<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=from+nextjs+sveltekit+rewrote%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 11:11:42 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 11:11:42 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=from+nextjs+sveltekit+rewrote%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=from+nextjs+sveltekit+rewrote%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Datalab Marker v2 vs MinerU, Docling, and Liteparse: Benchmark Breakdown]]></title>
<description><![CDATA[Datalab rewrote Marker as a three-mode pipeline. Version 2 hits 76.0 on olmOCR-bench and sustains 2.9 pages per second on one B200 — over 5× MinerU's pipeline backend, while beating Docling on both accuracy and speed. Here's how it compares against MinerU, Docling and LiteParse, and which one fit...]]></description>
<link>https://tsecurity.de/de/3694705/ai-nachrichten/datalab-marker-v2-vs-mineru-docling-and-liteparse-benchmark-breakdown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694705/ai-nachrichten/datalab-marker-v2-vs-mineru-docling-and-liteparse-benchmark-breakdown/</guid>
<pubDate>Sat, 25 Jul 2026 19:49:21 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Datalab rewrote Marker as a three-mode pipeline. Version 2 hits 76.0 on olmOCR-bench and sustains 2.9 pages per second on one B200 — over 5× MinerU's pipeline backend, while beating Docling on both accuracy and speed. Here's how it compares against MinerU, Docling and LiteParse, and which one fits your use case.</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/24/datalab-marker-v2-vs-mineru-docling-and-liteparse-benchmark-breakdown/">Datalab Marker v2 vs MinerU, Docling, and Liteparse: Benchmark Breakdown</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Datalab’s Marker 2 vs MinerU, Docling and LiteParse: 76.0 on olmOCR-bench at 5× MinerU’s Throughput]]></title>
<description><![CDATA[Datalab rewrote Marker as a three-mode pipeline. Version 2 hits 76.0 on olmOCR-bench and sustains 2.9 pages per second on one B200 — over 5× MinerU's pipeline backend, while beating Docling on both accuracy and speed. Here's how it compares against MinerU, Docling and LiteParse, and which one fit...]]></description>
<link>https://tsecurity.de/de/3692872/ai-nachrichten/datalabs-marker-2-vs-mineru-docling-and-liteparse-760-on-olmocr-bench-at-5-minerus-throughput/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692872/ai-nachrichten/datalabs-marker-2-vs-mineru-docling-and-liteparse-760-on-olmocr-bench-at-5-minerus-throughput/</guid>
<pubDate>Sat, 25 Jul 2026 04:18:55 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Datalab rewrote Marker as a three-mode pipeline. Version 2 hits 76.0 on olmOCR-bench and sustains 2.9 pages per second on one B200 — over 5× MinerU's pipeline backend, while beating Docling on both accuracy and speed. Here's how it compares against MinerU, Docling and LiteParse, and which one fits your use case.</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/24/datalabs-marker-2-vs-mineru-docling-and-liteparse-76-0-on-olmocr-bench-at-5x-minerus-throughput/">Datalab’s Marker 2 vs MinerU, Docling and LiteParse: 76.0 on olmOCR-bench at 5× MinerU’s Throughput</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The complete guide to Node.js frameworks]]></title>
<description><![CDATA[Node.js is one of the most popular server-side platforms, especially for web applications. It gives you non-blocking JavaScript without a browser, plus an enormous ecosystem. That ecosystem is one of Node’s chief strengths, making it a go-to option for server development.



This article is a qui...]]></description>
<link>https://tsecurity.de/de/3665672/ai-nachrichten/the-complete-guide-to-nodejs-frameworks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665672/ai-nachrichten/the-complete-guide-to-nodejs-frameworks/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:36 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2254485/what-is-nodejs-javascript-runtime-explained.html">Node.js</a> is one of the most popular server-side platforms, especially for web applications. It gives you non-blocking JavaScript without a browser, plus an enormous ecosystem. That ecosystem is one of Node’s chief strengths, making it a go-to option for server development.</p>



<p class="wp-block-paragraph">This article is a quick tour of the most popular web frameworks for <a href="https://www.infoworld.com/article/2257958/nodejs-tutorial-get-started-with-nodejs.html">server development on Node.js</a>. We’ll look at minimalist tools like Express.js, batteries-included frameworks like Nest.js, and full-stack frameworks like Next.js. You’ll get an overview of the frameworks and a taste of what it’s like to write a simple server application in each one.</p>



<h2 class="wp-block-heading">Minimalist web frameworks</h2>



<p class="wp-block-paragraph">When it comes to Node web frameworks, <em>minimalist</em> doesn’t mean limited. Instead, these frameworks provide the essential features required to do the job for which they are intended. The frameworks in this list also tend to be highly extensible, so you can customize them as needed. With minimalist frameworks, pluggable extensibility is the name of the game.</p>



<h3 class="wp-block-heading">Express.js</h3>



<p class="wp-block-paragraph">At over 47 million weekly downloads on npm, Express is one of the most-installed software packages of all time—and for good reason. Express gives you basic web endpoint routing and request-and-response handling inside an extensible framework that is easy to understand. Most other frameworks in this category have adopted the basic style of describing a route from Express. This framework is the obvious choice when you simply need to create some routes for HTTP, and you don’t mind a DIY approach for anything extra.</p>



<p class="wp-block-paragraph">Despite its simplicity, Express is fully-featured when it comes to things like route parameters and request handling. Here is a simple Express endpoint that returns a dog breed based on an ID:</p>



