| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing unauthorized modification of dashboard configuration and potential service disruption. This issue is fixed in version 4.0.8. |
| Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only for new-user creation and not when SSO_SIGNUPS_MATCH_EMAIL=true linked an IdP identity to an existing local account, allowing an attacker-controlled IdP identity asserting a victim email address to bind to and authenticate as that account. This issue is fixed in version 1.36.0. |
| Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. |
| Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
| Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally. |
| Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. |
| Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. |
| Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. |
| Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
| The charging station websocket endpoint accepts connections without
proper authentication, which could lead to privilege escalation. |
| Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls, upload, removefiles, rename, createfolder) without performing any ACL or role check. Any authenticated user, regardless of role, can perform all bucket operations on any named bucket, including buckets intended for admin use only. |
| Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. |
| Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. |
| Improper access control in Windows Server allows an authorized attacker to elevate privileges locally. |
| Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. |
| A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This vulnerability affects the function handleNavigate of the file pkg/browser/tool.go. Such manipulation of the argument args.targetUrl leads to information disclosure. The attack may be performed from remote. The exploit is publicly available and might be used. |
| A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. |
| A vulnerability was found in zhayujie CowAgent up to 2.1.0. This issue affects the function BrowserTool._do_navigate of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in information disclosure. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. |
| A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryController::storeFile of the file src/Http/Controllers/Admin/FileLibraryController.php of the component Media Library Insert Page. Such manipulation of the argument qqfilename leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. |