| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-68860 | Med | 0.44 | 6.8 | 0.00 | Sep 3, 2026 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Launch of phishing attacks. | ||
| CVE-2026-3852 | Med | 0.42 | 6.4 | 0.00 | Sep 3, 2026 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the Social Media Follow module in all versions up to, and including, 4.27.6. This is due to a three-part sanitization failure: (1) the `skype_url` field is not… | ||
| CVE-2026-3416 | — | Med | 0.38 | 5.9 | 0.00 | Sep 3, 2026 | The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future… | |
| CVE-2026-2573 | Med | 0.35 | 6.4 | 0.00 | Sep 3, 2026 | The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘postBodyCss’ parameter in all versions up to, and including, 2.4.4 due to insufficient input sanitization and… | ||
| CVE-2026-17539 | Med | 0.38 | 5.9 | 0.00 | Sep 3, 2026 | RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This can cause a BCI_IEC104 fatal write error, resulting in connection interruption and… | ||
| CVE-2026-15933 | Med | 0.45 | — | 0.00 | Sep 3, 2026 | OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, including SMTP, FTP (for scan delivery), Active Directory (for user list import), and SharePoint credentials, in… | ||
| CVE-2026-15926 | — | 0.00 | — | — | Sep 3, 2026 | Rejected reason: Red Hat Product Security has determined that this CVE ID is not needed | ||
| CVE-2021-43614 | Med | 0.44 | 6.7 | 0.00 | Sep 3, 2026 | Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure. | ||
| CVE-2021-43613 | Med | 0.42 | 6.5 | 0.00 | Sep 3, 2026 | An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are exposed in runtime UEFI variables, leading to escalation of privilege | ||
| CVE-2021-38489 | Hig | 0.53 | 8.2 | 0.00 | Sep 3, 2026 | HDD password plaintext is stored in a UEFI variable. | ||
| CVE-2026-71223 | mod | 0.45 | 7.0 | — | Sep 3, 2026 | gfs2-utils: gfs2-utils: integer overflow in resource group allocation size on 32-bit platforms | ||
| CVE-2025-10478 | hig | 0.49 | 7.5 | — | Sep 3, 2026 | A denial-of-service security issue exists in the Rockwell Automation 1756-ENBT module which is a ControlLogix EtherNet/IP bridge that enables communication between Logix 5000 controllers and Ethernet devices. An attacker could exploit this vulnerability by sending a crafted CIP… | ||
| CVE-2026-77477 | med | 0.30 | 4.6 | — | Sep 3, 2026 | An attacker can intercept a high-privilege console window launched during installation of the LDS. The attacker must be able to launch an installer with elevated privileges and have access to the keyboard and display while the installation is taking place. | ||
| CVE-2026-84888 | Med | 0.28 | 4.3 | 0.00 | Sep 3, 2026 | A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. This vulnerability affects the function shell_exec of the file crates/openfang-runtime/src/tool_runner.rs. This manipulation causes uncontrolled memory allocation. The attack is possible to be carried out… | ||
| CVE-2026-84887 | Med | 0.28 | 4.3 | 0.01 | Sep 3, 2026 | A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affected by this issue is some unknown functionality of the file grounding.py of the component Model-generated GUI Action Execution Workflow. The manipulation leads to denial of service. Remote exploitation of the… | ||
| CVE-2026-84886 | Med | 0.34 | 5.3 | 0.01 | Sep 3, 2026 | A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the function ImageData of the file gui_agents/s1/utils/ocr_server.py of the component OCR HTTP API. Executing a manipulation of the argument img_bytes can lead to resource… | ||
| CVE-2026-84885 | Med | 0.28 | 4.3 | 0.00 | Sep 3, 2026 | A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts an unknown function of the file code_agent.py of the component CodeAgent. Such manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the… | ||
| CVE-2026-84851 | Hig | 0.42 | 7.5 | 0.01 | Sep 3, 2026 | An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service. | ||
| CVE-2026-84394 | Hig | 0.42 | 7.5 | 0.00 | Sep 3, 2026 | fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end with a closing bracket is neither validated as an IP literal nor canonicalized as a domain name, so parse()… | ||
| CVE-2026-66049 | — | 0.00 | — | — | Sep 3, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||
| CVE-2026-66048 | — | 0.00 | — | — | Sep 3, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||
| CVE-2026-85218 | imp | 0.46 | 7.1 | — | Sep 3, 2026 | bluez: bluez: AVRCP ListPlayerAttributes double stack overflow in avrcp_list_player_attributes_rsp/avrcp_get_current_player_value | ||