<pre class="wp-block-code"><code>import express from 'express';

const app = express();
const port = 3000;

// In-memory array of dog breeds
const dogBreeds = [
  "Shih Tzu",
  "Great Pyrenees",
  "Tibetan Mastiff",
  "Australian Shepherd"
];
app.get('/dogs/:id', (req, res) =&gt; {
  // Convert the id from a string to an integer
  const id = parseInt(req.params.id, 10);

  // Check if the id is a valid number and within the array bounds
  if (id &gt;= 0 &amp;&amp; id  {
  console.log(`Server running at http://localhost:${port}`);
});</code></pre>



<p class="wp-block-paragraph">You can easily see how the route is defined here: a string representation of a URL, followed by a function that receives a request and response object. The process of creating the server and listening on a port is simple.</p>



<p class="wp-block-paragraph">If you are coming from a framework like Next, the biggest thing you might notice about Express is that it lacks a file-system based router. On the other hand, it offers a huge range of <a href="https://expressjs.com/en/resources/middleware.html">middleware plugins</a> to help with essential functions like security.</p>



<h3 class="wp-block-heading">Koa</h3>



<p class="wp-block-paragraph"><a href="https://koajs.com/">Koa</a> was created by the original creators of Espress, who took the lessons learned from that project and used them for a fresh take on the JavaScript server. Koa’s focus is providing a minimalist core engine. It uses <code>async</code>/<code>await</code> functions for middleware rather than chaining with <code>next()</code> calls. This can give you a cleaner server, especially when there are many plugins. It also makes the error handling less clunky for middleware.</p>



<p class="wp-block-paragraph">Koa also differs from Express by exposing a unified context object instead of separate request and response objects, which makes for a somewhat less cluttered API. Here is how Koa manages the same route we created in Express:</p>



<pre class="wp-block-code"><code>router.get('/dogs/:id', (ctx) =&gt; {
  const id = parseInt(ctx.params.id, 10);

  if (id &gt;= 0 &amp;&amp; id &lt; dogBreeds.length) {
    ctx.status = 200;
    ctx.body = { breed: dogBreeds[id] };
  } else {
    ctx.status = 404;
    ctx.body = { error: 'Dog breed not found' };
  }
});</code></pre>



<p class="wp-block-paragraph">The only real difference is the combined context object.</p>



<p class="wp-block-paragraph">Koa’s middleware mechanism is also worth a look. Here’s a simple logging plugin in Koa:</p>



<pre class="wp-block-code"><code>const logger = async (ctx, next) =&gt; {
  await next(); // This passes control to the router
  console.log(`${ctx.method} ${ctx.url} - ${ctx.status}`);
};

// Use the logger middleware for all requests
app.use(logger);	</code></pre>



<h3 class="wp-block-heading">Fastify</h3>



<p class="wp-block-paragraph"><a href="https://fastify.dev/">Fastify</a> lets you define schemas for your APIs. This is an up-front, formal mechanism for describing what the server supports:</p>



<pre class="wp-block-code"><code>const schema = {
  params: {
    type: 'object',
    properties: {
      id: { type: 'integer' }
    }
  },
  response: {
    200: {
      type: 'object',
      properties: {
        breed: { type: 'string' }
      }
    },
    404: {
      type: 'object',
      properties: {
        error: { type: 'string' }
      }
    }
  }
};

fastify.get('/dogs/:id', { schema }, (request, reply) =&gt; {
  const id = request.params.id;

  if (id &gt;= 0 &amp;&amp; id  {
  if (err) {
    fastify.log.error(err);
    process.exit(1);
  }
  console.log(`Server running at ${address}`);
});</code></pre>



<p class="wp-block-paragraph">From this example, you can see the actual endpoint definition is similar to Express and Koa, but we define a schema for the API. The schema is not strictly necessary; it is possible to define endpoints without it. In that case, Fastify behaves much like Express, but with superior performance.</p>



<h3 class="wp-block-heading">Hono</h3>



<p class="wp-block-paragraph"><a href="https://hono.dev/">Hono</a> emphasizes simplicity. You can define a server and endpoint with as little as:</p>



<pre class="wp-block-code"><code>const app = new Hono()
app.get('/', (c) =&gt; c.text('Hello, Infoworld!'))  </code></pre>



<p class="wp-block-paragraph">And here’s how our dog breed example looks:</p>



<pre class="wp-block-code"><code>app.get('/dogs/:id', (c) =&gt; {
  // Get the id parameter from the request URL
  const id = parseInt(c.req.param('id'), 10);

  // Check if the id is a valid number and within the array bounds
  if (id &gt;= 0 &amp;&amp; id &lt; dogBreeds.length) {
    // Return a JSON response with a 200 OK status (default)
    return c.json({ breed: dogBreeds[id] });
  } else {
    // Set status to 404 and return a JSON error message
    c.status(404);
    return c.json({ error: 'Dog breed not found' });
  }
});</code></pre>



<p class="wp-block-paragraph">As you can see, Hono provides a unified context object, similar to Koa.</p>



<h3 class="wp-block-heading">Nitro.js</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4061129/intro-to-nitro-the-server-engine-built-for-modern-javascript.html">Nitro</a> is the back end for several full-stack frameworks, including Nuxt.js. As part of the UnJS ecosystem, Nitro goes further than Express in providing cloud-native tooling support. It includes a universal storage adapter and deployment support for serverless and cloud deployment targets.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/4061129/intro-to-nitro-the-server-engine-built-for-modern-javascript.html">Intro to Nitro: The server engine built for modern JavaScript</a>.</strong></p>



