| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service. |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection.
This issue affects Booktics: from n/a through 1.0.22. |
| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. |
| Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
| Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally. |
| Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
| Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |
| basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that are forwarded to enabled upstream write or management endpoints, such as creating an Alertmanager silence or requesting a Prometheus reload. The final impact depends on the APIs enabled by the upstream services. |
| Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions. |
| Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions. |
| Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions. |
| Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. |
| Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. |
| Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. |
| Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. |
| Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. |
| Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions. |
| Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. |