Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
.NET and Visual Studio Elevation of Privilege Vulnerability
GDI Elevation of Privilege Vulnerability
Windows GDI Elevation of Privilege Vulnerability
Sysinternals Process Monitor for Windows Denial of Service Vulnerability
schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with el…
Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-…
The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack…
Gradio is an open-source Python library that is used to build machine learning and data science. Due to a lack of path filtering Gradio does not prop…
The `Release PR Merged` workflow in the github repo taosdata/grafanaplugin is subject to a command injection vulnerability which allows for arbitrary…
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
Memoru corruption in Audio when ADSP sends input during record use case.
Avo is an open source ruby on rails admin panel creation framework. The polymorphic field type stores the classes to operate on when updating a recor…
libspdm is a sample implementation that follows the DMTF SPDM specifications. Prior to versions 2.3.3 and 3.0, following a successful CAPABILITIES re…
In Sprecher Automation SPRECON-E-C/P/T3 CPU in variant PU244x a vulnerable firmware verification has been identified. Through physical access and har…
mx-chain-go is an implementation of the MultiversX blockchain protocol written in the Go language. Metachain cannot process a cross-shard miniblock. …
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
At the most basic level, an invalid pointer can be input that crashes the device, but with more knowledge of the device’s memory layout, further expl…
An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection s…
Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to tr…
Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1.
socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol. A specially crafted Socket.…
parse-server-push-adapter is the official Push Notification adapter for Parse Server. The Parse Server Push Adapter can crash Parse Server due to an …
CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have been discovered in Ckan which ma…
Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install …
InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute jav…
XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy St…
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3…
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the san…
IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 through FW1020.30, and FW1030.00 …