| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-72858 | — | 0.00 | — | — | Aug 20, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||
| CVE-2026-72848 | Hig | 0.56 | 8.6 | 0.01 | Aug 20, 2026 | SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sitemap elements passes the child… | ||
| CVE-2026-72846 | Med | 0.35 | 6.4 | 0.00 | Aug 20, 2026 | Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsClient.ts. In affected versions both call… | ||
| CVE-2026-72843 | Cri | 0.57 | 9.8 | 0.01 | Aug 20, 2026 | The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller, and no customer-session middleware… | ||
| CVE-2026-72818 | Hig | 0.42 | 7.5 | 0.01 | Aug 20, 2026 | The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label… | ||
| CVE-2026-70105 | Med | 0.42 | 6.5 | 0.01 | Aug 20, 2026 | Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-69855 | Hig | 0.50 | 7.7 | 0.01 | Aug 20, 2026 | Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-69851 | Cri | 0.64 | 9.9 | 0.01 | Aug 20, 2026 | Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-69836 | Cri | 0.65 | 10.0 | 0.02 | Aug 20, 2026 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69558 | Hig | 0.56 | 8.6 | 0.01 | Aug 20, 2026 | Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-69555 | Cri | 0.65 | 10.0 | 0.01 | Aug 20, 2026 | Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-69543 | Hig | 0.55 | 8.5 | 0.01 | Aug 20, 2026 | Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-69519 | Hig | 0.56 | 8.6 | 0.01 | Aug 20, 2026 | Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-69419 | Hig | 0.55 | 8.5 | 0.01 | Aug 20, 2026 | Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network. | ||
| CVE-2026-69400 | Cri | 0.62 | 9.6 | 0.01 | Aug 20, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-68789 | Cri | 0.64 | 9.9 | 0.01 | Aug 20, 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-68782 | Cri | 0.64 | 9.9 | 0.01 | Aug 20, 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-67448 | Med | 0.35 | 6.5 | 0.00 | Aug 20, 2026 | Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go's ServeMux routes using the percent-decoded URL path, and server/websockets/client.go… | ||
| CVE-2026-67447 | Med | 0.27 | 5.3 | 0.01 | Aug 20, 2026 | Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's internal/smtpd/smtpd.go readData() function calls bufio.Reader.ReadBytes before applying the len(data)+len(line) size check to the completed SMTP DATA line against Server.MaxSize. An… | ||
| CVE-2026-66800 | Hig | 0.56 | 8.6 | 0.01 | Aug 20, 2026 | Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-66309 | Cri | 0.59 | 9.1 | 0.01 | Aug 20, 2026 | Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-65816 | Cri | 0.65 | 10.0 | 0.01 | Aug 20, 2026 | Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-65801 | Cri | 0.65 | 10.0 | 0.01 | Aug 20, 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-65770 | Cri | 0.65 | 10.0 | 0.01 | Aug 20, 2026 | Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-64773 | Hig | 0.49 | 7.5 | 0.00 | Aug 20, 2026 | An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no cap on how much accumulates… | ||
| CVE-2026-63509 | Cri | 0.64 | 9.9 | 0.01 | Aug 20, 2026 | Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-62945 | Med | 0.21 | 4.3 | 0.00 | Aug 20, 2026 | TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-controlled reservation_id, place_id, and assignment_id values without using findForeignLinkTarget() to verify that the referenced object belongs to the file's trip.… | ||
| CVE-2026-62834 | Cri | 0.60 | 9.3 | 0.01 | Aug 20, 2026 | Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-55894 | Med | 0.37 | — | 0.00 | Aug 20, 2026 | Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it is within the active mode-specific decode[] function-pointer table. An… | ||
| CVE-2026-55893 | Hig | 0.40 | — | 0.00 | Aug 20, 2026 | Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without checking the fixed-size operands[] array. Repeated… | ||
| CVE-2026-55769 | Cri | 0.54 | — | 0.01 | Aug 20, 2026 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in fillDefaultParameters in pkg/management/postgres/pool/profiles.go. A role… | ||
| CVE-2026-55765 | Hig | 0.48 | 8.5 | 0.01 | Aug 20, 2026 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUserPassword in… | ||
