrary locations from the web application. This could be exploited to retrieve limited information from internal services.

2.1
Jan 3, 2025

WordPress Popular Posts Plugin Unauthenticated Arbitrary Shortcode Execution Vulnerability

A vulnerability allowing unauthenticated users to execute arbitrary shortcodes has been identified in the WordPress Popular Posts plugin, affecting all versions through 7.1.0. The issue arises because the plugin does not properly validate input before processing shortcodes, allowing for unauthorized shortcode execution.

6.1
Jan 3, 2025

Net::OAuth Nonce Generation Vulnerability in OAuth Client

A vulnerability exists in the Net::OAuth::Client component of the Net::OAuth package for Perl, affecting versions prior to 0.29. The issue arises because the default nonce is a 32-bit integer generated by the built-in rand() function, which lacks cryptographic strength. This weak random number generation can lead to predictable nonce values, potentially allowing for replay attacks or other forms of exploitation in OAuth 1.0 exchanges.

3.5
Jan 3, 2025

Roxy-WI OS Command Injection Vulnerability Allowing Remote Code Execution

A critical OS command injection vulnerability has been identified in Roxy-WI versions through 8.1.3. The issue resides in the 'action_service' function within 'app/modules/roxywi/roxy.py', where user-supplied service parameters are manipulated and executed as system commands. This vulnerability can be exploited remotely, leading to unauthorized code execution on the server.

3.2
Jan 3, 2025

Code-Projects Point of Sales and Inventory Management System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Code-Projects Point of Sales and Inventory Management System version 1.0. The issue arises in the file '/user/search_result.php', where the 'id' parameter is improperly processed, allowing for SQL injection. This vulnerability can be exploited remotely, potentially leading to unauthorized access to sensitive information in the server's database.

2.5
Jan 3, 2025

Next.js Denial-of-Service Vulnerability in Server Actions

A denial-of-service vulnerability has been identified in Next.js versions 13.0.0 prior to 13.5.8, 14.2.21, and 15.0.0 prior to 15.1.1. This vulnerability allows attackers to create requests that disrupt Server Actions by keeping them open until the hosting provider terminates the execution. During this time, the Next.js server remains idle, only maintaining the connection with low CPU and memory usage. This issue is particularly problematic for deployments on providers that charge based on response times, such as Vercel or Netlify, where default function execution limits are in place to prevent excessive costs. The vulnerability arises in environments lacking safeguards against prolonged Server Action processes, and it mirrors the effects of an HTTP request with an invalid 'Content-Length' header or one that fails to close properly.

4.6
Jan 3, 2025

Code-Projects Point of Sales and Inventory Management System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Code-Projects Point of Sales and Inventory Management System version 1.0. The issue resides in the file '/user/search.php', where the 'name' parameter can be manipulated to execute unauthorized SQL commands. This vulnerability can be exploited remotely, potentially allowing attackers to access sensitive information from the application's database.

2.5
Jan 3, 2025

Code-Projects Point of Sales and Inventory Management System SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in Code-Projects Point of Sales and Inventory Management System version 1.0. The issue resides in the file '/user/plist.php', where the 'cat' parameter can be manipulated to execute arbitrary SQL commands. This vulnerability can be exploited remotely, potentially allowing attackers to access sensitive information from the application's database.

2.5
Jan 3, 2025

Code-Projects Point of Sales and Inventory Management System SQL Injection Vulnerability in del_product.php

A critical SQL injection vulnerability has been identified in Code-Projects Point of Sales and Inventory Management System version 1.0. The issue resides in the file del_product.php, where the id parameter can be manipulated to execute unauthorized SQL commands. This vulnerability can be exploited remotely, potentially allowing attackers to access sensitive information from the application's database.

2.9
Jan 3, 2025

PhpSpreadsheet Cross-Site Scripting Vulnerability in the HTML Writer Component

A cross-site scripting (XSS) vulnerability has been identified in PhpSpreadsheet, a PHP library for reading and writing spreadsheet files. This issue affects versions 3.6.0, 2.3.4, 2.1.5, and prior to 1.29.7. The vulnerability arises in the HTML writer component, specifically within the 'generateRow' method. It allows an attacker to bypass the library's XSS sanitization by using special characters to manipulate the 'javascript' protocol, creating a hyperlink that executes arbitrary JavaScript in the browser. Exploitation occurs when a user views a specially crafted Excel file that triggers this behavior.

3.9
Jan 3, 2025

PhpSpreadsheet Hyperlink Base Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in PhpSpreadsheet, a PHP library for reading and writing spreadsheet files. This issue affects versions 3.6.0, 2.3.4, 2.1.5, and 1.29.6. The vulnerability arises because the HTML page header is generated without properly sanitizing the hyperlink base, allowing for the execution of arbitrary JavaScript in the browser. The issue is present in the 'Html' writer component, specifically within the 'generateHTMLHeader' method.

3.9
Jan 3, 2025

PhpSpreadsheet Cross-Site Scripting Vulnerability in Custom Properties

A cross-site scripting (XSS) vulnerability has been identified in PhpSpreadsheet, a PHP library for reading and writing spreadsheet files. This issue affects versions 3.6.0, 2.1.5, 2.3.4, and all versions prior to 1.29.7. The vulnerability arises because the library generates HTML pages without properly sanitizing custom properties, allowing attackers to inject malicious JavaScript that could be executed in the context of the user's browser.

