CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link. |
Microsoft Defender for IoT Elevation of Privilege Vulnerability |
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network. |
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration). |
If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash.
*This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3. |
"IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 236584." |
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598." |
Microsoft Azure Site Recovery Elevation of Privilege Vulnerability |
Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability |
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability |
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability |
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability |
A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process.
*This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3. |
Server-Side Request Forgery (SSRF) vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Data Center Analytics, Analytics probe components), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe components) allows Server Side Request Forgery.
This issue affects Hitachi Infrastructure Analytics Advisor: from 2.0.0-00 through 4.4.0-00; Hitachi Ops Center Analyzer: from 10.0.0-00 before 10.9.0-00.
|
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability |
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection. |