High · CVSS 8.8 · CISA KEV
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Jun 15, 2021 · Updated Oct 21, 2025
Critical · CVSS 9.1
The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server.
Published Jun 25, 2025 · Updated Jul 1, 2025
Critical · CVSS 9.8
A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php.
Published Jun 24, 2025 · Updated Jun 25, 2025
Medium · CVSS 5.7
In WhiteBeam 0.2.0 through 0.2.1 before 0.2.2, a user with local access to a server can bypass the allow-list functionality because a file can be truncated in the OpenFileDescriptor action before the VerifyCanWrite action is performed.
Published Jun 23, 2025 · Updated Jun 24, 2025
Unknown · CVSS Not scored
Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to Information Disclosure.
Published Jun 29, 2021 · Updated May 30, 2025
Unknown · CVSS Not scored
Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data.
Published Jun 29, 2021 · Updated May 30, 2025
Unknown · CVSS Not scored
Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).
Published Jun 29, 2021 · Updated May 30, 2025
Medium · CVSS 5.4
The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and escape its Label settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Published Jun 21, 2021 · Updated May 5, 2025
High · CVSS 8.8
Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published Jun 28, 2021 · Updated Apr 23, 2025
High · CVSS 8.8
Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published Jun 28, 2021 · Updated Apr 23, 2025
High · CVSS 8.8
Adobe InCopy version 16.0 (and earlier) is affected by an path traversal vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published Jun 28, 2021 · Updated Apr 23, 2025
High · CVSS 8.8
Adobe Illustrator version 25.2 (and earlier) is affected by a Path Traversal vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published Jun 28, 2021 · Updated Apr 23, 2025
Medium · CVSS 4.3
Adobe Animate version 21.0.5 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published Jun 28, 2021 · Updated Apr 23, 2025
Medium · CVSS 4.3
Adobe Animate version 21.0.5 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published Jun 28, 2021 · Updated Apr 23, 2025
Medium · CVSS 4.3
Adobe Animate version 21.0.5 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published Jun 28, 2021 · Updated Apr 23, 2025
High · CVSS 8.3
Adobe After Effects version 18.1 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An unauthenticated attacker could exploit this to to plant custom binaries and execute them with System permissions. Exploitation of this issue requires user interaction.
Published Jun 28, 2021 · Updated Apr 23, 2025
Medium · CVSS 4.3
Adobe Animate version 21.0.5 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published Jun 28, 2021 · Updated Apr 23, 2025
Medium · CVSS 4.3
Adobe Connect version 11.2.1 (and earlier) is affected by an Improper access control vulnerability that can lead to the elevation of privileges. An attacker with 'Learner' permissions can leverage this scenario to access the list of event participants.
Published Jun 28, 2021 · Updated Apr 23, 2025
Medium · CVSS 6.2
Adobe Photoshop Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An unauthenticated attacker could leverage this vulnerability to call functions against the installer to perform high privileged actions. Exploitation of this issue does not require user interaction.
Published Jun 28, 2021 · Updated Apr 23, 2025
Medium · CVSS 6.2
Adobe Premiere Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An unauthenticated attacker could leverage this vulnerability to call functions against the installer to perform high privileged actions. Exploitation of this issue does not require user interaction.
Published Jun 28, 2021 · Updated Apr 23, 2025
High · CVSS 7.8
Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file.
Published Jun 13, 2022 · Updated Apr 23, 2025
High · CVSS 7.8
Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file.
Published Jun 13, 2022 · Updated Apr 23, 2025
High · CVSS 7.8
Adobe Premiere Pro version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file.
Published Jun 13, 2022 · Updated Apr 23, 2025
High · CVSS 7.8
Adobe InDesign versions 16.3 (and earlier), and 16.3.1 (and earlier) is affected by an Out-of-bounds Write vulnerability due to insecure handling of a malicious TIFF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
Published Jun 15, 2022 · Updated Apr 23, 2025
High · CVSS 7.8
Access of Memory Location After End of Buffer (CWE-788
Published Jun 15, 2022 · Updated Apr 23, 2025
Medium · CVSS 6.1
Adobe Lightroom Classic 10.3 (and earlier) are affected by a privilege escalation vulnerability in the Offline Lightroom Classic installer. An authenticated attacker could leverage this vulnerability to escalate privileges. User interaction is required before product installation to abuse this vulnerability.
