VulnFeed
Showing 21914 of 21914 CVEs modified in the last 7 days
CVE-2026-6213
CRITICAL 10

Remote Spark SparkView RCE

CVE-2026-43208
CRITICAL 9.8

net: do not pass flow_id to set_rps_cpu()

CVE-2026-43198
CRITICAL 9.8

tcp: fix potential race in tcp_v6_syn_recv_sock()

CVE-2026-43186
CRITICAL 9.8

ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data()

CVE-2026-43185
CRITICAL 9.8

ksmbd: fix signededness bug in smb_direct_prepare_negotiation()

CVE-2026-43125
CRITICAL 9.8

dlm: validate length in dlm_search_rsb_tree

CVE-2026-43067
CRITICAL 9.8

ext4: handle wraparound when searching for blocks for indirect mapped blocks

CVE-2026-41501
CRITICAL 9.8

electerm has Command Injection Vulnerability via runLinux function

CVE-2026-41500
CRITICAL 9.8

electerm has Command Injection Vulnerability via runMac function

CVE-2026-8153
CRITICAL 9.8

Command injection in Dashboard Server interface

CVE-2026-43941
CRITICAL 9.6

Unvalidated shell.openExternal in electerm allows arbitrary protocol execution via terminal link click

CVE-2026-43944
CRITICAL 9.4

electerm: dangerous code can be run through links or command line

CVE-2026-43114
CRITICAL 9.4

netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry

CVE-2026-42208
CRITICAL 9.3

LiteLLM: SQL injection in Proxy API key verification

CVE-2026-8076
CRITICAL 9.3

Weak credentials vulnerability in the CashDro 3 web administration panel

CVE-2022-50994
CRITICAL 9.2

DrayTek Vigor 2960 < 1.5.1.4 OS Command Injection via mainfunction.cgi

CVE-2026-43197
CRITICAL 9.1

netconsole: avoid OOB reads, msg is not nul-terminated

CVE-2026-43117
CRITICAL 9.1

btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file()

CVE-2026-43083
CRITICAL 9.1

net: ioam6: fix OOB and missing lock

CVE-2026-43071
CRITICAL 9.1

dcache: Limit the minimal number of bucket to two

CVE-2026-43283
HIGH 8.8

net: ethernet: ec_bhf: Fix dma_free_coherent() dma handle

CVE-2026-43249
HIGH 8.8

9p/xen: protect xen_9pfs_front_free against concurrent calls

CVE-2026-43239
HIGH 8.8

smb: client: prevent races in ->query_interfaces()

CVE-2026-43232
HIGH 8.8

net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets

CVE-2026-43215
HIGH 8.8

cifs: Fix locking usage for tcon fields

CVE-2026-43187
HIGH 8.8

xfs: delete attr leaf freemap entries when empty

CVE-2026-43176
HIGH 8.8

wifi: rtw89: pci: validate release report content before using for RTL8922DE

CVE-2026-43172
HIGH 8.8

wifi: iwlwifi: fix 22000 series SMEM parsing

CVE-2026-43158
HIGH 8.8

xfs: fix freemap adjustments when adding xattrs to leaf blocks

CVE-2026-43113
HIGH 8.8

wifi: wl1251: validate packet IDs before indexing tx_frames

CVE-2026-43112
HIGH 8.8

fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath

CVE-2026-43110
HIGH 8.8

wifi: brcmfmac: validate bsscfg indices in IF events

CVE-2026-42278
HIGH 8.8

UltraDAG: Smart Account Spending Policy Bypass via Pockets

CVE-2026-41900
HIGH 8.8

OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment

CVE-2026-5127
HIGH 8.8

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Authenticated (Subscriber+) PHP Object Injection

CVE-2026-42275
HIGH 8.7

zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write

CVE-2026-42271
HIGH 8.7

LiteLLM: Authenticated command execution via MCP stdio test endpoints

CVE-2026-43139
HIGH 8.6

xfrm6: fix uninitialized saddr in xfrm6_get_saddr()

