| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The Image Source Control WordPress plugin before 2.3.1 allows users with a role as low as Contributor to change arbitrary post meta fields of arbitrary posts (even those they should not be able to edit) |
| The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download. |
| Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE. |
| In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex). |
| Microsoft Teams iOS Information Disclosure Vulnerability |
| Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| .NET Core Remote Code Execution Vulnerability |
| .NET Framework Denial of Service Vulnerability |
| HEVC Video Extensions Remote Code Execution Vulnerability |
| Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
| Microsoft Office Remote Code Execution Vulnerability |
| Windows Event Tracing Information Disclosure Vulnerability |
| Windows DirectX Information Disclosure Vulnerability |
| Microsoft SharePoint Server Spoofing Vulnerability |
| Windows Event Tracing Elevation of Privilege Vulnerability |
| Microsoft Dataverse Information Disclosure Vulnerability |
| Microsoft Edge for Android Information Disclosure Vulnerability |
| Skype for Business and Lync Denial of Service Vulnerability |
| Windows Console Driver Denial of Service Vulnerability |
| Windows TCP/IP Remote Code Execution Vulnerability |