| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier authentication result. A remote attacker who can reach ldapd can complete a Bind as another identity. A missing connection can also cause a NULL pointer dereference. (ldapd is not enabled by default.) |
| Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. |
| Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network. |
| In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree. |
| Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally. |
| Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally. |
| Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network. |
| SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words parameter. |
| SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API
endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows
remote attackers to execute arbitrary SQL commands via the id parameter. |
| Exposed Dangerous Method or Function in the
/WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote
authenticated users to execute arbitrary SQL commands via the sql parameter. |
| Unrestricted Upload of File with Dangerous Type in the
/WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version
before 2023/03/24 allows remote authenticated users to execute arbitrary
system commands via a malicious file. |
| Improper Limitation of a Pathname to a Restricted
Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp
API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote
authenticated users to write files to arbitrary locations outside the intended
upload directory via the path parameter. |
| A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions. |
| A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions. |
| Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets.
This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07. |
| A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect. |
| Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a crafted request that controls the output file name, path, extension, and content through request parameters. Due to the lack of authentication and input validation, the request is processed successfully, allowing an attacker to write and execute arbitrary PHP code, resulting in remote code execution (RCE).
This issue was fixed in version 2.3.9. |
| Missing Authorization vulnerability in Interprobe Information Technologies Inc. Qorela DC allows Privilege Abuse.
This issue affects Qorela DC: from 1.6.1-RC29 before v1.6.2. |
| OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer. |
| Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values. |