Vulnerabilities (CVE)
Yack CVE helps teams search and track vulnerabilities.
TOTAL
357,776 CVE
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API requ...Show more |
Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This issue affects : * D...Show more |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 12, 2026 Jun 9, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 12, 2026 Jun 9, 2026 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally. |
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, assistant create and update mass-assignment allows cross-workspace assistant takeover. This issue has been...Show more |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 12, 2026 Jun 9, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally. |
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJun 12, 2026 Jun 9, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 12, 2026 Jun 9, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
1Microsoft 4Windows Server 2016 Windows Server 2019Windows Server 2022+1 moreJun 12, 2026 Jun 9, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
Use after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium...Show more |
1Microsoft 15Remote Desktop Client Windows 10 1607Windows 10 1809+12 moreJun 12, 2026 Jun 9, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromiu...Show more |
Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a...Show more |
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authorization when setting the scheme_admin flag on group syncable link and pat...Show more |
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, which allows authenticated users with the {{manage_secure_connections}} pe...Show more |
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received from federated peers during shared channel file sync, which allows an a...Show more |
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-level permission when patching protected default system roles, which allows authenticated users with...Show more |
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Fail to enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation (the check was onl...Show more |
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot registration belongs to a bot account, which allows an unprivileged at...Show more |
Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded Cryptographic Key"...Show more |
The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of "CWE-1289: Improper Validation of Unsafe...Show more |
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redirection to Untrusted Site," with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N (6....Show more |
The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara.com) exhibit cross-origin request sharing, which is an instance of "CWE-942: Permissive Cross-domai...Show more |
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and has an estimated CVSS...Show more |