CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
WordPress Free Gifts for WooCommerce Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Free Gifts for WooCommerce plugin, affecting versions through 13.1.0. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Themefic Tourfic WordPress Plugin Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the Themefic Tourfic WordPress plugin, affecting versions through 2.22.5. This vulnerability arises from missing authorization checks, allowing unprivileged users to perform actions reserved for higher privileges.
Tribulant Software Newsletters Lite Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Tribulant Software Newsletters plugin, specifically in the Newsletters Lite version 4.14 and prior. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected page.
WordPress WooCommerce PDF Invoice Builder Sensitive Data Exposure Vulnerability
A vulnerability allowing the exposure of sensitive system information to an unauthorized control sphere has been identified in the WordPress WooCommerce PDF Invoice Builder plugin, specifically in versions through 2.0.8. This issue allows for the retrieval of embedded sensitive data that is not typically accessible to regular users.
Themefic Tourfic Plugin Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the Themefic Tourfic WordPress plugin, affecting versions through 2.22.5. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.
Tangible Loops & Logic WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Tangible Loops & Logic WordPress plugin, affecting versions through 4.2.3. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
EDGARROJAS Extra Product Options Builder for WooCommerce Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the EDGARROJAS Extra Product Options Builder for WooCommerce, specifically in versions through 1.2.167. This vulnerability arises from missing authorization checks, allowing unprivileged users to perform actions that require higher privileges.
Adrian Tobey Groundhogg Path Traversal Vulnerability Allowing Arbitrary File Deletion
A path traversal vulnerability has been identified in the Adrian Tobey Groundhogg WordPress plugin, specifically in versions through 4.4.1. This vulnerability allows for improper limitation of a pathname, potentially leading to arbitrary file deletion on the affected website.
Themefic Hydra Booking Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Themefic Hydra Booking WordPress plugin, affecting versions through 1.1.44. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Picu Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Picu plugin, affecting versions through 3.5.1. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Kodezen LLC aBlocks Plugin Privilege Escalation Vulnerability
A privilege escalation vulnerability has been identified in the Kodezen LLC aBlocks WordPress plugin, affecting versions prior to 2.9.1. This vulnerability allows low-privileged users to gain higher privileges, potentially leading to full control of the website.
WordPress Vitepos Plugin Blind SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in the WordPress Vitepos plugin, specifically in versions through 3.4.2. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially enabling attackers to manipulate database queries and interact with the database in unauthorized ways.
EyeCix JobSearch WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the EyeCix JobSearch WordPress plugin, specifically in versions through 3.2.9. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
Mitchell Bennis Simple File List Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Mitchell Bennis Simple File List WordPress plugin, affecting versions through 6.3.8. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Property Hive WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Property Hive WordPress plugin, specifically in versions through 2.2.3. This issue allows attackers to inject malicious scripts that are executed when users visit the affected page.
WordPress Extensions for Leaflet Map DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress Extensions for Leaflet Map plugin, affecting versions through 5.1. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
WPPOOL FormyChat Plugin Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WPPOOL FormyChat social-contact-form plugin, affecting versions through 2.15.3. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress Advanced Forms Plugin Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the WordPress Advanced Forms plugin, specifically in versions through 1.9.3.7. This vulnerability arises from missing authorization checks, allowing unprivileged users to perform actions reserved for higher privileges.
WordPress WowAddons Plugin Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the WordPress WowAddons Product Addons plugin, affecting versions through 1.6.8. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.
Element Invader Addons for Elementor DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the Element Invader Addons for Elementor plugin, affecting versions through 1.4.3. This vulnerability arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute scripts on the affected site.
WordPress MStore API Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the WordPress MStore API plugin, specifically in versions through 4.18.4. This vulnerability allows unprivileged users to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions.
WordPress WPJAM Basic Plugin Server-Side Request Forgery Vulnerability
A Server-Side Request Forgery (SSRF) vulnerability exists in the WordPress WPJAM Basic plugin, affecting versions through 7.0. This vulnerability allows attackers to make the server perform requests to arbitrary domains, potentially leading to the exposure of sensitive information from other services running on the system.
WPJAM Basic PHP Object Injection Vulnerability
A deserialization vulnerability allowing object injection has been identified in the WPJAM Basic WordPress plugin, affecting versions through 7.0. This vulnerability could lead to various injection attacks, including code injection, SQL injection, and path traversal, among other issues, if a suitable property-oriented programming chain is exploited.
Themify Builder WordPress Plugin Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Themify Builder WordPress plugin, affecting versions through 7.7.4. This issue allows attackers to inject malicious scripts that are executed when users visit the affected page.
NooTheme Jobmonster Theme Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the NooTheme Jobmonster WordPress theme, affecting versions through 4.8.5. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected page.
Hitesh Chandwani reCAPTCHA for Asgaros Forum DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the Hitesh Chandwani reCAPTCHA plugin (both v2 and v3) for Asgaros Forum, affecting versions through 1.1.0. This vulnerability arises from improper input sanitization during web page generation, allowing malicious users to inject harmful scripts that could be executed in the context of the user's browser.