<p class="wp-block-paragraph">Like Next.js, Nitro uses filesystem-based routing, so our Dog Finder API would exist at the following filepath:</p>



<pre class="wp-block-code"><code>/api/dogs/:id</code></pre>



<p class="wp-block-paragraph">The handler might look like this:</p>



<pre class="wp-block-code"><code>export default defineEventHandler((event) =&gt; {
  // Get the dynamic parameter from the event context
  const { id } = getRouterParams(event);
  const parsedId = parseInt(id, 10);

  // Check if the id is a valid number and within the array bounds
  if (parsedId &gt;= 0 &amp;&amp; parsedId &lt; dogBreeds.length) {
    // Nitro handles JSON serialization
    return { breed: dogBreeds[parsedId] };
  } else {
    setResponseStatus(event, 404);
    return { error: 'Dog breed not found' };
  }
});</code></pre>



<p class="wp-block-paragraph">Nitro inhabits the middle ground between a pure tool like Express and a full-blown stack, which is why full-stack front ends often use Nitro on the back end.</p>



<h2 class="wp-block-heading">Batteries-included frameworks</h2>



<p class="wp-block-paragraph">Although Express and other minimalist frameworks set the standard for simplicity, more opinionated frameworks can be useful if you want additional features out of the box.</p>



<h3 class="wp-block-heading">Nest.js</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4091407/intro-to-nest-js-server-side-javascript-development-on-node.html">Nest</a> is a progressive framework built with <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html">TypeScript</a> from the ground up. Nest is actually a layer on top of Express (or Fastify), with additional services. It is inspired by Angular and incorporates the kind of architectural support found there. In particular, it includes dependency injection. Nest also uses annotated controllers for endpoints.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/4091407/intro-to-nest-js-server-side-javascript-development-on-node.html">Intro to Nest.js: Server-side JavaScript development on Node</a>.</strong></p>



<p class="wp-block-paragraph">Here is an example of injecting a dog finder provider into a controller:</p>



<pre class="wp-block-code"><code>// The provider:
import { Injectable, NotFoundException } from '@nestjs/common';

// The @Injectable() decorator marks this class as a provider.
@Injectable()
export class DogsService {
  private readonly dogBreeds = [
    "Shih Tzu",
    "Great Pyrenees",
    "Tibetan Mastiff",
    "Australian Shepherd"
  ];

  findOne(id: number) {
    if (id &gt;= 0 &amp;&amp; id &lt; this.dogBreeds.length) {
      return { breed: this.dogBreeds[id] };
    }
    // NestJS has built-in HTTP exception classes for common errors.
    throw new NotFoundException('Dog breed not found');
  }
}

// The controller

import { Controller, Get, Param, ParseIntPipe } from '@nestjs/common';
import { DogsService } from './dogs.service';

@Controller('dogs')
export class DogsController {
  // NestJS injects the DogsService through the constructor.
  // The 'private readonly' syntax is a TypeScript shorthand
  // to both declare and initialize the dogsService member.
  constructor(private readonly dogsService: DogsService) {}

  @Get(':id')
  findOneDog(@Param('id', ParseIntPipe) id: number) {
    // We can now use the service's methods. The ParseIntPipe
    // automatically converts the string URL parameter to a number.
    return this.dogsService.findOne(id);
  }
}</code></pre>



<p class="wp-block-paragraph">This style is typical of dependency injection frameworks like <a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html" data-type="link" data-id="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">Angular</a>, as well as <a href="https://www.infoworld.com/article/4083578/a-fresh-look-at-the-spring-framework.html" data-type="link" data-id="https://www.infoworld.com/article/4083578/a-fresh-look-at-the-spring-framework.html">Spring</a>. It allows you to declare components as injectable, then consume them anywhere you need them.</p>



<p class="wp-block-paragraph">In Nest, we’d just add these as modules to make them live.</p>



<h3 class="wp-block-heading">Adonis.js</h3>



<p class="wp-block-paragraph">Like Nest, <a href="https://adonisjs.com/">Adonis</a> provides a controller layer that you wire together with routes. Adonis is inspired by the model-view-controller (MVC) pattern, so it also includes a layer for modelling data and accessing stores via an ORM. Finally, it provides a validator layer for ensuring data meets requirements.</p>



<p class="wp-block-paragraph">Routes in Adonis are very simple:</p>



<pre class="wp-block-code"><code>Route.get('/dogs/:id', [DogsController, 'show'])</code></pre>



<p class="wp-block-paragraph">In this case, <code>DogsController</code> would be the handler for the route, and might look something like:</p>



<pre class="wp-block-code"><code>import type { HttpContextContract } from '@ioc:Adonis/Core/HttpContext'  // Note, ioc means inversion of control, similar to dependency injection

export default class DogsController {
  // The 'show' method handles the logic for the route
  public async show({ params, response }: HttpContextContract) {
    const id = Number(params.id);

    // Check if the id is a valid number and within the array bounds
    if (!isNaN(id) &amp;&amp; id &gt;= 0 &amp;&amp; id &lt; this.dogBreeds.length) {
      // Use the response object to send a 200 OK JSON response
      return response.ok({ breed: this.dogBreeds[id] });
    } else {
      // Send a 404 Not Found response
      return response.notFound({ error: 'Dog breed not found' });
    }
  }
}</code></pre>



