| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permissions (at the root, namespace, or database level) to define custom database functions via DEFINE FUNCTION using nested FOR loops. Although a single loop's iteration count is constrained, nesting multiple loops (e.g., each with 1,000,000 iterations) is not, so an attacker can execute a function that consumes all server CPU time. Configured timeouts do not stop the execution, rendering the server unresponsive to other queries and connections until it is manually restarted. |
| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. |
| Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
| Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally. |
| Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
| Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |
| Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. |
| Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions. |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
| Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions. |
| Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions. |
| Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions. |
| Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions. |
| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. |
| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |