Azure Billing Elevation of Privilege Vulnerability
Nuvation Energy Multi-Stack Controller Authentication Bypass
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.
Upload Arbitrary Files
Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These issues include triggerable assertion failures and a stack-based buffer overflow.
Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt
Foreman: safemode bypass leading to rce
Authenticated SQL Injection Vulnerabilities in ClearPass Policy Manager Web-Based Management Interface
OneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on Probe
OneUptime ClickHouse SQL Injection via Aggregate Query Parameters
OneUptime Synthetic Monitor RCE via exposed Playwright browser object
OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header
WordPress IF AS Shortcode plugin <= 1.2 - Remote Code Execution (RCE) vulnerability
WordPress MapSVG plugin <= 8.7.3 - Arbitrary File Upload vulnerability
WordPress Corpkit theme <= 2.0 - Arbitrary File Upload vulnerability
StreamVault is Vulnerable to Authenticated Remote Code Execution (RCE) via ytdlpargs Configuration Injection
Coolify members can see private key of root user
Coolify has Git Repository RCE
WordPress Shopo <= 1.1.4 - Arbitrary File Upload Vulnerability
Handlebars: JavaScript Injection via AST Type Confusion in compile (Program.blockParams)
LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization
Langflow OSS is affected by multiple vulnerabilities
Kiteworks Core Authentication Bypass in the Password Reset Workflow
RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
RDMA/siw: Bound fragmented header copies by the remaining length
Langflow OSS is affected by multiple vulnerabilities
Authenticated Path Traversal Vulnerability Leads to Unauthorized File Access and Modification in ClearPass Policy Manager
Unauthenticated Missing Integrity Verification allows Remote Code Execution in ClearPass Policy Manager Client Agent
Authentication Bypass Vulnerabilities in ClearPass Policy Manager
Unauthenticated SQL Injection Vulnerability leads to Remote Code Execution in ClearPass Policy Manager
Unauthenticated Format String Vulnerability in HPE Networking ClearPass Policy Manager
Authentication Bypass Vulnerabilities in HPE Networking ClearPass Policy Manager Allow Unauthorized Administrative Access
Missing Integrity Verification in the OnGuard Agent of ClearPass Policy Manager Allows Unauthenticated Remote Code Execution
Unauthenticated Deserialization of Untrusted Data allows Remote Code Execution in the Web Interface of HPE Networking ClearPass Policy Manager
Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-S
Authentication Bypass Vulnerability in the Management Interface of AOS-S
Authentication Bypass in the Web Management Interface of AOS-S
In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations.
WordPress Newsletters plugin <= 4.11 - PHP Object Injection vulnerability
Harvest may expose OS default ssh login password via SUSE Virtualization Interactive Installer
File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell.
WordPress DZS Video Gallery plugin <= 12.37 - PHP Object Injection Vulnerability
WordPress InWave Jobs Plugin <= 3.5.8 - Broken Access Control vulnerability
WordPress Felan Framework plugin <= 1.1.3 - Account Takeover vulnerability
Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium
Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication Bypass.This issue affects com.Afmobi.Boomplayer: 7.4.63.
An unauthenticated user is able to introduce SQL Injection using the Awie export module
Unauthenticated configuration import allows administrative account creation using AWIE component
Optional Email <= 1.3.11 - Unauthenticated Privilege Escalation to Account Takeover
FS Registration Password <= 1.0.1 - Unauthenticated Privilege Escalation via Account Takeover
AS Password Field In Default Registration Form <= 2.0.0 - Unauthenticated Privilege Escalation via Account Takeover
XSS in Tegsoft's Online Support Application
Authentication bypass in IBM API Connect
Mentoring <= 1.2.8 - Unauthenticated Privilege Escalation in mentoring_process_registration
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors.
SQLi in Akıllı Ticaret's E-Commerce Pack
SQLi in Akilli Commerce's E-Commerce Website
Doctreat Core <= 1.6.8 - Unauthenticated Privilege Escalation
Backstage: Sensitive information exposure in Scaffolder
Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)
Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
OS command injection in Progress Software Autonomous REST Connector GenAI Agents
Unauthenticated Adjacent Memory Corruption Vulnerabilities Leading to Remote Code Execution in AOS-S
Microsoft SQL Server Elevation of Privilege Vulnerability
Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)
Coolify vulnerable to command injection via docker-compose.yaml parameters
Unauthenticated execution of arbitrary SQL queries in Sparx Pro Cloud Server
Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha
Undisclosed RCE in Zammad v6.3 and higher
Security Advisory 0193
Kiteworks Email Protection Gateway Improper Access Control
Colify has command injection vulnerability in project git source
This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.
Nuvation Energy nCloud Client-to-Client Communication
Nuvation Energy Multi-Stack Controller OS Command Injection
Coolify has Stored XSS in Project Name
Coolify has Docker Compose Injection issue
Authentication Bypass
Unsafe Deserialization Vulnerability in Manacle Technologies ERP System
SQL Injection Vulnerability in Manacle Technologies ERP System
Account Takeover Vulnerability in Manacle Technologies ERP System
Out-of-bounds write via the TLS 1.3 handshake message cache in NetX Duo in Eclipse ThreadX NetX Duo 6.5.1.202602 allows a handshake message larger than the cache writes past it and on into the rest of the session control block, which holds pointers. A malicious or compromised server can make a TLS 1.3 client produce such a message before certificate authentication completes, so no server certificate is needed to reach it.
Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0
Security Advisory 0190
Kiteworks Core Administrative Account Takeover through Stored Cross-site Scripting (XSS)
Security Advisory 0185
Security Advisory 0192
A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.
Unauthenticated Adjacent Buffer Overflow Vulnerability Leading to Information Disclosure in AOS-S
VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability
This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.
FlexNet Publisher lmadmin SOAP Authentication Bypass Vulnerability
A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code via a crafted configuration file upload that exceeds the expected buffer size.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a remote attacker to read DOM information, modify router settings, and cause a denial-of-service condition when an authenticated user visits a crafted URL.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
NetMan 204 Missing Authentication for Administrative Functions
NetMan 204 Hard-coded Backdoor Credentials
Synway SMG Gateway Management Software OS Command Injection via radius_address
WordPress Infility Global plugin <= 2.15.06 - SQL Injection vulnerability
WordPress Automotive Listings plugin <= 18.6 - SQL Injection vulnerability
Nuvation Energy BMS Client-side Authentication
SQL injection in Zeon Academy Pro by Zeon Global Tech
WordPress Entrada Theme <= 5.7.7 - SQL Injection vulnerability
WordPress WPCHURCH plugin <= 2.7.0 - SQL Injection Vulnerability
WordPress Amazon Native Shopping Recommendations Plugin <= 1.3 - SQL Injection Vulnerability
WordPress Felan Framework plugin <= 1.1.3 - SQL Injection vulnerability
Plaintext Storage of a Password in Sparx Pro Cloud Server.
Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user
The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploited if the service is exposed in environments where the remoting ports are accessible.
wolfSSL Python library `CERT_REQUIRED` mode fails to enforce client certificate requirement
WELLTEND TECHNOLOGY| BPMFlowWebkit - Arbitrary File Upload
Sunnet|WMPro - Arbitrary File Upload
GOSTCTR implementation unable to process more than 255 blocks correctly
Contemporary Controls BASC 20T Reliance on Untrusted Inputs in a Security Decision
Shell command injection in 3onedata GW1101-1D(RS-485)-TB-P modbus gateway
apidoc-core - prototype pollution in api_group.js, api_param_title.js, api_use.js, and api_permission.js worker
MegaSys Computer Technologies Telenium Online Web Application Improper Input Validation
FileThingie 2.5.7 Arbitrary File Upload via ft2.php
Crashmail 1.6 Stack-based Buffer Overflow Remote Code Execution
Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization.
llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser
Handlebars: JavaScript Injection via Own Property Check Bypass
An HTTP header injection vulnerability was found in the ADM
jsPDF has Local File Inclusion/Path Traversal vulnerability
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions < V2506.6000 with Cloud Entitlement (bundled as NX X)), Simcenter 3D (All versions < V2506.6000 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Femap (All versions < V2506.0002 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Studio (All versions < V2506.0001), Simcenter System Architect (All versions < V2506.0001), Tecnomatix Plant Simulation (All versions < V2504.0007). The SALT SDK is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.
Rockwell Automation FactoryTalk Historian Site Edition - Authentication Bypass
Gitea built-in SSH server authentication bypass through key case folding
Foreman: excessive permissions for viewer role on preview
Authenticated SQL Injection Vulnerability in ClearPass Policy Manager Web-based Management Interface
Unauthenticated Buffer Overflow Vulnerabilities lead to Information Disclosure in AOS-S
The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arbitrary locations outside the `openai_files` directory by crafting malicious filenames.
Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
LibreChat is vulnerable to Server-Side Request Forgery due to missing restrictions
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution.
Apache Uniffle: Insecure SSL Configuration in Uniffle HTTP Client
Signal K Server vulnerable to JWT Token Theft via WebSocket Enumeration and Unauthenticated Polling
Apache Airflow: Airflow Logout Not Invalidating JWT
Sensitive COS `SecretKey` exposed in plaintext via configuration API due to missing type protection
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2412 (All versions < V2412.8700), NX V2506 (All versions < V2506.6000), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Solid Edge SE2025 (All versions < V225.0 Update 10), Solid Edge SE2026 (All versions < V226.0 Update 1). The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.
Order Notification for WooCommerce < 3.6.3 - Unauthenticated WooCommerce REST Permission Bypass
DVP-12SE11T - Out-of-bound memory write Vulnerability
DVP-12SE11T - Password Protection Bypass
Openshift-gitops-operator: openshift gitops: namespace admin cluster takeover via privileged jobs
Hitachi Vantara Pentaho Data Integration & Analytics - Dependency on Vulnerable Third-Party Component
Recoverable obfuscation using the OECH1 prefix encoding in OpenEdge
Security Advisory 0197
wolfSSH ECDSA host key curve not validated against negotiated algorithm
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.
This vulnerability allows a Backup or Tape Operator to write files as root.
This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.
StableLib: Prototype poisoning via `__proto__` map keys in CBOR decoding
C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite files on the local system, or retrieve arbitrary files from the local system.
TRENDnet TEW-713RE formFSrvX os command injection
D-Link DIR-600 HTTP Header hedwig.cgi stack-based overflow
Backstage: Improper validation of TechDocs MkDocs configuration
Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Incorrect authorization in Transactions Platform in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Incorrect authorization in Bluetooth in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Incorrect authorization in Selection in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Incorrect authorization in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible
Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)
Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Code injection via unencoded configuration values during Python code generation in Bedrock AgentCore Starter Toolkit agent import
Langflow OSS is affected by multiple vulnerabilities
An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product.
Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Tenant Data Interception
Kiteworks Core OS Command Injection
Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
wifi: cfg80211: don't filter by BSS type when removing stale entries
KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
Langflow OSS is affected by multiple vulnerabilities
Langflow OSS is affected by multiple vulnerabilities
Langflow OSS is affected by multiple vulnerabilities
Langflow OSS is affected by multiple vulnerabilities
Langflow OSS is affected by multiple vulnerabilities
String Locator < 2.6.8 - Unauthenticated PHP Object Injection via Database Editor
Langflow OSS is affected by multiple vulnerabilities
Langflow OSS is affected by multiple vulnerabilities
Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator
Authenticated Command Injection Leading to Privilege Escalation in ClearPass Policy Manager API
Command Injection Vulnerability in the ClearPass Policy Manager Client Software
Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in ClearPass Policy Manager
Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in ClearPass Policy Manager Web-Based Management Interface
Improper Access Control in HPE Networking ClearPass Android Client Application
Authenticated Privilege Escalation Vulnerability in the API of AOS-S
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
In multiple locations, there is a possible out-of-bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
Bluetooth Mesh solicitation PDU stack buffer overflow via oversized advertisement
Rubygem-foreman_remote_execution: command injection in job invocations via effective_user parameter
WordPress Timetics plugin <= 1.0.46 - Broken Authentication vulnerability
lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()
An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.
Apache Kyuubi: Unauthorized directory access due to missing path normalization
NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)
A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Privilege escalation during the installation of Norton Secure VPN via the Microsoft Store
muffon has One-click Remote Code Execution via XSS and Custom URL Handling
Priority - CWE-434 Unrestricted Upload of File with Dangerous Type
A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets.
WordPress DZS Video Gallery plugin <= 12.25 - PHP Object Injection vulnerability
Integer Overflow or Wraparound in GPS
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing a file may lead to memory corruption.
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (AP)
HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability
WordPress WPCHURCH plugin <= 2.7.0 - Privilege Escalation Vulnerability
WordPress Themify Edmin theme <= 2.0.0 - PHP Object Injection Vulnerability
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox.
WP Enable WebP <= 1.0 - Authenticated (Author+) Arbitrary File Upload
IDOR in Yordam Informatics' Library Automation System
RCE in Yordam Informatics' Library Automation System
Improper Access Control in Yordam Informatics' Library Automation System
BuddyPress Xprofile Custom Field Types <= 1.2.8 - Authenticated (Subscriber+) Arbitrary File Deletion
Career Section <= 1.6 - Cross-Site Request Forgery to Arbitrary File Deletion
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking.
IDOR in APPYAP's Yaay Social Media App
Arbitrary File Upload in EchoCCS's Specto CM
ownDMS 4.7 SQL Injection via pdfstream.php imagestream.php
phpTransformer 2016.9 SQL Injection via GeneratePDF.php
PlayJoom 0.10.1 SQL Injection via catid Parameter
ServerZilla 1.0 SQL Injection via email Parameter
EdTv 2 SQL Injection via id Parameter
BitZoom 1.0 SQL Injection via rollno Parameter
StableLib: Stack exhaustion denial of service via deeply nested CBOR arrays, maps, or tags
GitAhead through 2.7.1 on macOS Command Injection via Show in Finder AppleScript
Authenticated RCE via render-components Entry Type overrides
In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse resulting in privilege escalation. It was possible for the built-in role to be weakened and the attacker's account added to a privileged team. This was achievable due to improper validation of unsafe equivalence in inputs.
