| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-82795 | Med | 0.35 | 5.4 | 0.00 | Sep 14, 2026 | SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | ||
| CVE-2026-82794 | Hig | 0.57 | 8.8 | 0.01 | Sep 14, 2026 | SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | ||
| CVE-2026-82793 | Hig | 0.47 | 7.2 | 0.00 | Sep 14, 2026 | Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product. | ||
| CVE-2026-82792 | Med | 0.34 | 5.2 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2026-82791 | Hig | 0.57 | 8.8 | 0.01 | Sep 14, 2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in… | ||
| CVE-2026-82790 | Med | 0.35 | 5.4 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2026-82789 | Hig | 0.57 | 8.8 | 0.00 | Sep 14, 2026 | An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product. | ||
| CVE-2026-82788 | Med | 0.40 | 6.1 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2026-82787 | Cri | 0.64 | 9.8 | 0.00 | Sep 14, 2026 | Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication. | ||
| CVE-2026-82786 | Med | 0.41 | 6.3 | 0.00 | Sep 14, 2026 | Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulnerability is exploited, sensitive information may be restored from a backup file. | ||
| CVE-2026-82785 | Med | 0.28 | 4.3 | 0.00 | Sep 14, 2026 | Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition. | ||
| CVE-2026-82784 | Med | 0.42 | 6.5 | 0.00 | Sep 14, 2026 | Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values and/or control the output. | ||
| CVE-2026-82783 | Med | 0.27 | 4.2 | 0.00 | Sep 14, 2026 | Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product may obtain credentials. | ||
| CVE-2026-82782 | Med | 0.28 | 4.3 | 0.00 | Sep 14, 2026 | Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition. | ||
| CVE-2026-82781 | Med | 0.35 | 5.4 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2026-82780 | Hig | 0.57 | 8.8 | 0.00 | Sep 14, 2026 | Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product. | ||
| CVE-2026-82779 | Hig | 0.57 | 8.8 | 0.01 | Sep 14, 2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | ||
| CVE-2026-82778 | Med | 0.28 | 4.3 | 0.00 | Sep 14, 2026 | An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication. | ||
| CVE-2026-82777 | Hig | 0.57 | 8.8 | 0.01 | Sep 14, 2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | ||
| CVE-2026-82776 | Med | 0.40 | 6.1 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2026-82775 | Med | 0.28 | 4.3 | 0.00 | Sep 14, 2026 | An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication. | ||
| CVE-2026-82774 | Hig | 0.57 | 8.8 | 0.01 | Sep 14, 2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in… | ||
| CVE-2026-82773 | Med | 0.40 | 6.1 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2026-82772 | Hig | 0.57 | 8.8 | 0.00 | Sep 14, 2026 | Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed. | ||
| CVE-2026-82771 | Med | 0.35 | 5.4 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2026-82770 | Hig | 0.57 | 8.8 | 0.00 | Sep 14, 2026 | Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed. | ||
| CVE-2026-82769 | Med | 0.35 | 5.4 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2026-82768 | Hig | 0.53 | 8.1 | 0.00 | Sep 14, 2026 | Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP. | ||
| CVE-2026-82767 | Med | 0.34 | 5.2 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2026-82766 | Hig | 0.57 | 8.8 | 0.01 | Sep 14, 2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | ||
| CVE-2026-82765 | Hig | 0.53 | 8.1 | 0.00 | Sep 14, 2026 | Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP. | ||
| CVE-2026-82764 | Med | 0.28 | 4.3 | 0.00 | Sep 14, 2026 | Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed. | ||
| CVE-2026-82763 | Med | 0.35 | 5.4 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2026-82762 | Hig | 0.57 | 8.8 | 0.01 | Sep 14, 2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the… | ||
| CVE-2026-71198 | Hig | 0.45 | — | 0.00 | Sep 14, 2026 | In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply the import_filtering_opts host restrictions. An… | ||
| CVE-2026-68955 | Hig | 0.51 | 7.8 | 0.00 | Sep 14, 2026 | The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the… | ||
| CVE-2026-25832 | Low | 0.17 | 3.7 | 0.00 | Sep 14, 2026 | In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group. | ||
| CVE-2025-26790 | Low | 0.24 | 3.7 | 0.00 | Sep 14, 2026 | Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine. | ||
| CVE-2024-23176 | Med | 0.28 | 5.4 | 0.00 | Sep 14, 2026 | An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS. | ||
| CVE-2023-51769 | Med | 0.33 | 6.1 | 0.00 | Sep 14, 2026 | Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages. | ||
| CVE-2023-50462 | Med | 0.34 | 5.3 | 0.00 | Sep 14, 2026 | An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier is permitted by the plugin. This enables an unauthenticated user to display various content elements, leading… | ||
| CVE-2023-50461 | Hig | 0.57 | 8.8 | 0.00 | Sep 14, 2026 | An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead… | ||
| CVE-2023-50460 | Med | 0.35 | 5.4 | 0.00 | Sep 14, 2026 | An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system. | ||
