High · CVSS 7.5
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1.
Published Dec 14, 2022 · Updated Nov 3, 2025
High · CVSS 7.5
DCMTK v3.6.7 was discovered to contain a memory leak via the T_ASC_Association object.
Published Dec 2, 2022 · Updated Nov 3, 2025
Medium · CVSS 5.3
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim performing a single private-key operation, if the window size (MBEDTLS_MPI_WINDOW_SIZE) used for the exponentiation is 3 or smaller.
Published Dec 15, 2022 · Updated Nov 3, 2025
Medium · CVSS 4.4
OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linux. Using a modified USB device an attacker can leak stack addresses of the `razer_attr_read_dpi_stages`, potentially bypassing KASLR. To exploit this vulnerability an attacker would need to access to a users keyboard or mouse or would need to convince a user to use a modified device. The issue has been patched in v3.5.1. Users are advised to upgrade and should be reminded not to plug in unknown USB devices.
Published Dec 5, 2022 · Updated Nov 3, 2025
High · CVSS 8.8 · CISA KEV
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published Dec 2, 2022 · Updated Oct 21, 2025
Critical · CVSS 9.8 · CISA KEV
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if a specific data source was selected for any monitored device. The vulnerability resides in the `remote_agent.php` file. This file can be accessed without authentication. This function retrieves the IP address of the client via `get_client_addr` and resolves this IP address to the corresponding hostname via `gethostbyaddr`. After this, it is verified that an entry within the `poller` table exists, where the hostname corresponds to the resolved hostname. If such an entry was found, the function returns `true` and the client is authorized. This authorization can be bypassed due to the implementation of the `get_client_addr` function. The function is defined in the file `lib/functions.php` and checks serval `$_SERVER` variables to determine the IP address of the client. The variables beginning with `HTTP_` can be arbitrarily set by an attacker. Since there is a default entry in the `poller` table with the hostname of the server running Cacti, an attacker can bypass the authentication e.g. by providing the header `Forwarded-For: <TARGETIP>`. This way the function `get_client_addr` returns the IP address of the server running Cacti. The following call to `gethostbyaddr` will resolve this IP address to the hostname of the server, which will pass the `poller` hostname check because of the default entry. After the authorization of the `remote_agent.php` file is bypassed, an attacker can trigger different actions. One of these actions is called `polldata`. The called function `poll_for_data` retrieves a few request parameters and loads the corresponding `poller_item` entries from the database. If the `action` of a `poller_item` equals `POLLER_ACTION_SCRIPT_PHP`, the function `proc_open` is used to execute a PHP script. The attacker-controlled parameter `$poller_id` is retrieved via the function `get_nfilter_request_var`, which allows arbitrary strings. This variable is later inserted into the string passed to `proc_open`, which leads to a command injection vulnerability. By e.g. providing the `poller_id=;id` the `id` command is executed. In order to reach the vulnerable call, the attacker must provide a `host_id` and `local_data_id`, where the `action` of the corresponding `poller_item` is set to `POLLER_ACTION_SCRIPT_PHP`. Both of these ids (`host_id` and `local_data_id`) can easily be bruteforced. The only requirement is that a `poller_item` with an `POLLER_ACTION_SCRIPT_PHP` action exists. This is very likely on a productive instance because this action is added by some predefined templates like `Device - Uptime` or `Device - Polling Time`.
This command injection vulnerability allows an unauthenticated user to execute arbitrary commands if a `poller_item` with the `action` type `POLLER_ACTION_SCRIPT_PHP` (`2`) is configured. The authorization bypass should be prevented by not allowing an attacker to make `get_client_addr` (file `lib/functions.php`) return an arbitrary IP address. This could be done by not honoring the `HTTP_...` `$_SERVER` variables. If these should be kept for compatibility reasons it should at least be prevented to fake the IP address of the server running Cacti. This vulnerability has been addressed in both the 1.2.x and 1.3.x release branches with `1.2.23` being the first release containing the patch.
Published Dec 5, 2022 · Updated Oct 21, 2025
Critical · CVSS 9.8 · CISA KEV
Unauthenticated remote arbitrary code execution
Published Dec 13, 2022 · Updated Oct 21, 2025
High · CVSS 8.8 · CISA KEV
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..
Published Dec 15, 2022 · Updated Oct 21, 2025
High · CVSS 8.8 · CISA KEV
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
Published Dec 22, 2022 · Updated Oct 21, 2025
Critical · CVSS 9.6 · CISA KEV
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
Published Dec 22, 2022 · Updated Oct 21, 2025
High · CVSS 7.5
A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of the component Web Service Handler. The manipulation of the argument palette leads to command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.49.16 can resolve this issue. Upgrading the affected component is advised. The vendor points out: "FLIR AX8 internal web site has been refactored to be able to handle the reported vulnerabilities."
Published Dec 8, 2022 · Updated Oct 15, 2025
High · CVSS 7.8
Microsoft Office Visio Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Aug 27, 2025
High · CVSS 7.8
Microsoft Office OneNote Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Aug 27, 2025
High · CVSS 7.8
Windows Contacts Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Aug 27, 2025
High · CVSS 7.8
Microsoft Office Graphics Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Microsoft Office Graphics Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Microsoft Office Graphics Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.5
Microsoft Outlook for Mac Spoofing Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
DirectX Graphics Kernel Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
Medium · CVSS 5.5
Azure Network Watcher Agent Security Feature Bypass Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Raw Image Extension Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Windows Graphics Component Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 8.1
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7
Windows Error Reporting Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Windows Graphics Component Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Windows Fax Compose Form Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
Medium · CVSS 6.6
Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 8.5
PowerShell Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
Medium · CVSS 5.5
Windows Graphics Component Information Disclosure Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Windows Hyper-V Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Microsoft Office Graphics Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Microsoft Office Graphics Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Microsoft Office Graphics Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
Medium · CVSS 6.3
Outlook for Android Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 8.3
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
Medium · CVSS 6.5
Windows Kernel Denial of Service Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Windows Graphics Component Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Microsoft Office Visio Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Microsoft Office Visio Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 8.8
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Microsoft Office Graphics Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 8.8
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
Medium · CVSS 4.3
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Windows Kernel Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
Medium · CVSS 6.8
Windows Hyper-V Denial of Service Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Windows Print Spooler Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
High · CVSS 7.8
Windows Graphics Component Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
Medium · CVSS 6.5
Windows Graphics Component Information Disclosure Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025