| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. |
| Trueview TI8161 6.0.23.4 is vulnerable to information disclosure due to the transmission of MQTT communications in plaintext over TCP port 1883. An unauthenticated attacker with access to the same network segment can intercept MQTT traffic and obtain sensitive device information and operational data, including device identifiers, message metadata, and control-related information. |
| UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain (via a reflected XSS) that leverages the browser's internal JavaScript bridge to register a deferred callback, navigate the tab to a victim site, and then execute attacker-controlled code on that site when a login dialog is dismissed. |
| Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network. |
| No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack. |
| Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally. |
| Use after free in DNS Server allows an unauthorized attacker to execute code over a network. |
| Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
| Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
| Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| Use after free in IP Helper allows an unauthorized attacker to execute code over a network. |
| Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
| Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. |
| Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. |
| Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally. |
| Heap-based buffer overflow in Windows Schannel allows an unauthorized attacker to execute code over a network. |
| Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. |
| Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally. |