Security Advisory 0195
Security Advisory 0190
Kiteworks Core stored XSS
Kiteworks Core stored XSS
Budibase Unrestricted Server-Side Request Forgery (SSRF) via REST Datasource Query Preview
OneUptime: WhatsApp Webhook Missing Signature Verification
QGIS had validated RCE and Repository Takeover via GitHub Actions
Hardcoded credentials in Comarch ERP Optima
Coolify has a privilege escalation - low privileged user can invite themselves as an admin user
Nuvation Energy Multi-Stack Controller OS Command Injection
Columbia Weather Systems MicroServer Improper Restriction of Communication Channel to Intended Endpoints
iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - get8021xSettings
iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - getOptionsInfo
Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This could allow an unauthenticated remote attacker e.g. to interfere with connection setup, potentially leading to a denial of service. The attack succeeds only if an attacker can inject IP packets with spoofed addresses at precisely timed moments, and it affects only TCP-based services.
SQL injection in Eventobot
Quanta Computer|QOCA aim AI Medical Cloud Platform - Arbitrary File Upload
WELLTEND TECHNOLOGY| BPMFlowWebkit - Arbitrary File Read
Sunnet|WMPro - Arbitrary File Read
Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities
Arista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis Session
Mitsubishi Electric Europe smartRTU Missing Authentication for Critical Function
AMPPS 2.7 Denial of Service via Malformed Socket Connection
Telegram Desktop before 7.2.9 IPC Record Injection File Exfiltration via interpret: Scheme
Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 155.0.8059.39 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low)
Security Advisory 0190
Security Advisory 0189
Security Advisory 0189
BentoML has an Arbitrary File Write via Symlink Path Traversal in Tar Extraction
Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injection vulnerability. An arbitrary OS command may be executed on the product by an attacker who logs in to the CLI service.
Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
WordPress Five Star Restaurant Reservations plugin <= 2.7.4 - Insecure Direct Object References (IDOR) vulnerability
Columbia Weather Systems MicroServer Command Shell in Externally Accessible Directory
Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the software package. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.
A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.
Data Exposure in Kings Information & Network KESS Enterprise
Plugin Organizer < 10.2.4 - Subscriber+ SQLi
webERP 4.15.1 - Unauthenticated Backup File Access
SIPP 3.3 Stack-Based Buffer Overflow via Configuration File
PMS 0.42 Stack-Based Buffer Overflow via Configuration File
SC v7.16 Stack-Based Buffer Overflow Remote Code Execution
iSelect 1.4.0-2+b1 Local Buffer Overflow via key parameter
HNB Organizer 1.9.18-10 Local Buffer Overflow via -rc Parameter
PInfo 0.6.9-5.1 Local Buffer Overflow via -m Parameter
HDF5 heap buffer overflow in H5VM_array_fill via crafted fill-value metadata
Backstage: Improper task state validation in Scaffolder backend
Backstage: Improper filesystem validation in Bitbucket pull-request scaffolder actions
Backstage: Improper input validation in Sentry scaffolder actions
patool before 4.0.6 OS Command Injection on Windows via shell_quote_nt
Langflow OSS is affected by multiple vulnerabilities
Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.
WordPress Ninja Tables plugin <= 5.2.4 - SQL Injection vulnerability
WordPress BWL Pro Voting Manager plugin <= 1.4.9 - SQL Injection vulnerability
WordPress Brands for WooCommerce plugin <= 3.8.6.3 - SQL Injection vulnerability
WordPress Lobo theme < 2.8.6 - SQL Injection vulnerability
Coolify has host header injection in forgot password
Authenticated RCE in KAON PG5298
Apache Ignite: REST HTTP arbitrary file read vulnerability
Versa SASE Client for Windows < 7.9.5 Arbitrary Folder Deletion Leading to Local Privilege Escalation
WordPress Premium SEO Pack <= 3.3.2 - SQL Injection Vulnerability
WordPress Workreap (theme's plugin) plugin <= 3.3.6 - SQL Injection vulnerability
WordPress WooCommerce Orders & Customers Exporter plugin <= 5.4 - SQL Injection vulnerability
Account Takeover in Gmission Web FAX
Unrestricted File Upload and RCE in Innorix WP
Eddie VPN 2.24.6 - Local Privilege Escalation
SonarQube 8.3.1 - Unquoted Service Path
AnyDesk 5.4.0 - Unquoted Service Path
Insertion of Sensitive Information into Log File in certain ASUS router models allows a remote authenticated attacker to obtain DDNS credentials from the system log, potentially enabling modification of DNS settings.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Dify Vulnerable to Plaintext API Key Exposure via Model Provider Configuration Endpoint
Microsoft Office Remote Code Execution Vulnerability
Reusing a Nonce, Key Pair in Encryption in Automotive Platform
Privilege Escalation in Gmission Web FAX
Cache Misconfiguration Leading to Cross-User Data Exposure
During an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some ThinkPad products could allow a privileged local user to execute code in System Management Mode (SMM).
During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions.
Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Race condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Langflow OSS is affected by multiple vulnerabilities
libexpat Heap Buffer Over-read in xmlparse.c via XML_ParseBuffer
This vulnerability in Veeam Backup & Replication allows an authenticated Cloud Connect tenant to read arbitrary files on the service provider host.
Wazuh GitHub Actions Workflow Exposure of Sensitive Credentials
Rockwell Automation FactoryTalk Analytics PavilionX
Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in ClassParser
Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Completion and Order Key Disclosure
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
Foreman: command injection in foreman-rake database tasks
Foreman: command injection in foreman-rake errors:fetch_log via request_id parameter
Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service.
Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)
Malicious Code Execution Vulnerability in the Software Keyboard Function of GENESIS64, ICONICS Suite, Mobile HMI, and MC Works64
Unauthorized Arbitrary File Read via RMI in AdminServer Interface
Backstage: Scaffolder action input authorization bypass
Backstage: Improper authentication in the OIDC provider
Candlepin: candlepin: broken object-level authorization via verifyauthorizationfilter multi-@verify hasaccess latching
Langflow OSS is affected by multiple vulnerabilities
Kiteworks Core Stored Cross-site Scripting (XSS)
Kiteworks Core deserialization of untrusted data
IB/isert: wait for deferred control PDU completions before releasing the connection
cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
net: lan743x: fix RX checksum use-after-free
Langflow OSS is affected by multiple vulnerabilities
Gitea installer authentication bypass for existing accounts
Langflow OSS is affected by multiple vulnerabilities
VMware Workstation and Fusion HGFS stack-based buffer-overflow vulnerability
OneUptime: ClickHouse SQL Injection via unvalidated column identifiers in sort, select, and groupBy parameters
Integer underflow in IEEE 802.15.4 frame decryption leads to out-of-bounds read and write
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
Tugtainer has RCE in Agent Command Execution Api
WordPress FreeAgent theme <= 2.1.2 - Local File Inclusion vulnerability
WordPress Issabella theme <= 1.1.2 - Local File Inclusion vulnerability
WordPress Frappé theme <= 1.8 - Local File Inclusion vulnerability
WordPress Hope theme <= 3.0.0 - Local File Inclusion vulnerability
WordPress Gecko theme <= 1.9.8 - Local File Inclusion vulnerability
WordPress Lekker theme <= 1.8 - Local File Inclusion vulnerability
WordPress Docket Cache plugin <= 24.07.03 - Local File Inclusion vulnerability
WordPress Hendon theme < 1.7 - Local File Inclusion vulnerability
WordPress Curly theme < 3.3 - Local File Inclusion vulnerability
WordPress Optimize theme < 2.4 - Local File Inclusion vulnerability
WordPress Wellspring theme < 2.8 - Local File Inclusion vulnerability
WordPress Neo Ocular theme < 1.2 - Local File Inclusion vulnerability
Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access to
WordPress VideoPro theme <= 2.3.8.1 - Local File Inclusion vulnerability
Apache Airflow: RCE by race condition in example_xcom dag
Apache NuttX RTOS: fs/vfs/fs_rename: use after free
Apache StreamPipes: Leverage of User ID for Privilege Escalation
LogicalDOC Enterprise up to and for 9.1.1 is vulnerable to blind SQL injection in the WorkflowsDataServlet component, allowing authenticated user to manipulate SQL queries via crafted workflow template name.
WordPress WPCHURCH plugin <= 2.7.0 - Local File Inclusion vulnerability
WordPress Typify theme <= 3.0.2 - Local File Inclusion vulnerability
WordPress Mitech theme <= 2.3.4 - Local File Inclusion vulnerability
WordPress Moody theme <= 2.7.3 - Local File Inclusion vulnerability
WordPress Atlas theme <= 2.1.0 - Local File Inclusion vulnerability
DVP-12SE11T - Authentication Bypass via Partial Password Disclosure
Poly Video - Sensitive Data Might Be Written to Log File
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN).
Apache CloudStack: MinIO policy remains intact on bucket deletion
In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
An OS Command Injection vulnerability in Nokia MantaRay NM
An OS Command Injection vulnerability in Nokia MantaRay NM
Firebird: Information leak vulnerability in firebird3 client when used with newer server
Nuvation Energy Multi-Stack Controller Proxy service allows arbitrary BMS access
Hydra instantiate target blacklist bypasses permit code execution
Gimp: gimp: heap buffer overflow in dds loader on crafted directdraw surface file
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 appliance which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
Kiteworks Core before version 9.5.0 is vulnerable to Local Privilege Escalation
Kiteworks Core Local Privilege Escalation
Kiteworks Core Local Privilege Escalation
Ghostscript: ghostscript: -dsafer sandbox bypass via type 5 shading oob write and procedure-stream use-after-free
xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()
esp: downgrade zerocopy managed frags before mutating skb frags
RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept
RDMA/rxe: validate access flags before swapping the MR's PD
xfrm: hold net_device reference under RCU in bundle creation
RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths
wifi: cfg80211: don't free driver-owned scan requests
dmaengine: pxa: fix double counting of the hw descriptors
netfilter: flowtable: hold reference on ct until flow is released
smb: client: validate absolute native symlink targets before NT fixups
ntfs: protect runlist updates with the runlist lock
wifi: virt_wifi: don't transfer operstate before register
net: dsa: mxl862xx: disable the stats poll on teardown
futex: Also allocate private hash on vfork()
net: lock the socket in sock_gettstamp()
exec: Cleanup POSIX timers right after de_thread()
posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
signal: Prevent exec() race
swiotlb: use the adjusted address for the highmem page lookup
RDMA/ucma: Serialize join and leave on copy_to_user failure
openvswitch: avoid reallocating confirmed conntrack labels
ipv6: xfrm: use full sockets in local error paths
xfrm: save input state data before secpath resets
mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
drm/ttm: fix swapped-out resources never leaving their bulk_move range
cgroup: Avoid iteration of dying tasks with zero refcount
Local Authenticated Buffer Overflow Vulnerability in the ClearPass Policy Manager OnGuard Agent
Authenticated Local Missing Integrity Verification Vulnerability leads to Local Privilege Escalation in the ClearPass Policy Manager Windows Client Software
Authenticated Local Privilege Escalation in ClearPass Policy Manager OnGuard Linux Agent
NVIDIA Model-Optimizer contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In multiple locations, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In multiple functions of VirtualAudioControllerTest.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In multiple locations, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety issue due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In handle_le_monitor_device_event of msft.cc, there is a possible control-flow hijack in the privileged bluetooth process due to an uninitialized pointer dereference. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In multiple functions of nfa_nfcee_act.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
BentoML has Dockerfile Command Injection via system_packages in bentofile.yaml
In Settings, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In updateState of DeviceAdminAppsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In shouldDisableUninstallButton of ApplicationActionButtonsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Missing Authorization in Core
Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbitrary code execution . This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.
Microsoft Access Remote Code Execution Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Projected File System Elevation of Privilege Vulnerability
Windows Client-Side Caching Elevation of Privilege Vulnerability
Windows Projected File System Elevation of Privilege Vulnerability
Windows Projected File System Elevation of Privilege Vulnerability
Windows Projected File System Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Storage VSP Driver Elevation of Privilege Vulnerability
Windows Storage VSP Driver Elevation of Privilege Vulnerability
Windows Projected File System Elevation of Privilege Vulnerability
This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.
PowerShell Remote Code Execution Vulnerability
In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Untrusted Pointer Dereference in Power Optimization Firmware
Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service
Untrusted Pointer Dereference in Camera
Double Free in Graphics
Buffer Copy Without Checking Size of Input in DSP Service
Improper Validation of Array Index in Automotive Linux OS
Stack-based Buffer Overflow in Camera Driver
Buffer Over-read in Camera
Buffer Copy Without Checking Size of Input in Automotive Platform
Buffer Copy without Checking Size of Input in DSP Service
Untrusted Pointer Dereference in Camera
Double Free in Video
Use of Uninitialized Variable in HLOS
Out-of-bounds Write in HLOS
Untrusted Pointer Dereference in Video
Use After Free in HLOS
An integer overflow was addressed by adopting 64-bit timestamps. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. An app may be able to gain root privileges.
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory shared between processes.
Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain an insufficiently protected credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to credential exposure. The attacker may be able to use the exposed credentials to access the system with privileges of the compromised account.
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.
In mminfra, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10267349; Issue ID: MSV-5033.
In c2ps, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10274607; Issue ID: MSV-5049.
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315812; Issue ID: MSV-5533.
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315812; Issue ID: MSV-5534.
In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10314745; Issue ID: MSV-5553.
In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10276761; Issue ID: MSV-5141.
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182914; Issue ID: MSV-4699.
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184061; Issue ID: MSV-4712.
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184870; Issue ID: MSV-4729.
IBM Concert Software Improper Restriction of Operations within the Bounds of a Memory Buffer.