Published Jun 15, 2022 · Updated Apr 23, 2025
High · CVSS 7.8
Adobe Prelude version 22.1.1 (and earlier) is affected by an Out-of-bounds Write vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
Published Jun 15, 2022 · Updated Apr 23, 2025
High · CVSS 7.8
Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an Out-of-bounds Write vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published Jun 15, 2022 · Updated Apr 23, 2025
High · CVSS 7.8
Adobe Photoshop version 22.5.1 (and earlier versions ) is affected by an Access of Memory Location After End of Buffer vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
Published Jun 15, 2022 · Updated Apr 23, 2025
High · CVSS 7.8
Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an Out-of-bounds Write vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
Published Jun 15, 2022 · Updated Apr 23, 2025
Medium · CVSS 4.3
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Published Jun 30, 2023 · Updated Apr 14, 2025
Medium · CVSS 5.3
A SQL injection vulnerability exists in some configurations of ArcGIS Server versions 10.8.1 and earlier. Specially crafted web requests can expose information that is not intended to be disclosed (not customer datasets). Web Services that use file based data sources (file Geodatabase or Shape Files or tile cached services) are unaffected by this issue.
Published Jun 7, 2021 · Updated Apr 10, 2025
High · CVSS 7.5
ClassGraph before 4.8.112 was not resistant to XML eXternal Entity (XXE) attacks.
Published Jun 21, 2024 · Updated Mar 13, 2025
High · CVSS 7.3
Microsoft Outlook Remote Code Execution Vulnerability
Published Jun 8, 2021 · Updated Feb 28, 2025
High · CVSS 8.8
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Published Jun 30, 2023 · Updated Feb 28, 2025
High · CVSS 8.2
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Published Jun 28, 2023 · Updated Feb 28, 2025
Unknown · CVSS Not scored
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.
Published Jun 2, 2021 · Updated Feb 13, 2025
Unknown · CVSS Not scored
Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For header to a local IP-address.
Published Jun 28, 2023 · Updated Feb 13, 2025
Unknown · CVSS Not scored
An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parameters in the out.UsrMgr.php file.
Published Jun 7, 2023 · Updated Jan 7, 2025
Medium · CVSS 6.1
An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the keywords parameter.
Published Jun 14, 2023 · Updated Jan 3, 2025
Medium · CVSS 6.1
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Published Jun 30, 2023 · Updated Jan 1, 2025
Medium · CVSS 5.4
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Published Jun 30, 2023 · Updated Jan 1, 2025
Critical · CVSS 9.8
The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiwi_social_share_get_option AJAX action in version 2.1.0. This makes it possible for unauthenticated attackers to read and modify arbitrary options on a WordPress site that can be used for complete site takeover. This was a previously fixed vulnerability that was reintroduced in this version.
Published Jun 7, 2023 · Updated Dec 28, 2024
Unknown · CVSS Not scored
In PVRSRVBridgeSyncPrimOpCreate of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published Jun 15, 2023 · Updated Dec 18, 2024
Unknown · CVSS Not scored
In _PMRCreate of the PowerVR kernel driver, a missing bounds check means it is possible to overwrite heap memory via PhysmemNewRamBackedPMR. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published Jun 15, 2023 · Updated Dec 18, 2024
Unknown · CVSS Not scored
Emby Server versions < 4.6.0.50 is vulnerable to Cross Site Scripting (XSS) vulnerability via a crafted GET request to /web.
Published Jun 28, 2023 · Updated Dec 5, 2024
Unknown · CVSS Not scored
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
Published Jun 26, 2023 · Updated Dec 5, 2024
Unknown · CVSS Not scored
Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to browse departments and usernames.
Published Jun 27, 2023 · Updated Dec 5, 2024
Unknown · CVSS Not scored
A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary web scripts or HTML.
Published Jun 27, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connectivity to the device via Modbus TCP protocol when an attacker sends a specially crafted HTTP request.
Published Jun 11, 2021 · Updated Nov 24, 2024