| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-93765 | Cri | 0.59 | 9.1 | 0.00 | Sep 18, 2026 | Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the… | ||
| CVE-2026-85497 | Cri | 0.64 | 9.8 | 0.00 | Sep 18, 2026 | CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may… | ||
| CVE-2026-81321 | Cri | 0.64 | 9.8 | 0.00 | Sep 18, 2026 | CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerability could recover the configured network identifier and… | ||
| CVE-2026-77240 | Cri | 0.57 | 9.9 | 0.00 | Sep 18, 2026 | WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security policy in supabase/migrations/017_account_sharing.sql permits authenticated users to modify their own account_role and account_id, allowing a viewer to… | ||
| CVE-2026-84383 | Cri | 0.57 | 9.8 | 0.01 | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_channel_from_image_as() append duplicate Alpha planes with different bit depths… | ||
| CVE-2026-75031 | Cri | 0.57 | 9.8 | 0.01 | Sep 18, 2026 | In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code… | ||
| CVE-2026-61682 | Cri | 0.57 | 9.9 | 0.00 | Sep 18, 2026 | kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* identity headers before forwarding requests… | ||
| CVE-2026-10858 | Cri | 0.64 | 9.9 | 0.00 | Sep 18, 2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages. | ||
| CVE-2026-10747 | Cri | 0.65 | 10.0 | 0.01 | Sep 18, 2026 | IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication. | ||
| CVE-2025-53837 | Cri | 0.57 | 9.9 | 0.01 | Sep 18, 2026 | XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary… | ||
| CVE-2025-15399 | Cri | 0.65 | 10.0 | 0.00 | Sep 18, 2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | ||
| CVE-2026-93606 | Cri | 0.58 | 10.0 | 0.01 | Sep 18, 2026 | vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCallback / normalizeHostPromiseCallbacks… | ||
| CVE-2026-93605 | Cri | 0.58 | 10.0 | 0.00 | Sep 18, 2026 | vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is… | ||
| CVE-2026-93603 | Cri | 0.58 | 10.0 | 0.00 | Sep 18, 2026 | vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver — e.g. `fn()`, a detached method,… | ||
| CVE-2026-93019 | Cri | 0.52 | 9.1 | 0.01 | Sep 18, 2026 | Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts… | ||
| CVE-2026-13684 | Cri | 0.64 | 9.8 | 0.00 | Sep 18, 2026 | An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks. | ||
| CVE-2026-13639 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2026 | An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks. | ||
| CVE-2026-67101 | Cri | 0.60 | 9.3 | 0.00 | Sep 18, 2026 | HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet. | ||
| CVE-2026-67100 | Cri | 0.64 | 9.8 | 0.00 | Sep 18, 2026 | HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain… | ||
| CVE-2026-84738 | Cri | 0.59 | 9.1 | 0.01 | Sep 18, 2026 | The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote Code Execution. | ||
| CVE-2026-93467 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2026 | The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content. | ||
| CVE-2026-85878 | Cri | 0.64 | 9.9 | 0.01 | Sep 18, 2026 | Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-69843 | Cri | 0.65 | 10.0 | 0.01 | Sep 18, 2026 | Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-62874 | Cri | 0.65 | 10.0 | 0.00 | Sep 18, 2026 | Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-87701 | Cri | 0.62 | 9.6 | 0.00 | Sep 17, 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-85889 | Cri | 0.65 | 10.0 | 0.00 | Sep 17, 2026 | Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-85885 | Cri | 0.64 | 9.9 | 0.01 | Sep 17, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-83944 | Cri | 0.65 | 10.0 | 0.00 | Sep 17, 2026 | Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-77903 | Cri | 0.59 | 9.0 | 0.00 | Sep 17, 2026 | Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-70200 | Cri | 0.65 | 10.0 | 0.01 | Sep 17, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-70009 | Cri | 0.60 | 9.3 | 0.00 | Sep 17, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-69865 | Cri | 0.65 | 10.0 | 0.00 | Sep 17, 2026 | Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-69399 | Cri | 0.65 | 10.0 | 0.00 | Sep 17, 2026 | Azure Arc Elevation of Privilege Vulnerability | ||
| CVE-2026-76949 | Cri | 0.52 | — | 0.00 | Sep 17, 2026 | Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated session with one for the attacker's own account. … | ||
| CVE-2026-73639 | Cri | 0.52 | 9.1 | 0.00 | Sep 17, 2026 | Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8. With a tRNS chunk, read_direct8() adds an alpha channel to the image it creates but still sizes the row buffer from the… | ||
| CVE-2026-54767 | Cri | 0.52 | 9.1 | 0.00 | Sep 17, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded in the public source… | ||
| CVE-2026-54734 | Cri | 0.58 | 10.0 | 0.00 | Sep 17, 2026 | Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious actor who can supply bid-request… | ||
| CVE-2026-54670 | Cri | 0.52 | 9.1 | 0.01 | Sep 17, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and method allowlist, exempts sensitive… | ||
| CVE-2026-93374 | Cri | 0.62 | 9.6 | 0.00 | Sep 17, 2026 | Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2026-93373 | Cri | 0.62 | 9.6 | 0.00 | Sep 17, 2026 | Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High) | ||
| CVE-2026-93372 | Cri | 0.62 | 9.6 | 0.00 | Sep 17, 2026 | Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2026-54501 | Cri | 0.54 | — | 0.01 | Sep 17, 2026 | Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom Behaviors, allowing command injection… | ||
| CVE-2026-54460 | Cri | 0.57 | 9.8 | 0.01 | Sep 17, 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passkeys accepts a request-body userId and attacker-supplied passkey without an authenticated session, does not call… | ||
| CVE-2026-54237 | Cri | 0.53 | — | 0.01 | Sep 17, 2026 | Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanitized input reaches write_config() and… | ||