| CVE-2026-55491 | Med | 0.35 | 5.4 | 0.00 | Aug 20, 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/playback/index.html.erb when generating the screenshare playback format. A low-privileged user could store a crafted meeting name… | ||
| CVE-2026-55489 | Med | 0.32 | 4.9 | 0.00 | Aug 20, 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could submit a presentationId through /api/graphql that identified a presentation belonging to another meeting. akka-bbb-apps/src/main/scala/org/bigbluebutton/core/apps/presentationpod/Re… | ||
| CVE-2026-55015 | Med | 0.36 | 5.5 | 0.01 | Aug 20, 2026 | Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally. | ||
| CVE-2026-55013 | Hig | 0.46 | 7.1 | 0.00 | Aug 20, 2026 | Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally. | ||
| CVE-2026-54509 | Med | 0.42 | 6.5 | 0.00 | Aug 20, 2026 | TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src/routes/journey.ts returns the result of getJourneyShareLink() from server/src/services/journeyShareService.ts without checking whether the authenticated… | ||
| CVE-2026-54508 | Med | 0.34 | — | 0.00 | Aug 20, 2026 | TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before native redirect following in importGoogleList() and importNaverList() in server/src/services/placeService.ts and resolveGoogleMapsUrl() in server/src/services/mapsService.ts. The… | ||
| CVE-2026-54505 | Low | 0.13 | — | 0.01 | Aug 20, 2026 | TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK interpolates the unescaped activeSuggestion.title value into journey.frontpage.suggestionText through client/src/i18n/TranslationContext.tsx and renders the result with… | ||
| CVE-2026-54389 | Med | 0.36 | 5.5 | 0.00 | Aug 20, 2026 | Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser that allows attackers to terminate the Ghidra process by supplying a crafted PDB file with an oversized parameters section. The AbstractPdb deserialization routine reads all… | ||
| CVE-2026-50192 | Med | 0.38 | — | 0.00 | Aug 20, 2026 | Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKey` request headers to the operator-configured Hub… | ||
| CVE-2026-49436 | Hig | 0.47 | 7.3 | 0.00 | Aug 20, 2026 | LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format validation, allowing an authenticated user to store a `javascript:` URI. The stored URI is later rendered… | ||
| CVE-2026-49245 | Low | 0.17 | 3.7 | 0.00 | Aug 20, 2026 | SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment, allowing an attacker-controlled HTML file stored… | ||
| CVE-2026-49244 | Med | 0.31 | 5.9 | 0.00 | Aug 20, 2026 | SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a browsable share validates client-supplied files entries with a raw byte-prefix comparison rather than a directory-boundary-aware… | ||
| CVE-2026-49217 | Hig | 0.49 | 7.5 | 0.00 | Aug 20, 2026 | Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comment field from any existing user token provided… | ||
| CVE-2026-46682 | Hig | 0.55 | 8.5 | 0.01 | Aug 20, 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers in akka-bbb-apps/src/main/scala/org/bigbluebutton/core/db/BreakoutR… | ||
| CVE-2026-46355 | Hig | 0.46 | 7.1 | 0.00 | Aug 20, 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy. A requester able to supply an… | ||
| CVE-2026-19783 | Med | 0.44 | 6.7 | 0.00 | Aug 20, 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted filesystem image can trigger an out-of-bounds kernel-stack write during directory reads, causing a system crash or potentially… | ||
| CVE-2026-19449 | Hig | 0.57 | 8.8 | 0.00 | Aug 20, 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root. | ||
| CVE-2026-19448 | Med | 0.42 | 6.5 | 0.00 | Aug 20, 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, resulting in denial of service. |
- CVE-2026-72858Aug 20, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- risk 0.56cvss 8.6epss 0.01
SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sitemap elements passes the child…
- risk 0.35cvss 6.4epss 0.00
Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsClient.ts. In affected versions both call…
- risk 0.57cvss 9.8epss 0.01
The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller, and no customer-session middleware…
- risk 0.42cvss 7.5epss 0.01
The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label…
- risk 0.42cvss 6.5epss 0.01
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
- risk 0.50cvss 7.7epss 0.01
Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.