Avira antivirus engine heap buffer OOB read when scanning a malformed Windows MSI file
Avast antivirus heap OOB when scanning a malformed zip file
Avast antivirus heap buffer OOB read when scanning a malformed PE file
Avast antivirus heap buffer OOB read when scanning a malformed PE file
Avast antivirus heap buffer OOB write when scanning a malformed PE file
Avira antivirus engine heap buffer OOB read when scanning a malformed PDF file (variant 1)
Avira antivirus engine heap buffer OOB read when scanning a malformed PDF file (variant 2)
Linux-pam: linux-pam directory traversal
Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c
An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit through 7.00.6742 allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages components.
Backstage: Configuration bypass in TechDocs mkdocs.yml sanitization
Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml
Backstage: Improper validation of MkDocs theme configuration in TechDocs
Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend
Backstage: Improper URL validation in catalog entity placeholder resolution
Backstage: Improper validation of MkDocs plugin configuration in TechDocs
GitAhead through 2.7.1 OS Command Injection via Git Filter Filenames
Rundeck before 6.2.0 OS Command Injection via Windows Job Option Quoting
Arbitrary File Write via Write-Time Symlink Following (TOCTOU) in Claude Code
Security Advisory 0198
Langflow OSS is affected by multiple vulnerabilities
Gitea migration SSRF through ALLOWED_DOMAINS address check bypass
Langflow OSS is affected by multiple vulnerabilities
wolfSSHd on Windows race condition leading to logon token reused across connections
Improper input validation in the AMD ROCm Communication Collectives Library (RCCL) could allow a compromised peer rank or network-adjacent attacker to dereference an attacker-controlled pointer, potentially resulting in remote code execution.
InvenTree Vulnerable to ORM Filter Injection
A predictable seed in the pseudo-random number generator (PRNG) in the IFTTT pairing token generation of the ASUS RT-BE57 router allows an unauthenticated nearby user to derive the pairing token and read or modify router settings via observed values from an administrator-initiated IFTTT pairing session.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Foreman: ssti and insecure deserialization in foreman-rake configuration
WordPress VidMov theme <= 2.3.8 - Path Traversal vulnerability
Multiple Vulnerabilities in IBM Concert Software.
Coolify has a Privilege Escalation - low privileged users can see and use admin invitation links
Frontend File Manager < 23.5 - Subscriber+ Arbitrary File Deletion
Stored Cross-site Scripting (XSS) in Kentico Xperience 13
Express Gateway through 1.16.11 OAuth 2.0 Refresh Token Validation Bypass
Backstage: Improper preservation of access restrictions during service credential delegation
Security Advisory 0187
Langflow OSS is affected by multiple vulnerabilities
WordPress affiliate-toolkit plugin <= 3.9.1 - SQL Injection vulnerability
WordPress Dynamic User Directory plugin <= 2.4 - SQL Injection vulnerability
WordPress Pix por Piggly (para Woocommerce) plugin <= 2.1.2 - SQL Injection vulnerability
WordPress Post title marquee scroll plugin <= 9.9 - SQL Injection vulnerability
WordPress Slider by 10Web plugin <= 1.2.63 - SQL Injection vulnerability
WordPress WP Post Author plugin <= 4.0.0 - SQL Injection vulnerability
OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")
WordPress Integration for Contact Form 7 HubSpot plugin <= 1.4.2 - SQL Injection vulnerability
WordPress User Feedback plugin <= 1.10.0 - SQL Injection vulnerability
WordPress Team Member plugin <= 8.5 - SQL Injection vulnerability
WordPress WCFM Marketplace plugin <= 3.7.1 - SQL Injection vulnerability
Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended sphere of control.
XSS in Verisay Communication's Trizbi
XSS in Verisay Communication's Titarus
XSS in Verisay Communication's Aidango
Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup
rds: ib: use rds_conn_drop() on protocol version mismatch
smb: client: cancel reconnect work in clean_demultiplex_info()
smb: client: fix rlist race and missing initialization
smb: client: fix use-after-free of iface in cifs_try_adding_channels()
Langflow OSS is affected by multiple vulnerabilities
Langflow OSS is affected by multiple vulnerabilities
Unrestricted Upload of File with Dangerous Type in BugTracker.NET
Improper Neutralization of Special Elements used in an OS Command in BugTracker.NET
Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Bypass via NPG Notification Handler
In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Openshift/oauth-server: openshift/oauth-server: quadratic-time dos via accept-language header underscore bypass on unauthenticated login endpoints
WordPress Easy Digital Downloads plugin <= 3.7.1 - Broken Access Control vulnerability
Foreman: unauthenticated information disclosure via provisioning token validation flaw
WordPress TheGem Theme Elements (for Elementor) plugin <= 5.11.0 - Local File Inclusion vulnerability
WordPress Calafate theme <= 1.7.7 - Local File Inclusion vulnerability
A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability.
A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability..
Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.
phpMyFAQ has unauthenticated config backup download via /api/setup/backup
WordPress Responsive Posts Carousel Pro plugin <= 15.1 - Local File Inclusion vulnerability
WordPress Cinerama theme <= 2.9 - Local File Inclusion vulnerability
WordPress Aora theme <= 1.3.15 - Local File Inclusion vulnerability
WordPress Puca theme <= 2.6.39 - Local File Inclusion vulnerability
WordPress Greenmart theme <= 4.2.11 - Local File Inclusion vulnerability
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced
WordPress CedCommerce Integration for Good Market plugin <= 1.0.6 - Local File Inclusion vulnerability
WordPress CookieHint WP plugin <= 1.0.0 - Local File Inclusion vulnerability
WordPress Sell Downloads plugin <= 1.1.12 - Broken Access Control vulnerability
HCL Hive is affected by incorrect default permissions
WordPress Userpro plugin <= 5.1.9 - Broken Access Control vulnerability
WordPress Subscribe to Unlock Lite plugin <= 1.3.0 - Local File Inclusion vulnerability
WordPress Follow My Blog Post plugin <= 2.4.0 - Arbitrary Content Deletion vulnerability
WordPress Fana theme <= 1.1.35 - Local File Inclusion vulnerability
WordPress Zota theme <= 1.3.14 - Local File Inclusion vulnerability
WordPress Bookory theme <= 2.2.7 - Local File Inclusion vulnerability
Privilege Escalation in Comarch ERP Optima
Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding
WordPress WP Event SOlution plugin <= 4.1.12 - Broken Access Control vulnerability
WordPress CubeWP plugin <= 1.1.27 - Broken Access Control vulnerability
WordPress Custom Related Posts plugin <= 1.8.0 - Sensitive Data Exposure vulnerability
WordPress BulletProof Security plugin <= 6.9 - Sensitive Data Exposure vulnerability
WordPress Corpkit theme <= 2.0 - Local File Inclusion vulnerability
WordPress Membership For WooCommerce plugin <= 3.0.3 - Insecure Direct Object References (IDOR) vulnerability
Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8.
A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.
Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial of service.
Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service.
Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operation of other nodes within the installation.
Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI
Apache DolphinScheduler: Users can access sensitive information through the actuator endpoint.
A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. This plugin is disabled by default. Affected Products: UCRM Argentina AFIP invoices Plugin (Version 1.2.0 and earlier) Mitigation: Update UCRM Argentina AFIP invoices Plugin to Version 1.3.0 or later.
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.
WordPress Premium Age Verification / Restriction for WordPress Plugin <= 3.0.2 - Arbitrary File Download Vulnerability
Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.
Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user data.
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app may be able to access sensitive user data.
WordPress LoginWP - Pro Plugin <= 4.0.8.5 - Settings Change vulnerability
A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An attacker may be able to cause a persistent denial-of-service.
WordPress BuddyForms plugin <= 2.10.2 - Local File Inclusion vulnerability
Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigger a software abort, resulting in a denial of service.
Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a software abort via a crafted signalling message, resulting in a denial of service.
WordPress WP Attractive Donations System - Easy Stripe & Paypal donations plugin <= 1.25 - Arbitrary Content Deletion vulnerability
KL-001-2026-01: yintibao Fun Print Mobile Unauthorized Access via Context Hijacking
DVP-12SE11T - Denial of Service Vulnerability
Nodemailer: nodemailer: denial of service via crafted email address header
An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.
WordPress Case Theme User < 1.0.4 - Local File Inclusion Vulnerability
Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens
Incorrect reference resolution in Passwords in Google Chrome on on iOS prior to 155.0.8059.39 allowed a local attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
Kiteworks Core Path Traversal
AuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Authentication Bypass
Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
UTT 进取 520W ConfigAdvideo strcpy buffer overflow
UTT 进取 520W formTaskEdit strcpy buffer overflow
UTT 进取 520W formPptpClientConfig strcpy buffer overflow
UTT 进取 520W formUser strcpy buffer overflow
UTT 进取 512W formFtpServerDirConfig strcpy buffer overflow
UTT 进取 512W formFtpServerShareDirSelcet strcpy buffer overflow
UTT 进取 512W formConfigCliForEngineerOnly strcpy buffer overflow
UTT 进取 512W formRemoteControl strcpy buffer overflow
Tenda M3 setInternetLanInfo formSetRemoteInternetLanInfo heap-based overflow
Tenda M3 setAdInfoDetail formSetAdInfoDetails heap-based overflow
Tenda M3 setAdPushInfo formSetAdPushInfo stack-based overflow
Tenda M3 setVlanInfo formSetRemoteVlanInfo stack-based overflow
Tenda M3 setVlanPolicyData formSetVlanPolicy heap-based overflow
Tenda AC10U POST Request Parameter AdvSetLanip fromadvsetlanip buffer overflow
Tenda AC23 HTTP POST Request formSetPPTPUserList buffer overflow
Tenda AC23 SetIpMacBind fromSetIpMacBind stack-based overflow
Tenda AC10U HTTP POST Request setPptpUserList formSetPPTPUserList buffer overflow
D-Link DWR-M920 formParentControl sub_423848 buffer overflow
D-Link DWR-M920 formFilter sub_42261C stack-based overflow
D-Link DWR-M920 formDefRoute sub_464794 buffer overflow
TRENDnet TEW-800MB NTPSyncWithHost.cgi sub_F934 command injection
TRENDnet TEW-800MB Management wizardset do_setWizard_asp command injection
UTT 进取 512W ConfigExceptMSN strcpy buffer overflow
UTT 进取 512W formPictureUrl strcpy buffer overflow
UTT 进取 512W formConfigNoticeConfig strcpy buffer overflow
UTT 进取 512W APSecurity strcpy buffer overflow
Possible QML code injection in VectorImage component
yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user
Unauthenticated Path Traversal in ClearPass Policy Manager API Endpoint Leads to Authorization Bypass
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
Improper Neutralization of HTML Tags in a Web Page in libredesk
Signal K Server Vulnerable to Remote Code Execution via Malicious npm Package
TRENDnet TEW-811DRU httpd uapply.cgi setDeviceURL os command injection
Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword
Tenda WH450 HTTP Request webExcptypemanFilte stack-based overflow
Tenda WH450 qossetting stack-based overflow
Tenda WH450 HTTP Request VirtualSer stack-based overflow
Tenda WH450 HTTP Request SetIpBind stack-based overflow
Tenda WH450 SafeMacFilter stack-based overflow
Tenda WH450 SafeEmailFilter stack-based overflow
Tenda WH450 RouteStatic stack-based overflow
Tenda WH450 PPTPUserSetting stack-based overflow
Tenda WH450 PPTPServer stack-based overflow
GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances
Heap-based buffer overflow in Siemens Simcenter Femap
Cisco IOS XE SD-WAN Software Arbitrary Command Execution Vulnerability
WP Coder 4.0 - 4.5.1 - Editor+ RCE via Global PHP
Incorrect Authorization in Elasticsearch Leading to Privilege Escalation
A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution.
Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Unauthenticated Stored Cross-Site Scripting via Registration Metadata
Kiteworks Secure Data Forms Missing Authentication for Critical Function
Kiteworks Core Remote Code Execution through Server-Side Template Injection
Kiteworks Core Privilege Escalation through Improper Access Control
Kiteworks Core OS Command Injection
Kiteworks Core arbitrary file write
Kiteworks Core SQL Injection
Kiteworks Core OS command injection
Kiteworks Core improper privilege management
Security Advisory 0188
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. <= 6.3.10 - Unauthenticated Stored Cross-Site Scripting via 's' Search Parameter in comments-atom Feed
Authenticated SQL Injection allows Remote Code Execution in ClearPass Policy Manager API
Authenticated Remote Code Execution Vulnerabilities in HPE Networking ClearPass Policy Manager
In wpas_handle_robust_av_scs_recv_action of robust_av.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.
OneUptime: Path Traversal — Arbitrary File Read (No Auth)
WordPress Icegram Express Pro plugin < 5.9.14 - PHP Object Injection vulnerability
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
Nuvation Energy Multi-Stack Controller Private Key Stored on Device
An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to read kernel memory or co-located guest VM memory, potentially resulting in loss of confidentiality or availability.
DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information
An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.
