CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Travel Tour Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Travel Tour WordPress theme, versions prior to 5.2.4. The issue arises because the theme fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.
WordPress Category Post Shortcode Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Category Post Shortcode plugin, affecting versions through 2.4. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress SvegliaT Buttons Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress SvegliaT Buttons plugin, affecting versions through 1.3.0. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
Yulio Aleman Jimenez Smart Shopify Product Missing Authorization Vulnerability Allowing Arbitrary Content Deletion
A missing authorization vulnerability has been identified in the Yulio Aleman Jimenez Smart Shopify Product plugin, specifically in versions through 1.0.2. This vulnerability arises from incorrectly configured access control security levels, allowing unauthorized deletion of content such as images, posts, or pages from affected websites.
Next.js Authorization Bypass Vulnerability in Middleware
A vulnerability allowing authorization bypass in Next.js applications has been identified. This issue affects versions 9.5.5 through 14.2.14. The vulnerability arises when authorization in middleware is based on pathname, allowing bypass for pages directly under the application's root directory. For instance, authorization would be bypassed on 'https://example.com/foo' but not on 'https://example.com/' or 'https://example.com/foo/bar'. This vulnerability has been automatically mitigated for Next.js applications hosted on Vercel, regardless of the Next.js version.
CRM Perks WordPress HelpDesk Integration Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the CRM Perks WordPress HelpDesk Integration plugin, specifically in versions through 1.1.6. The issue arises from inadequate input sanitization and output escaping on user-supplied attributes, particularly within the 'crm-perks-tickets' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected page.
WordPress Advanced Fancybox Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Advanced Fancybox plugin, specifically in versions through 1.1.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.
WP Engine Advanced Custom Fields PRO Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Engine Advanced Custom Fields PRO plugin, affecting versions prior to 6.3.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Perfect Font Awesome Integration Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Perfect Font Awesome Integration plugin for WordPress, affecting all versions through 2.3. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'pfai' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
Angular Expressions Remote Code Execution Vulnerability
A remote code execution vulnerability exists in Angular Expressions versions prior to 1.4.3. The issue arises because an attacker can craft a malicious expression that escapes the sandbox environment, allowing arbitrary code execution on the system. This vulnerability can be exploited by using a complex, undisclosed payload. The vulnerability has been patched in version 1.4.3.
Webflow Webflow Pages Plugin Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the Webflow Pages WordPress plugin, affecting versions through 1.0.8. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.
Zendesk Support for WordPress Missing Authorization Vulnerability Allowing Broken Access Control
A missing authorization vulnerability has been identified in the Zendesk Support for WordPress plugin, affecting versions through 1.8.4. This vulnerability allows unprivileged users to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions that require higher privileges.
WordPress Stored Cross-Site Scripting Vulnerability in Multiple Plugins
A stored cross-site scripting vulnerability has been identified in several WordPress plugins, including Envira Gallery Lite and Getwid, all utilizing a vulnerable version of the FancyBox JavaScript library. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes, allowing authenticated attackers with contributor-level access or higher to inject arbitrary scripts. These scripts are executed when a user accesses the affected page.
PHP Buffer Overread Vulnerability in Convert.quoted-printable-decode Filter
A buffer overread vulnerability has been identified in PHP versions 8.1.* prior to 8.1.31, 8.2.* prior to 8.2.26, and 8.3.* prior to 8.3.14. The issue arises in the convert.quoted-printable-decode filter, where certain data can cause a buffer overread by one byte. This vulnerability can lead to crashes or the unintentional disclosure of memory content from other areas.
PHP Integer Overflow Vulnerability in ldap_escape() Function on 32-bit Systems Allowing Out-of-Bounds Write
In PHP versions 8.1 prior to 8.1.31, 8.2 prior to 8.2.26, and 8.3 prior to 8.3.14, an integer overflow vulnerability has been identified in the ldap_escape() function. This issue arises on 32-bit systems, where uncontrolled long string inputs can lead to an overflow, causing an out-of-bounds write. The vulnerability is particularly exploitable in PHP's Firebird and DBLIB drivers, where similar integer overflow issues have been introduced by unquoted string handling, allowing for out-of-bounds writes as well.
PHP HTTP Request Smuggling Vulnerability via CRLF Injection in Stream Proxies
A vulnerability in PHP streams when using a proxy and the 'request_fulluri' option can lead to HTTP request smuggling. This issue is present in PHP versions 8.1.* prior to 8.1.31, 8.2.* prior to 8.2.26, and 8.3.* prior to 8.3.14. The vulnerability arises because the URI is not properly sanitized, allowing an attacker to inject CRLF characters. This injection can be exploited to perform arbitrary HTTP requests through the proxy, potentially accessing resources not normally available to the user.