CVE-2026-42203
HIGH 8.6

LiteLLM: Server-Side Template Injection in /prompts/test endpoint

CVE-2026-8077
HIGH 8.6

Weak credentials vulnerability in the CashDro 3 web administration panel

CVE-2026-8069
HIGH 8.5

PredatorSense V3: Local Privilege Escalation (LPE) vulnerability

CVE-2026-43940
HIGH 8.4

electerm: Path traversal in electerm runWidget leads to arbitrary code execution

CVE-2026-43274
HIGH 8.4

mailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq()

CVE-2026-43233
HIGH 8.2

netfilter: nf_conntrack_h323: fix OOB read in decode_choice()

CVE-2026-43190
HIGH 8.2

netfilter: xt_tcpmss: check remaining length before reading optlen

CVE-2026-43134
HIGH 8.1

Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ

CVE-2025-66467
HIGH 8

Apache CloudStack: MinIO policy remains intact on bucket deletion

CVE-2026-43133
HIGH 7.9

KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation

CVE-2026-43943
HIGH 7.8

electerm: RCE via malicious SSH server filename in openFileWithEditor

CVE-2026-43279
HIGH 7.8

ALSA: usb-audio: Add sanity check for OOB writes at silencing

CVE-2026-43278
HIGH 7.8

dm: clear cloned request bio pointer when last clone bio completes

CVE-2026-43263
HIGH 7.8

media: chips-media: wave5: Fix Null reference while testing fluster

CVE-2026-43258
HIGH 7.8

alpha: fix user-space corruption during memory compaction

CVE-2026-43256
HIGH 7.8

media: qcom: camss: vfe: Fix out-of-bounds access in vfe_isr_reg_update()

CVE-2026-43248
HIGH 7.8

vhost: move vdpa group bound check to vhost_vdpa

CVE-2026-43237
HIGH 7.8

drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4

CVE-2026-43236
HIGH 7.8

drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release

CVE-2026-43222
HIGH 7.8

media: verisilicon: AV1: Fix tile info buffer size

CVE-2026-43214
HIGH 7.8

KVM: x86: Add SRCU protection for reading PDPTRs in __get_sregs2()

CVE-2026-43212
HIGH 7.8

LoongArch: Make cpumask_of_node() robust against NUMA_NO_NODE

CVE-2026-43211
HIGH 7.8

PCI: Fix pci_slot_trylock() error handling

CVE-2026-43207
HIGH 7.8

media: mtk-mdp: Fix error handling in probe function

CVE-2026-43206
HIGH 7.8

drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set()

CVE-2026-43180
HIGH 7.8

net: usb: kaweth: remove TX queue manipulation in kaweth_set_rx_mode

CVE-2026-43178
HIGH 7.8

procfs: fix possible double mmput() in do_procmap_query()

CVE-2026-43153
HIGH 7.8

xfs: remove xfs_attr_leaf_hasname

CVE-2026-43150
HIGH 7.8

perf/arm-cmn: Reject unsupported hardware configurations

CVE-2026-43128
HIGH 7.8

RDMA/umem: Fix double dma_buf_unpin in failure path

CVE-2026-43126
HIGH 7.8

ALSA: mixer: oss: Add card disconnect checkpoints

CVE-2026-43120
HIGH 7.8

RDMA/irdma: Fix double free related to rereg_user_mr

CVE-2026-43116
HIGH 7.8

netfilter: ctnetlink: ensure safe access to master conntrack

CVE-2026-43111
HIGH 7.8

HID: roccat: fix use-after-free in roccat_report_event

CVE-2026-43106
HIGH 7.8

cachefiles: fix incorrect dentry refcount in cachefiles_cull()

