CVE-2026-21519 | HIGH | 7.8 | 0.0242 | 57.05 | Yes | No | 2026-02-10 | 2026-02-10 | cisa.gov, euvd | Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges loca…Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. |
CVE-2021-22242 | HIGH | 8.7 | 0.63555 | 57.04 | No | No | 2021-08-25 | 2024-08-03 | euvd | Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site sc…Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown |
CVE-2022-41073 | HIGH | 7.8 | 0.02389 | 57.04 | Yes | No | 2022-11-08 | 2022-11-08 | cisa.gov, euvd | Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges. |
CVE-2019-0880 | HIGH | 7.8 | 0.02404 | 57.04 | Yes | No | 2022-05-23 | 2022-05-23 | cisa.gov, euvd | A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vu…A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity. |
CVE-2021-29442 | HIGH | 8.6 | 0.64697 | 57.04 | No | No | 2021-04-27 | 2024-08-03 | euvd | Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the Conf…Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform management operations like querying the database or even wiping it out. While the /data/remove endpoint is properly protected with the @Secured annotation, the /derby endpoint is not protected and can be openly accessed by unauthenticated users. These endpoints are only valid when using embedded storage (derby DB) so this issue should not affect those installations using external storage (e.g. mysql) |
CVE-2023-40495 | HIGH | 7.5 | 0.77245 | 57.04 | No | No | 2024-05-03 | 2025-02-04 | euvd | LG Simple Editor copyTemplateAll Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to dis…LG Simple Editor copyTemplateAll Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the copyTemplateAll method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM.
. Was ZDI-CAN-19922. |
CVE-2023-40496 | HIGH | 7.5 | 0.77245 | 57.04 | No | No | 2024-05-03 | 2024-09-18 | euvd | LG Simple Editor copyStickerContent Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to …LG Simple Editor copyStickerContent Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the implementation of the copyStickerContent command. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM.
. Was ZDI-CAN-19923. |
CVE-2023-27856 | HIGH | 7.5 | 0.77225 | 57.03 | No | No | 2023-03-21 | 2025-02-25 | euvd | In affected versions, path traversal exists when processing a message of type 8
in Rockwell Automation's ThinManager ThinServer.
An unau…In affected versions, path traversal exists when processing a message of type 8
in Rockwell Automation's ThinManager ThinServer.
An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed. |
CVE-2022-23270 | HIGH | 8.1 | 0.7035 | 57.02 | No | No | 2022-05-10 | 2025-01-02 | euvd | Windows Point-to-Point Tunneling Protocol Remote Code Execution VulnerabilityWindows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability |
CVE-2026-56155 | HIGH | 7.8 | 0.02333 | 57.02 | Yes | No | 2026-07-14 | 2026-07-14 | cisa.gov, euvd | Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorize…Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. |
CVE-2022-31061 | CRITICAL | 9.8 | 0.50889 | 57.01 | No | No | 2022-06-28 | 2025-04-23 | euvd | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.…GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions there is a SQL injection vulnerability which is possible on login page. No user credentials are required to exploit this vulnerability. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue. |
CVE-2025-26794 | HIGH | 7.5 | 0.77173 | 57.01 | No | No | 2025-02-21 | 2025-12-18 | euvd | Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires a…Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.) |
CVE-2021-34646 | CRITICAL | 9.8 | 0.50869 | 57.0 | No | No | 2021-08-30 | 2025-05-05 | euvd | Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the proces…Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activation_link function found in the ~/includes/class-wcj-emails-verification.php file. This allows attackers to impersonate users and trigger an email address verification for arbitrary accounts, including administrative accounts, and automatically be logged in as that user, including any site administrators. This requires the Email Verification module to be active in the plugin and the Login User After Successful Verification setting to be enabled, which it is by default. |
CVE-2019-1130 | HIGH | 7.8 | 0.02284 | 57.0 | Yes | No | 2022-05-23 | 2022-05-23 | cisa.gov, euvd | A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. |
CVE-2021-43890 | HIGH | 7.1 | 0.10295 | 57.0 | Yes | No | 2021-12-15 | 2026-08-06 | cisa.gov, euvd, nvd | We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks tha…We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader.
An attacker could craft a malicious attachment to be used in phishing campaigns. The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Please see the Security Updates table for the link to the updated app. Alternatively you can download and install the Installer using the links provided in the FAQ section.
Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability.