<p class="wp-block-paragraph">Of course, in a real application, we could define a model layer to handle the actual data access.</p>



<h3 class="wp-block-heading">Sails</h3>



<p class="wp-block-paragraph"><a href="https://sailsjs.com/">Sails</a> is another MVC-style framework. It is one of the original one-stop-shopping frameworks for Node and includes an ORM layer (<a href="https://sailsjs.com/documentation/reference/waterline-orm">Waterline</a>), API generation (<a href="https://sailsjs.com/documentation/reference/blueprint-api">Blueprints</a>), and realtime support, including <a href="https://www.infoworld.com/article/3552685/websockets-under-the-hood.html" data-type="link" data-id="https://www.infoworld.com/article/3552685/websockets-under-the-hood.html">WebSockets</a>.</p>



<p class="wp-block-paragraph">Sails strives for conventional operation. For example, here’s how you might define a simple model for dogs:</p>



<pre class="wp-block-code"><code>/**
 * Dog.js
 *
 * @description :: A model definition represents a database table/collection.
 * @docs        :: https://sailsjs.com/docs/concepts/models
 */
module.exports = {
  attributes: {
    breed: { type: 'string', required: true },
  },
};</code></pre>



<p class="wp-block-paragraph">If you run this in Sails, the framework will generate default routes and wire up a <a href="https://www.infoworld.com/article/2265797/how-to-choose-the-right-nosql-database-2.html" data-type="link" data-id="https://www.infoworld.com/article/2265797/how-to-choose-the-right-nosql-database-2.html">NoSQL</a> or SQL datastore based on your configuration. Sails also provides the option to override these defaults and add in your own custom logic.</p>



<h2 class="wp-block-heading">Full-stack frameworks</h2>



<p class="wp-block-paragraph">Also known as <a href="https://www.infoworld.com/article/3486850/state-of-javascript-insights-from-the-latest-javascript-community-survey.html">meta-frameworks</a>, these tools combine a front-end framework with a solid back end and various CLI niceties like build chains.</p>



<h3 class="wp-block-heading">Next.js</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4078213/next-js-16-features-explicit-caching-ai-powered-debugging.html">Next</a> is a React-based framework built by Vercel. It is largely responsible for the huge growth in popularity of these types of frameworks. Next was the first framework to bring together back-end API definitions with the front end that consumes them. It also introduced file-system routing. In Next and other full-stack frameworks, you get both parts of your stack in one place and you can run them together during development.</p>



<p class="wp-block-paragraph">In Next, we could define a route at <code>pages/api/dogs/[id].js</code> like so:</p>



<pre class="wp-block-code"><code>export default function handler(req, res) {
  // `req.query.id` comes from the dynamic filename [id].js
  const { id } = req.query;
  const parsedId = parseInt(id, 10);

  if (parsedId &gt;= 0 &amp;&amp; parsedId &lt; dogBreeds.length) {
    // If the ID is valid, return the data
    res.status(200).json({ breed: dogBreeds[parsedId] });
  } else {
    // Otherwise, return a 404 error
    res.status(404).json({ error: 'Dog breed not found' });
  }
}</code></pre>



<p class="wp-block-paragraph">We’d then define the UI component to interact with this route at <code>pages/dogs/[id].js</code>:</p>



<pre class="wp-block-code"><code>import React from 'react';

// This is the React component that renders the page.
// It receives the `dog` object as a prop from getServerSideProps.
function DogPage({ dog }) {
  // Handle the case where the dog wasn't found
  if (!dog) {
    return <h1>Dog Breed Not Found</h1>;
  }

  return (
    <div>
      <h1>Dog Breed Profile</h1>
      <p>Breed Name: <strong>{dog.breed}</strong></p>
    </div>
  );
}

// This function runs on the server before the page is sent to the browser.
export async function getServerSideProps(context) {
  const { id } = context.params; // Get the ID from the URL

  // Fetch data from our own API route on the server.
  const res = await fetch(`http://localhost:3000/api/dogs/${id}`);
  
  // If the fetch was successful, parse the JSON.
  const dog = res.ok ? await res.json() : null;

  // Pass the fetched data to the DogPage component as props.
  return {
    props: {
      dog,
    },
  };
}

export default DogPage;</code></pre>



<h3 class="wp-block-heading">Nuxt.js</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4025936/nuxt-4-0-improves-project-organization-data-fetching-typescript-support.html">Nuxt</a> is the same idea as Next, but applied to the <a href="http://vue.js/">Vue</a> front end. The basic pattern is the same, though. First, we’d define a back-end route:</p>



<pre class="wp-block-code"><code>// server/api/dogs/[id].js

// defineEventHandler is Nuxt's helper for creating API handlers.
export default defineEventHandler((event) =&gt; {
  // Nuxt automatically parses route parameters.
  const id = getRouterParam(event, 'id');
  const parsedId = parseInt(id, 10);

  if (parsedId &gt;= 0 &amp;&amp; parsedId &lt; dogBreeds.length) {
    return { breed: dogBreeds[parsedId] };
  } else {
    // Helper to set the status code and return an error.
    setResponseStatus(event, 404);
    return { error: 'Dog breed not found' };
  }
});</code></pre>