CVE-2026-43093
HIGH 7.8

xsk: tighten UMEM headroom validation to account for tailroom and min frame

CVE-2026-43091
HIGH 7.8

xfrm: Wait for RCU readers during policy netns exit

CVE-2026-43084
HIGH 7.8

netfilter: nfnetlink_queue: make hash table per queue

CVE-2026-43078
HIGH 7.8

crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl

CVE-2026-43076
HIGH 7.8

ocfs2: validate inline data i_size during inode read

CVE-2026-43075
HIGH 7.8

ocfs2: fix out-of-bounds write in ocfs2_write_end_inline

CVE-2026-43074
HIGH 7.8

eventpoll: defer struct eventpoll free to RCU grace period

CVE-2026-43070
HIGH 7.8

bpf: Reset register ID for BPF_END value tracking

CVE-2026-43063
HIGH 7.8

xfs: don't irele after failing to iget in xfs_attri_recover_work

CVE-2026-43060
HIGH 7.8

netfilter: nft_ct: drop pending enqueued packets on removal

CVE-2026-42274
HIGH 7.8

Heimdall: Authorization bypass via path normalization mismatch

CVE-2026-42273
HIGH 7.8

Heimdall: Case-sensitive host matching may lead to policy bypass

CVE-2026-42272
HIGH 7.8

Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation

CVE-2026-31731
HIGH 7.8

thermal: core: Address thermal zone removal races with resume

CVE-2026-31730
HIGH 7.8

misc: fastrpc: possible double-free of cctx->remote_heap

CVE-2026-31431
HIGH 7.8

crypto: algif_aead - Revert to operating out-of-place

CVE-2026-43254
HIGH 7.5

ovpn: tcp - fix packet extraction from stream

CVE-2026-43253
HIGH 7.5

iommu/amd: move wait_on_sem() out of spinlock

CVE-2026-43245
HIGH 7.5

ntfs: ->d_compare() must not block

CVE-2026-43230
HIGH 7.5

net/rds: Clear reconnect pending bit

CVE-2026-43226
HIGH 7.5

net/rds: No shortcut out of RDS_CONN_ERROR

CVE-2026-43213
HIGH 7.5

wifi: rtw89: pci: validate sequence number of TX release report

CVE-2026-43203
HIGH 7.5

atm: fore200e: fix use-after-free in tasklets during device removal

CVE-2026-43199
HIGH 7.5

net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query

CVE-2026-43194
HIGH 7.5

net: consume xmit errors of GSO frames

CVE-2026-43184
HIGH 7.5

rnbd-srv: Zero the rsp buffer before using it

CVE-2026-43164
HIGH 7.5

udplite: Fix null-ptr-deref in __udp_enqueue_schedule_skb().

CVE-2026-43101
HIGH 7.5

ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data()

CVE-2026-43099
HIGH 7.5

ipv4: icmp: fix null-ptr-deref in icmp_build_probe()

CVE-2026-8093
HIGH 7.5

Memory safety bugs fixed in Thunderbird 150.0.2

CVE-2026-42264
HIGH 7.4

Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking

CVE-2026-8138
HIGH 7.4

Tenda CX12L SetPptpServerCfg” formSetPPTPServer stack-based overflow

CVE-2026-8137
HIGH 7.4

Totolink X5000R formDdns sub_458E40 buffer overflow

CVE-2026-8090
HIGH 7.3

Use-after-free in the DOM: Networking component

CVE-2026-7330
HIGH 7.2

Auto Affiliate Links <= 6.8.8 - Unauthenticated Stored Cross-Site Scripting via 'url' Parameter

CVE-2026-43280
HIGH 7.1

drm/xe: Add bounds check on pat_index to prevent OOB kernel read in madvise

CVE-2026-43166
HIGH 7.1

erofs: fix interlaced plain identification for encoded extents

CVE-2026-43062
HIGH 7.1

Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp()

CVE-2026-42261
HIGH 7.1

PromptHub: Authenticated SSRF via IPv6 filter bypass in `POST /api/skills/fetch-remote`

CVE-2026-3508
MEDIUM 6.8

An Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) via a read size that exceeds the buffer size.Refer to the ' Security Update for MyASUS ' section on the ASUS Security Advisory for more information.

