Critical · CVSS 9.8
Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability affects the MSI file format
Published Jul 21, 2023 · Updated Nov 4, 2025
Critical · CVSS 9.8
Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.The loop that stores the coordinates does not check its index against nAtoms
Published Jul 21, 2023 · Updated Nov 4, 2025
Critical · CVSS 9.8
Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.nAtoms calculation wrap-around, leading to a small buffer allocation
Published Jul 21, 2023 · Updated Nov 4, 2025
Medium · CVSS 5.3
NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.
Published Jul 5, 2022 · Updated Nov 4, 2025
Low · CVSS 3.7
An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
Published Jul 6, 2022 · Updated Nov 3, 2025
Low · CVSS 3.7
An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
Published Jul 6, 2022 · Updated Nov 3, 2025
High · CVSS 7.5
moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rfc2822 parsing, which is tried by default) has quadratic (N^2) complexity on specific inputs. Users may notice a noticeable slowdown is observed with inputs above 10k characters. Users who pass user-provided strings without sanity length checks to moment constructor are vulnerable to (Re)DoS attacks. The problem is patched in 2.29.4, the patch can be applied to all affected versions with minimal tweaking. Users are advised to upgrade. Users unable to upgrade should consider limiting date lengths accepted from user input.
Published Jul 6, 2022 · Updated Nov 3, 2025
High · CVSS 7.8
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
Published Jul 5, 2022 · Updated Nov 3, 2025
Unknown · CVSS Not scored
squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer overflow vulnerability due to a defect in the metadata reading process. Loading a specially crafted squashfs image may lead to a denial-of-service (DoS) condition or arbitrary code execution.
Published Jul 20, 2022 · Updated Nov 3, 2025
Unknown · CVSS Not scored
Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir().
Published Jul 1, 2022 · Updated Nov 3, 2025
High · CVSS 7.8 · CISA KEV
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Oct 21, 2025
Critical · CVSS 9.8 · CISA KEV
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution.
Published Jul 17, 2022 · Updated Oct 21, 2025
High · CVSS 8.8 · CISA KEV
The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as. This affects Apache Spark versions 3.0.3 and earlier, versions 3.1.1 to 3.1.2, and versions 3.2.0 to 3.2.1.
Published Jul 18, 2022 · Updated Oct 21, 2025
Critical · CVSS 9.8 · CISA KEV
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
Published Jul 19, 2022 · Updated Oct 21, 2025
High · CVSS 8.8 · CISA KEV
Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Jul 22, 2022 · Updated Oct 21, 2025
High · CVSS 8.8 · CISA KEV
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Jul 26, 2022 · Updated Oct 21, 2025
High · CVSS 8.5
A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC STEP 7 V16 (All versions), SIMATIC STEP 7 V17 (All versions), SIMATIC STEP 7 V18 (All versions < V18 Update 2). Affected applications do not properly restrict the .NET BinaryFormatter when deserializing user-controllable input. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected application.
This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300.
Published Jul 9, 2024 · Updated Aug 27, 2025
High · CVSS 8
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2100NC, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM M2200NC, RUGGEDCOM M969, RUGGEDCOM M969F, RUGGEDCOM M969NC, RUGGEDCOM RMC30, RUGGEDCOM RMC30NC, RUGGEDCOM RMC8388 V4.X, RUGGEDCOM RMC8388 V5.X, RUGGEDCOM RMC8388NC V4.X, RUGGEDCOM RMC8388NC V5.X, RUGGEDCOM RP110, RUGGEDCOM RP110NC, RUGGEDCOM RS1600, RUGGEDCOM RS1600F, RUGGEDCOM RS1600FNC, RUGGEDCOM RS1600NC, RUGGEDCOM RS1600T, RUGGEDCOM RS1600TNC, RUGGEDCOM RS400, RUGGEDCOM RS400F, RUGGEDCOM RS400NC, RUGGEDCOM RS401, RUGGEDCOM RS401NC, RUGGEDCOM RS416, RUGGEDCOM RS416F, RUGGEDCOM RS416NC, RUGGEDCOM RS416NCv2 V4.X, RUGGEDCOM RS416NCv2 V5.X, RUGGEDCOM RS416P, RUGGEDCOM RS416PF, RUGGEDCOM RS416PNC, RUGGEDCOM RS416PNCv2 V4.X, RUGGEDCOM RS416PNCv2 V5.X, RUGGEDCOM RS416Pv2 V4.X, RUGGEDCOM RS416Pv2 V5.X, RUGGEDCOM RS416v2 V4.X, RUGGEDCOM RS416v2 V5.X, RUGGEDCOM RS8000, RUGGEDCOM RS8000A, RUGGEDCOM RS8000ANC, RUGGEDCOM RS8000H, RUGGEDCOM RS8000HNC, RUGGEDCOM RS8000NC, RUGGEDCOM RS8000T, RUGGEDCOM RS8000TNC, RUGGEDCOM RS900, RUGGEDCOM RS900 (32M) V4.X, RUGGEDCOM RS900 (32M) V5.X, RUGGEDCOM RS900F, RUGGEDCOM RS900G, RUGGEDCOM RS900G (32M) V4.X, RUGGEDCOM RS900G (32M) V5.X, RUGGEDCOM RS900GF, RUGGEDCOM