Lucky Wheel for WooCommerce – Spin a Sale <= 1.1.13 - Authenticated (Administrator+) PHP Code Injection via Conditional Tags
Advanced Ads <= 2.0.14 - Authenticated (Editor+) Remote Code Execution via Shortcode
Microsoft Playwright MCP Server < 0.0.40 DNS Rebinding via Missing Origin Header Validation
RCE via the backup feature available only to user with high privilege
Bluechi: privilege escalation in bluechi via unrestricted cross-node systemd dependencies
MISP: Forced TOTP Enrolment Bypassed via Non-Browser Request Types on otp_required Instances
MiniUPnPd through 2.3.11 Divide-by-Zero DoS via SSDP M-SEARCH MX Header
Backstage: Improper repository path validation in a Scaffolder backend module
Authorization bypass through a user-controlled key in the Amazon Q Business Lambda hook sample in QnABot on AWS
Magee Shortcodes <= 2.1.1 - Reflected XSS via live_preview and magee_create_shortcode Actions
Obot 0.12.0 before 0.26.2 Credential Exposure via MCP Catalog Entry API
Unauthenticated TDP Function Pointer Dispatch Denial of Service in TP-Link Tapo C500
Authorization Bypass Through User-Controlled Key in Elasticsearch Leading to Information Disclosure
Security Advisory 0194
Security Advisory 0194
Security Advisory 0190
Security Advisory 0190
WordPress If-So Dynamic Content Personalization plugin <= 1.10.1 - Cross Site Scripting (XSS) vulnerability
wifi: libipw: reject too-short beacon and probe responses
wifi: libipw: reject too-short association responses
dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3
IB/hfi1: Fix the PIO_CRED credit-return mmap
drm/msm: RCU-free the scheduler-containing ring and VM objects
smb: client: fix potential OOB read in smb3_enum_snapshots()
KVM: x86/mmu: Check write tracking in all address spaces
Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without authentication, with delete enabled
Path Traversal in BugTracker.NET
If-So Dynamic Content 1.4.4 - 1.10.1 - Reflected XSS via 'message' Parameter
Kube-compare: container:// reference extraction runs the image entrypoint and silently escalates to sudo
Gitea deploy key pushes acting as the repository owner
wger: Trainer Privilege Escalation - Improper Privilege Management
wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views)
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that allows an attacker to corrupt one byte of heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by reading the special crafted file.
WordPress Social Rocket plugin <= 1.3.5 - Cross Site Scripting (XSS) vulnerability
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
Path Traversal in Satel Iberia SenNet Datalogger Serie 200
In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account.
LibreChat has Insufficient Access Control for Agent Files
WordPress JobBank plugin <= 1.2.2 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress Photo Gallery plugin <= 2.7.7.26 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress Arlo theme <= 6.0.3 - Cross Site Scripting (XSS) vulnerability
WordPress Scroll rss excerpt plugin <= 5.0 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress WP App Bar plugin <= 1.5 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress e-shops plugin <= 1.0.4 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress WP-BusinessDirectory plugin <= 4.0.1 - Cross Site Scripting (XSS) vulnerability
WordPress Content Grid Slider plugin <= 1.5 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress Advanced Custom CSS plugin <= 1.1.0 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress Invelity SPS connect plugin <= 1.0.8 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress Visitor Stats Widget plugin <= 1.5.0 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress PRIMER by chloédigital plugin <= 1.0.25 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress Eli's WordCents adSense Widget with Analytics plugin <= 1.3.03.27 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress Plugin Optimizer plugin <= 1.3.7 - Broken Access Control vulnerability
WordPress Okay Toolkit plugin <= 2.3 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress iRobots.txt SEO plugin <= 1.1.2 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress Listeo Core plugin < 2.0.19 - Cross Site Scripting (XSS) vulnerability
WordPress eHive Search plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerability
WordPress Link Whisper Free plugin <= 0.8.8 - Cross Site Scripting (XSS) vulnerability
WordPress Grand Restaurant theme < 7.0.9 - Cross Site Scripting (XSS) vulnerability
WordPress Woffice theme <= 5.4.30 - Cross Site Scripting (XSS) vulnerability
WordPress Jobify theme <= 4.3.0 - Cross Site Scripting (XSS) vulnerability
WordPress Evergreen Post Tweeter plugin <= 1.8.9 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability
Columbia Weather Systems MicroServer Cleartext Storage in a File or on Disk
Junos OS Evolved: QFX5000 Series and PTX Series: An attacker sending crafted multicast packets will cause evo-aftmand / evo-pfemand to crash and restart
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.
WordPress Cerato theme <= 2.2.18 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress Themebox - Digital Products Ecommerce theme <= 1.4.2 - Cross Site Scripting (XSS) vulnerability
Buffer Over-read in Computer Vision
WordPress WidgetKit Pro plugin <= 1.13.1 - Reflected Cross Site Scripting (XSS) vulnerability
Reflected XSS vulnerability in pxc_portSfp.php
Reflected XSS vulnerability in pxc_portCntr.php
Reflected XSS vulnerability in pxc_PortCfg.php
Reflected XSS vulnerability in port_util.php
Reflected XSS vulnerability in pxc_Dot1xCfg.php
Reflected XSS vulnerability in pxc_vlanIntfCfg.php
Reflected XSS vulnerability in pxc_portSecCfg.php
Reflected XSS vulnerability in pxc_portCntr2.php
Reflected XSS vulnerability in dyn_conn.php
WordPress DZS Video Gallery plugin <= 12.25 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress WPCHURCH plugin <= 2.7.0 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress Themify Folo theme <= 1.9.6 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress Famous - Responsive Image And Video Grid Gallery WordPress Plugin plugin <= 1.4 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress CountDown With Image or Video Background plugin <= 1.5 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress Off Page SEO plugin <= 3.0.3 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress Product Puller plugin <= 1.5.1 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress Ads24 Lite plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress Felan Framework plugin <= 1.1.3 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress WP Virtual Assistant plugin <= 3.1 - Cross Site Scripting (XSS) vulnerability
Quanta Computer|QOCA aim AI Medical Cloud Platform - SQL Injection
Quanta Computer|QOCA aim AI Medical Cloud Platform - SQL Injection
Quanta Computer|QOCA aim AI Medical Cloud Platform - Missing Authorization
WP Photo Album Plus <= 9.1.05.008 - Reflected Cross-Site Scripting
Arista CloudVision Exchange Cluster Instability via Unexpected Switch Messages
Arista EOS SysDB Agent Denial of Service via Malformed CVX Client/Server Messages
RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds
RDMA/core: Reject unregistering netdevs in ib_get_eth_speed
wifi: mac80211: unlist vifs when their netdev is unregistered
wifi: cfg80211: get the wiphy out of a dying network namespace
RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()
xfrm: use hlist_del_init_rcu for state_cache and state_cache_input
hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove
Out of Bound Write on WibuKey for Windows
In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Unauthenticated Craft CMS users can trigger a database backup
Microsoft Word Remote Code Execution Vulnerability
In seninf, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10251210; Issue ID: MSV-4926.
In display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184084; Issue ID: MSV-4720.
ASRock, ASRockRack, ASRockInd|Motherboard - Protection Mechanism Failure
GIGABYTE|Motherboard - Protection Mechanism Failure
Apstra: SSH host key validation vulnerability for managed devices
An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software utility, and may lead to uncontrolled resource consumption that increases the risk of unauthorized direct memory access (DMA). Refer to the 'Security Update for UEFI firmware' section on the ASUS Security Advisory for more information.
Coturn 4.10.0 Uninitialized Stack Memory Disclosure via ERROR-CODE
NetBox 2.9.5 < 4.7.0 Session Hijacking via Custom Links
Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6
Security Advisory 0191
wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated client, causing pre-authentication primality-test CPU exhaustion and key exchange role confusion
OneUptime: Password Reset Token Logged at INFO Level
Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)
CasaOS <= 0.4.15 Unauthenticated File and Debug Data Exposure
Wazuh Manager authd service Improper SSL/TLS Renegotiation Handling leading to Denial of Service
Petlibro Smart Pet Feeder Platform through 1.7.31 Authentication Bypass via API endpoint
Arbitrary File Download through Path Traversal in Innorix WP
Command injection in Kieback&Peter Neutrino-GLT
Petlibro Smart Pet Feeder Platform through 1.7.31 Broken Access Control via API endpoint
Petlibro Smart Pet Feeder Platform through 1.7.31 Information Disclosure via API endpoint
Petlibro Smart Pet Feeder through 1.7.31 Platform Improper Access Control via API endpoint
Petlibro Smart Pet Feeder Platform through 1.7.31 Audio Information Disclosure via API endpoint
Petlibro Smart Pet Feeder Platform through 1.7.31 Authorization Bypass via Device Share API
NSauditor 3.1.2.0 Denial of Service via Community Field
jetAudio 8.1.7.20702 Basic Denial of Service via URL Handler
NordVPN 6.19.6 Denial of Service via Email Field Buffer Overflow
MediaMonkey 4.1.23 Denial of Service via Malformed URL
BlueStacks 4.80.0.1060 Denial of Service via Search Field
WebDrive 18.00.5057 Denial of Service via Secure WebDAV
HeidiSQL 9.5.0.5196 Denial of Service via Preferences
NetSetMan 4.7.1 Workgroup Buffer Overflow Denial of Service
Backstage: Explicit negative email verification can be ignored during shared OAuth profile normalization
Backstage: Insufficient audience validation in the Cloudflare Access auth provider
MPG < 4.2.3 - Editor+ SQLi via Project Import
Authenticated ONVIF PTZ Out-of-Bounds Stack Write Denial of Service in TP-Link Tapo C500
Animated Number Counters < 3.1 - Editor+ Second-Order SQLi via Counter Order
Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Crop Dimensions
Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image ID
Sssd: sssd: authorization bypass via cross-domain username collision in hbac evaluation
This vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate arbitrary processes on the system.
HDF5 scale-offset filter heap buffer over-read via crafted chunk
Shell access to UART Console
Weak/Predictable root Password
HCL DevOps Velocity is susceptible to brute-force attacks
Netskope Client Service Insufficient Access Controls
Netskope Client Exposed IOCTL with Insufficient Access Controls
Form Maker < 1.15.38 - SQL Injection
Data Exposure in Gmission Web FAX
Rapid7 Velociraptor Directory Traversal Vulnerability
Privilege boundary violation in Radiometer Products
Kiteworks Core Privilege Escalation through External Control of File Name or Path
Local Arbitrary File Write Leading to Local Privilege Escalation in ClearPass Policy Manager OnGuard Agent
Local Privilege Escalation in ClearPass Client Software
In platform_msg_handler_init of default_msg_handlers.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Out-of-bounds Write in Camera Driver
Rubygem-hammer_cli: command injection via insecure editor invocation
Dbit WIFI4 N300 1.0.0 devices allows administrators (from the local Wi-Fi network) to execute OS commands by leveraging a stack-based buffer overflow via the /api/addStaticDHCP comment field,
Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the file system. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.
Time-of-check Time-of-use (TOCTOU) Race Condition in Camera Driver
Use After Free in Camera Driver
Use After Free in Camera Driver
Buffer Copy Without Checking Size of Input in Camera Driver
Buffer Copy Without Checking Size of Input in Camera Driver
Time-of-check Time-of-use (TOCTOU) Race Condition in Camera Driver
Missing Authorization with the DS8900F and DS8A00 Hardware Management Console
In dpe, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114841; Issue ID: MSV-4451.
In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114835; Issue ID: MSV-4479.
In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114696; Issue ID: MSV-4480.
In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10198951; Issue ID: MSV-4503.
In dpe, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10199779; Issue ID: MSV-4504.
In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10238968; Issue ID: MSV-4914.
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10149879; Issue ID: MSV-4658.
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10149882; Issue ID: MSV-4673.
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10149882; Issue ID: MSV-4677.
In display, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182882; Issue ID: MSV-4683.
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182882; Issue ID: MSV-4684.
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182882; Issue ID: MSV-4685.
WordPress WordPress Social Login and Register plugin <= 7.7.0 - Local File Inclusion vulnerability
Use After Free in HLOS
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.
Keycloak-services: keycloak-services: smtp starttls plaintext credential and message downgrade
In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data.
Backstage: Sensitive information exposure in scaffolder task logs
Backstage: Improper input validation in TechDocs static content requests
Backstage: Improper authorization enforcement for TechDocs static content
Backstage: Inconsistent repository filtering in Bitbucket Server catalog event updates
Uninitialized resource in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Missing authorization in SignIn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Low)
Use of released resource in FontAccess in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Incorrect authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
Information leak in Omnibox in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)
WordPress Rocket Lazy Load plugin <= 2.4.0 - Cross Site Scripting (XSS) vulnerability
WordPress Prime Slider – Addons For Elementor plugin <= 4.6.2 - Cross Site Scripting (XSS) vulnerability
WordPress Element Pack Elementor Addons plugin <= 8.8.6 - Cross Site Scripting (XSS) vulnerability
WordPress Element Pack Elementor Addons plugin <= 8.8.6 - Cross Site Scripting (XSS) vulnerability
WordPress Happy Addons for Elementor plugin <= 3.50.0 - Cross Site Scripting (XSS) vulnerability
WordPress Quiz And Survey Master plugin <= 11.2.7 - Cross Site Scripting (XSS) vulnerability
Pulp-ansible: bearer tokens are reused across remotes in a worker
Pulp-container: registry credentials are reused across remotes in a worker
Geliver Akıllı Kargo Pazaryeri 3.0.0 - 3.1.0 - Unauthenticated API Key Disclosure via Public Log File
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service
Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure
Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
WordPress Optimole plugin <= 4.2.14 - Broken Access Control vulnerability
Kiteworks Email Protection Gateway Incorrect Authorization
Langflow OSS is affected by multiple vulnerabilities
Langflow OSS is affected by multiple vulnerabilities
WordPress Media LIbrary Assistant plugin <= 3.41 - Cross Site Scripting (XSS) vulnerability
Optimole 4.0.0 - 4.2.14 - Subscriber+ Sensitive Data Disclosure via Dashboard Widget
Langflow OSS is affected by multiple vulnerabilities
WordPress Product Catalog Enquiry for WooCommerce by MultiVendorX plugin <= 6.1.5 - Privilege Escalation vulnerability
Foreman: cross-tenant disclosure of template revisions via unauthorized audit lookup
Authenticated Command Injection Vulnerability in the ClearPass Policy Manager OnGuard Agent
Unauthenticated Sensitive Information Disclosure in AOS-S
Authenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in AOS-S
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
PraisonAI: Platform members can delete owner issue dependencies through member-owned related issues
.NET Information Disclosure Vulnerability
WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.22 - Cross Site Scripting (XSS) vulnerability
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
Rubygem-katello: sql injection in registry proxy via labels
In multiple functions of PduParser.java, there is a possible out of bounds read due to a missing bounds check. This could lead to a remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry
A path traversal vulnerability exists in the unzip_http RemoteZipFile extract functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .zip file can lead to arbitrary file write. An attacker can provide a crafted URL to trigger this vulnerability.
