| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Elementor Website Builder: from n/a through 4.1.0. |
| Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. |
| Memory corruption in windows drivers while sending incorrect trusted application request |
| Memory Corruption when output buffer size is smaller than input buffer size during data copying operation. |
| Memory Corruption when sending random number generator command with insufficient output buffer size. |
| Memory Corruption when processing display command line information due to improper initialization of a variable. |
| Memory corruption while processing fastboot OEM commands. |
| Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. |
| Memory corruption while processing fastboot commands with invalid input. |
| Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow. |
| Memory corruption while processing fastboot commands with improperly formatted input. |
| Memory Corruption when processing fastboot commands to set display mode. |
| IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction. |
| Memory corruption while processing IOCTL calls for escape operations. |
| Memory corruption while processing multiple IOCTL command for escape operations. |
| Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications. |
| IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption. |
| A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affected is an unknown function of the file /admin/products/manage_product.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. |
| A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument page results in file inclusion. The attack is possible to be carried out remotely. The exploit is now public and may be used. |
| A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the add_roles_for_object_creator method). This method finds the object creator by checking the current authenticated user. For objects that are created within a task, this current user is set by the first user with any permissions on the task object. This means the oldest user with model/domain-level task permissions will always be set as the current user of a task, even if they didn't dispatch the task. Therefore, all objects created in tasks will have their permissions assigned to this oldest user, and the creating user will receive nothing. |