WPDeveloper Better Payment Plugin Access Control Vulnerability
A vulnerability has been identified in the WPDeveloper Better Payment plugin, specifically in versions through 2.2.0. This issue arises from improper validation of input quantities, allowing users to access functionalities that are not adequately restricted by Access Control Lists (ACLs).
QuantumCloud ChatBot Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the QuantumCloud ChatBot plugin for WordPress, affecting versions through 8.3.7. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
Apache Gravitino Authenticated Server-Side Request Forgery Vulnerability in JobManager
A vulnerability allowing authenticated server-side request forgery (SSRF) has been identified in the JobManager component of Apache Gravitino. This issue arises in versions 1.0.0 through 1.2.1 and allows HTTP requests to be sent from the server to internal network resources and cloud metadata endpoints. The vulnerability is exploited through unvalidated job template URIs.
Apache Gravitino URL Path Injection Vulnerability Allowing Unintended API Endpoint Access
A URL path injection vulnerability has been identified in Apache Gravitino versions 1.0.0 prior to 1.2.1. This issue arises from unencoded user-supplied identifiers, which can be exploited to traverse paths and access unintended API endpoints via the MCP REST client.
EVbee Service App and DC Quick Charger Command Injection Vulnerability
A command injection vulnerability has been identified in the NPC start endpoint of the web server running on port 8090. This issue affects the EVbee Service App versions prior to 1.4.710 and the DC Quick Charger Firmware versions prior to V1.5.1.
EVbee Service App and DC Quick Charger Arbitrary File Overwrite Vulnerability
A vulnerability allowing arbitrary file overwriting has been identified in the EVbee Service App and the DC Quick Charger Firmware, both prior to their respective latest versions. This issue arises from a web server endpoint that accepts file names in the Content-Disposition header without proper validation. Exploitation of this vulnerability could lead to a denial-of-service by overwriting critical system files or allow remote code execution by replacing shell scripts that could be executed through other means.
EVbee Service App and DC Quick Charger Command Injection Vulnerability in OCPP ReserveLogin Message
A command injection vulnerability has been identified in the EVbee Service App and the DC Quick Charger Firmware, both prior to their respective latest versions. This vulnerability allows arbitrary operating system commands to be executed as root by manipulating the data value in the OCPP DataTransfer message 'ReserveLogin'.
EVbee Service App and DC Quick Charger Missing Authentication Vulnerability for Bluetooth Commands
A vulnerability exists in the EVbee Service App and the DC Quick Charger Bluetooth communication, where authentication is not required for Bluetooth commands. This flaw allows for unauthorized actions such as accessing sensitive information, triggering reboots, or initiating a firmware update process. The issue is present in the EVbee Service App versions prior to 1.4.710 and in the DC Quick Charger Firmware versions prior to V1.5.1.
EVbee Service App and DC Quick Charger Sensitive Information Logging Vulnerability
A vulnerability exists in the EVbee Service App and the DC Quick Charger Firmware, prior to version 1.5.1, allowing sensitive information such as passwords and charging card UIDs to be logged insecurely. This issue has been addressed in the latest version of the EVbee Service App.
EVbee Service App and DC Quick Charger Firmware Missing Firmware Validation Vulnerability Allowing Remote Code Execution
A vulnerability exists in the EVbee Service App versions prior to 1.4.710 and in the DC Quick Charger Firmware versions prior to V1.5.1. The issue arises because the firmware update mechanism lacks cryptographic signature validation. This flaw enables individuals with access to the firmware update feature to upload arbitrary files, potentially leading to unauthorized code execution.
EVbee Service App and DC Quick Charger Missing Authentication Vulnerability
A vulnerability has been identified in the webserver running on port 8090, which lacks authentication. This flaw allows for the unauthorized access and leakage of sensitive information, such as configured passwords, and enables file uploads through various endpoints. The issue affects the EVbee Service App prior to version 1.4.710 and DC Quick Charger Firmware prior to V1.5.1.
EVbee Service App and DC Quick Charger Command Injection Vulnerability
A command injection vulnerability has been identified in the network diagnosis endpoint of the web server running on port 8090. This issue affects the EVbee Service App versions prior to 1.4.710 and the DC Quick Charger Firmware versions prior to V1.5.1.
EVbee Service Android App Adversary-in-the-Middle Vulnerability
A vulnerability allowing an Adversary-in-the-Middle (AitM) attack has been identified in the EVbee Service Android app, specifically in versions prior to 1.4.710. The app uses TLS for encrypted communication with the EVbee server but fails to validate the server's certificate. This flaw enables an attacker to intercept and manipulate the communication between the app and the server. The encryption is weak, utilizing RC4 with a hardcoded key, which could allow an attacker to access sensitive information such as access codes to charging stations. This vulnerability affects the EVbee Service app version 1.4.101.00.
waooAI waoowaoo Improper Authentication Vulnerability in Internal Task Header Handler
A vulnerability allowing improper authentication has been identified in waooAI waoowaoo versions through 0.4.1. The issue arises in the Internal Task Header Handler component, specifically within the getInternalTaskSession, getAuthSession, requireUserAuth, requireProjectAuth, and requireProjectAuthLight functions in src/lib/api-auth.ts. The vulnerability is triggered by manipulating the x-internal-user-id request header, which can lead to unauthorized user impersonation. This flaw can be exploited remotely, and a public exploit is available.
