Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler i…
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in sr…
An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5.…
fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are affected by a schema validation bypass when a req…
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might…
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP…
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster ad…
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions t…
In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation i…
Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens.
The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to,…
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in s…
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/Hes…
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() a…
SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a rece…
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to u…
NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper i…
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.