Dolibarr Core Discloses Sensitive Data via Authenticated Local File Inclusion in selectobject.php
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
WordPress Responsive Addons for Elementor plugin <= 2.0.8 - Broken Access Control vulnerability
WordPress TheGem Theme Elements (for WPBakery) plugin <= 5.11.0 - Cross Site Scripting (XSS) vulnerability
WordPress TheGem Theme Elements (for Elementor) plugin <= 5.11.0 - Cross Site Scripting (XSS) vulnerability
WordPress Team Showcase plugin <= 2.9 - Cross Site Scripting (XSS) vulnerability
WordPress Wishlist for WooCommerce plugin <= 3.3.0 - Cross Site Scripting (XSS) vulnerability
WordPress Bookify plugin <= 1.1.1 - Broken Access Control vulnerability
Apache CloudStack: Domain/account resources limits not honored
Pterodactyl TOTPs can be reused during validity window
WordPress Essential Addons for Elementor plugin <= 6.5.3 - Cross Site Scripting (XSS) vulnerability
WordPress Auto Listings plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability
WordPress Combo Offers WooCommerce plugin <= 4.2 - Cross Site Scripting (XSS) vulnerability
WordPress Blog Filter plugin <= 1.7.3 - Cross Site Scripting (XSS) vulnerability
WordPress BizPrint plugin <= 4.6.7 - Broken Access Control vulnerability
WordPress Newsletters plugin <= 4.12 - Cross Site Scripting (XSS) vulnerability
WordPress Web Directory Free plugin <= 1.7.12 - Cross Site Scripting (XSS) vulnerability
WordPress RestroPress plugin <= 3.2.8.6 - Cross Site Scripting (XSS) vulnerability
WordPress BWL Knowledge Base Manager plugin <= 1.6.3 - Cross Site Scripting (XSS) vulnerability
WordPress BWL Pro Voting Manager plugin <= 1.4.9 - Cross Site Scripting (XSS) vulnerability
WordPress DesignThemes Core plugin <= 1.6 - Cross Site Scripting (XSS) vulnerability
WordPress DesignThemes Portfolio Addon plugin <= 1.5 - Cross Site Scripting (XSS) vulnerability
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker can delete the LOGINFAILEDTABLE table.
WordPress Flaming Password Reset plugin <= 1.0.3 - Cross Site Scripting (XSS) vulnerability
WordPress Wp Text Slider Widget plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability
WordPress Effect Maker plugin <= 1.2.1 - Cross Site Scripting (XSS) vulnerability
WordPress Custom Field Template plugin <= 2.7.7 - Cross Site Scripting (XSS) vulnerability
WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.23 - Cross Site Scripting (XSS) vulnerability
WordPress YouTube Embed plugin <= 5.4 - Cross Site Scripting (XSS) vulnerability
WordPress Jobs for WordPress plugin <= 2.8.1 - Cross Site Scripting (XSS) vulnerability
WordPress WC Builder plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability
WordPress ModelTheme Addons for WPBakery and Elementor plugin < 1.5.6 - Cross Site Scripting (XSS) vulnerability
WordPress Free Shipping Bar: Amount Left for Free Shipping for WooCommerce plugin <= 2.4.9 - Cross Site Scripting (XSS) vulnerability
WordPress Academy LMS plugin <= 3.4.0 - Cross Site Scripting (XSS) vulnerability
WordPress Bold Timeline Lite plugin <= 1.2.7 - Cross Site Scripting (XSS) vulnerability
WordPress Real 3D FlipBook plugin <= 4.11.4 - Cross Site Scripting (XSS) vulnerability
WordPress Gutenverse Form plugin <= 2.3.1 - Broken Access Control vulnerability
WordPress JetSearch plugin <= 3.5.16 - Cross Site Scripting (XSS) vulnerability
WordPress JetBlog plugin <= 2.4.7 - Broken Access Control vulnerability
WordPress JetTabs plugin <= 2.2.12 - Cross Site Scripting (XSS) vulnerability
WordPress JetTabs plugin <= 2.2.12 - Broken Access Control vulnerability
libheif has Potential Heap Buffer Over-Read
Apache SIS: XML External Entity (XXE) vulnerability
WordPress WP Project Manager plugin <= 3.0.1 - Sensitive Data Exposure vulnerability
WordPress AweBooking plugin <= 3.2.26 - Sensitive Data Exposure vulnerability
WordPress Fluent Support plugin <= 1.10.4 - Broken Access Control vulnerability
WordPress Woffice Core plugin <= 5.4.30 - Insecure Direct Object References (IDOR) vulnerability
WordPress Traveler theme <= 3.2.6 - Broken Access Control vulnerability
WordPress Aruba HiSpeed Cache plugin < 3.0.3 - Broken Access Control vulnerability
Apache CloudStack: Any user can create a new VM from backups they should not have access to
Apache CloudStack: Any user can list backups that they should not have access to
WordPress MasterStudy LMS Pro plugin < 4.7.16 - Broken Access Control vulnerability
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
DirectX Graphics Kernel Denial of Service Vulnerability
WordPress Rescue Shortcodes plugin <= 3.3 - Cross Site Scripting (XSS) vulnerability
A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or commands via specially crafted packets.
Apache NuttX RTOS: fs/inode: fs_inoderemove root inode removal
Buffer Copy Without Checking Size of Input in Automotive Audio
Buffer Over-read in WLAN Firmware
Buffer Over-read in WLAN HAL
Buffer Over-read in WLAN Firmware
Use After Free in Camera Driver
WordPress The Plus Addons for Elementor Pro plugin < 6.3.7 - Broken Access Control vulnerability
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An attacker may be able to spoof their FaceTime caller ID.
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.
Improper certificate validation in multiple RouterOS services
Authenticated Denial-of-Service via Webshell
WordPress LoginWP - Pro Plugin <= 4.0.8.5 - Broken Access Control vulnerability
WordPress Dokan Pro plugin <= 3.14.5 - Cross Site Scripting (XSS) vulnerability
IBM® Db2® is vulnerable to a denial of service with a specially crafted query when stmtheap is set to automatic
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689259 / MOLY01586470; Issue ID: MSV-4847.
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01430930; Issue ID: MSV-4836.
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01685181; Issue ID: MSV-4760.
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01311265; Issue ID: MSV-4655.
In Modem, there is a possible read of uninitialized heap data due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01676750; Issue ID: MSV-4653.
WordPress Elizaibots plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability
WordPress YouTube Showcase plugin <= 3.5.1 - Cross Site Scripting (XSS) vulnerability
Eleganzo <= 1.2 - Authenticated (Subscriber+) Arbitrary Directory Deletion
Advanced Custom Fields: Extended <= 0.9.2.3 - Unauthenticated Arbitrary Shortcode Execution
Bit Form – Contact Form Plugin <= 2.21.6 - Missing Authorization to Unauthenticated Workflow Replay
Flashcard Plugin for WordPress <= 0.9 - Authenticated (Contributor+) Arbitrary File Read via Path Traversal
Widgets for Social Photo Feed <= 1.8 - Missing Authentication to Unauthenticated Plugin Settings Access/Update via trustindex_feed_hook_instagram REST API endpoints
YML for Yandex Market < 5.0.26 - Shop Manager+ RCE via Feed Generation
Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow
Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads
Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter
Appointment Booking and Scheduling Calendar Plugin – WP Timetics <= 1.0.36 - Missing Authorization to Unauthenticated Booking Details View And Modification
Xpro Elementor Addons - Pro <= 1.4.7 - Authenticated (Contributor+) Arbitrary File Read via Draw SVG
Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extraction
Backstage: Improper input validation in proxy-backend
Backstage: Scaffolder credential handling may allow unintended GitHub authentication fallback
ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.
ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.
ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.
WordPress Advanced Database Cleaner PRO Plugin <= 3.2.10 - Limited .txt Path Traversal vulnerability
WordPress nK Themes Helper plugin <= 1.7.9 - Server Side Request Forgery (SSRF) vulnerability
Responsive Pricing Table <= 5.1.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'table_currency'
Gutenverse Form <= 2.3.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Customer Reviews for WooCommerce <= 5.93.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via displayName Parameter
My Album Gallery <= 1.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via Image Title
King Addons for Elementor <= 51.1.38 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Widgets
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'put_wpgm' Shortcode
Password Protect WordPress Lite <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting
Mechrevo Control Center GX V2 Powershell Script Command uncontrolled search path
Mechrevo Control Center GX V2 reg File uncontrolled search path
Phlox <= 2.17.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-caption` HTML Attribute
Backstage: Improper input validation in Confluence to Markdown scaffolder module
Gimp: gimp: heap buffer overflow in gif export on oversized image dimensions
Gimp: gimp: heap buffer overflow in dicom export on oversized image dimensions
wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorization check
Unauthenticated DOM-Based Cross-Site Scripting (XSS) Vulnerability in the ClearPass Policy Manager Client Interface
In µURU, a Specially Crafted Federation Name Allows Dialplan Injection
Signal K Server Vulnerable to Access Request Spoofing
WordPress Wallet System for WooCommerce plugin <= 2.7.3 - Sensitive Data Exposure vulnerability
Multiple vulnerabilities have been addressed in IBM Aspera Shares
Apache DolphinScheduler: Deserialization of untrusted data in RPC
jupyter_server next parameter open redirect can redirect users to external domains
Knowage is vulnerable to blind server-side request forgery (SSRF)
Hardcoding sensitive information
Inadequate account permissions management
Insufficient certificate validation
Wazuh Provisioning Scripts / Build Infrastructure Improper Certificate Validation leading to MITM and RCE
An unsanitized format validation vulnerability in Nokia SR Linux
A local privilege escalation vulnerability in Nokia SR Linux
M17n-lib: null-pointer write in read_mtext_element() on malformed utf-8
M17n-lib: parser infinite loop on malformed utf-8 in count_utf_8_chars()
M17n-lib: heap use-after-free write in re_init_ic()
Sssd: sssd: denial of service via incomplete identity provider authentication requests
Uncaught Exception in Elastic Endpoint Leading to Denial of Service
Security Advisory 0192
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper restriction of excessive authentication attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Vulnerabilities found
IBM Concert Software Cleartext Storage in a File or on Disk.
Sparx Enterprise Architect Client reveals plaintext OAuth2 client secret
Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Post-authentication Stored Cross-Site Scripting (XSS) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to store and potentially execute arbitrary JavaScript code in the Appliance Management Console (AMC).
This vulnerability in Veeam Backup & Replication allows a Backup Viewer to modify the Enterprise Manager master key and stored antivirus update credentials.
Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect
Authenticated Local Denial-of-Service Vulnerability in the OnGuard Agent of ClearPass Policy Manager
ESF-IDF Has Out-of-Bounds Write in ESP32 Bluetooth AVRCP Vendor Command Handling
An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
SimpleSAMLphp-casserver has an Open Redirect vulnerability via logout
DOM-based Cross-Site Scripting (XSS) vulnerability in 201206030 novel V3.5.0 allows remote attackers to execute arbitrary JavaScript code or disclose sensitive information (e.g., user session cookies) via a crafted "wvstest" parameter in the URL or malicious script injection into window.localStorage. The vulnerability arises from insufficient validation and encoding of user-controllable data in the book comment module: unfiltered user input is stored in the backend database (book_comment table, commentContent field) and returned via API, then rendered directly into the page DOM via Vue 3's v-html directive without sanitization. Even if modern browsers' built-in XSS filters block pop-up alerts, attackers can use concealed payloads to bypass interception and achieve actual harm.
An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL. This issue affects the next_url parameter in the login endpoint and could lead to phishing or token theft after successful authentication.
Priority - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
Buffer Over-read in DSP Service
Buffer Over-read in Video
MapGeo - Interactive Geo Maps <= 1.6.27 - Reflected Cross-Site Scripting via 'map' Parameter
HBLPAY Payment Gateway for WooCommerce <= 5.0.0 - Reflected Cross-Site Scripting via 'cusdata' Parameter
Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.2 - Unauthenticated Limited Arbitrary File Upload
Advance WP Query Search Filter <= 1.0.10 - Reflected XSS via taxo_ajax
Advance WP Query Search Filter <= 1.0.10 - Reflected XSS via counter
Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
Reflected Cross-Site Scripting via Authentication Endpoint in WSO2 Identity Server
Security Advisory 0190
axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header
Weak Algorithm Support in SSH Server on TL-WR820N
Improper Token Invalidation in WSO2 Identity Server Allows Access After Account Lock
Authentication Weakness on Omada Controllers, Gateways and Access Points
Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated requests
Incorrect authorization in PDF in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)
Incorrect authorization in Sync in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)
Integration for Epos Now and WooCommerce 4.6.0 - 4.11.1 - Unauthenticated Action Scheduler Queue Disclosure
WordPress UiChemy plugin <= 4.4.2 - Cross Site Scripting (XSS) vulnerability
WordPress Accordion plugin <= 3.0.3 - Cross Site Scripting (XSS) vulnerability
WordPress Inboxify Sign Up Form plugin <= 1.0.4 - Cross Site Scripting (XSS) vulnerability
WordPress Popping Sidebars and Widgets Light plugin <= 1.27 - Cross Site Scripting (XSS) vulnerability
WordPress AM Events plugin <= 1.13.1 - Cross Site Scripting (XSS) vulnerability
WordPress WPBakery Visual Composer WHMCS Elements plugin <= 1.0.4.3 - Cross Site Scripting (XSS) vulnerability
WordPress My auctions allegro plugin <= 3.6.35 - Cross Site Scripting (XSS) vulnerability
WordPress Category Icon plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability
WordPress Astra Widgets plugin <= 1.2.16 - Cross Site Scripting (XSS) vulnerability
WordPress Greenhouse Job Board plugin <= 2.7.3 - Cross Site Scripting (XSS) vulnerability
WordPress Google AdSense for Responsive Design – GARD plugin <= 2.23 - Cross Site Scripting (XSS) vulnerability
WordPress Gift Hunt plugin <= 2.0.2 - Cross Site Scripting (XSS) vulnerability
WordPress WH Tweaks plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability
WordPress Basticom Framework plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability
WordPress Review Disclaimer plugin <= 2.0.3 - Cross Site Scripting (XSS) vulnerability
WordPress Draft Notify plugin <= 1.5 - Cross Site Scripting (XSS) vulnerability
Quarkus REST has potential worker thread starvation when HTTP connection is closed while waiting to write
Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node.