CVE-2026-42277
MEDIUM 6.5

Onyx: IDOR in /chat/file/{file_id} allows any authenticated user to download other users files

CVE-2025-69233
MEDIUM 6.5

Apache CloudStack: Domain/account resources limits not honored

CVE-2025-68900
MEDIUM 6.5

WordPress Enfold theme <= 7.1.3 - Cross Site Scripting (XSS) vulnerability

CVE-2026-7650
MEDIUM 6.4

E2Pdf – Export Pdf Tool for WordPress <= 1.32.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute

CVE-2026-7475
MEDIUM 6.4

Sky Addons <= 3.3.2 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Script

CVE-2026-5341
MEDIUM 6.4

NMR Strava activities <= 1.0.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

CVE-2026-5588
MEDIUM 6.3

PKIX draft CompositeVerifier accepts empty signature sequence as valid.

CVE-2026-42279
MEDIUM 5.8

solidtime: Time entry update endpoint allows cross-organization modification of a known time-entry UUID

CVE-2026-43942
MEDIUM 5.5

electerm: Full process.env exposed to renderer via window.pre.env in electerm

CVE-2026-41646
MEDIUM 5.5

Nuclei: Local File Read via require() Module Loader Bypass

CVE-2026-8133
MEDIUM 5.5

zyx0814 FilePress Shares Filelist API admin.php sql injection

CVE-2026-8132
MEDIUM 5.5

CodeAstro Leave Management System login.php sql injection

CVE-2026-8131
MEDIUM 5.5

SourceCodester SUP Online Shopping replymsg.php sql injection

CVE-2026-8130
MEDIUM 5.5

SourceCodester SUP Online Shopping message.php sql injection

CVE-2026-8129
MEDIUM 5.5

SourceCodester SUP Online Shopping wishlist.php sql injection

CVE-2026-8128
MEDIUM 5.5

SourceCodester SUP Online Shopping viewmsg.php sql injection

CVE-2026-8126
MEDIUM 5.5

SourceCodester Comment System post_comment.php sql injection

CVE-2026-42267
MEDIUM 5.4

Kimai: Formula Injection via tag names in XLSX export

CVE-2026-41645
MEDIUM 5.3

Nuclei: Environment variable disclosure via Response-Derived DSL Expressions

CVE-2026-3318
MEDIUM 5.3

Multiple vulnerabilities in Cradle e-commerce

CVE-2026-42150
MEDIUM 5.1

wlc: print_html outputs API data without HTML escaping, enabling stored XSS

CVE-2026-8149
MEDIUM 5.1

GCM chunking can lead to bad tag exception on decryption

CVE-2026-42276
MEDIUM 4.3

Onyx: IDOR in /chat/stop-chat-session allows any authenticated user to interrupt other users chat sessions

CVE-2026-44298
MEDIUM 4.1

Kimai: Arbitrary file read in invoice PDF renderer (admin)

CVE-2026-41498
LOW 3.3

Kimai: Team API Missing Object-Level Authorization

CVE-2026-44916
LOW 3

In OpenStack Ironic through 35.x, instance_info['ks_template'] is rendered without sandboxing.

CVE-2026-44928
LOW 2.9

In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.

CVE-2026-44927
LOW 2.9

In uriparser before 1.0.2, there is pointer difference truncation to int in various places.

CVE-2026-8127
LOW 2.1

eladmin Users API Endpoint UserController.java checkLevel access control

CVE-2026-8125
LOW 2.1

code-projects Simple Chat System sendMessage.php sql injection

CVE-2026-8123
LOW 2.1

Open5GS NSSF message.c ogs_sbi_discovery_option_add_snssais denial of service

CVE-2026-8122
LOW 2.1

Open5GS NSSF message.c ogs_sbi_discovery_option_add_service_names denial of service

CVE-2026-8121
LOW 2.1

Open5GS NSSF conv.c ogs_sbi_parse_plmn_list denial of service

CVE-2026-8120
LOW 2.1

Open5GS NSSF nnssf-handler.c denial of service

CVE-2026-8117
LOW 2.1

SourceCodester Pizzafy Ecommerce System index.php cross site scripting

CVE-2026-8116
LOW 2.1

huangjunsen0406 xiaozhi-mcphub dxtController.ts path traversal

CVE-2026-6737
LOW 2

An Exposed IOCTL with Insufficient Access Control vulnerability in AsusPTPFilter allows a local user to bypass driver security mechanisms and obtain restricted touchpad information or render the touchpad unusable via crafted IOCTL requests.Refer to the ' Security Update for ASUS Precision Touchpad ' section on the ASUS Security Advisory for more information.