| CVE-2026-84923 | 0.00 | — | — | Sep 2, 2026 | Mentioned in Drupal. See https://www.drupal.org/security for vendor details. | |||
| CVE-2026-84924 | 0.00 | — | — | Sep 2, 2026 | Mentioned in Drupal. See https://www.drupal.org/security for vendor details. | |||
| CVE-2026-84916 | 0.00 | — | — | Sep 2, 2026 | Mentioned in Drupal. See https://www.drupal.org/security for vendor details. | |||
| CVE-2026-84917 | 0.00 | — | — | Sep 2, 2026 | Mentioned in Drupal. See https://www.drupal.org/security for vendor details. | |||
| CVE-2026-16648 | 0.00 | — | — | Sep 2, 2026 | Mentioned in Drupal. See https://www.drupal.org/security for vendor details. | |||
| CVE-2026-81163 | 0.00 | — | — | Sep 2, 2026 | Mentioned in Drupal. See https://www.drupal.org/security for vendor details. | |||
| CVE-2026-84918 | 0.00 | — | — | Sep 2, 2026 | Mentioned in Drupal. See https://www.drupal.org/security for vendor details. | |||
| CVE-2026-84919 | 0.00 | — | — | Sep 2, 2026 | Mentioned in Drupal. See https://www.drupal.org/security for vendor details. | |||
| CVE-2026-84920 | 0.00 | — | — | Sep 2, 2026 | Mentioned in Drupal. See https://www.drupal.org/security for vendor details. | |||
| CVE-2026-84921 | 0.00 | — | — | Sep 2, 2026 | Mentioned in Drupal. See https://www.drupal.org/security for vendor details. | |||
| CVE-2026-84857 | Med | 0.35 | 5.3 | 0.01 | Sep 2, 2026 | A flaw has been found in sigoden aichat up to 0.30.4. This affects an unknown function of the file src/serve.rs of the component API Endpoint. This manipulation causes uncontrolled memory allocation. The attack can be initiated remotely. The exploit has been published and may be… | ||
| CVE-2026-84856 | Med | 0.28 | 5.3 | 0.01 | Sep 2, 2026 | A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The impacted element is the function request.text/req.json of the file apps/rowboat/app/api/composio/webhook/route.ts of the component Composio Webhook Endpoint. The manipulation results in denial of service. It is… | ||
| CVE-2026-84852 | Med | 0.29 | 4.4 | 0.00 | Sep 2, 2026 | A security vulnerability has been detected in Reader Tools PDF Reader App 98.8 on Android. The affected element is the function ActSplashNew.handleDeeplink of the component File Handler. The manipulation of the argument _display_name leads to path traversal. An attack has to be… | ||
| CVE-2026-84452 | Hig | 0.49 | — | 0.02 | Sep 2, 2026 | Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI commands through a localhost HTTP API without authentication and configures the… | ||
| CVE-2026-84292 | Hig | 0.42 | 7.5 | 0.00 | Sep 2, 2026 | fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting… | ||
| CVE-2026-82524 | Hig | 0.40 | 7.2 | 0.01 | Sep 2, 2026 | UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint due to missing file extension and MIME type validation. Attackers can upload a PHP web shell… | ||
| CVE-2026-78662 | Hig | 0.42 | 7.5 | 0.00 | Sep 2, 2026 | Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such… | ||
| CVE-2026-75137 | Med | 0.40 | 6.1 | 0.00 | Sep 2, 2026 | UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover cleartext vault data from process memory even after the application has been locked. Attackers can use the PROCESS_VM_READ permission to read the memory… | ||
| CVE-2026-75136 | Med | 0.40 | 6.1 | 0.00 | Sep 2, 2026 | UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to retrieve the biometric unlock key stored in the Windows PasswordVault API without triggering any authentication prompt. Attackers can access the stored… | ||
| CVE-2026-75135 | Med | 0.40 | 6.1 | 0.00 | Sep 2, 2026 | UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by reading a retained backup key from the process memory of UpSignOn.exe, even after the vault has been… | ||
| CVE-2026-75134 | Med | 0.42 | 6.4 | 0.00 | Sep 2, 2026 | SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe… | ||
| CVE-2026-56855 | Hig | 0.42 | 7.5 | 0.01 | Sep 2, 2026 | Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and… | ||
| CVE-2023-20577 | Hig | 0.48 | 7.4 | 0.00 | Sep 2, 2026 | A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution. | ||
| CVE-2023-20576 | Hig | 0.50 | 7.7 | 0.00 | Sep 2, 2026 | Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation. | ||
| CVE-2026-84841 | Hig | 0.40 | 7.3 | 0.01 | Sep 2, 2026 | A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of server-side security. The attack can be launched remotely. The exploit has been released to the public and… | ||
| CVE-2026-84840 | Med | 0.35 | 6.5 | 0.01 | Sep 2, 2026 | A vulnerability was identified in tsi-coop tsi-dpdp-cms up to 0.5.0. This affects an unknown part of the file InterceptingFilter.java of the component Bootstrap Setup Endpoint. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is… | ||