PHP MySQLnd Heap Buffer Over-Read Vulnerability Allowing Information Disclosure
A vulnerability exists in PHP versions 8.1.* prior to 8.1.31, 8.2.* prior to 8.2.26, and 8.3.* prior to 8.3.14. When a PHP client connects to a malicious MySQL server, it can be tricked into leaking heap memory contents. This memory may contain sensitive data from previous SQL queries or information belonging to other users on the same server. The issue arises in the MySQLnd extension while processing field packets, where improper handling can lead to over-reading of the heap buffer.
PHP Integer Overflow Vulnerability in ldap_escape Function on 32-Bit Systems
An integer overflow vulnerability has been identified in PHP versions 8.1.* prior to 8.1.31, 8.2.* prior to 8.2.26, and 8.3.* prior to 8.3.14. This vulnerability arises from uncontrolled long string inputs to the ldap_escape() function on 32-bit systems, leading to an out-of-bounds write.
Slick Sitemap WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Slick Sitemap plugin for WordPress, affecting all versions up to and including 2.0.0. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'slick-sitemap' shortcode. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
Apple WebKit Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been identified in WebKit, the engine used by Safari and other Apple applications, including iOS, iPadOS, macOS Sequoia, and visionOS. This vulnerability arises from a cookie management issue that was addressed with improved state management. However, processing maliciously crafted web content could still lead to a cross-site scripting attack. Apple is aware of reports that this issue may have been actively exploited on Intel-based Mac systems.
Apple WebKit and JavaScriptCore Arbitrary Code Execution Vulnerability
A vulnerability allowing arbitrary code execution has been identified in the WebKit component of multiple Apple products, including Safari, iOS, iPadOS, macOS Sequoia, and visionOS. This vulnerability arises from improper handling of maliciously crafted web content. Notably, there are reports of this issue being actively exploited on Intel-based Mac systems.
Surbma Font Awesome Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the Surbma Font Awesome WordPress plugin, affecting versions through 3.0. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute scripts on the site.
Offshorent Solutions OS BXSlider Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Offshorent Solutions OS BXSlider WordPress plugin, specifically in versions through 2.6. This vulnerability arises from improper input sanitization during web page generation, allowing malicious actors to inject scripts that are executed when users visit the affected site.
Amazon S3 Unclaimed Bucket Data Integrity Vulnerability
A vulnerability exists due to the use of an unclaimed Amazon S3 bucket named 'codeconf' in an audio file link within the documentation of the 'psf/requests' repository. This bucket has been claimed by an external party. The vulnerability could lead to various issues, including data integrity problems, data leakage, availability disruptions, loss of trustworthiness, and potential further attacks if the bucket is used to host malicious content or as a pivot point for additional attacks.
Slickstream Engagement and Conversions WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Slickstream: Engagement and Conversions plugin for WordPress, affecting all versions through 1.4.4. The issue arises from inadequate input sanitization and output escaping on user-supplied attributes in the plugin's slick-grid shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.
WP Grids Slicko for Elementor DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WP Grids Slicko plugin for Elementor, affecting versions through 1.2.0. This vulnerability arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute scripts on the affected site.
Akamai SIA ThreatAvert Applications Portal Broken Access Control Vulnerability
A broken access control vulnerability has been identified in Akamai SIA ThreatAvert, specifically in the Applications Portal. This issue is present in the SPS (Security and Personalization Services) version prior to the latest 19.2.0 patch, as well as in Apps Portal versions prior to 19.2.0.3 or 19.2.0.20240814. The vulnerability allows authenticated standard users to bypass authorization controls on the ThreatAvert Policy page. By directly navigating to the policy URI, these users can disable policy enforcement, potentially impacting the application's threat management capabilities.
ReCaptcha Integration for WordPress Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the ReCaptcha Integration for WordPress plugin, affecting all versions through 1.2.5. The issue arises from the plugin's use of add_query_arg without proper escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link.
WPEngine Advanced Custom Fields PRO Missing Authorization Vulnerability Allowing Broken Access Control
A missing authorization vulnerability has been identified in the WPEngine Advanced Custom Fields PRO plugin, affecting versions prior to 6.3.2. This vulnerability allows exploitation of incorrectly configured access control security levels, enabling unprivileged users to perform actions reserved for higher privileges.