Joomla! Core - [20260102] - XSS vector in the pagebreak plugin
Joomla! Core - [20260101] - Inadequate content filtering for data URLs
WordPress WEN Logo Slider plugin <= 3.4.0 - Cross Site Scripting (XSS) vulnerability
Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a crafted calendar invite, leading to a denial of service.
WordPress WP Emmet plugin <= 0.3.4 - Cross Site Scripting (XSS) vulnerability
YaMaps < 0.6.40 - Contributor+ Stored XSS
Multiple vulnerabilities have been addressed in IBM Aspera Shares
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information or conduct limited denial-of-service in SRM.
Recoverable passwords in Asseco Infomedica Plus
BM Concert Software Improper Clearing of Heap Memory Before Release.
Improper Input Validation
Encryption vulnerable to brute-force decryption in GoAnywhere MFT
Server-side request forgery and local file read via unrestricted external OpenAPI reference resolution in Bedrock AgentCore Starter Toolkit agent import
Coolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members` API endpoint
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. A malicious HID device may cause an unexpected process crash.
A Relative Path Traversal vulnerability in Nokia MantaRay NM
Sparx Enterprise Architect Client does not verify the receiver of OAuth2 credentials during OpenID authentication
Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenance data is accessible by a principal/authority other than ETERNUS SF Admin, allows an attacker to potentially affect system confidentiality, integrity, and availability.
Freelance Security Lock – Access to Windows OS
Gimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on crafted file
Local Disclosure of Sensitive Information in HPE Networking ClearPass Policy Manager Client Software
Cri-o: cri-o: bind_mount_prefix intermediate-symlink prefix bypass
Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain a Plaintext Storage of Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
NVIDIA TensorRT contains a vulnerability where an attacker can cause an out of bounds read. A successful exploit of this vulnerability may lead to denial of service.
In setPermissionGrantState of DevicePolicyManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
In NTFS-3G before 2026.7.7, a out-of-bounds read exists in ntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to read possibly confidential information in ntfs-3g process memory by crafting a malicious NTFS image. The out-of-bounds read is triggered by a readlink on a corrupted file.
A path traversal vulnerability exists in the EmailSheet extract_parts functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .eml file can lead to arbitrary file write. An attacker can provide a malicious file to trigger this vulnerability.
In multiple functions of rw_t5t.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS via a crafted banner.
Multiple vulnerabilities have been addressed in IBM Aspera Shares
Rate-limit bypass on login via X-Forwarded-Host header
Windows Defender Firewall Service Information Disclosure Vulnerability
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
Information Exposure in Computer Vision
Buffer Over-read in Video
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An app may be able to access sensitive payment tokens.
An information disclosure issue was addressed with improved privacy controls. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An app may be able to access sensitive user data.
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sonoma 14.8.3, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An app may be able to access sensitive user data.
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to access sensitive user data.
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
Security vulnerability has been detected in IBM Security Verify Directory
A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access private information.
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.
bg5sbk MiniCMS Article post-edit.php improper authentication
bg5sbk MiniCMS Trash File Restore post.php improper authentication
bg5sbk MiniCMS Publish page-edit.php improper authentication
bg5sbk MiniCMS File Recovery Request page.php delete_page improper authentication
Yonyou KSOA work_edit.jsp sql injection
Yonyou KSOA work_update.jsp sql injection
Yonyou KSOA PrintZPYG.jsp sql injection
yeqifu carRental com.yeqifu.sys.controller.FileController downloadShowFile.action downloadShowFile path traversal
Yonyou KSOA HTTP GET Parameter del_user.jsp sql injection
Yonyou KSOA HTTP GET Parameter agent_worksdel.jsp sql injection
EmpireSoft EmpireCMS IP Address connect.php egetip protection mechanism
Yonyou KSOA HTTP GET Parameter agent_worksadd.jsp sql injection
Yonyou KSOA agent_work_report.jsp sql injection
code-projects Online Guitar Store login.php sql injection
code-projects Online Guitar Store Delete_product.php sql injection
code-projects Online Guitar Store Create_product.php sql injection
code-projects Online Guitar Store Create_category.php sql injection
gmg137 snap7-rs client.rs download heap-based overflow
code-projects Simple Stock System login.php sql injection
Tenda CH22 DhcpListClient fromDhcpListClient denial of service
code-projects Refugee Food Management System editrefugee.php sql injection
Campcodes Supplier Management System view_products.php sql injection
Campcodes Supplier Management System add_area.php sql injection
code-projects College Notes Uploading System login.php sql injection
code-projects Assessment Management login.php sql injection
code-projects Assessment Management add-module.php sql injection
code-projects Refugee Food Management System addusers.php sql injection
code-projects Refugee Food Management System refugeesreport.php sql injection
code-projects Refugee Food Management System refugeesreport2.php sql injection
code-projects Refugee Food Management System viewtakenfd.php sql injection
code-projects Refugee Food Management System served.php sql injection
code-projects Refugee Food Management System pagenateRefugeesList.php sql injection
itsourcecode Student Management System statistical.php sql injection
itsourcecode Online Cake Ordering System detailtransac.php sql injection
itsourcecode Online Cake Ordering System updatesupplier.php sql injection
itsourcecode Online Cake Ordering System updatecustomer.php sql injection
9786 phpok3w show.php sql injection
saiftheboss7 onlinemcqexam quesadd.php sql injection
ZKTeco BioTime Endpoint safe_setting credentials storage
FantasticLBP Hotels_Server Room.php sql injection
jackq XCMS upload.php unrestricted upload
simstudioai sim CRON Secret internal.ts improper authentication
TOZED ZLT M30s Web Management proc_post information disclosure
itsourcecode Student Management System list_report.php sql injection
itsourcecode Student Management System form137.php sql injection
Tenda CH22 public path traversal
itsourcecode Student Management System student_p.php sql injection
itsourcecode Online Frozen Foods Ordering System customer_details.php sql injection
itsourcecode Online Frozen Foods Ordering System contact_us.php sql injection
WPC Badge Management for WooCommerce <= 3.1.6 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'text' Attribute
Avast antivirus stack overflow when scanning a malformed Office Open XML file
Avira antivirus engine null pointer dereference when scanning a malformed PE file
Avast antivirus stack overflow when scanning a malformed PDF file
Avast antivirus use of stack memory after free when scanning a malformed PE file
Avast antivirus infinite recursion when scanning a malformed PE file
Backstage: Improper authorization in GitLab organizational user ingestion
Incorrect calculation in API in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)
Code injection in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)
Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Clickjacking in Messages in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
UI misrepresentation in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Clickjacking in EVP in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Improper state validation in Autofill AI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
UI misrepresentation in PictureInPicture in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
UI misrepresentation in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Incorrect authorization in Input in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
UI misrepresentation in FullScreen in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)
Clickjacking in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
UI misrepresentation in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
UI misrepresentation in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
UI misrepresentation in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
UI misrepresentation in WebOTP in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
UI misrepresentation in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Incorrect authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
UI misrepresentation in File in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Missing authorization in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)
Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)
UI misrepresentation in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Ansible: ansible-ui: ansible ui dom xss in /redirect next parameter
Incorrect Authorization in Elasticsearch Leading to Unauthorized Data Stream Modification
Kiteworks Core Unprotected Alternate Channel
Sssd: sssd: fail-open in ldap ppolicy access check allows continued authorization
Gitea push-to-create bypass of FORCE_PRIVATE policy
MetForm < 4.3.1 - Unauthenticated HTML Injection in Notification Emails via Field Shortcodes
Entity PDF - Moderately critical - Access bypass - SA-CONTRIB-2026-114
wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
WordPress The Events Calendar plugin <= 6.15.12.2 - Broken Access Control vulnerability
WordPress RSS Feed Widget plugin <= 3.0.2 - Broken Access Control vulnerability
WordPress WeDesignTech Ultimate Booking Addon plugin <= 1.0.3 - Broken Access Control vulnerability
WordPress Easy Media Download plugin <= 1.1.11 - CSS Injection vulnerability
WordPress FiveStar theme <= 1.7 - Insecure Direct Object References (IDOR) vulnerability
WordPress Backpack Traveler theme <= 2.10.3 - Insecure Direct Object References (IDOR) vulnerability
WordPress Struktur theme <= 2.5.1 - Insecure Direct Object References (IDOR) vulnerability
WordPress HR Management Lite plugin <= 3.6 - Broken Access Control vulnerability
WordPress Popup box plugin <= 6.0.7 - Cross Site Request Forgery (CSRF) vulnerability
WordPress Heateor Social Login plugin <= 1.1.39 - Cross Site Request Forgery (CSRF) vulnerability
WordPress Eagle Booking plugin <= 1.3.4.3 - Settings Change vulnerability
phpMyFAQ has stored XSS in admin "List of users" via display_name HTML entity decoding (html_entity_decode) + Twig |raw
Frappe CRM vulnerable to authenticated XSS via website field
WordPress Editorial Calendar plugin <= 3.8.8 - Broken Access Control vulnerability
WordPress Five Star Restaurant Reservations plugin <= 2.7.8 - Cross Site Request Forgery (CSRF) vulnerability
WordPress WP Adminify plugin <= 4.0.6.1 - Broken Access Control vulnerability
WordPress Simple File List plugin <= 6.1.18 - Broken Access Control vulnerability
WordPress YITH Slider for page builders plugin <= 1.0.11 - Broken Access Control vulnerability
WordPress Simple Keyword to Link plugin <= 1.5 - Cross Site Request Forgery (CSRF) vulnerability
WordPress My auctions allegro plugin <= 3.6.33 - Cross Site Request Forgery (CSRF) vulnerability
WordPress Tablesome plugin <= 1.1.35.1 - Broken Access Control vulnerability
WordPress 6Storage Rentals plugin <= 2.22.0 - Server Side Request Forgery (SSRF) vulnerability
Multiple vulnerabilities have been addressed in IBM Aspera Shares
HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced.
HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations
XSS in IBM Aspera Faspex
Popup Box AYS Pro < 5.5.0 - Admin+ Stored Cross-Site Scripting (XSS) via CSRF
LearnPress – WordPress LMS Plugin <= 4.3.2.2 - Insecure Direct Object Reference to Authenticated (Instructor+) Teacher Material Deletion
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors.
Stored XSS in EchoCCS's Specto CM
MISP Correlation Engine Fails to Refresh When Event Distribution or Sharing Group Changes
Backstage: Improper entity validation in deprecated Kubernetes services endpoint
Backstage: Potential file exposure through local TechDocs publisher
Backstage: TechDocs arbitrary file read via mkdocs snippets
Backstage: Improper input validation in scaffolder task list ordering
Backstage: Sensitive information may be exposed in Scaffolder task failure events
yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryError
yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream header
yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputs
Missing authorization in DataTransfer in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Observable discrepancy in Autofill AI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Incomplete cleanup in Proxy Auth in Google Chrome prior to 155.0.8059.39 allowed an adjacent attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: High)
WordPress Modula Image Gallery plugin <= 3.0.11 - Sensitive Data Exposure vulnerability
Magee Shortcodes <= 2.1.1 - Unauthenticated Mail Relay via Contact Form
Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content
Apache log4net: Oversize EventLogAppender record silently discarded
Apache log4net: Request validation failure drops the event in the aspnet-request converter
Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch
Apache log4net: NUL character truncates OutputDebugStringAppender records
Apache log4net: NUL character truncates EventLogAppender records
Obot 0.26.0 before 0.26.2 Authorization Bypass via vMCP Profile Prompts and Resources
Sssd: sssd: information disclosure via query injection in entra id lookups
Kiteworks Email Protection Gateway Uncontrolled Resource Consumption
Security Advisory 0187
WPCafe < 3.0.21 - Unauthenticated Product Data Disclosure via REST API
wstrncat() unsigned integer underflow leads to an off-by-one null write in wolfSSH on non-Windows platforms
Authentication Bypass in the API Interface Allows Unauthorized Information Disclosure in ClearPass Policy Manager
Nexus Repository 3 - Denial of Service via Unbounded Maven POM Metadata Fields
Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing
OneUptime has WhatsApp Resend Verification Authorization Bypass
WordPress WP Rentals theme <= 3.14.2 - Broken Access Control vulnerability
Foreman: command injection in foreman-tail
WordPress Breeze plugin <= 2.2.21 - Broken Access Control vulnerability
WordPress Creator LMS plugin <= 1.1.12 - Broken Access Control vulnerability
WordPress ShopMagic plugin <= 4.7.2 - Broken Access Control vulnerability
WordPress Arcane theme <= 3.6.6 - Broken Access Control vulnerability
WordPress weForms plugin <= 1.6.25 - Broken Access Control vulnerability
WordPress Product Delivery Date for WooCommerce – Lite plugin <= 3.2.0 - Broken Access Control vulnerability
WordPress Themebeez Toolkit plugin <= 1.3.5 - Broken Access Control vulnerability
WordPress Medicalequipment theme <= 1.0.9 - Broken Access Control vulnerability
WordPress wpDiscuz plugin <= 7.6.43 - Insecure Direct Object References (IDOR) vulnerability
WordPress Product Loops for WooCommerce plugin <= 2.1.2 - Broken Access Control vulnerability
WordPress Share, Print and PDF Products for WooCommerce plugin <= 3.1.2 - Broken Access Control vulnerability
WordPress E-Invoice App Malaysia plugin <= 1.3.0 - Sensitive Data Exposure vulnerability
WordPress DesignThemes LMS Addon plugin <= 2.6 - Broken Access Control vulnerability
WordPress HomeFix Elementor Portfolio plugin <= 1.0.1 - Broken Access Control vulnerability
WordPress WeDesignTech Portfolio plugin <= 1.0.2 - Broken Access Control vulnerability
WordPress Google Calendar Events plugin <= 3.5.9 - Insecure Direct Object References (IDOR) vulnerability
HCL Hive is affected by use of a cryptographic primitive with a risky implementation
WordPress PostX plugin <= 5.0.3 - Sensitive Data Exposure vulnerability
WordPress Bit Assist plugin <= 1.5.11 - Broken Access Control vulnerability
WordPress Widgets for Social Photo Feed plugin <= 1.8 - Broken Access Control vulnerability
WordPress WP Telegram Widget and Join Link plugin <= 2.2.12 - Broken Access Control vulnerability
WordPress Cooked plugin <= 1.11.3 - Broken Access Control vulnerability
WordPress Funnelforms Free plugin <= 3.8 - Broken Access Control vulnerability
WordPress FV Simpler SEO plugin <= 1.9.6 - Broken Access Control vulnerability
WordPress BBP Core plugin <= 1.4.1 - Broken Access Control vulnerability
WordPress SALESmanago plugin <= 3.9.0 - Broken Access Control vulnerability
WordPress Claspo – Popups, Spin the Wheel & Email Capture plugin <= 1.0.7 - Broken Access Control vulnerability
WordPress Twitch Player plugin <= 2.1.3 - Broken Access Control vulnerability
WordPress H5P plugin <= 1.16.1 - Broken Access Control vulnerability
WordPress Premium Addons for Elementor plugin <= 4.11.53 - Sensitive Data Exposure vulnerability
Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed Endpoints
Apache Doris MCP Server: MCP SQL inject
WordPress Bus Ticket Booking with Seat Reservation plugin < 5.6.8 - Broken Access Control vulnerability
WordPress BuddyForms plugin <= 2.10.2 - Broken Access Control vulnerability
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty on large deployments). No publicly available exploits are known.