| CVE-2026-84839 | Med | 0.27 | 5.3 | 0.01 | Sep 2, 2026 | A vulnerability was determined in tsi-coop tsi-dpdp-cms up to 0.5.0. Affected by this issue is some unknown functionality of the file web.xml of the component Admin Console/DPO Compliance Console. Executing a manipulation can lead to missing authentication. It is possible to… | ||
| CVE-2026-84382 | Hig | 0.42 | 7.5 | 0.01 | Sep 2, 2026 | HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bounded pieces to the application. A 64 KiB… |
- risk 0.44cvss 6.8epss 0.00
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Launch of phishing attacks.
- risk 0.42cvss 6.4epss 0.00
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the Social Media Follow module in all versions up to, and including, 4.27.6. This is due to a three-part sanitization failure: (1) the `skype_url` field is not…
- risk 0.38cvss 5.9epss 0.00
The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future…
- risk 0.35cvss 6.4epss 0.00
The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘postBodyCss’ parameter in all versions up to, and including, 2.4.4 due to insufficient input sanitization and…
- risk 0.38cvss 5.9epss 0.00
RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This can cause a BCI_IEC104 fatal write error, resulting in connection interruption and…
- risk 0.45cvss —epss 0.00
OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, including SMTP, FTP (for scan delivery), Active Directory (for user list import), and SharePoint credentials, in…
- CVE-2026-15926Sep 3, 2026risk 0.00cvss —epss —
Rejected reason: Red Hat Product Security has determined that this CVE ID is not needed
- risk 0.44cvss 6.7epss 0.00
Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure.
- risk 0.42cvss 6.5epss 0.00
An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are exposed in runtime UEFI variables, leading to escalation of privilege
- risk 0.53cvss 8.2epss 0.00
HDD password plaintext is stored in a UEFI variable.
- risk 0.45cvss 7.0epss —
gfs2-utils: gfs2-utils: integer overflow in resource group allocation size on 32-bit platforms
- risk 0.49cvss 7.5epss —
A denial-of-service security issue exists in the Rockwell Automation 1756-ENBT module which is a ControlLogix EtherNet/IP bridge that enables communication between Logix 5000 controllers and Ethernet devices. An attacker could exploit this vulnerability by sending a crafted CIP…
- risk 0.30cvss 4.6epss —
An attacker can intercept a high-privilege console window launched during installation of the LDS. The attacker must be able to launch an installer with elevated privileges and have access to the keyboard and display while the installation is taking place.
- risk 0.28cvss 4.3epss 0.00
A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. This vulnerability affects the function shell_exec of the file crates/openfang-runtime/src/tool_runner.rs. This manipulation causes uncontrolled memory allocation. The attack is possible to be carried out…
- risk 0.28cvss 4.3epss 0.01
A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affected by this issue is some unknown functionality of the file grounding.py of the component Model-generated GUI Action Execution Workflow. The manipulation leads to denial of service. Remote exploitation of the…
- risk 0.34cvss 5.3epss 0.01
A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the function ImageData of the file gui_agents/s1/utils/ocr_server.py of the component OCR HTTP API. Executing a manipulation of the argument img_bytes can lead to resource…
- risk 0.28cvss 4.3epss 0.00
A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts an unknown function of the file code_agent.py of the component CodeAgent. Such manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the…
- risk 0.42cvss 7.5epss 0.01
An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service.
- risk 0.42cvss 7.5epss 0.00
fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end with a closing bracket is neither validated as an IP literal nor canonicalized as a domain name, so parse()…
- CVE-2026-66049Sep 3, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- CVE-2026-66048Sep 3, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- risk 0.46cvss 7.1epss —
bluez: bluez: AVRCP ListPlayerAttributes double stack overflow in avrcp_list_player_attributes_rsp/avrcp_get_current_player_value
- CVE-2026-84923Sep 2, 2026risk 0.00cvss —epss —
Mentioned in Drupal. See https://www.drupal.org/security for vendor details.