WPEngine Advanced Custom Fields PRO Missing Authorization Vulnerability Allowing Broken Access Control
A missing authorization vulnerability has been identified in the WPEngine Advanced Custom Fields PRO plugin, affecting versions prior to 6.3.2. This vulnerability allows exploitation of incorrectly configured access control security levels, potentially leading to unauthorized users performing actions reserved for higher privileges.
Amazon Application Load Balancer OpenID Connect Middleware JWT Validation Vulnerability
A vulnerability exists in the Amazon Application Load Balancer (ALB) OpenID Connect middleware for ASP.NET Core. This issue arises because the middleware, while it correctly validates JWT signatures, fails to properly verify the JWT issuer and signer identity. This oversight can be exploited, particularly if the ALB is configured to accept internet traffic to its targets, allowing an untrusted entity to sign JWTs. As a result, an actor could impersonate valid OIDC-federated sessions to the ALB targets.
jQuery UI Cross-Site Scripting Vulnerability
A Cross-Site Scripting (XSS) vulnerability exists in jQuery UI version 1.13.1. This issue allows remote attackers to execute arbitrary code and access sensitive information by injecting a malicious payload into the window.addEventListener component. The vulnerability is categorized as Reflected Cross-Site Scripting, where the injected script is executed immediately when the payload is processed.
Next.js Denial-of-Service Vulnerability in Image Optimization
A denial-of-service vulnerability has been identified in the image optimization feature of Next.js. This issue is present in versions 10.x, 11.x, 12.x, 13.x, and in the 14.x branch prior to 14.2.7. The vulnerability allows for excessive CPU consumption, leading to potential service disruption. However, applications hosted on Vercel or those with specific configurations in the 'next.config.js' file are not affected. The vulnerability has been fully patched in Next.js version 14.2.7.
Zendesk Email Spoofing Vulnerability Allows Unauthorized Access to Ticket History
A vulnerability in Zendesk's email handling system prior to July 2, 2024, allows remote attackers to read ticket histories by spoofing email addresses. This issue arises because the Cc fields in incoming emails are used to grant additional access to ticket information, and Zendesk's mechanisms for verifying email authenticity are inadequate. The vulnerability is exacerbated by the predictability of support email addresses linked to individual tickets.
h2o HTTP/3 Reverse Proxy Assertion Failure Denial-of-Service Vulnerability
An assertion failure vulnerability has been identified in the h2o HTTP server when it is configured as a reverse proxy and handling HTTP/3 requests. If a client cancels an HTTP/3 request, h2o may crash due to the assertion failure. This crash can be exploited to disrupt service, causing a denial-of-service condition. Although the h2o standalone server typically restarts automatically, minimizing the disruption, concurrent HTTP requests that were being served will still be interrupted. The vulnerability affects h2o versions between commits 16b13ee and 15ed15a.
h2o HTTP Server IP Address Spoofing Vulnerability Bypassing Access Control
A vulnerability in h2o, an HTTP server supporting HTTP/1.x, HTTP/2, and HTTP/3, allows for bypassing IP address-based access control. This issue arises when HTTP requests using TLS 1.3 early data over TCP Fast Open or QUIC 0-RTT packets are received. The access control fails to detect and block requests from spoofed source addresses, enabling attackers to send HTTP requests from rejected addresses. The vulnerability affects h2o versions prior to the patch in commit 15ed15a.
h2o Headers Configuration Directive Ignored Vulnerability
A vulnerability exists in the h2o HTTP server that affects the headers configuration directive. When a header is set in an inner scope, such as at the path level, it overrides the headers defined in outer scopes, like the global level. This can result in expected headers not being sent, potentially leading to unintended behavior for clients. The issue has been observed in h2o versions prior to the patch included in commit 123f5e2.
Ivanti Cloud Services Appliance OS Command Injection Vulnerability Allowing Remote Code Execution
A command injection vulnerability has been identified in the admin web console of Ivanti Cloud Services Appliance (CSA) versions prior to 5.0.2. This vulnerability allows remote authenticated attackers with admin privileges to execute arbitrary commands on the underlying operating system, potentially leading to unauthorized access or manipulation of system resources.
Ivanti Cloud Services Appliance SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the admin web console of Ivanti Cloud Services Appliance (CSA) versions prior to 5.0.2. This vulnerability allows remote authenticated attackers with admin privileges to execute arbitrary SQL statements. While exploitation of this vulnerability in CSA 5.0 has not been observed, it has been exploited in CSA 4.6 when chained with another vulnerability, leading to unauthorized remote code execution.