3.9
Jan 3, 2025

FFmpeg Integer Overflow Vulnerability in DXA Demuxer Allowing Denial-of-Service

A vulnerability allowing integer overflow has been identified in the DXA demuxer of FFmpeg version n6.1.1, within the libavformat library. This overflow could lead to a denial-of-service condition or cause other undefined behavior.

5.2
Jan 3, 2025

FFmpeg Double-Free Vulnerability in Audio Stream Handling

A double-free vulnerability has been identified in FFmpeg version n6.1.1, specifically within the audio stream processing function of the fftools component. The issue arises in the 'new_stream_audio' function, where improper management of memory allocation and deallocation creates the potential for exploitation.

5.8
Jan 3, 2025

Trix Editor Cross-Site Scripting Vulnerability via Malicious Links

A cross-site scripting (XSS) vulnerability has been identified in the Trix editor, a WYSIWYG rich text editor, in versions prior to 2.1.12. The issue arises when users paste malicious 'javascript:' URLs into the link field, which can execute arbitrary JavaScript within the user's session. This could lead to unauthorized actions or the disclosure of sensitive information.

3.4
Jan 3, 2025

SiYuan Note Arbitrary File Deletion Vulnerability

An arbitrary file deletion vulnerability has been identified in SiYuan Note version 3.1.18. The issue arises in the 'POST /api/history/getDocHistoryContent' endpoint, where an attacker can send a crafted payload to delete arbitrary files on the server. This vulnerability has been patched in version 3.1.19.

4.2
Jan 3, 2025

Karmada CRD Tar Slip Vulnerability Allowing Arbitrary File Write

A vulnerability exists in Karmada's command-line tool, 'karmadactl', and the 'karmada-operator' component, prior to version 1.12.0. These versions allow users to specify a filesystem path or an HTTP(s) URL to download custom resource definitions (CRDs) as a gzipped tar file. This CRD handling is susceptible to a Tar Slip vulnerability, where an attacker can manipulate the CRD file to write arbitrary files to any location on the filesystem during Karmada initialization. From version 1.12.0 onwards, Karmada includes a verification process for CRD archives to prevent such vulnerabilities. Users can manually inspect CRD files for malicious content before uploading them.

3.5
Jan 3, 2025

Karmada Excessive Privileges Vulnerability in Pull Mode Clusters

A vulnerability exists in Karmada versions prior to 1.12.0, where pull mode clusters registered with the 'karmadactl register' command are granted excessive privileges. This allows an authenticated attacker to the Karmada cluster as a 'karmada-agent' to gain administrative rights over the entire federation system, including all registered member clusters. The issue arises because the 'karmada-agent' is assigned high-level RBAC permissions that inadvertently allow access to sensitive control plane resources. In Karmada v1.12.0 and later, this vulnerability has been addressed by restricting the permissions of pull mode member clusters, preventing agents from controlling other member clusters.

3.2
Jan 3, 2025

PhpSpreadsheet Unauthorized Reflected Cross-Site Scripting Vulnerability in Currency.php

A reflected cross-site scripting vulnerability has been identified in PhpSpreadsheet versions 3.6.0, 2.3.4, 2.1.5, and prior to 1.29.7. The issue arises in the 'Currency.php' file, where user-controlled input is not properly sanitized, allowing for the injection of malicious scripts. This vulnerability can be exploited by an unauthorized user through the '/vendor/phpoffice/phpspreadsheet/samples/Wizards/NumberFormat/Currency.php' script.

4.4
Jan 3, 2025

PhpSpreadsheet Unauthorized Reflected Cross-Site Scripting Vulnerability in Accounting.php

A reflected cross-site scripting vulnerability has been identified in PhpSpreadsheet versions 3.6.0, 2.3.4, 2.1.5, and prior to 1.29.7. The issue resides in the Accounting.php file, specifically within the NumberFormat Wizard sample. This vulnerability allows an attacker to inject malicious scripts that are executed in the context of the user's browser.

4.4
Jan 3, 2025

PhpSpreadsheet Unauthorized Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in PhpSpreadsheet versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7. The issue arises in the constructor of the 'Downloader' class, where user-supplied GET parameters are processed without proper sanitization. This vulnerability can be exploited by an unauthorized user through the '/vendor/phpoffice/phpspreadsheet/samples/download.php' script, leading to the execution of arbitrary JavaScript in the victim's browser.

4.4
Jan 3, 2025

PHPOffice PhpSpreadsheet Cross-Site Scripting Vulnerability in Convert-Online.php

A cross-site scripting (XSS) vulnerability has been identified in the PHPOffice PhpSpreadsheet library, specifically in versions 3.6.0 prior to 3.7.0, 2.1.5, and 2.3.4. The issue arises from a lack of input sanitization in the 'Convert-Online.php' sample file, located within the 'Engineering' folder. This oversight allows attackers to inject malicious JavaScript that is executed in the context of the user's browser.

4.4
Jan 3, 2025

GoCD XXE Injection Vulnerability in Group Admin Pipeline XML Editing

A vulnerability allowing XML External Entity (XXE) injection has been identified in GoCD, a continuous delivery server, in versions prior to 24.5.0. This issue arises from the ability of 'group admins' to edit raw XML configurations for their groups, which can be exploited to inject malicious XML that the server processes. While this XXE vulnerability could theoretically lead to additional attacks such as Server-Side Request Forgery (SSRF), information disclosure, or directory traversal, these secondary exploits have not been demonstrated as possible.

2.7