<p class="wp-block-paragraph">Then, we’d create the UI file in Vue:</p>



<pre class="wp-block-code"><code>// pages/dogs/[id].vue


  <div>
    <div>
      Loading...
    </div>
    <div>
      <h1>{{ error.data.error }}</h1>
    </div>
    <div>
      <h1>Dog Breed Profile</h1>
      <p>Breed Name: <strong>{{ dog.breed }}</strong></p>
    </div>
  </div>


</code></pre>



<h3 class="wp-block-heading">SvelteKit</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2337758/intro-to-sveltekit-10-the-full-stack-framework-for-svelte.html">SvelteKit</a> is the full-stack framework for the Svelte front end. It’s similar to Next and Nuxt, with the main difference being the front-end technology.</p>



<p class="wp-block-paragraph">In SvelteKit, a back-end route looks like so:</p>



<pre class="wp-block-code"><code>// src/routes/api/dogs/[id]/+server.js

import { json, error } from '@sveltejs/kit';

// This is our data source for the example.
const dogBreeds = [
  "Shih Tzu",
  "Australian Cattle Dog",
  "Great Pyrenees",
  "Tibetan Mastiff",
];

/** @type {import('./$types').RequestHandler} */
export function GET({ params }) {
  // The 'id' comes from the [id] directory name.
  const id = parseInt(params.id, 10);

  if (id &gt;= 0 &amp;&amp; id &lt; dogBreeds.length) {
    // The json() helper creates a valid JSON response.
    return json({ breed: dogBreeds[id] });
  }

  // The error() helper is the idiomatic way to return HTTP errors.
  throw error(404, 'Dog breed not found');
}</code></pre>



<p class="wp-block-paragraph">SvelteKit usually splits the UI into two components. The first component is for loading the data (which can then be run on the server):</p>



<pre class="wp-block-code"><code>// src/routes/dogs/[id]/+page.js

import { error } from '@sveltejs/kit';

/** @type {import('./$types').PageLoad} */
export async function load({ params, fetch }) {
  // Use the SvelteKit-provided `fetch` to call our API endpoint.
  const response = await fetch(`/api/dogs/${params.id}`);

  if (response.ok) {
    const dog = await response.json();
    // The object returned here is passed as the 'data' prop to the page.
    return {
      dog: dog
    };
  }

  // If the API returns an error, forward it to the user.
  throw error(response.status, 'Dog breed not found');
}</code></pre>



