| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-19760 | Hig | 0.47 | 7.2 | 0.00 | Aug 26, 2026 | The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTTP Host Header in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for… | ||
| CVE-2026-19718 | Hig | 0.53 | 8.1 | 0.00 | Aug 26, 2026 | The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a… | ||
| CVE-2026-19226 | Med | 0.44 | 6.8 | 0.00 | Aug 26, 2026 | The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputting them inside an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks. | ||
| CVE-2026-19220 | Low | 0.24 | 3.7 | 0.00 | Aug 26, 2026 | The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated visitors to create a new site on a WordPress multisite network and gain administrator privileges on it. | ||
| CVE-2026-19094 | Med | 0.34 | 5.3 | 0.00 | Aug 26, 2026 | The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database query, and does not restrict which template file a request may load, allowing unauthenticated users to inject SQL and to read question and answer content belonging to courses that are… | ||
| CVE-2026-16986 | Med | 0.34 | 5.3 | 0.00 | Aug 26, 2026 | The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied request values instead, so an unauthenticated attacker can pay an arbitrary fraction of a… | ||
| CVE-2026-16984 | Med | 0.42 | 6.5 | 0.00 | Aug 26, 2026 | The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress plugin before 3.7.1 does not include an authorization check on a REST route that returns stored account data, allowing unauthenticated visitors to retrieve the connected… | ||
| CVE-2026-15203 | Cri | 0.60 | — | 0.00 | Aug 26, 2026 | Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via… | ||
| CVE-2026-14550 | Med | 0.34 | 5.3 | 0.00 | Aug 26, 2026 | The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through its REST API, verifying only a publicly available nonce, allowing unauthenticated users to submit reservations with an arbitrary approval status and bypass the… | ||
| CVE-2026-14216 | Med | 0.42 | 6.5 | 0.00 | Aug 26, 2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks. | ||
| CVE-2026-14212 | Med | 0.31 | 4.7 | 0.00 | Aug 26, 2026 | The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password… | ||
| CVE-2026-13406 | Med | 0.34 | 5.3 | 0.00 | Aug 26, 2026 | The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before returning taxonomy term data for an arbitrary, caller-supplied taxonomy, allowing unauthenticated users to disclose the names and IDs of terms belonging to… | ||
| CVE-2026-13404 | Med | 0.34 | 5.3 | 0.00 | Aug 26, 2026 | The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated… | ||
| CVE-2026-13172 | Med | 0.34 | 5.3 | 0.00 | Aug 26, 2026 | The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and private posts belonging to other users, along with the passwords… | ||
| CVE-2026-9805 | Low | 0.18 | 2.7 | 0.00 | Aug 26, 2026 | SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size and could cause buffer overflow. | ||
| CVE-2026-80214 | Hig | 0.49 | — | 0.01 | Aug 26, 2026 | LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated admin user can execute arbitrary code on the host server. | ||
| CVE-2026-80202 | Hig | 0.50 | 8.8 | 0.00 | Aug 26, 2026 | Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. As a result, any authenticated user with ROLE_TEAMLEAD (or a role holding edit_other_timesheet/delete_other_timesheet… | ||
| CVE-2026-80201 | Low | 0.06 | 2.0 | 0.00 | Aug 26, 2026 | Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with template creation permissions can embed these method calls in invoice templates to leak hashed API… | ||
| CVE-2026-80200 | Med | 0.24 | 4.7 | 0.00 | Aug 26, 2026 | Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with IdP access can supply malicious RelayState values to redirect authenticated users… | ||
| CVE-2026-80199 | Low | 0.17 | 3.7 | 0.00 | Aug 26, 2026 | Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response time differences when the password hasher runs only for existing users,… | ||
| CVE-2026-80198 | Hig | 0.42 | 7.5 | 0.00 | Aug 26, 2026 | Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers with admin privileges can upload malicious templates to exfiltrate server-wide secrets… | ||
| CVE-2026-80197 | Med | 0.21 | 4.3 | 0.00 | Aug 26, 2026 | Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that allows authenticated users to manipulate other users' bookmarks. Attackers can add or remove timesheet entries from another user's favorite list by… | ||
| CVE-2026-80196 | Hig | 0.42 | 7.5 | 0.01 | Aug 26, 2026 | Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLink signature covers only the user id, not the password hash. Attackers who intercept or cache a password reset link can use it up… | ||
| CVE-2026-80195 | Med | 0.28 | 5.4 | 0.00 | Aug 26, 2026 | Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members before validating the submitted replacement member list. An authenticated teamlead (or other… | ||
| CVE-2026-80194 | Med | 0.21 | 4.3 | 0.00 | Aug 26, 2026 | Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_project_view_export). The authorization guards are attached to the sibling __invoke method rather than at the class level, so the export route inherits no… | ||
| CVE-2026-80193 | Hig | 0.50 | 8.8 | 0.00 | Aug 26, 2026 | Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members by submitting the… | ||