Shibby Tomato Stack-Based Buffer Overflow Vulnerability in DNS List Rendering
A stack-based buffer overflow vulnerability has been identified in Shibby Tomato firmware versions prior to 1.28.0000. This issue arises in the DNS list rendering function 'sub_407220' within the 'httpd' component, located at '/usr/sbin/httpd'. The vulnerability can be exploited remotely by manipulating the size of the DNS list being processed.
PrestaShop Incorrect Sanitization Vulnerability in Address Update Function Allowing Data Injection
A vulnerability exists in PrestaShop version 8.2.1 due to improper sanitization of elements, specifically in the 'Update your address' function. The issue arises from insufficient validation of the 'Alias' parameter, enabling attackers to inject malicious expressions. These expressions are executed when the 'Get my data in CSV' tool is used, potentially leading to unauthorized access to the victim's personal data.
Thales CERT Suspicious Application Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in the Thales CERT 'Suspicious' application, versions through 1.3.4. This vulnerability allows an unauthenticated attacker to execute arbitrary code and overwrite writable application files, including Python modules, configuration files, cron inputs, and runtime artifacts. The issue leads to a persistent denial of service, potential compromise of application secrets or integrations, and root-level execution within the Django application container.
Mattermost Incoming Webhook User Access Vulnerability Allowing Impersonation
A vulnerability exists in Mattermost versions 11.7.x through 11.7.2, 11.6.x through 11.6.4, and 10.11.x through 10.11.19. The issue arises because the application fails to properly validate whether a user assigned to an incoming webhook has the appropriate access to the designated team or channel. This flaw enables a requester with webhook management permissions to send posts or direct messages on behalf of another user by manipulating the incoming webhook configuration and payloads.
Mattermost Session Management Vulnerability for Deactivated Guest Accounts
A vulnerability exists in Mattermost versions 11.7.x through 11.7.2 and 11.6.x through 11.6.4, where the application fails to check if a guest account is deactivated before creating a session via the magic-link token login process. This oversight allows a deactivated guest user to gain a fully functional session using a magic-link token that was issued prior to the account's deactivation.
Mattermost OAuth Token Refresh Vulnerability in Deactivated User Accounts
A vulnerability exists in Mattermost versions 11.7.x through 11.7.2, 11.6.x through 11.6.4, and 10.11.x through 10.11.19. These versions fail to invalidate OAuth refresh tokens when a user account is deactivated. As a result, a deactivated user or an attacker with a valid refresh token can obtain new access tokens through the OAuth refresh token grant endpoint.
Mattermost Denial-of-Service Vulnerability in Message Attachment Handling
A denial-of-service vulnerability has been identified in Mattermost versions 11.7.x prior to 11.7.2, 11.6.x prior to 11.6.4, and 10.11.x prior to 10.11.19. The issue arises because these versions do not properly validate the length and content of message attachment field values. This flaw allows an authenticated attacker to disrupt service for all users in a channel by posting a message with a specially crafted payload that exploits catastrophic backtracking in the client-side markdown parser.
MISP misp-modules Server-Side Request Forgery Protection Bypass Vulnerability
A Server-Side Request Forgery (SSRF) protection bypass vulnerability has been identified in the html_to_markdown expansion module of MISP misp-modules. This vulnerability arises because the module's IP address validation does not properly normalize IPv4-mapped IPv6 addresses before checking them against blocked ranges. As a result, an authenticated attacker can exploit this flaw by sending requests to loopback, private, link-local, or other restricted IP ranges, potentially accessing internal services or metadata. The vulnerability has been addressed by normalizing IPv4-mapped IPv6 addresses to their IPv4 equivalents before applying range checks, and by rejecting URLs without valid hostnames.
Red Hat OpenShift AI vllm-orchestrator-gateway Component Logging Vulnerability Allowing Information Disclosure
A vulnerability exists in the vllm-orchestrator-gateway component of Red Hat OpenShift AI. The issue arises because the production binary logs all incoming authorization headers and complete chat payloads, which may include personally identifiable information (PII) and secrets, to persistent logs. This sensitive information, such as bearer tokens and chat content, can be accessed by any user with logging privileges. The vulnerability leads to unauthorized information disclosure, potentially allowing an attacker to collect credentials and sensitive conversation details.
Shibby Tomato OS Command Injection Vulnerability in CIFS Mount Handler
A command injection vulnerability has been identified in Shibby Tomato firmware versions prior to 1.28.0000. The issue resides in the CIFS mount handler, specifically within the 'sbin/rc' component, which is hardlinked to 'mount-cifs'. The vulnerability allows remote execution of arbitrary commands by manipulating the 'cifs1' or 'cifs2' NVRAM keys. The exploitation occurs after successfully mounting a CIFS share, where the unsanitized command from the NVRAM is executed as root via the 'system()' function.