RS900GNC, RUGGEDCOM RS900GNC(32M) V4.X, RUGGEDCOM RS900GNC(32M) V5.X, RUGGEDCOM RS900GP, RUGGEDCOM RS900GPF, RUGGEDCOM RS900GPNC, RUGGEDCOM RS900L, RUGGEDCOM RS900LNC, RUGGEDCOM RS900M-GETS-C01, RUGGEDCOM RS900M-GETS-XX, RUGGEDCOM RS900M-STND-C01, RUGGEDCOM RS900M-STND-XX, RUGGEDCOM RS900MNC-GETS-C01, RUGGEDCOM RS900MNC-GETS-XX, RUGGEDCOM RS900MNC-STND-XX, RUGGEDCOM RS900MNC-STND-XX-C01, RUGGEDCOM RS900NC, RUGGEDCOM RS900NC(32M) V4.X, RUGGEDCOM RS900NC(32M) V5.X, RUGGEDCOM RS900W, RUGGEDCOM RS910, RUGGEDCOM RS910L, RUGGEDCOM RS910LNC, RUGGEDCOM RS910NC, RUGGEDCOM RS910W, RUGGEDCOM RS920L, RUGGEDCOM RS920LNC, RUGGEDCOM RS920W, RUGGEDCOM RS930L, RUGGEDCOM RS930LNC, RUGGEDCOM RS930W, RUGGEDCOM RS940G, RUGGEDCOM RS940GF, RUGGEDCOM RS940GNC, RUGGEDCOM RS969, RUGGEDCOM RS969NC, RUGGEDCOM RSG2100, RUGGEDCOM RSG2100 (32M) V4.X, RUGGEDCOM RSG2100 (32M) V5.X, RUGGEDCOM RSG2100F, RUGGEDCOM RSG2100NC, RUGGEDCOM RSG2100NC(32M) V4.X, RUGGEDCOM RSG2100NC(32M) V5.X, RUGGEDCOM RSG2100P, RUGGEDCOM RSG2100P (32M) V4.X, RUGGEDCOM RSG2100P (32M) V5.X, RUGGEDCOM RSG2100PF, RUGGEDCOM RSG2100PNC, RUGGEDCOM RSG2100PNC (32M) V4.X, RUGGEDCOM RSG2100PNC (32M) V5.X, RUGGEDCOM RSG2200, RUGGEDCOM RSG2200F, RUGGEDCOM RSG2200NC, RUGGEDCOM RSG2288 V4.X, RUGGEDCOM RSG2288 V5.X, RUGGEDCOM RSG2288NC V4.X, RUGGEDCOM RSG2288NC V5.X, RUGGEDCOM RSG2300 V4.X, RUGGEDCOM RSG2300 V5.X, RUGGEDCOM RSG2300F, RUGGEDCOM RSG2300NC V4.X, RUGGEDCOM RSG2300NC V5.X, RUGGEDCOM RSG2300P V4.X, RUGGEDCOM RSG2300P V5.X, RUGGEDCOM RSG2300PF, RUGGEDCOM RSG2300PNC V4.X, RUGGEDCOM RSG2300PNC V5.X, RUGGEDCOM RSG2488 V4.X, RUGGEDCOM RSG2488 V5.X, RUGGEDCOM RSG2488F, RUGGEDCOM RSG2488NC V4.X, RUGGEDCOM RSG2488NC V5.X, RUGGEDCOM RSG907R, RUGGEDCOM RSG908C, RUGGEDCOM RSG909R, RUGGEDCOM RSG910C, RUGGEDCOM RSG920P V4.X, RUGGEDCOM RSG920P V5.X, RUGGEDCOM RSG920PNC V4.X, RUGGEDCOM RSG920PNC V5.X, RUGGEDCOM RSL910, RUGGEDCOM RSL910NC, RUGGEDCOM RST2228, RUGGEDCOM RST2228P, RUGGEDCOM RST916C, RUGGEDCOM RST916P. Affected devices are vulnerable to a web-based code injection attack via the console.
An attacker could exploit this vulnerability to inject code into the web server and cause malicious behavior in legitimate users accessing certain web resources on the affected
device.
Published Jul 12, 2022 · Updated Aug 12, 2025
Medium · CVSS 5.9
The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair implementation leads to a simple computation for extracting a private key.
Published Jul 28, 2025 · Updated Jul 28, 2025
Medium · CVSS 4.2
All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.
Published Jul 15, 2022 · Updated Jul 28, 2025
Medium · CVSS 6.5
Microsoft Defender for Endpoint Tampering Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
High · CVSS 7.2
Azure Site Recovery Remote Code Execution Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
High · CVSS 7.2
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
High · CVSS 7.2
Azure Site Recovery Remote Code Execution Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
High · CVSS 7.8
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
High · CVSS 8.3
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 6.5
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 6.5
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 4.9
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 4.9
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 4.9
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 6.5
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 6.5
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 6.5
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 4.9
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 6.5
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 6.5
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 6.5
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 4.9
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 4.9
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 4.9
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 6.5
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 6.5
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 6.5
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 4.9
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 4.9
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 4.9
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 4.9
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
Medium · CVSS 4.9
Azure Site Recovery Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025
High · CVSS 7
Xbox Live Save Service Elevation of Privilege Vulnerability
Published Jul 12, 2022 · Updated Jul 8, 2025