SonarSource SonarQube Authorization API Blind SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in the authorizations/group-memberships API endpoint of SonarSource SonarQube versions 10.4 through 10.5 prior to 10.6. This vulnerability allows users with the administrator role to inject SQL commands that are not visible but can be executed by the database.
SonarQube GitHub Integration Information Leakage Vulnerability
A vulnerability exists in SonarSource SonarQube versions prior to 9.9.5 LTA and 10.x prior to 10.5. Users with the Administrator role can alter GitHub integration settings to exfiltrate a pre-signed JSON Web Token (JWT).
VLC Media Player Denial-of-Service Vulnerability via Integer Overflow in MMS Stream
A denial-of-service vulnerability has been identified in VLC media player versions through 3.0.20. The issue stems from an integer overflow that can be exploited with a maliciously crafted MMS stream, leading to a heap-based buffer overflow. Successful exploitation could cause VLC to crash or allow arbitrary code execution with the user's privileges.
MailOptin WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the MailOptin WordPress plugin, specifically in the Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber version 1.2.70.3 and prior. This vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'post-meta' shortcode. As a result, authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages, which will execute when a user accesses the compromised page.
Ivanti Cloud Services Appliance Path Traversal Vulnerability
A path traversal vulnerability has been identified in Ivanti Cloud Services Appliance (CSA) versions 4.6 prior to Patch 519. This vulnerability allows remote, unauthenticated attackers to access restricted functionality. The issue was inadvertently addressed in Patch 519, released on September 10, 2024. However, since Ivanti CSA 4.6 has reached end-of-life and will not receive further updates, users are advised to upgrade to Ivanti CSA 5.0.
Ivanti Cloud Services Appliance OS Command Injection Vulnerability Allowing Remote Code Execution
A command injection vulnerability has been identified in Ivanti Cloud Services Appliance (CSA) versions 4.6 Patch 518 and prior. This vulnerability allows remote authenticated attackers with admin privileges to execute arbitrary commands on the underlying operating system. Exploitation of this vulnerability could lead to unauthorized access and control over the affected system.
AngularJS Improper Sanitization Vulnerability in Source Elements Allowing Content Spoofing
A vulnerability exists in AngularJS due to improper sanitization of the 'srcset' attribute in '<source>' HTML elements. This flaw allows attackers to bypass standard image source restrictions, potentially leading to content spoofing. The issue affects all versions of AngularJS, which is no longer actively maintained. When exploited, this vulnerability could result in unauthorized addition or modification of data.
AngularJS Improper 'srcset' Attribute Sanitization Vulnerability Bypasses Image Source Restrictions
A vulnerability in AngularJS has been identified, stemming from improper sanitization of the 'srcset' attribute. This issue allows attackers to bypass standard image source restrictions, potentially leading to content spoofing. The vulnerability affects AngularJS versions 1.3.0-rc.4 and later. Notably, the AngularJS project is no longer actively maintained, and this vulnerability will not be addressed in future updates.
Apache OFBiz Forced Browsing Vulnerability
A forced browsing vulnerability has been identified in Apache OFBiz versions prior to 18.12.16. This vulnerability allows unauthorized access to rendered views by exploiting confused controller-view authorization logic. Users are advised to upgrade to version 18.12.16, which addresses this issue by introducing a new permission check for view-maps and changing the default settings for request-maps.
HubSpot WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the HubSpot WordPress plugin, specifically in the CRM, Email Marketing, Live Chat, Forms & Analytics version 11.1.22 and prior. The issue arises from inadequate input sanitization and output escaping in the 'url' attribute of the HubSpot Meeting Widget. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected page.
Webpack DOM Clobbering Vulnerability in AutoPublicPathRuntimeModule Leading to Cross-Site Scripting
A DOM clobbering vulnerability has been identified in Webpack's AutoPublicPathRuntimeModule, affecting versions prior to 5.93.0. This vulnerability allows for cross-site scripting (XSS) attacks in web pages that include Webpack-generated files and permit the injection of certain scriptless HTML elements, such as an image tag with an unsanitized name attribute. The issue arises when the output.publicPath configuration is set to auto or left unset, enabling an attacker to manipulate the current script context and inject malicious payloads that are executed as JavaScript. This vulnerability has been observed in the Canvas Learning Management System, where it was exploited through Webpack-compiled code.
