Vulnerabilities (CVE)
Yack CVE helps teams search and track vulnerabilities.
TOTAL
390,172 CVE
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks. |
Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked authorization checks and CSRF token validation.. Users could...Show more |
Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission (age...Show more |
Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses...Show more |
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client...Show more |
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, a...Show more |
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows SQL Injection. This issue affects Access Contro...Show more |
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens within the same company by manipulating two writable Symfon...Show more |
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop...Show more |
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a fallback to the `X-API-TOKEN` header. This causes long-...Show more |
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry timestamp. Invitation links mailed to users remain valid indefinitely, meaning a leaked, forwarded, or a...Show more |
The Notiqoo WordPress plugin before 1.4.14 does not have capability checks on several of its AJAX actions and builds the name of the option to write from user input, allowing users with a role as low as contributor to m...Show more |
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitr...Show more |
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not reconcile the value of the gift card coupon it issues against the amount actually collected at checkout, allowing unauthenticated users to o...Show more |
1Adobe 3Acrobat Acrobat DcAcrobat Reader DcSep 10, 2026 Sep 8, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op...Show more |
1Adobe 3Acrobat Acrobat DcAcrobat Reader DcSep 10, 2026 Sep 8, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op...Show more |
1Adobe 3Acrobat Acrobat DcAcrobat Reader DcSep 10, 2026 Sep 8, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this i...Show more |
A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into th...Show more |
1Adobe 3Acrobat Acrobat DcAcrobat Reader DcSep 10, 2026 Sep 8, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim m...Show more |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreSep 10, 2026 Sep 8, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. |
1Adobe 3Acrobat Acrobat DcAcrobat Reader DcSep 10, 2026 Sep 8, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim m...Show more |
1Microsoft 8Windows 10 1809 Windows 10 21h2Windows 10 22h2+5 moreSep 10, 2026 Sep 8, 2026 N/A· v4 8.2 HIGH· v3 N/A· v2 Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. |
1Microsoft 5Windows 11 23h2 Windows 11 24h2Windows 11 25h2+2 moreSep 10, 2026 Sep 8, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. |
Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
1Adobe 3Acrobat Acrobat DcAcrobat Reader DcSep 10, 2026 Sep 8, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim m...Show more |