Meshtastic firmware allows forged DMs with no PKC to show up as encrypted
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to leak sensitive user information.
A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.1), RUGGEDCOM RS416Pv2 V5.X (All versions < V5.10.1), RUGGEDCOM RS416v2 V5.X (All versions < V5.10.1), RUGGEDCOM RS900 (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RS900G (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RSG2100 (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RSG2100P (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RSG2288 V5.X (All versions < V5.10.1), RUGGEDCOM RSG2300 V5.X (All versions < V5.10.1), RUGGEDCOM RSG2300P V5.X (All versions < V5.10.1), RUGGEDCOM RSG2488 V5.X (All versions < V5.10.1), RUGGEDCOM RSG907R (All versions < V5.10.1), RUGGEDCOM RSG908C (All versions < V5.10.1), RUGGEDCOM RSG909R (All versions < V5.10.1), RUGGEDCOM RSG910C (All versions < V5.10.1), RUGGEDCOM RSG920P V5.X (All versions < V5.10.1), RUGGEDCOM RSL910 (All versions < V5.10.1), RUGGEDCOM RST2228 (All versions < V5.10.1), RUGGEDCOM RST2228P (All versions < V5.10.1), RUGGEDCOM RST916C (All versions < V5.10.1), RUGGEDCOM RST916P (All versions < V5.10.1). Affected devices do not properly validate input during the TLS certificate upload process of the web service. This could allow an authenticated remote attacker to trigger a device crash and reboot, leading to a temporary Denial of Service on the device.
Inadequate Pod Communication Restrictions, affects watsonx.data
HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption
HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module
WordPress Plant - Gardening & Houseplants WordPress Theme <= 1.0.0 - Sensitive Data Exposure Vulnerability
Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application
AuntyFey Smart Combination Lock BLE Connection Flood DoS
cld378632668 JavaMall MinioController.java delete path traversal
cld378632668 JavaMall MinioController.java upload unrestricted upload
Quanta Computer|QOCA aim AI Medical Cloud Platform - Path Traversal
Quanta Computer|QOCA aim AI Medical Cloud Platform - Path Traversal
h-moses moga-mall PmsProductController.java addProduct unrestricted upload
Backup Migration <= 2.0.0 - Missing Authorization to Unauthenticated Backup Upload to Offline Storage
Frontend Post Submission Manager Lite <= 1.2.6 - Incorrect Authorization to Unauthenticated Arbitrary Attachment Deletion
Cost Calculator Builder <= 4.0.1 - Unauthenticated Price Manipulation and Insecure Direct Object Reference
IBM® Db2® is vulnerable to a denial of service when fetching from certain tables under specific configurations
PixelYourSite <= 11.1.5 - Sensitive Information Exposure via Log File
ilGhera Support System for WooCommerce <= 1.3.0 - Missing Authorization to Unauthenticated Sensitive Information Exposure
Broadstreet <= 1.53.1 - Authenticated (Subscriber+) Information Disclosure
On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption o
Information disclosure via IDOR in Asseco AMDX
Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI
Improper Input Validation
Incorrect authorization in Browser in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)
Information leak in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)
Security Advisory 0186
Security Advisory 0186
HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed
HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions
Reflected Cross-Site Scripting (XSS) in Eventobot
AutoGPT has missing Docker log rotation on platform containers that allows host disk-exhaustion DoS
NGSurvey Enterprise 3.6.4 incorrect authorization exposes other users’ API keys and personal data
NetVision Information|ISOinsight - Reflected Cross-site Scripting
Incorrect authorization in Fudo Enterprise
DLL Hijacking in EfficientLab Controlio Leads to Local Privilege Escalation
Improper Access Control in Asseco Infomedica Plus
GOautodial 4.0 - Persistent Cross-Site Scripting
Backstage: Sensitive information disclosure in Kubernetes resource queries
Pulp-rpm: distribution tree publish creates directories from .treeinfo ids
Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions
WordPress e2pdf plugin <= 1.28.15 - Broken Access Control vulnerability
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unrelated access) via a shared_servers endpoint.
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrelated access) via clients.plex.tv/devices.xml.
WordPress Tablesome plugin <= 1.1.35.1 - Sensitive Data Exposure vulnerability
Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation
Backstage: Secret-derived values may be exposed in scaffolder task logs
Kiteworks Core Improper Validation of Specified Quantity in Input
InvenTree has Path Traversal In Report Templates
WordPress WordPress Image shrinker plugin <= 1.1.0 - Server Side Request Forgery (SSRF) vulnerability
WordPress Link Library plugin <= 7.8.7 - Server Side Request Forgery (SSRF) vulnerability
WordPress Prime Slider – Addons For Elementor plugin <= 4.0.10 - Server Side Request Forgery (SSRF) vulnerability
Craft CMS vulnerable to potential information disclosure via unchecked asset relocation
HCL DevOps Deploy is susceptible to insufficiently protected credentials
WordPress External Media plugin <= 1.0.36 - Server Side Request Forgery (SSRF) vulnerability
JFrog Artifactory Cross-Site Scripting
Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that contain sensitive information and infer a value from API responses. If the attacker has super admin access, then this can be exploited to discover the password hash and password reset token of all users. If the attacker has admin panel access to an account with permission to access the username and email of API users with a lower privileged role (e.g., Editor or Author), then this can be exploited to discover sensitive information for all API users but not other admin accounts.
Backstage: Inconsistent credential enforcement for overlapping proxy routes
Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)
Apache YuniKorn: Admission control bypass via system label forgery
wger: API credentials remain valid after logout/password change
Multiple vulnerabilities have been addressed in IBM Aspera Shares
This vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script in the browser of a portal user who opens a crafted link.
Priority - CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Priority - CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Priority - CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials
PX4 PX4-Autopilot mavlink_log_handler.cpp log_entry_from_id stack-based overflow
Libnbd: libnbd: arbitrary code execution via ssh argument injection through a malicious uri
Improper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking App
Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates
Sssd: sssd: denial of service via race condition in autofs responder
WordPress Accept Donations with PayPal plugin <= 1.5.2 - Open Redirection vulnerability
WordPress User Submitted Posts plugin <= 20251121 - Open Redirection vulnerability
Kiteworks Core user impersonation in a file-request feature
HCL BigFix Service Management (SM) is affected by use of a vulnerable component
Hardcoded User Password
HCL BigFix Service Management (SM) does not adequately sanitize or safely render
Backstage: Improper input validation in cloud storage URL readers
Confused deputy in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions into a privileged page via a co-installed app. (Chromium security severity: Medium)
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
WordPress PopAd Plugin <= 1.0.4 - Server Side Request Forgery (SSRF) Vulnerability
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service.
Page Keys <= 1.3.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'page_key' Parameter
Simple User Meta Editor <= 1.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via User Meta Value Field
twinklesmtp – Email Service Provider For WordPress <= 1.03 - Authenticated (Administrator+) Stored Cross-Site Scripting via Sender Settings
Key Figures <= 1.1 - Authenticated (Admin+) Stored Cross-Site Scripting via kf_field_figure_default_color_render
Improper input validation in NETGEAR Nighthawk routers
Broadstreet <= 1.53.1 - Authenticated (Admin+) Stored Cross-Site Scripting
Backstage: Incorrect authorization in search engine permission filtering
Backstage: Inconsistent catalog property permission evaluation
Backstage: Incorrect authorization in scaffolder task listing
Twisted: IMAP wildcardToRegexp() ReDoS
Information leak in Enterprise in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Incorrect authorization in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Incomplete cleanup in Glic in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Information leak in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Incorrect provision of specified functionality in SanitizerAPI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Uninitialized resource in Skia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Improper resource exposure in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Observable discrepancy in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Integer overflow in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Information leak in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Incorrect reference resolution in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Information leak in Editing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Incorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)
Uninitialized resource in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Uninitialized resource in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Yaad Sarig Payment Gateway For WC < 2.2.13 - Subscriber+ Arbitrary Order Payment Manipulation via IDOR
WordPress Booktics plugin <= 1.0.27 - Broken Access Control vulnerability
Academy LMS < 4.0.0 - Subscriber+ Cross-Course Quiz Answer Disclosure via render_quiz_answers
Academy LMS < 4.0.0 - Subscriber+ Arbitrary Lesson Content Disclosure via Topic REST Endpoint
Frontend Dashboard < 3.0.0 - Subscriber+ Profile and Post Field Deletion via fed_user_profile_delete
WordPress Hustle plugin <= 7.8.14.2 - Broken Access Control vulnerability
Missing Authorization in Kibana Leading to Information Disclosure
Inefficient Regular Expression Complexity in Elasticsearch Leading to Denial of Service
Kiteworks Core Incorrect Authorization
Kiteworks Core content injection
User Private Files < 2.1.9 - Subscriber+ User Email Address Disclosure via dpk_upvf_rmv_access
Gitea private repository access retained after rejected transfer
Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS
Langflow OSS is affected by multiple vulnerabilities
Rubygem-katello: improper authorization logic allows resource enumeration
Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service
WordPress Post Expirator plugin <= 4.9.3 - Broken Access Control vulnerability
WordPress Better Business Reviews plugin <= 0.1.1 - Broken Access Control vulnerability
WordPress The Events Calendar Countdown Addon plugin <= 1.4.15 - Broken Access Control vulnerability
WordPress AffiliateX plugin <= 1.3.9.3 - Broken Access Control vulnerability
WordPress Oneline Lite theme <= 6.6 - Broken Access Control vulnerability
WordPress Ultimate Store Kit Elementor Addons plugin <= 2.9.4 - Broken Access Control vulnerability
WordPress JetEngine plugin <= 3.8.1.1 - Broken Access Control vulnerability
WordPress Theater for WordPress plugin <= 0.19 - Broken Access Control vulnerability
WordPress Car Rental Manager plugin <= 1.0.9 - Broken Access Control vulnerability
In plane.io, a Guest User to a Workspace can still be able to see list of members
LibreChat has Insufficient Access Control for Agent Permission Queries
Hemmelig has SSRF Filter bypass in Secret Request functionality
WordPress Demo Importer Plus plugin <= 2.0.8 - Broken Access Control vulnerability
WordPress PopupKit plugin <= 2.1.5 - Sensitive Data Exposure vulnerability
WordPress Poptics plugin <= 1.0.20 - Sensitive Data Exposure vulnerability
WordPress Discussion Board plugin <= 2.5.7 - Broken Access Control vulnerability
WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.22 - Broken Access Control vulnerability
WordPress Stratum plugin <= 1.6.1 - Broken Access Control vulnerability
WordPress Event Organiser plugin <= 3.12.8 - Broken Access Control vulnerability
WordPress My Sticky Elements plugin <= 2.3.3 - Broken Access Control vulnerability
WordPress Contact Form 7 Extension For Mailchimp plugin <= 0.9.68 - Sensitive Data Exposure vulnerability
WordPress Eagle Booking plugin <= 1.3.4.3 - Insecure Direct Object References (IDOR) vulnerability
WordPress WP Adminify plugin <= 4.0.6.1 - Broken Access Control vulnerability
WordPress TS Poll plugin <= 2.5.5 - Broken Access Control vulnerability
WordPress Watu Quiz plugin <= 3.4.5 - Broken Access Control vulnerability
WordPress Vimeotheque plugin <= 2.3.5.2 - Cross Site Request Forgery (CSRF) vulnerability
WordPress Fast User Switching plugin <= 1.4.10 - Cross Site Request Forgery (CSRF) vulnerability
WordPress Advanced Classifieds & Directory Pro plugin <= 3.2.9 - Cross Site Request Forgery (CSRF) vulnerability
WordPress Sunshine Photo Cart plugin <= 3.5.7.1 - Broken Access Control vulnerability
WordPress WP Email Capture plugin <= 3.12.5 - Cross Site Request Forgery (CSRF) vulnerability
WordPress Spiffy Calendar plugin <= 5.0.7 - Broken Access Control vulnerability
WordPress JetPopup plugin <= 2.0.20.1 - Insecure Direct Object References (IDOR) vulnerability
WordPress Trade Runner plugin <= 3.14 - Cross Site Request Forgery (CSRF) vulnerability
WordPress Eight Day Week Print Workflow plugin <= 1.2.5 - Sensitive Data Exposure vulnerability
HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels.