| CVE-2023-50459 | Med | 0.35 | 5.4 | 0.00 | Sep 14, 2026 | An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts. | ||
| CVE-2026-90687 | Med | 0.34 | 6.3 | 0.00 | Sep 14, 2026 | A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes use after free. It is possible to initiate the attack remotely. The… | ||
| CVE-2026-90686 | Med | 0.27 | 5.3 | 0.01 | Sep 14, 2026 | A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. The attack may be performed from remote. The exploit has been made public and… | ||
| CVE-2026-90685 | Low | 0.11 | 2.8 | 0.00 | Sep 14, 2026 | A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit… | ||
| CVE-2026-16726 | Med | 0.44 | — | 0.00 | Sep 14, 2026 | Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows attackers to stop Windows. | ||
| CVE-2023-46273 | Hig | 0.57 | 8.8 | 0.00 | Sep 14, 2026 | Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send. | ||
| CVE-2023-46035 | Med | 0.31 | 5.9 | 0.00 | Sep 14, 2026 | The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents. |
- risk 0.35cvss 5.4epss 0.00
SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
- risk 0.57cvss 8.8epss 0.01
SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
- risk 0.47cvss 7.2epss 0.00
Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product.
- risk 0.34cvss 5.2epss 0.00
Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in…
- risk 0.35cvss 5.4epss 0.00
Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.57cvss 8.8epss 0.00
An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.
- risk 0.40cvss 6.1epss 0.00
Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.64cvss 9.8epss 0.00
Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.
- risk 0.41cvss 6.3epss 0.00
Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulnerability is exploited, sensitive information may be restored from a backup file.
- risk 0.28cvss 4.3epss 0.00
Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.
- risk 0.42cvss 6.5epss 0.00
Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values and/or control the output.
- risk 0.27cvss 4.2epss 0.00
Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product may obtain credentials.
- risk 0.28cvss 4.3epss 0.00
Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.
- risk 0.35cvss 5.4epss 0.00
Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.57cvss 8.8epss 0.00
Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
- risk 0.28cvss 4.3epss 0.00
An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
- risk 0.40cvss 6.1epss 0.00
Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.28cvss 4.3epss 0.00
An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in…
- risk 0.40cvss 6.1epss 0.00
Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.57cvss 8.8epss 0.00
Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.
- risk 0.35cvss 5.4epss 0.00
Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.57cvss 8.8epss 0.00
Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.
- risk 0.35cvss 5.4epss 0.00
Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.53cvss 8.1epss 0.00
Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.
- risk 0.34cvss 5.2epss 0.00
Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
- risk 0.53cvss 8.1epss 0.00
Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.
- risk 0.28cvss 4.3epss 0.00
Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed.
- risk 0.35cvss 5.4epss 0.00
Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the…
- risk 0.45cvss —epss 0.00
In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply the import_filtering_opts host restrictions. An…
- risk 0.51cvss 7.8epss 0.00
The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the…
- risk 0.17cvss 3.7epss 0.00
In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.
- risk 0.24cvss 3.7epss 0.00
Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine.
- risk 0.28cvss 5.4epss 0.00
An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.
- risk 0.33cvss 6.1epss 0.00
Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier is permitted by the plugin. This enables an unauthenticated user to display various content elements, leading…
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead…
- risk 0.35cvss 5.4epss 0.00
An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system.
- risk 0.35cvss 5.4epss 0.00
An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts.
- risk 0.34cvss 6.3epss 0.00
A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes use after free. It is possible to initiate the attack remotely. The…
- risk 0.27cvss 5.3epss 0.01
A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. The attack may be performed from remote. The exploit has been made public and…
- risk 0.11cvss 2.8epss 0.00
A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit…
- risk 0.44cvss —epss 0.00
Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows attackers to stop Windows.
- risk 0.57cvss 8.8epss 0.00
Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.
- risk 0.31cvss 5.9epss 0.00
The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.