| CVE | Vendors | Products | Updated | CVSS v3.1 | 
        | Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | 
    
    
    
        | Windows TCP/IP Denial of Service Vulnerability | 
    
    
    
        | Windows Kernel Elevation of Privilege Vulnerability | 
    
    
    
        | DHCP Server Service Information Disclosure Vulnerability | 
    
    
    
        | Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability | 
    
    
    
        | Windows GDI Elevation of Privilege Vulnerability | 
    
    
    
        | DHCP Server Service Denial of Service Vulnerability | 
    
    
    
        | Azure DevOps Server Remote Code Execution Vulnerability | 
    
    
    
        | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 
    
    
    
        | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | 
    
    
    
        | Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts a redirect parameter without validation, allowing attackers to redirect authenticated users to arbitrary external sites. This vulnerability is fixed in 0.69.0. | 
    
    
    
        | Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This vulnerability is fixed in 5.22.1. | 
    
    
    
        | An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute injected JavaScript in the administrator’s browser and intercept credentials. | 
    
    
    
        | Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource. | 
    
    
    
        | HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified vectors. | 
    
    
    
        | Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can log in as a normal user. This can result in illegal access being granted to the system. Version 23.3 fixes this vulnerability. | 
    
    
    
        | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability.  The application does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways. | 
    
    
    
        | An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges on a vulnerable device. | 
    
    
    
        | An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from V1.20 through V1.31 could allow an authenticated local attacker with low privileges to gain access to the Linux shell and escalate their privileges by crafting malicious scripts or modifying system configurations with administrator-level access through a stolen token. Modifying the system configuration is only possible if the administrator has not logged out and the token remains valid. | 
    
    
    
        | In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana.
This issue affects Grafana: before 11.6.2 and is fixed in 11.6.2 and higher. |