- CVE-2026-84924Sep 2, 2026risk 0.00cvss —epss —
Mentioned in Drupal. See https://www.drupal.org/security for vendor details.
- CVE-2026-84916Sep 2, 2026risk 0.00cvss —epss —
Mentioned in Drupal. See https://www.drupal.org/security for vendor details.
- CVE-2026-84917Sep 2, 2026risk 0.00cvss —epss —
Mentioned in Drupal. See https://www.drupal.org/security for vendor details.
- CVE-2026-16648Sep 2, 2026risk 0.00cvss —epss —
Mentioned in Drupal. See https://www.drupal.org/security for vendor details.
- CVE-2026-81163Sep 2, 2026risk 0.00cvss —epss —
Mentioned in Drupal. See https://www.drupal.org/security for vendor details.
- CVE-2026-84918Sep 2, 2026risk 0.00cvss —epss —
Mentioned in Drupal. See https://www.drupal.org/security for vendor details.
- CVE-2026-84919Sep 2, 2026risk 0.00cvss —epss —
Mentioned in Drupal. See https://www.drupal.org/security for vendor details.
- CVE-2026-84920Sep 2, 2026risk 0.00cvss —epss —
Mentioned in Drupal. See https://www.drupal.org/security for vendor details.
- CVE-2026-84921Sep 2, 2026risk 0.00cvss —epss —
Mentioned in Drupal. See https://www.drupal.org/security for vendor details.
- risk 0.35cvss 5.3epss 0.01
A flaw has been found in sigoden aichat up to 0.30.4. This affects an unknown function of the file src/serve.rs of the component API Endpoint. This manipulation causes uncontrolled memory allocation. The attack can be initiated remotely. The exploit has been published and may be…
- risk 0.28cvss 5.3epss 0.01
A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The impacted element is the function request.text/req.json of the file apps/rowboat/app/api/composio/webhook/route.ts of the component Composio Webhook Endpoint. The manipulation results in denial of service. It is…
- risk 0.29cvss 4.4epss 0.00
A security vulnerability has been detected in Reader Tools PDF Reader App 98.8 on Android. The affected element is the function ActSplashNew.handleDeeplink of the component File Handler. The manipulation of the argument _display_name leads to path traversal. An attack has to be…
- risk 0.49cvss —epss 0.02
Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI commands through a localhost HTTP API without authentication and configures the…
- risk 0.42cvss 7.5epss 0.00
fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting…
- risk 0.40cvss 7.2epss 0.01
UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint due to missing file extension and MIME type validation. Attackers can upload a PHP web shell…
- risk 0.42cvss 7.5epss 0.00
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such…
- risk 0.40cvss 6.1epss 0.00
UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover cleartext vault data from process memory even after the application has been locked. Attackers can use the PROCESS_VM_READ permission to read the memory…
- risk 0.40cvss 6.1epss 0.00
UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to retrieve the biometric unlock key stored in the Windows PasswordVault API without triggering any authentication prompt. Attackers can access the stored…
- risk 0.40cvss 6.1epss 0.00
UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by reading a retained backup key from the process memory of UpSignOn.exe, even after the vault has been…
- risk 0.42cvss 6.4epss 0.00
SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe…
- risk 0.42cvss 7.5epss 0.01
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and…
- risk 0.48cvss 7.4epss 0.00
A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.
- risk 0.50cvss 7.7epss 0.00
Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation.
- risk 0.40cvss 7.3epss 0.01
A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of server-side security. The attack can be launched remotely. The exploit has been released to the public and…
- risk 0.35cvss 6.5epss 0.01
A vulnerability was identified in tsi-coop tsi-dpdp-cms up to 0.5.0. This affects an unknown part of the file InterceptingFilter.java of the component Bootstrap Setup Endpoint. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is…
- risk 0.27cvss 5.3epss 0.01
A vulnerability was determined in tsi-coop tsi-dpdp-cms up to 0.5.0. Affected by this issue is some unknown functionality of the file web.xml of the component Admin Console/DPO Compliance Console. Executing a manipulation can lead to missing authentication. It is possible to…
- risk 0.42cvss 7.5epss 0.01
HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bounded pieces to the application. A 64 KiB…