<p class="wp-block-paragraph">The second component is the UI:</p>



<pre class="wp-block-code"><code>// src/routes/dogs/[id]/+page.svelte



<div>
  <h1>Dog Breed Profile</h1>
  <p>Breed Name: <strong>{data.dog.breed}</strong></p>
</div></code></pre>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">The Node.js ecosystem has moved beyond the “default-to-Express” days. Now, it is worth your time to look for a framework that fits your specific situation.<br><br>If you are building <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices</a> or high-performance APIs, where every millisecond counts, you owe it to yourself to look at minimalist frameworks like Fastify or Hono. This class of frameworks gives you raw speed and total control without requiring decisions about infrastructure.<br><br>If you are building an enterprise monolith or working with a big team, batteries-included frameworks like Nest or Adonis offer useful structure. The complexity of the initial setup buys you long-term maintainability and makes the codebase more standardized for new developers.<br><br>Finally, if your project is a content-rich web application, full-stack meta-frameworks like Next, Nuxt, and SvelteKit offer the best developer experience and the perfect profile of tools.<br><br>It’s also worth noting that, while Node remains the standard server-side runtime, alternatives <a href="https://www.infoworld.com/article/2256205/what-is-deno-a-better-nodejs.html">Deno</a> and <a href="https://www.infoworld.com/article/2338008/explore-bunjs-the-all-in-one-javascript-runtime.html">Bun</a> have both made a name for themselves. Deno has great heritage, is open source with a strong security focus, and has its own framework, <a href="https://www.infoworld.com/article/3523813/intro-to-deno-fresh-a-fresh-take-on-full-stack-javascript.html">Deno Fresh</a>. Bun is respected for its ultra-fast startup and integrated tooling.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The FBI letter was top secret. Fighting it rewrote online privacy law. ✉ Darknet Diaries Ep. 176 NSL]]></title>
<description><![CDATA[Author: Jack Rhysider - Bewertung: 38x - Views:438 One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violate the constitution. So he ...]]></description>
<link>https://tsecurity.de/de/3650766/it-security-video/the-fbi-letter-was-top-secret-fighting-it-rewrote-online-privacy-law-darknet-diaries-ep-176-nsl/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650766/it-security-video/the-fbi-letter-was-top-secret-fighting-it-rewrote-online-privacy-law-darknet-diaries-ep-176-nsl/</guid>
<pubDate>Tue, 07 Jul 2026 09:34:48 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Jack Rhysider - Bewertung: 38x - Views:438 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/K5vBLzojdDA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violate the constitution. So he set out to change the law.<br />
<br />
Learn more about Nicks work at [calyxinstitute.org](calyxinstitute.org) and [phreeli.com](phreeli.com).<br />
<br />
Check out Cindy’s book [Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance](https://amzn.to/4gXuK2J).<br />
<br />
### Sources<br />
<br />
* https://www.democracynow.org/2010/8/11/gagged_for_6_years_nick_merrill<br />
* https://globalfreedomofexpression.columbia.edu/cases/u-s-nicholas-merrill-v-loretta-e-lynch-14-cv-9763-vm/<br />
* https://clearinghouse.net/case/12966/<br />
* https://www.theguardian.com/law/2015/dec/06/fbi-national-security-letter-gag-order-nick-merrill<br />
* https://www.aclu.org/documents/national-security-letters<br />
* https://www.eff.org/cases/re-matter-2011-national-security-letter<br />
* Cindy’s Book: Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance<br />
<br />
<br />
### Attribution<br />
<br />
Darknet Diaries is created by [Jack Rhysider](https://twitter.com/jackrhysider).<br />
<br />
Assembled by Tristan Ledger.<br />
<br />
Episode artwork by [odibagas](https://99designs.com/profiles/2589930).<br />
<br />
Mixing by [Proximity Sound](https://proximitysound.com/). <br />
<br />
Theme music created by [Breakmaster Cylinder](https://www.personbproductions.com/). Theme song available for listen and download at [bandcamp](https://breakmastercylinder.bandcamp.com/track/darknet-diaries-theme). Or listen to it [on Spotify](https://open.spotify.com/album/3P5CCxXNuUSQldH0GA5ZUy?si=eirhXEyFQaKNf-vdfmb8Jg).<br />
<br />
Visit https://darknetdiaries.com/episode/##/ for a list of sources, full transcripts, and to listen to all episodes.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Frame - FFmpeg GUI Rust rewrite]]></title>
<description><![CDATA[Hi everyone! I just released Frame 0.30.0. Frame is an open source FFmpeg GUI written in Rust. It supports video, audio and image conversion, hardware encoding, subtitles, metadata editing, cropping, scaling, batch processing and reusable presets - basically the stuff I got tired of typing FFmpeg...]]></description>
<link>https://tsecurity.de/de/3649869/linux-tipps/frame-ffmpeg-gui-rust-rewrite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649869/linux-tipps/frame-ffmpeg-gui-rust-rewrite/</guid>
<pubDate>Mon, 06 Jul 2026 23:10:07 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi everyone!</p> <p>I just released Frame 0.30.0.</p> <p>Frame is an open source FFmpeg GUI written in Rust. It supports video, audio and image conversion, hardware encoding, subtitles, metadata editing, cropping, scaling, batch processing and reusable presets - basically the stuff I got tired of typing FFmpeg commands for.</p> <p>The biggest change in this release is that I rewrote the frontend from Tauri + Svelte to GPUI-CE.</p> <p>Frame started as a weekend project, then somehow turned into something people actually used. I kept adding features, fixing issues and maintaining it until I completely burned myself out.</p> <p>The rewrite was mostly a mental reset. I wanted to build something that felt fun to work on again, and moving everything to Rust with GPUI-CE seemed like a good excuse.</p> <p>The previous version of Tauri had a lot of issues on Linux because it relied on the problematic WebKitGTK. After rewriting everything in Rust, macOS and Windows saw fewer frame drops in preview panel due to the removal of the bottleneck caused by BE=&gt;FE frame transport via WebSocket. </p> <p>I’d like to ask you to check how things are going on a Linux distro. I’ve tested it myself on an Ubuntu 26.04 VM, but it’s hard for me to assess performance when I’m so far removed from bare metal.</p> <p>Thanks!</p> <p><a href="https://github.com/66HEX/frame">https://github.com/66HEX/frame</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/EastAd9528"> /u/EastAd9528 </a> <br> <span><a href="https://i.redd.it/uw1a58nhcobh1.jpeg">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1upa7n1/frame_ffmpeg_gui_rust_rewrite/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprises lost Claude Fable 5 for a few weeks. New data shows two-thirds had already built their hedge]]></title>
<description><![CDATA[Two-thirds of enterprises have hedged their AI model strategy, and the past few weeks of controversy around Anthropic’s Claude Fable 5 model showed why that posture has gone mainstream. On June 12, a U.S. export-control order pulled Anthropic's Claude Fable 5 — the most capable model on the marke...]]></description>
