OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attack...
A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument url leads to stack-based bu...
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation of the argument pin results in stack-based bu...
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope.
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backen...
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.