CVE-2026-8136
LOW 1.9

SourceCodester Pharmacy Sales and Inventory System index.php users cross site scripting

CVE-2026-8124
LOW 1.9

GPAC box_code_base.c sidx_box_read allocation of resources

CVE-2026-8119
LOW 1.9

Open5GS NSSF nghttp2-server.c ogs_sbi_stream_find_by_id denial of service

CVE-2026-43284
NONE

xfrm: esp: avoid in-place decrypt on shared skb frags

CVE-2026-25199
NONE

Apache CloudStack: Proxmox Extension Allows Unauthorized Cross-Tenant Instance Access

CVE-2026-25077
NONE

Apache CloudStack: Unauthenticated Command Injection in Direct Download Templates

CVE-2026-8148
NONE

NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks.

CVE-2026-8094
NONE

Other issue in the WebRTC component

CVE-2026-8092
NONE

Memory safety bugs fixed in Thunderbird ESR 140.10.2 and Thunderbird 150.0.2

CVE-2026-7448
NONE

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

CVE-2026-4935
NONE

SureTriggers < 1.1.23 – Unauthenticated SQLi

CVE-2025-69691
NONE

Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.

CVE-2025-69690
NONE

Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to admins and they are intentionally allowed to execute PHP code.

CVE-2025-69599
NONE

RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: this is disputed because ability of an attacker to control the environment is a site-specific misconfiguration.

CVE-2025-67888
NONE

An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php (when the "api" parameter is set) is not properly sanitized before being used to execute OS commands. This can be exploited by unauthenticated attackers to inject and execute arbitrary OS commands with the privileges of root on the web server. Softaculous or SitePad must be present.

CVE-2025-67887
NONE

1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file. NOTE: this is disputed by the Supplier because this is intended behavior for the high-privileged users who can upload new translated pages to the website.

CVE-2025-67886
NONE

Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file. NOTE: this is disputed by the Supplier because this is intended behavior for the high-privileged users who can upload new translated pages to the website.

CVE-2025-66172
NONE

Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access to

CVE-2025-66171
NONE

Apache CloudStack: Any user can create a new VM from backups they should not have access to

CVE-2025-66170
NONE

Apache CloudStack: Any user can list backups that they should not have access to

CVE-2025-55449
NONE

AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.

CVE-2024-53326
NONE

LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(), leading to code execution.

CVE-2024-51092
NONE

LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsController.php's update(), and PollDevice.php's initRrdDirectory().

CVE-2024-46508
NONE

yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).

CVE-2024-46507
NONE

A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.

CVE-2024-45257
NONE

A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in freeze in core/generators.py.

CVE-2024-33724
NONE

SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.

CVE-2024-33722
NONE

SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].

CVE-2024-33288
NONE

Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page.

CVE-2024-30167
NONE

/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a POST request that carries a serverName parameter.

CVE-2024-27686
NONE

Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.

CVE-2023-47268
NONE

In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrary code on a host where the project is sliced and G-code exported.

CVE-2023-46453
NONE

Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both a valid SQL statement and a valid regular expression. For example, this affects version 4.3.7 on GL-MT3000 GL-AR300M GL-B1300 GL-AX1800 GL-AR750S GL-MT2500 GL-AXT1800 GL-X3000 and GL-SFT1200.

CVE-2023-42346
NONE

Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.

CVE-2023-42345
NONE

A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp.

CVE-2023-42344
NONE

Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet.

CVE-2023-42343
NONE

A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.

CVE-2022-45899
NONE

Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacters in the Log Scanner Search Pattern field.

CVE-2022-26523
NONE

The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xbb94.

CVE-2022-26522
NONE

The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xc4a3.

CVE-2022-23961
NONE

In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by unauthenticated remote attackers to target users of the monitoring interface.

CVE-2013-10075
NONE

Apache::Session versions through 1.94 for Perl re-creates deleted sessions