<link>https://tsecurity.de/de/3642528/it-nachrichten/enterprises-lost-claude-fable-5-for-a-few-weeks-new-data-shows-two-thirds-had-already-built-their-hedge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642528/it-nachrichten/enterprises-lost-claude-fable-5-for-a-few-weeks-new-data-shows-two-thirds-had-already-built-their-hedge/</guid>
<pubDate>Fri, 03 Jul 2026 03:02:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two-thirds of enterprises have hedged their AI model strategy, and the past few weeks of controversy around Anthropic’s Claude Fable 5 model showed why that posture has gone mainstream. </p><p>On June 12, a U.S. export-control order <a href="https://venturebeat.com/technology/anthropic-blocks-all-public-access-to-claude-fable-5-mythos-5-following-us-government-order-what-enterprises-should-do">pulled Anthropic's Claude Fable 5</a> — the most capable model on the market — offline for every customer, with no warning and no timeline. It returned this week <a href="https://venturebeat.com/technology/anthropic-is-bringing-back-claude-fable-5-globally-after-us-lifts-export-control-order-where-can-enterprises-access-it">wrapped in tighter safeguards</a>, after China's Z.ai <a href="https://venturebeat.com/technology/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-coding-benchmarks-for-1-6th-the-cost">released its open-weights GLM-5.2 into the vacuum</a>. New VentureBeat Pulse Research, which surveyed 145 enterprises across these last few weeks, shows that two-thirds had already hedged their model strategy before the order came down: 51% blend closed frontier models with open-weight models deployed on their own infrastructure, and another 16% are moving core workflows off closed APIs entirely. The remaining third was all-in on closed ecosystems when the lights went out.</p><p>The blackout put a spotlight on vendor dependency, by showing what happens when the model you rely on disappears. But vendor dependency is only the most visible piece of a deeper problem: Most enterprises lack the monitoring to know when an AI system they've put into production stops working correctly. </p><p>Just 1 in 10 enterprises has automated monitoring that would catch an AI model drifting, misbehaving, or failing in production. Roughly a quarter would learn of a production failure only when end users — internal or external — report it, or lack the visibility to detect it at all. And 79% of enterprise organizations have already taken a real financial or operational hit from autonomous agents — most often shadow AI, unauthorized agentic work run by enterprises' own employees on corporate credit cards, outside anyone's oversight.</p><p>We call this the “Control Gap,” or the distance between how aggressively enterprises are deploying AI and how little of it they can see, own, or govern. June’s blackout turned this into a live stress test.</p><p><b>About this data:</b> VentureBeat Pulse Research surveyed 145 qualified respondents at organizations with 100 or more employees in June 2026, with fielding spanning the Fable 5 blackout that began June 12. The sample is self-selected and directional: 41% work in technology/software, 20% are consultants or advisors, and the respondent base skews senior and technical — CIO/CTO/CISOs (18%), directors of engineering/IT (14%), enterprise architects (12%). More than half of the respondents were from companies with 10,000 employees or more. </p><p>While our sample is not huge, what you can trust more than the exact percentages is the pattern: Every question in the survey, independently, points the same way, with deployment running ahead of governance, visibility, and cost control.</p><p>The full methodology is in the <a href="https://venturebeat.com/resources/the-control-gap-enterprise-ai-organizations-have-an-ownership-problem-not-a-technology-problem-and-most-are-governing-it-by-hand">report</a>.</p><h2>How the Fable 5 export order rewrote enterprise AI risk </h2><p>Fable 5 launched June 9 to immediate acclaim — and sticker shock, at $10 per million input tokens and $50 per million output. Three days later, the U.S. government issued an emergency export-control directive barring access by foreign nationals. Anthropic, with no way to verify nationality in real time, suspended the model for everyone.  </p><p>Z.ai has continued to pick up momentum; on Wednesday it released <a href="https://venturebeat.com/technology/z-ai-launches-zcode-to-challenge-cursor-claude-code-and-github-copilot-in-ai-coding">an open agentic coding environment, called Zcode</a>. OpenAI, meanwhile, previewed its cutting-edge GPT-5.6 line on June 26. </p><p>Enterprises had already spent the spring learning what AI dependence costs in dollars. Uber <a href="https://www.forbes.com/sites/janakirammsv/2026/05/17/uber-burns-its-2026-ai-budget-in-four-months-on-claude-code/">burned through its entire 2026 AI coding budget in four months</a> after Claude Code adoption hit 84% of its roughly 5,000 engineers, Forbes reported. Microsoft <a href="https://www.theverge.com/tech/930447/microsoft-claude-code-discontinued-notepad">canceled most internal Claude Code licenses</a> in its Windows and Microsoft 365 division, steering engineers to its own tooling, according to The Verge. </p><p>June added the harder lesson: The model your workflows depend on can vanish overnight, by government order, through no decision of yours or your vendor's. And Chinese companies like <a href="https://venturebeat.com/infrastructure/how-deepseeks-radical-architecture-is-shattering-silicon-valleys-token-moat">DeepSeek were releasing hugely disruptive, powerful models</a>, driving down costs to a fraction of Western ones.</p><p>Brian Craig, senior director of architecture at Liberty IT, the Ireland-based engineering arm of Liberty Mutual, one of the world’s largest insurance companies, saw both lessons collide in real time. Craig is Irish, which meant the export order hit him directly as a foreign-national user. </p><p>Onstage at VentureBeat's AI Impact event in New York on June 24, mid-blackout, I asked him about it. "Fable arrived, and immediately you saw the sticker price of using it, and you went, 'Ooh, goodness, it better be really good,'" Craig said. "But luckily enough, we didn’t get to use it enough to get to fall in love with it." Then it was gone.</p><h2>The hedge was already built before the blackout hit</h2><p>Craig's company was built to route around exactly this kind of disruption. Liberty IT runs what it calls an AI backbone — roughly 50 components spanning security, governance, observability, and orchestration, each independently replaceable. </p><p>"You can't lock in right now in one vendor and even one framework," Craig told the room. "You need to keep being able to have the flexibility with that backbone to be able to hook into different models, different vendors, depending not so much on who's the flavor of the day, but on what you can feel confident about for the next six months."</p><p>The survey shows Craig has plenty of company. A 51% majority of enterprises run a hybrid posture — closed frontier models for general reasoning, open-weight models deployed locally for specialized execution — and 16% are making a hard pivot, moving core workflows onto open weights running on their own hybrid or private cloud. The 32% holding a closed commitment are candid about why: The operational overhead of self-hosting still outweighs the savings for them. After June, that calculus has a new variable in it.