WordPress ACF Galerie 4 plugin <= 1.4.2 - Broken Access Control vulnerability
Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use something else like FTS tika. No publicly available exploits are known.
WordPress Avada theme < 7.13.2 - Cross Site Request Forgery (CSRF) vulnerability
WordPress Userpro plugin < 5.1.11 - Cross Site Request Forgery (CSRF) vulnerability
WordPress Thim Core Plugin <= 2.3.3 - Cross Site Request Forgery (CSRF) Vulnerability
In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.
Authenticated Denial-of-Service via SSH
WordPress AnyWhere Elementor Pro plugin <= 2.29 - Broken Access Control Vulnerability
WordPress Smart Online Order for Clover plugin <= 1.6.0 - Cross Site Request Forgery (CSRF) vulnerability
Latest Tabs <= 1.5 - Cross-Site Request Forgery to Plugin's Settings Update
Newsletter Email Subscribe <= 2.4 - Cross-Site Request Forgery to Plugin Settings Update
NS IE Compatibility Fixer <= 2.1.5 - Cross-Site Request Forgery to Plugin Settings Update
Client-Side Enforcement of Server-Side Security in IBM Db2 Intelligence Center
HubSpot All-In-One Marketing - Forms, Popups, Live Chat <= 11.3.32 - Missing Authorization to Authenticated (Contributor+) Installed Plugin Disclosure
Broadstreet <= 1.53.1 - Missing Authorization to Authenticated (Subscriber+) Advertiser Creation
Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion
Multicollab: Content Team Collaboration and Editorial Workflow <= 5.2 - Missing Authorization to Authenticated (Subscriber+) Collaboration Comment
In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation.
Race condition in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Incorrect authorization in WebShare in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Use of released resource in Session in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Use of released resource in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Incorrect authorization in Unbounded Element in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Incomplete cleanup in GetUserMedia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Improper input validation in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
PowerPress 11.13.12 - 11.17.9 - Contributor+ SSRF via Media URL Redirects
This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it.
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service.
Insufficient DPA countermeasure reseeding
Sssd: sssd: denial of service in nss responder via crafted zero-length requests
HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only
WordPress Crowdsignal Forms plugin <= 1.7.2 - Broken Access Control vulnerability
Incorrect Execution-Assigned Permissions in IBM Aspera Faspex
In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is contraindicated by the arXiv 2609.07709 "Crossing the Streams" findings.
yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability
HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header
HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header
HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directl
HCL BigFix Service Management (SM) is susceptible to HTTP Request Smuggling
In sshd in OpenSSH before 10.6, the value "none" for a configuration option is sometimes interpreted as a filename but was intended to mean that a feature is disabled.
Backstage: Unsupported catalog cluster authentication mode in kubernetes backend
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images.
FlexTable Google Sheets Connector < 3.19.2 - Admin+ Stored XSS
In returnOutputBufferLocked of DeprecatedCamera3StreamSplitter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. An app may be able to identify what other apps a user has installed.
In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss of sandboxing, which is potentially unexpected.
Backstage: Inconsistent enforcement of allowed location types during catalog processing
Use of released resource in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Observable discrepancy in Scroll in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)
Observable discrepancy in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability
HCL DFXAnalytics is affected by an Improper Error Handling vulnerability
A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.
Exposure of Sensitive System Information to an Unauthorized Control Sphere in IBM Aspera Faspex
Backstage: Cloud storage catalog locations may cross configured storage boundaries
HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication
M17n-lib: null dereference in minput_open_im() after failed m17n_init()
In sshd in OpenSSH through 10.6, in certain environments such as QNX 6 and SCO OpenServer 5, sshd-session can unexpectedly have root privileges. This is related to the GatewayPorts and StreamLocalForwarding configuration options, and lack of support for file-descriptor passing and unprivileged allocation of PTY devices.
Internal Filesystem Exploration vulnerability
HCL BigFix IVR is impacted by improper authentication and missing CSRF protection
TaleLin Lin-CMS Tests Folder config.py password in configuration file
PandaXGO PandaX JWT Secret config.yml hard-coded key
actiontech sqle JWT Secret jwt.go hard-coded key
getmaxun auth.ts hard-coded key
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing malicious data may lead to unexpected app termination.
CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update
WordPress WP Document Revisions plugin <= 3.7.2 - Broken Access Control vulnerability
Multiple vulnerabilities have been addressed in IBM Aspera Shares
HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability
Senstive information disclosure was affecting ubuntu-desktop-provision
Senstive information disclosure was affecting subiquity
HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters.
HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields.
HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified.
HCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability.
In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a different vulnerability than CVE-2026-73283.
In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling. There can be a slightly more severe effect on users in certain Antarctic locations.
In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command-line username, leading to injection.
Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 Race Condition Restores Revoked Group Membership
Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS
Security Advisory 0196
HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured
Dromara Sa-Token SaJdkSerializer.java ObjectInputStream.readObject deserialization
In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts.
In sshd in OpenSSH before 10.6, credentials can incorrectly persist after failure of a GSSAPIAuthentication authentication attempt.
HCL BigFix IVR is impacted by an improper service binding configuration
XnView Classic FLI File heap-based overflow
Apache YuniKorn: LDAP Group provider panics on lowercase attribute name
sfturing hosp_order orderHos findOrderHosNum sql injection
EmpireSoft EmpireCMS connect.php CheckSaveTranFiletype unrestricted upload
PHPGurukul Online Course Registration authorization
campcodes School File Management System save_file.php unrestricted upload
aizuda snail-job API FurySerializer.deserialize deserialization
SohuTV CacheCloud LoginController.java init cross site scripting
code-projects Student File Management System File Download download.php improper authorization
code-projects Refugee Food Management System regfood.php sql injection
code-projects Refugee Food Management System refugee.php sql injection
code-projects Refugee Food Management System editrefugee.php sql injection
code-projects Refugee Food Management System editfood.php sql injection
code-projects Student File Management System download.php sql injection
code-projects College Notes Uploading System userprofile.php unrestricted upload
D-Link DWR-M920 formLtefotaUpgradeQuectel sub_415328 command injection
D-Link DWR-M920 formLtefotaUpgradeFibocom sub_4155B4 command injection
Advaya Softech GEMS ERP Portal Error Message home.jsp cross site scripting
omec-project UPF PFCP Session Establishment Request messages_session.go handleSessionEstablishmentRequest null pointer dereference
dayrui XunRuiCMS JSONP Callback Init.php dr_exit_msg cross site scripting
TRENDnet TEW-822DRE formWsc sub_43ACF4 command injection
joey-zhou xiaozhi-esp32-server-java Cookie AuthenticationInterceptor.java tryAuthenticateWithCookies improper authentication
ZSPACE Z4Pro+ HTTP POST Request close zfilev2_api_CloseSafe command injection
ZSPACE Z4Pro+ HTTP POST Request open zfilev2_api_open command injection
ZSPACE Z4Pro+ HTTP POST Request status zfilev2_api_SafeStatus command injection
ChenJinchuang Lin-CMS-TP5 File Upload LocalUploader.php upload code injection
macrozheng mall Member Endpoint update improper authorization
getmaxun Authentication Endpoint auth.ts router.get improper authorization
sunkaifei FlyCMS User Login UserController.java userLogin cross site scripting
sunkaifei FlyCMS Admin Login IndexAdminController.java cross site scripting
ketr JEPaaS loadPostil postilService.loadPostils sql injection
youlaitech youlai-mall OrderController.java submitOrderPayment improper authorization
youlaitech youlai-mall MemberController.java getMemberByMobile access control
youlaitech youlai-mall Balance MemberController.java deductBalance improper authorization
JD Cloud BE6500 jdcapi sub_4780 command injection
Apache YuniKorn: Admission control bypass via workload UPDATE operation
HCL BigFix IVR is impacted by an insufficient session expiration vulnerability
1Panel-dev MaxKB MdPreview chat.ts cross site scripting
xnx3 wangmarket XML File uploadImage.do uploadImage unrestricted upload
go-sonic Theme Fetching API git_fetcher.go FetchTheme server-side request forgery
D-Link DCS-850L Firmware Update Service uploadfirmware path traversal
CloudPanel Community Edition HTTP Header users redirect
SohuTV CacheCloud AppDataMigrateController.java index cross site scripting
SohuTV CacheCloud MachineManageController.java doPodList cross site scripting
SohuTV CacheCloud WebResourceController.java redirectNoPower cross site scripting
code-projects/anirbandutta9 Content Management System/News-Buzz editposts.php unrestricted upload
SohuTV CacheCloud AppController.java appCommandAnalysis cross site scripting
SohuTV CacheCloud AppManageController.java doAppAuditList cross site scripting
SohuTV CacheCloud InstanceController.java advancedAnalysis cross site scripting
SohuTV CacheCloud RedisConfigTemplateController.java preview cross site scripting
SohuTV CacheCloud ServerController.java index cross site scripting
BiggiDroid Simple PHP CMS editsite.php sql injection
prasathmani TinyFileManager tinyfilemanager.php path traversal
yourmaileyes MOOC Submission MainController.java subreview cross site scripting
shanyu SyCms Administrative Panel FileManageController.class.php addPost code injection
jackq XCMS Backend ProductImageController.class.php upload unrestricted upload
xnx3 wangmarket Backend Variable Search variableList.do variableList cross site scripting
xnx3 wangmarket System Variables variableSave.do cross site scripting
xnx3 wangmarket Add Global Variable save.do cross site scripting
WebAssembly wabt wasm-decompile VarName out-of-bounds
WebAssembly wabt wasm-decompile InsertNode memory corruption
Campcodes Park Ticketing System admin_class.php save_pricing cross site scripting
SohuTV CacheCloud QuartzManageController.java doQuartzList cross site scripting
SohuTV CacheCloud ResourceController.java index cross site scripting
SohuTV CacheCloud TaskController.java taskQueueList cross site scripting
SohuTV CacheCloud AppClientDataShowController.java doIndex cross site scripting
Campcodes Complete Online Beauty Parlor Management System search-invoices.php cross site scripting
floooh sokol sokol_gfx.h _sg_pipeline_desc_defaults stack-based overflow
rawchen ecms Add New Product updateProductServlet.java updateProductServlet cross site scripting
SohuTV CacheCloud UserManageController.java doUserList cross site scripting
SohuTV CacheCloud TotalManageController.java doTotalList cross site scripting
PhonePe App SQLite Database databases cleartext storage in file
zhanglun lettura RSS ContentRender.tsx cross site scripting
Dromara Sa-Token SaSerializerTemplateForJdkUseBase64.java ObjectInputStream.readObject deserialization
youlaitech youlai-mall Order Payment OrderController.java orderService.payOrder access control
Grafana Alerting Editors can edit destination of webhooks they did not create
QTS, QuTS hero
QTS, QuTS hero
TOZED ZLT M30s UART on-chip debug and test interface with improper access control
CVE-2026-107202
CVE-2026-106550
CVE-2026-106511
Gitea issue attachment API allows changing comment attachments
Gitea tag delete route deletes releases without release permission
Gitea SSRF through Git HTTP redirects in mirrors and fetches
Gitea migration memory exhaustion from zero page size
Gitea fork workflow approval bypass through cancel and rerun
Gitea fork workflow job revival through later approval
Gitea trusted workflow cancellation by unapproved fork runs
Gitea container registry stored XSS through blob media type
Gitea API team demotion not applied to unit permissions
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.
Gitea migration and pull mirror SSRF through multi-answer DNS
Gitea OAuth2 refresh token grant accepts access tokens
tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()
mm/hugetlb: preserve mremap address delta when skipping page tables
ALSA: core: Fix potential UAF after asynchronous card release
drm/amdkfd: Avoid integer underflow in EOP ring size calculation.
drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc
Apache Impala: Impala Executor Webserver Auth Bypass
Gitea profile feed disclosure bypassing user visibility
Gitea push mirror API bypass of DISABLE_NEW_PUSH policy
Gitea repository media API stored XSS
Gitea Actions memory exhaustion through large static matrices
Gitea denial of service through external issue tracker patterns
Gitea issue reference parsing CPU exhaustion
Gitea review and execution mismatch through duplicate tree entries
Gitea fork workflow approval bypass through maintainer-triggered events
Apache Impala: Stored XSS in Impala query plans
Apache Impala: Path traversal executes JARs outside trusted paths
Gitea push mirror SSRF and forced writes to internal Git hosts
An issue in iTerm2 macOS before 3.6.12 allows a local attacker to obtain sensitive information.
Gitea push mirror local path check uses the repository owner
Sssd: sssd-kcm: local denial of service via excessive memory preallocation
Gitea WebAuthn bypass during OAuth and OIDC sign-in
Gitea repository migration SSRF through DNS rebinding
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by creating a file in a specially crafted directory.
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by reading the special crafted file metadata.
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a directory, e.g., by creating a file.
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a directory, e.g., by creating a file.
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in cat() in ntfscat.c that allows an attacker to corrupt heap memory in the ntfscat binary by crafting a malicious NTFS image. The overflow is triggered by reading a file.
The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.
The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system.
The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests.
The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component.
The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system.
The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.
The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests.
The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component.
ESF-IDF Has Out-of-Bounds Read in ESP32 Bluetooth SDP Result Handling
Chamilo LMS has validation-less redirect on login page
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none