December 27 2023 Update:
In recent months, Microsoft Threat Intelligence has seen an increase in activity from threat actors leveraging social engineering and phishing techniques to target Windows OS users and utilizing the ms-appinstaller URI scheme.
To address this increase in activity, we have updated the App Installer to disable the ms-appinstaller protocol by default and recommend other potential mitigations. |
CVE-2025-24993 | HIGH | 7.8 | 0.02173 | 56.96 | Yes | No | 2025-03-11 | 2025-03-11 | cisa.gov, euvd | Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker…Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally. |
CVE-2023-26035 | HIGH | 7.2 | 0.80462 | 56.96 | No | No | 2023-02-25 | 2025-02-13 | euvd | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versio…ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions check on the snapshot action, which expects an id to fetch an existing monitor but can be passed an object to create a new one instead. TriggerOn ends up calling shell_exec using the supplied Id. This issue is fixed in This issue is fixed in versions 1.36.33 and 1.37.33. |
CVE-2025-32706 | HIGH | 7.8 | 0.02139 | 56.95 | Yes | No | 2025-05-13 | 2025-05-13 | cisa.gov, euvd | Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacke…Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally. |
CVE-2010-3035 | HIGH | 7.5 | 0.05562 | 56.95 | Yes | No | 2022-03-25 | 2022-03-25 | cisa.gov, euvd | Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS). |
CVE-2023-22047 | HIGH | 7.5 | 0.7698 | 56.94 | No | No | 2023-07-18 | 2024-09-13 | euvd | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affect…Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). |
CVE-2023-6623 | CRITICAL | 9.8 | 0.50673 | 56.94 | No | No | 2024-01-15 | 2025-06-11 | euvd | The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when renderin…The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks. |
CVE-2021-40450 | HIGH | 7.8 | 0.02076 | 56.93 | Yes | No | 2022-04-25 | 2022-04-25 | cisa.gov, euvd | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. |
CVE-2021-41357 | HIGH | 7.8 | 0.02076 | 56.93 | Yes | No | 2022-04-25 | 2022-04-25 | cisa.gov, euvd | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. |
CVE-2024-5084 | CRITICAL | 9.8 | 0.50653 | 56.93 | No | No | 2024-05-23 | 2026-04-08 | euvd | The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in…The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. |
CVE-2021-44427 | CRITICAL | 9.8 | 0.50641 | 56.92 | No | No | 2021-11-29 | 2024-08-04 | euvd | An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers t…An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) through /Side.php via the syear parameter. |
CVE-2024-45488 | CRITICAL | 9.8 | 0.50603 | 56.91 | No | No | 2024-08-30 | 2025-03-13 | euvd | One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only af…One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2. |
CVE-2023-23836 | HIGH | 7.2 | 0.80298 | 56.9 | No | No | 2023-02-15 | 2025-03-18 | euvd | SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remot…SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to the SolarWinds Web Console to execute arbitrary commands. |
CVE-2025-32375 | CRITICAL | 9.8 | 0.50446 | 56.86 | No | Yes | 2025-04-09 | 2025-04-09 | euvd, github | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an inse…BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure deserialization in BentoML's runner server. By setting specific headers and parameters in the POST request, it is possible to execute any unauthorized arbitrary code on the server, which will grant the attackers to have the initial access and information disclosure on the server. This vulnerability is fixed in 1.4.8. |
CVE-2021-38645 | HIGH | 7.8 | 0.0189 | 56.86 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for p…Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation. |
CVE-2019-0797 | HIGH | 7.8 | 0.0189 | 56.86 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Success…Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode. |
CVE-2018-19322 | HIGH | 7.8 | 0.01872 | 56.86 | Yes | No | 2022-10-24 | 2022-10-24 | cisa.gov, euvd | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functional…The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges. |
CVE-2022-41033 | HIGH | 7.8 | 0.01811 | 56.83 | Yes | No | 2022-10-11 | 2022-10-11 | cisa.gov, euvd | Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation. |
CVE-2025-30400 | HIGH | 7.8 | 0.01772 | 56.82 | Yes | No | 2025-05-13 | 2025-05-13 | cisa.gov, euvd | Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. |
CVE-2019-1129 | HIGH | 7.8 | 0.01782 | 56.82 | Yes | No | 2022-03-15 | 2022-03-15 | cisa.gov, euvd | A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this …A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. |
CVE-2020-11261 | HIGH | 7.8 | 0.01772 | 56.82 | Yes | No | 2021-12-01 | 2021-12-01 | cisa.gov, euvd | Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, …Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables |
CVE-2021-30533 | MEDIUM | 6.5 | 0.16611 | 56.81 | Yes | No | 2022-06-27 | 2022-06-27 | cisa.gov, euvd | Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation re…Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. |
CVE-2024-1222 | HIGH | 8.6 | 0.63984 | 56.79 | No | No | 2024-03-14 | 2024-09-26 | euvd | This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This ap…This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls. |
CVE-2025-32709 | HIGH | 7.8 | 0.01666 | 56.78 | Yes | No | 2025-05-13 | 2025-05-13 | cisa.gov, euvd | Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escala…Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privileges to administrator. |
CVE-2024-38107 | HIGH | 7.8 | 0.01635 | 56.77 | Yes | No | 2024-08-13 | 2024-08-13 | cisa.gov, euvd | Microsoft Windows Power Dependency Coordinator contains an unspecified vulnerability that allows for privilege escalation, enabling a local …Microsoft Windows Power Dependency Coordinator contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to obtain SYSTEM privileges. |
CVE-2023-44351 | CRITICAL | 9.8 | 0.5016 | 56.76 | No | No | 2023-11-17 | 2024-09-04 | euvd | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability …Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction. |
CVE-2025-58434 | CRITICAL | 9.8 | 0.50156 | 56.75 | No | No | 2025-09-12 | 2025-09-15 | euvd | Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password`…Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint in Flowise returns sensitive information including a valid password reset `tempToken` without authentication or verification. This enables any attacker to generate a reset token for arbitrary users and directly reset their password, leading to a complete account takeover (ATO). This vulnerability applies to both the cloud service (`cloud.flowiseai.com`) and self-hosted/local Flowise deployments that expose the same API. Commit 9e178d68873eb876073846433a596590d3d9c863 in version 3.0.6 secures password reset endpoints. Several recommended remediation steps are available. Do not return reset tokens or sensitive account details in API responses. Tokens must only be delivered securely via the registered email channel. Ensure `forgot-password` responds with a generic success message regardless of input, to avoid user enumeration. Require strong validation of the `tempToken` (e.g., single-use, short expiry, tied to request origin, validated against email delivery). Apply the same fixes to both cloud and self-hosted/local deployments. Log and monitor password reset requests for suspicious activity. Consider multi-factor verification for sensitive accounts. |
CVE-2018-7357 | MEDIUM | 6.5 | 0.8787 | 56.75 | No | No | 2018-11-14 | 2024-08-05 | euvd | ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerab…ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerability, which may allow an unauthorized user to gain unauthorized access. |
CVE-2022-36067 | CRITICAL | 10.0 | 0.47868 | 56.75 | No | No | 2022-09-06 | 2025-04-22 | euvd | vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor c…vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds. |
CVE-2025-21334 | HIGH | 7.8 | 0.0153 | 56.74 | Yes | No | 2025-01-14 | 2025-01-14 | cisa.gov, euvd | Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM priv…Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges. |
CVE-2025-21418 | HIGH | 7.8 | 0.01537 | 56.74 | Yes | No | 2025-02-11 | 2025-02-11 | cisa.gov, euvd | Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escala…Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. |
CVE-2026-21514 | HIGH | 7.8 | 0.01517 | 56.73 | Yes | No | 2026-02-10 | 2026-02-10 | cisa.gov, euvd | Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker t…Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally. |
CVE-2024-47175 | HIGH | 8.6 | 0.63811 | 56.73 | No | No | 2024-09-26 | 2025-11-03 | euvd | CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCrea…CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFromIPP2` does not sanitize IPP attributes when creating the PPD buffer. When used in combination with other functions such as `cfGetPrinterAttributes5`, can result in user controlled input and ultimately code execution via Foomatic. This vulnerability can be part of an exploit chain leading to remote code execution (RCE), as described in CVE-2024-47176. |
CVE-2024-23225 | HIGH | 7.8 | 0.01481 | 56.72 | Yes | No | 2024-03-06 | 2024-03-06 | cisa.gov, euvd | Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrar…Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections. |
CVE-2023-1133 | CRITICAL | 9.8 | 0.5005 | 56.72 | No | No | 2023-03-27 | 2025-02-13 | euvd | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on por…Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code. |
CVE-2012-0003 | HIGH | 8.1 | 0.69499 | 56.72 | No | No | 2012-01-10 | 2024-10-17 | euvd | Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Serv…Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via a crafted MIDI file, aka "MIDI Remote Code Execution Vulnerability." |