Currently trending CVE - Hype Score: 5 - Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Currently trending CVE - Hype Score: 1 - An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes
sensitive geolocation information without requiring authentication. This issue
allows an attacker on the same local network to retrieve ...
Currently trending CVE - Hype Score: 1 - Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem
that is shared across devices. An
attacker with access to the firmware image can extract the embedded key.
Successful
exploitation may allow an ...
Currently trending CVE - Hype Score: 10 - Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.doggo2), are vulnerable to remote code execution due to missing integrity protection and validation of user-created programmes. The Android application stores ...
Currently trending CVE - Hype Score: 10 - Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDDS topic rt/api/programming_actuator/request handled by actuator_manager.py. A network-adjacent, unauthenticated attacker can join ...
Currently trending CVE - Hype Score: 1 - A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via
Currently trending CVE - Hype Score: 1 - A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS ...
Currently trending CVE - Hype Score: 1 - NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with ...
Currently trending CVE - Hype Score: 11 - Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Currently trending CVE - Hype Score: 11 - Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Currently trending CVE - Hype Score: 8 - Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Currently trending CVE - Hype Score: 4 - Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
Currently trending CVE - Hype Score: 20 - Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
Currently trending CVE - Hype Score: 2 - Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Currently trending CVE - Hype Score: 3 - Description information displayed in the site administration live log
required additional sanitizing to prevent a stored XSS risk.
Currently trending CVE - Hype Score: 8 - Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
Currently trending CVE - Hype Score: 10 - Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Currently trending CVE - Hype Score: 6 - A missing authorization vulnerability exists in the embedded webserver of HP Deskjet 2800 Series Printers running firmware version <=TBP1CN2612AR. An unauthenticated attacker with network access can send GET requests to multiple exposed administrative API endpoints and retrieve ...