| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A flaw was found in SSSD. A local attacker with access to the Name Service Switch (NSS) responder UNIX socket can trigger an integer underflow by sending a specially crafted request with an undersized packet header. This issue causes an out-of-bounds memory read during packet parsing, crashing the responder process and resulting in a Denial of Service (DoS). |
| A flaw was found in sssd. A local attacker can trigger a Denial of Service (DoS) by sending a specially crafted Pluggable Authentication Module (PAM) request when passkey authentication is enabled. Due to a missing state validation check in passkey Kerberos handling, the PAM responder dereferences an uninitialized pointer and crashes. This failure disrupts authentication services on the host. |
| Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one.
On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it.
A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx. |
| An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints. |
| Subscriber SQL Injection in ListingPro <= 2.9.12 versions. |
| Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions. |
| Subscriber SQL Injection in UDesign Core <= 4.15.0 versions. |
| Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Social Rocket <= 1.3.5 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Video Background Block – Use video as background in the section. <= 2.0.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WooCommerce Simple Auctions <= 3.0.10 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.4.6 versions. |
| Unauthenticated Settings Change in PayPlug for WooCommerce (Official) <= 3.1.0 versions. |
| Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.7.1 versions. |
| Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0. |
| Unauthenticated Broken Access Control in Sermon'e <= 1.0.2 versions. |
| Subscriber Broken Access Control in Progress Planner <= 1.10.0 versions. |
| Unauthenticated Broken Access Control in The7 <= 14.2.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack <= 6.2.13 versions. |
| Unauthenticated Broken Access Control in BEAR <= 1.2.2 versions. |