Unknown · CVSS Not scored
An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::canUpload, leading to XSS attack vectors.
Published May 26, 2021 · Updated Feb 25, 2026
Unknown · CVSS Not scored
An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint.
Published May 26, 2021 · Updated Feb 25, 2026
Medium · CVSS 5.2
Script injection in M-Files Admin versions before 22.2.11051.0, allows executing stored script in admin tool. M-Files Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitable
Published May 2, 2022 · Updated Feb 23, 2026
Medium · CVSS 5.7
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.
Published May 20, 2021 · Updated Dec 18, 2025
High · CVSS 8.6
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.
Published May 19, 2021 · Updated Dec 2, 2025
Unknown · CVSS Not scored
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
Published May 6, 2021 · Updated Nov 3, 2025
High · CVSS 7.8
XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
Published May 2, 2022 · Updated Nov 3, 2025
High · CVSS 7.8
XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
Published May 2, 2022 · Updated Nov 3, 2025
High · CVSS 7.8
XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
Published May 2, 2022 · Updated Nov 3, 2025
High · CVSS 7.8
XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
Published May 2, 2022 · Updated Nov 3, 2025
Medium · CVSS 5.5
XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published May 2, 2022 · Updated Nov 3, 2025
Unknown · CVSS Not scored
A flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to memory corruption and other potential consequences.
Published May 26, 2021 · Updated Nov 3, 2025
Unknown · CVSS Not scored
A flaw was found in libcaca. A heap buffer overflow in export.c in function export_tga might lead to memory corruption and other potential consequences.
Published May 26, 2021 · Updated Nov 3, 2025
High · CVSS 8.8 · CISA KEV
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
Published May 4, 2021 · Updated Oct 21, 2025
Critical · CVSS 9.8 · CISA KEV
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Published May 6, 2021 · Updated Oct 21, 2025
Critical · CVSS 9.8 · CISA KEV
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Published May 6, 2021 · Updated Oct 21, 2025
Critical · CVSS 9.8 · CISA KEV
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_check in web_hook.o. An attacker-supplied value of '\0' matches the device's default value of '\0' in some situations. Note: All versions of Lyra Mini and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability, Consumers can mitigate this vulnerability by disabling the remote access features from WAN.
Published May 6, 2021 · Updated Oct 21, 2025
High · CVSS 8.4 · CISA KEV
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published May 7, 2021 · Updated Oct 21, 2025
Medium · CVSS 6.2 · CISA KEV
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published May 7, 2021 · Updated Oct 21, 2025
Critical · CVSS 9.8 · CISA KEV
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.
Published May 7, 2021 · Updated Oct 21, 2025
High · CVSS 8.8 · CISA KEV
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.
Published May 10, 2021 · Updated Oct 21, 2025
High · CVSS 8.8 · CISA KEV
The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0.
Published May 10, 2021 · Updated Oct 21, 2025
Critical · CVSS 9.8 · CISA KEV
HTTP Protocol Stack Remote Code Execution Vulnerability
Published May 11, 2021 · Updated Oct 21, 2025
Medium · CVSS 6.6 · CISA KEV
Microsoft Exchange Server Security Feature Bypass Vulnerability
Published May 11, 2021 · Updated Oct 21, 2025
Critical · CVSS 10 · CISA KEV
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .
Published May 13, 2021 · Updated Oct 21, 2025
High · CVSS 8.8 · CISA KEV
. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0.
Published May 24, 2021 · Updated Oct 21, 2025
Medium · CVSS 5.5 · CISA KEV
In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.
Published May 25, 2021 · Updated Oct 21, 2025
Critical · CVSS 9.8 · CISA KEV
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
Published May 26, 2021 · Updated Oct 21, 2025
High · CVSS 8.8 · CISA KEV
A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.
Published May 27, 2021 · Updated Oct 21, 2025
High · CVSS 8.8 · CISA KEV
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature
Published May 27, 2021 · Updated Oct 21, 2025
High · CVSS 7.2 · CISA KEV
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
Published May 27, 2021 · Updated Oct 21, 2025
Critical · CVSS 9.8 · CISA KEV
Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.
Published May 27, 2021 · Updated Oct 21, 2025
High · CVSS 8.8
RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service condition and information exposure.
Published May 5, 2022 · Updated Jun 23, 2025
High · CVSS 7.5
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.
Published May 28, 2021 · Updated May 29, 2025
High · CVSS 8.2
Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.
Published May 21, 2025 · Updated May 21, 2025
High · CVSS 8.3
Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.
Published May 21, 2025 · Updated May 21, 2025
Medium · CVSS 6.9
Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.
Published May 21, 2025 · Updated May 21, 2025
High · CVSS 8
Improper input validation for the Intel(R) Manageability Commander before version 2.2 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
Published May 12, 2022 · Updated May 5, 2025
High · CVSS 7.8
Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
Published May 12, 2022 · Updated May 5, 2025
High · CVSS 7.8
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
Published May 12, 2022 · Updated May 5, 2025
Medium · CVSS 5.5
Unchecked return value in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Published May 12, 2022 · Updated May 5, 2025
High · CVSS 7.8
Improper input validation in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
Published May 12, 2022 · Updated May 5, 2025
High · CVSS 7.8
Return of pointer value outside of expected range in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
Published May 12, 2022 · Updated May 5, 2025
High · CVSS 7.8
Use of out-of-range pointer offset in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
Published May 12, 2022 · Updated May 5, 2025
High · CVSS 7.8
Uncaught exception in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
Published May 12, 2022 · Updated May 5, 2025
High · CVSS 7.2
Improper authentication in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escalation of privilege via network access.
Published May 12, 2022 · Updated May 5, 2025
High · CVSS 7.2
Improper access control in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escalation of privilege via network access.
Published May 12, 2022 · Updated May 5, 2025
High · CVSS 7.8
Improper access control for the Intel(R) Killer(TM) Control Center software before version 2.4.3337.0 may allow an authorized user to potentially enable escalation of privilege via local access.
Published May 12, 2022 · Updated May 5, 2025
High · CVSS 7.5
An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c function.
Published May 9, 2023 · Updated May 5, 2025
Medium · CVSS 4.6
Protection mechanism failure in firmware for some Intel(R) SSD, Intel(R) SSD DC and Intel(R) Optane(TM) SSD Products may allow an unauthenticated user to potentially enable information disclosure via physical access.
Published May 12, 2022 · Updated May 5, 2025