| CVE-2026-80192 | Hig | 0.46 | 8.1 | 0.00 | Aug 26, 2026 | @better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws. When domain verification is disabled, automatic organization assignment accepts unverified provider domains, allowing an… | ||
| CVE-2026-80191 | Hig | 0.42 | 7.5 | 0.00 | Aug 26, 2026 | GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated user. retrieveAttachmentFromIdParam in apps/app/src/server/routes/attachment/get.ts guards the check with a condition requiring the user to be non-null, so a… | ||
| CVE-2026-80189 | Med | 0.35 | 6.5 | 0.01 | Aug 26, 2026 | LeafWiki extracts an uploaded ZIP archive without limiting how much data it will write. ZipExtractor.ExtractToDir in internal/importer/zip_extractor.go opens each entry and copies it to the destination with io.Copy, which runs to the end of the decompressed stream, so only the… | ||
| CVE-2026-76149 | Med | 0.22 | 4.4 | 0.00 | Aug 26, 2026 | CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file. | ||
| CVE-2026-76148 | Hig | 0.44 | 7.8 | 0.00 | Aug 26, 2026 | CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product. | ||
| CVE-2026-73335 | Med | 0.34 | 5.3 | 0.00 | Aug 26, 2026 | Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, potentially allowing… | ||
| CVE-2026-58092 | Hig | 0.46 | 8.1 | 0.00 | Aug 26, 2026 | In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID is stored in a dedicated field. This… | ||
| CVE-2026-58091 | Hig | 0.51 | 7.8 | 0.00 | Aug 26, 2026 | The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would block, it releases the sync group list lock and sleeps. Upon reawakening, it is possible that the sync group structure is freed, but the implementation did… | ||
| CVE-2026-58090 | Hig | 0.51 | 7.8 | 0.00 | Aug 26, 2026 | The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unprivileged local user… | ||
| CVE-2026-58089 | Hig | 0.51 | 7.8 | 0.00 | Aug 26, 2026 | When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly. An unprivileged local user who has attached PMCs to a process can… | ||
| CVE-2026-57171 | Hig | 0.43 | 7.7 | 0.00 | Aug 26, 2026 | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author commands write generated Markdown to an… | ||
| CVE-2026-57170 | Hig | 0.44 | 7.8 | 0.00 | Aug 26, 2026 | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an included Markdown… | ||
| CVE-2026-54467 | Hig | 0.46 | 7.0 | 0.00 | Aug 26, 2026 | On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer. | ||
| CVE-2026-52776 | Hig | 0.49 | — | 0.00 | Aug 26, 2026 | Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's remote-fetch paths against server-side request forgery can be bypassed to reach… | ||
| CVE-2026-29988 | Hig | 0.49 | 7.6 | 0.00 | Aug 26, 2026 | A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D… | ||
| CVE-2026-19632 | Cri | 0.57 | 9.8 | 0.09 | Aug 26, 2026 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated… | ||
| CVE-2026-74749 | mod | 0.29 | 5.5 | 0.00 | Aug 26, 2026 | kernel: rseq: Prevent hard lockup on granted time slice extension | ||
| CVE-2026-80529 | mod | 0.29 | 5.5 | 0.00 | Aug 26, 2026 | kernel: xfs: don't swallow dquot recovery verification errors | ||
| CVE-2026-80532 | low | 0.29 | 5.5 | 0.00 | Aug 26, 2026 | kernel: xfs: fix another iunlink infinite loop bug in online fsck | ||
| CVE-2026-80533 | low | 0.29 | 5.5 | 0.00 | Aug 26, 2026 | kernel: xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair | ||
| CVE-2026-80535 | low | 0.29 | 5.5 | 0.00 | Aug 26, 2026 | kernel: xfs: don't double-lock when deleting a self-referential directory | ||
| CVE-2026-80138 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary… | ||
| CVE-2026-79912 | Hig | 0.54 | 8.3 | 0.02 | Aug 25, 2026 | A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely.… | ||
| CVE-2026-79911 | Cri | 0.65 | 10.0 | 0.01 | Aug 25, 2026 | A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer… |
- risk 0.47cvss 7.2epss 0.00
The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTTP Host Header in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for…
- risk 0.53cvss 8.1epss 0.00
The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a…
- risk 0.44cvss 6.8epss 0.00
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputting them inside an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
- risk 0.24cvss 3.7epss 0.00
The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated visitors to create a new site on a WordPress multisite network and gain administrator privileges on it.
- risk 0.34cvss 5.3epss 0.00
The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database query, and does not restrict which template file a request may load, allowing unauthenticated users to inject SQL and to read question and answer content belonging to courses that are…
- risk 0.34cvss 5.3epss 0.00
The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied request values instead, so an unauthenticated attacker can pay an arbitrary fraction of a…
- risk 0.42cvss 6.5epss 0.00
The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress plugin before 3.7.1 does not include an authorization check on a REST route that returns stored account data, allowing unauthenticated visitors to retrieve the connected…
- risk 0.60cvss —epss 0.00
Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via…
- risk 0.34cvss 5.3epss 0.00
The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through its REST API, verifying only a publicly available nonce, allowing unauthenticated users to submit reservations with an arbitrary approval status and bypass the…
- risk 0.42cvss 6.5epss 0.00
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.
- risk 0.31cvss 4.7epss 0.00
The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password…
- risk 0.34cvss 5.3epss 0.00
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before returning taxonomy term data for an arbitrary, caller-supplied taxonomy, allowing unauthenticated users to disclose the names and IDs of terms belonging to…
- risk 0.34cvss 5.3epss 0.00
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated…
- risk 0.34cvss 5.3epss 0.00
The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and private posts belonging to other users, along with the passwords…
- risk 0.18cvss 2.7epss 0.00
SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size and could cause buffer overflow.
- risk 0.49cvss —epss 0.01
LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated admin user can execute arbitrary code on the host server.
- risk 0.50cvss 8.8epss 0.00
Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. As a result, any authenticated user with ROLE_TEAMLEAD (or a role holding edit_other_timesheet/delete_other_timesheet…
- risk 0.06cvss 2.0epss 0.00
Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with template creation permissions can embed these method calls in invoice templates to leak hashed API…
- risk 0.24cvss 4.7epss 0.00
Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with IdP access can supply malicious RelayState values to redirect authenticated users…
- risk 0.17cvss 3.7epss 0.00
Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response time differences when the password hasher runs only for existing users,…
- risk 0.42cvss 7.5epss 0.00
Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers with admin privileges can upload malicious templates to exfiltrate server-wide secrets…
- risk 0.21cvss 4.3epss 0.00
Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that allows authenticated users to manipulate other users' bookmarks. Attackers can add or remove timesheet entries from another user's favorite list by…
- risk 0.42cvss 7.5epss 0.01
Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLink signature covers only the user id, not the password hash. Attackers who intercept or cache a password reset link can use it up…
- risk 0.28cvss 5.4epss 0.00
Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members before validating the submitted replacement member list. An authenticated teamlead (or other…
- risk 0.21cvss 4.3epss 0.00
Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_project_view_export). The authorization guards are attached to the sibling __invoke method rather than at the class level, so the export route inherits no…
- risk 0.50cvss 8.8epss 0.00
Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members by submitting the…
- risk 0.46cvss 8.1epss 0.00
@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws. When domain verification is disabled, automatic organization assignment accepts unverified provider domains, allowing an…
- risk 0.42cvss 7.5epss 0.00
GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated user. retrieveAttachmentFromIdParam in apps/app/src/server/routes/attachment/get.ts guards the check with a condition requiring the user to be non-null, so a…
- risk 0.35cvss 6.5epss 0.01
LeafWiki extracts an uploaded ZIP archive without limiting how much data it will write. ZipExtractor.ExtractToDir in internal/importer/zip_extractor.go opens each entry and copies it to the destination with io.Copy, which runs to the end of the decompressed stream, so only the…
- risk 0.22cvss 4.4epss 0.00
CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file.
- risk 0.44cvss 7.8epss 0.00
CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product.
- risk 0.34cvss 5.3epss 0.00
Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, potentially allowing…
- risk 0.46cvss 8.1epss 0.00
In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID is stored in a dedicated field. This…
- risk 0.51cvss 7.8epss 0.00
The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would block, it releases the sync group list lock and sleeps. Upon reawakening, it is possible that the sync group structure is freed, but the implementation did…
- risk 0.51cvss 7.8epss 0.00
The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unprivileged local user…
- risk 0.51cvss 7.8epss 0.00
When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly. An unprivileged local user who has attached PMCs to a process can…
- risk 0.43cvss 7.7epss 0.00
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author commands write generated Markdown to an…
- risk 0.44cvss 7.8epss 0.00
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an included Markdown…
- risk 0.46cvss 7.0epss 0.00
On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.
- risk 0.49cvss —epss 0.00
Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's remote-fetch paths against server-side request forgery can be bypassed to reach…
- risk 0.49cvss 7.6epss 0.00
A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D…
- risk 0.57cvss 9.8epss 0.09
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated…
- risk 0.29cvss 5.5epss 0.00
kernel: rseq: Prevent hard lockup on granted time slice extension
- risk 0.29cvss 5.5epss 0.00
kernel: xfs: don't swallow dquot recovery verification errors
- risk 0.29cvss 5.5epss 0.00
kernel: xfs: fix another iunlink infinite loop bug in online fsck
- risk 0.29cvss 5.5epss 0.00
kernel: xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair
- risk 0.29cvss 5.5epss 0.00
kernel: xfs: don't double-lock when deleting a self-referential directory
- risk 0.57cvss 9.8epss 0.01
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary…
- risk 0.54cvss 8.3epss 0.02
A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely.…
- risk 0.65cvss 10.0epss 0.01
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer…