Latest CVE Feed
Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.
Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, the worker's code-compilation pipeline builds the on-disk path for a Code step from the step's name and passes that pa…
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security meas…
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to c…
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to ex…
is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arb…
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized…
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unau…
Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.