- risk 0.64cvss 9.9epss 0.01
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.02
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
- risk 0.56cvss 8.6epss 0.01
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
- risk 0.65cvss 10.0epss 0.01
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- risk 0.55cvss 8.5epss 0.01
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
- risk 0.56cvss 8.6epss 0.01
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
- risk 0.55cvss 8.5epss 0.01
Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.
- risk 0.62cvss 9.6epss 0.01
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.9epss 0.01
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.9epss 0.01
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
- risk 0.35cvss 6.5epss 0.00
Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go's ServeMux routes using the percent-decoded URL path, and server/websockets/client.go…
- risk 0.27cvss 5.3epss 0.01
Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's internal/smtpd/smtpd.go readData() function calls bufio.Reader.ReadBytes before applying the len(data)+len(line) size check to the completed SMTP DATA line against Server.MaxSize. An…
- risk 0.56cvss 8.6epss 0.01
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
- risk 0.59cvss 9.1epss 0.01
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.00
An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no cap on how much accumulates…
- risk 0.64cvss 9.9epss 0.01
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
- risk 0.21cvss 4.3epss 0.00
TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-controlled reservation_id, place_id, and assignment_id values without using findForeignLinkTarget() to verify that the referenced object belongs to the file's trip.…
- risk 0.60cvss 9.3epss 0.01
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
- risk 0.37cvss —epss 0.00
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it is within the active mode-specific decode[] function-pointer table. An…
- risk 0.40cvss —epss 0.00
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without checking the fixed-size operands[] array. Repeated…
- risk 0.54cvss —epss 0.01
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in fillDefaultParameters in pkg/management/postgres/pool/profiles.go. A role…
- risk 0.48cvss 8.5epss 0.01
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUserPassword in…
- risk 0.35cvss 5.4epss 0.00
BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/playback/index.html.erb when generating the screenshare playback format. A low-privileged user could store a crafted meeting name…
- risk 0.32cvss 4.9epss 0.00
BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could submit a presentationId through /api/graphql that identified a presentation belonging to another meeting. akka-bbb-apps/src/main/scala/org/bigbluebutton/core/apps/presentationpod/Re…
- risk 0.36cvss 5.5epss 0.01
Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.
- risk 0.46cvss 7.1epss 0.00
Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.
- risk 0.42cvss 6.5epss 0.00
TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src/routes/journey.ts returns the result of getJourneyShareLink() from server/src/services/journeyShareService.ts without checking whether the authenticated…
- risk 0.34cvss —epss 0.00
TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before native redirect following in importGoogleList() and importNaverList() in server/src/services/placeService.ts and resolveGoogleMapsUrl() in server/src/services/mapsService.ts. The…
- risk 0.13cvss —epss 0.01
TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK interpolates the unescaped activeSuggestion.title value into journey.frontpage.suggestionText through client/src/i18n/TranslationContext.tsx and renders the result with…
- risk 0.36cvss 5.5epss 0.00
Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser that allows attackers to terminate the Ghidra process by supplying a crafted PDB file with an oversized parameters section. The AbstractPdb deserialization routine reads all…
- risk 0.38cvss —epss 0.00
Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKey` request headers to the operator-configured Hub…
- risk 0.47cvss 7.3epss 0.00
LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format validation, allowing an authenticated user to store a `javascript:` URI. The stored URI is later rendered…
- risk 0.17cvss 3.7epss 0.00
SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment, allowing an attacker-controlled HTML file stored…
- risk 0.31cvss 5.9epss 0.00
SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a browsable share validates client-supplied files entries with a raw byte-prefix comparison rather than a directory-boundary-aware…
- risk 0.49cvss 7.5epss 0.00
Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comment field from any existing user token provided…
- risk 0.55cvss 8.5epss 0.01
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers in akka-bbb-apps/src/main/scala/org/bigbluebutton/core/db/BreakoutR…
- risk 0.46cvss 7.1epss 0.00
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy. A requester able to supply an…
- risk 0.44cvss 6.7epss 0.00
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted filesystem image can trigger an out-of-bounds kernel-stack write during directory reads, causing a system crash or potentially…
- risk 0.57cvss 8.8epss 0.00
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root.
- risk 0.42cvss 6.5epss 0.00
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, resulting in denial of service.