| CVE-2026-45143 | Cri | 0.52 | 9.0 | 0.00 | Sep 17, 2026 | Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server-side sanitization and renders it as HTML in assets/vue/views/message/MessageShow.vue and public/main/template/default/message/vie… | ||
| CVE-2026-45140 | Cri | 0.57 | 9.8 | 0.01 | Sep 17, 2026 | Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, component, input, or exploitation… | ||
| CVE-2025-55787 | Cri | 0.64 | 9.8 | 0.00 | Sep 17, 2026 | In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists. | ||
| CVE-2026-54752 | Cri | 0.55 | 9.6 | 0.00 | Sep 17, 2026 | NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_data function in… | ||
| CVE-2026-54627 | Cri | 0.57 | 9.8 | 0.00 | Sep 17, 2026 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap color mode to… | ||
| CVE-2026-54626 | Cri | 0.57 | 9.8 | 0.01 | Sep 17, 2026 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_INDEXED_RLE path selected by image_type == 9 allocates an image buffer using the one-byte-per-pixel… |
- risk 0.59cvss 9.1epss 0.00
Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the…
- risk 0.64cvss 9.8epss 0.00
CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may…
- risk 0.64cvss 9.8epss 0.00
CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerability could recover the configured network identifier and…
- risk 0.57cvss 9.9epss 0.00
WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security policy in supabase/migrations/017_account_sharing.sql permits authenticated users to modify their own account_role and account_id, allowing a viewer to…
- risk 0.57cvss 9.8epss 0.01
libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_channel_from_image_as() append duplicate Alpha planes with different bit depths…
- risk 0.57cvss 9.8epss 0.01
In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code…
- risk 0.57cvss 9.9epss 0.00
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* identity headers before forwarding requests…
- risk 0.64cvss 9.9epss 0.00
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
- risk 0.65cvss 10.0epss 0.01
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
- risk 0.57cvss 9.9epss 0.01
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary…
- risk 0.65cvss 10.0epss 0.00
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
- risk 0.58cvss 10.0epss 0.01
vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCallback / normalizeHostPromiseCallbacks…
- risk 0.58cvss 10.0epss 0.00
vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is…
- risk 0.58cvss 10.0epss 0.00
vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver — e.g. `fn()`, a detached method,…
- risk 0.52cvss 9.1epss 0.01
Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts…
- risk 0.64cvss 9.8epss 0.00
An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
- risk 0.64cvss 9.8epss 0.01
An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
- risk 0.60cvss 9.3epss 0.00
HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet.
- risk 0.64cvss 9.8epss 0.00
HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain…
- risk 0.59cvss 9.1epss 0.01
The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote Code Execution.
- risk 0.64cvss 9.8epss 0.01
The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
- risk 0.64cvss 9.9epss 0.01
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.00
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
- risk 0.62cvss 9.6epss 0.00
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.00
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.9epss 0.01
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.00
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
- risk 0.59cvss 9.0epss 0.00
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
- risk 0.60cvss 9.3epss 0.00
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.00
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.00
Azure Arc Elevation of Privilege Vulnerability
- risk 0.52cvss —epss 0.00
Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated session with one for the attacker's own account. …
- risk 0.52cvss 9.1epss 0.00
Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8. With a tRNS chunk, read_direct8() adds an alpha channel to the image it creates but still sizes the row buffer from the…
- risk 0.52cvss 9.1epss 0.00
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded in the public source…
- risk 0.58cvss 10.0epss 0.00
Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious actor who can supply bid-request…
- risk 0.52cvss 9.1epss 0.01
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and method allowlist, exempts sensitive…
- risk 0.62cvss 9.6epss 0.00
Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.62cvss 9.6epss 0.00
Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)
- risk 0.62cvss 9.6epss 0.00
Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.54cvss —epss 0.01
Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom Behaviors, allowing command injection…
- risk 0.57cvss 9.8epss 0.01
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passkeys accepts a request-body userId and attacker-supplied passkey without an authenticated session, does not call…
- risk 0.53cvss —epss 0.01
Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanitized input reaches write_config() and…
- risk 0.52cvss 9.0epss 0.00
Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server-side sanitization and renders it as HTML in assets/vue/views/message/MessageShow.vue and public/main/template/default/message/vie…
- risk 0.57cvss 9.8epss 0.01
Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, component, input, or exploitation…
- risk 0.64cvss 9.8epss 0.00
In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists.
- risk 0.55cvss 9.6epss 0.00
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_data function in…
- risk 0.57cvss 9.8epss 0.00
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap color mode to…
- risk 0.57cvss 9.8epss 0.01
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_INDEXED_RLE path selected by image_type == 9 allocates an image buffer using the one-byte-per-pixel…