Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement text using string concatenation, with neither parameterised queries nor escaping. The application's own escaping helper, Dazadi.sql_txt(), is not invoked on these code paths, so a party that sends an invoice can break out o
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
Private Repository Metadata Remains Accessible After Access Revocation
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
REST API exposes organization membership of private organizations to public
Two SSRF findings in Gitea 1.26.2
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)
The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.