Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability
Microsoft Teams for Android Information Disclosure Vulnerability
An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service.
An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of spec…
An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper i…
An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.
In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This …
In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjac…
PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user can define a masking functio…
Numbas editor before 7.3 mishandles editing of themes and extensions.
Numbas editor before 7.3 mishandles reading of themes and extensions.
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.4. Processing malicious input may lead to code execu…
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma…
A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, mac…
JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution whe…
The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, an…
Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Insufficient validation of parameters in `Deno.makeTemp*` APIs would …
Transient DOS while processing CAG info IE received from NW.
Transient DOS while processing PDU Release command with a parameter PDU ID out of range.
Memory corruption in Core Services while executing the command for removing a single event listener.
In battery, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System e…
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additiona…
IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a denial of service due to incor…
Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad actors can send emails with …
Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a Improper Input Validation vulnerability. An unauthenticated…
The SE menu contains information used by Lexmark to diagnose device errors. A vulnerability in one of the SE menu routines can be leveraged by an att…
Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a differ…
Minder is a Software Supply Chain Security Platform. In version 0.0.31 and earlier, it is possible for an attacker to register a repository with a in…
pretix before 2024.1.1 mishandles file validation.
Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticate…