CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 32m ago | 8.8 | Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREENSHOT via a broadcast receiver. That would allow the application to impersonate the com.oculus.horizon package towards any endpoint within the OS that uses CallerIdentity authentication. |
| Exploit 32m ago | 7.5 | bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Directory Traversal in src/backend/bisheng/linsight/domain/task_exec.py. |
| Exploit 32m ago | 7.5 | agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, allowing the agent to access any file on the system without restriction. |
| Exploit 32m ago | 7.5 | agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks. |
| Exploit 32m ago | 8.1 | modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file. |
| Exploit 32m ago | 8.1 | modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file. |
| Exploit 32m ago | 7.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory and potentially making the application unavailable. This issue is fixed in version 6.19.0. |
| Exploit 32m ago | 7.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each content lookup, producing repeated work and long runtimes when an application accesses the embedded-file mapping. This issue is fixed in version 6.19.0. |
| Exploit 32m ago | 7.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work inside a loop when an application updates fields with flattening enabled, resulting in excessive runtimes and application unavailability. This issue is fixed in version 6.19.0. |
| Exploit 32m ago | 7.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while the earlier recovery counter fails to advance for bytes that successfully decode, causing long runtimes and application unavailability. This is a residual issue after the malformed FlateDecode recovery fix. This issue is fixed in version 6.18.1. |
| Exploit 32m ago | 7.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and consume excessive memory during operations such as text extraction. This issue is fixed in version 6.18.1. |
| Exploit 32m ago | 7.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode and retain oversized values during operations such as text extraction and consume excessive memory. This is a second follow-up to earlier /ToUnicode resource-consumption fixes and is limited to the remaining token-length path. This issue is fixed in version 6.18.1. |
| Exploit 32m ago | 7.2 | A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions. |
| Exploit 32m ago | 7.5 | An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location. |
| Exploit 32m ago | 7.2 | A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated expressions contained in the stored template body. An authenticated System Administrator could potentially store a crafted template that executed operating-system commands on the appliance when the notification was next sent. |
| Exploit 32m ago | 7.2 | An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A delegated administrator holding a single narrowly scoped administrative permission could therefore obtain full system administrator privileges, without any action by an existing system administrator. |
| Exploit 32m ago | 7.2 | Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account. |
| Exploit 32m ago | 7.2 | Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account. |
| Exploit 32m ago | 7.2 | A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges. |
| Exploit 32m ago | 7.5 | An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account. |
| Exploit 32m ago | 7 | An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including cryptographic key material and credentials, and have them sent to a destination they control. |
| Exploit 32m ago | 8.1 | A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticated session of a System Administrator who views the affected page. This could have permitted the lower-privileged administrator to escalate to full administrative control of the tenant, including the creation of a new administrative account. |
| Exploit 32m ago | 8.8 | The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the code running inside it. Code already executing within that sandbox could potentially escape its confinement and act with the privileges of the service account that runs the application, which could allow an attacker in that position to read or modify application data and configuration, or to disrupt the service on the affected appliance. |
| Exploit 32m ago | 7.4 | A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended directory, which could allow an unauthenticated attacker to write a file to any location writable by the affected service account, potentially compromising the integrity of the appliance or rendering it unavailable until an operator intervenes. Exploitation requires network access to the affected interface, which is not reachable on a fully configured appliance in its default configuration; reaching it depends on either the transient window while an appliance is first being provisioned or a non-default appliance configuration. |
| Exploit 32m ago | 8.6 | A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned more data than the form itself required. Anyone who knew the web address of a published form could potentially retrieve the form owner's Kiteworks account profile, including personal details, along with parts of the deployment's configuration settings; no passwords, authentication tokens, or multi-factor secrets were exposed. |
| Exploit 32m ago | 8.8 | A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another node of the same cluster. Insufficient input validation in an internal cluster management function let attacker-supplied values reach a privileged execution context; exploitation requires existing access to a node in the cluster, and the affected function is not reachable from outside the cluster. |
| Exploit 32m ago | 7.2 | A path traversal weakness in an optional, non-default administrative feature allowed an authenticated administrator to move files to unintended locations outside the feature's designated directory. This could potentially be leveraged to execute arbitrary code on the underlying system. |
| Exploit 32m ago | 7.8 | A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance. |
| Exploit 32m ago | 7.2 | On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of their choosing. That destination could then have operating-system commands executed on the node and receive their output, potentially resulting in remote code execution with the privileges of a local service account. |
| Exploit 32m ago | 7.2 | -A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account. |