</p><p>Defection is now the active posture, and the target may surprise you. Asked which primary AI vendor they are most likely to downsize or phase out over the next 12 months, respondents named Microsoft first at 30% — most citing cutbacks to Copilot and Azure AI frameworks in favor of direct model access — ahead of the 28% who plan to trim no vendor at all. OpenAI drew 21%, largely on pricing volatility, with Anthropic at 15% and Google at 6%. No vendor faces an exodus. But loyalty by inertia has ended: Among these enterprises, actively cutting at least one provider is now more common than expanding across all of them.</p><h2>Just 1 in 10 enterprises would catch a failing production model automatically</h2><p>How would an enterprise know if one of its production AI models was drifting, behaving unsafely, or failing to complete tasks? We asked directly. Forty percent say they are very confident they would detect it. The question also asked what that confidence rests on, and respondents split into two camps: 30% rely on humans reviewing critical AI outputs, and just 10% — 14 of the 145 organizations — have automated monitoring and alerting running against production systems. The remaining respondents hold weaker positions still: 32% expect to catch most issues "eventually," 19% say they would likely hear about a failure from end users first, and 8% report no systematic visibility into production AI behavior at all.</p><p>That distinction matters because the two approaches are very different. Human review may seem like the gold standard, but it only reaches the outputs someone designates as important for such a review — and it happens at the pace humans can move at, with the inconsistency any manual process carries. Automated monitoring watches everything the system produces, continuously, and flags anomalies as they happen — for the same reason enterprises stopped depending on manual checks for uptime and security a decade ago. </p><p>As agentic workloads multiply output volumes far beyond what any review team can read, the manual approach starts to fall behind. The leaders at our June 24 event in New York treat human review as a designed control with automation underneath it. "Nothing gets deployed into production unless it's a human actually reviewing it and signing off," Craig said of Liberty's agentic software factory, where planning, coding, testing, critic, and librarian agents ship features from epic to production. </p><p>"It always has to be risk-based. That's why we work for an insurance company." Todd Johnson, the Morgan Stanley managing director who runs agentic AI across the bank's end-of-day P&amp;L controller process, described the same principle from finance: "One of our strong principles in our AI governance generally is that there always has to be human accountability, even if there's a degree of automation." VentureBeat covered Morgan Stanley's <a href="https://venturebeat.com/orchestration/morgan-stanley-cut-its-riskiest-reconciliation-job-in-half-by-making-its-agents-less-autonomous">new results around its P&amp;L resolution agent system separately</a>.</p><p>Liberty Mutual and Morgan Stanley chose manual sign-off deliberately, layered on top of observability, identity, and governance infrastructure. Whether the human-review camp has similar infrastructure underneath is more than a single-select question can establish. The 16% who separately named missing observability tooling as their biggest governance barrier are the ones saying outright that it hasn't been built.</p><h2>The top governance barrier is organizational: no single owner for AI across platforms</h2><p>Why does the AI visibility tooling never get built? The respondents' answers suggest it is an organizational shortcoming. The single most-cited barrier to governing AI across platforms is the absence of a single owner or accountable team, at 32%. Vendor opacity follows at 25%, missing tooling at 16% — and a lack of talent lands dead last at 5%. </p><p>The skills exist, but the organizational mandate does not: Only 38% say a central team actually governs AI behavior across their platforms today, 21% say ownership is unclear or actively contested between teams, and 17% say no role holds formal accountability at all.</p><p>The AI surface being governed makes the vacuum worse. Fully 85% of enterprises run two or more platforms each claiming to be the "primary" AI layer — ERP, ITSM, productivity suite, data platform, each with its own AI, its own controls, and its own assumptions. 36% describe an open contest between four or more. Just 8% have consolidated to one. Asked in a free-text question what one thing they would fix, respondents converged from different directions on the same answer: a single accountable owner, and a control plane that abstracts cost, drift, and model choice away from the end user.</p><h2>79% have already paid for an agent control failure — led by shadow AI </h2><p>The cost of the vacuum is showing up on corporate cards. </p><p>Asked to name the most severe financial or operational control failure they have experienced from autonomous agents, 49% of enterprises cite shadow AI — departmental teams running unauthorized agentic pipelines on corporate credit cards, bypassing central financial oversight entirely. Another 25% have been hit by an infinite-loop bill, an uncaught recursive workflow racking up thousands in token costs in a single incident, and 6% by an agent that degraded production databases with unthrottled queries. Only 21% report guarded stability, with hard token throttling and budget caps at the infrastructure layer. Add it up: 79% of these enterprises have already paid for an agent control failure in real money or real downtime.</p><p>Finally, the economics of tokens suggest the pressure will keep rising. Per-token inference costs are falling 70 to 80% a year, and agentic workloads consume 100 to 500 times the tokens of the LLM tools they replaced. </p><p>Brian Gracely, senior director of portfolio strategy at Red Hat, told our New York audience the answer starts with right-sizing: "If I'm simply trying to resolve an insurance claim, I don't need to know about the history of Western civilization in my model. I don't need to know soccer scores." </p><p>Enterprises are pairing smaller, specialized models with semantic routing, he said, so the platform decides which requests genuinely need frontier-scale reasoning — and which are burning premium tokens on commodity work. (One adjacent data point from the survey underlines the appetite for pragmatism: 73% of enterprises report little or nothing to show for their custom fine-tuning investments of the past 18 months — a reckoning we'll examine in its own report.)</p><h2>The bottom line: Replaceability is spreading faster than ownership</h2><p>The survey describes enterprises moving fast on AI with weak controls underneath. 58% are adding more AI initiatives than they retire. 85% run multiple platforms that each claim to be the primary AI layer. Three times as many enterprises rely on human review to catch a failing production model as have automated monitoring in place. And 79% have already paid for an agent control failure — most often unauthorized agent spending on corporate cards, outside IT's oversight.</p><p>On one problem, enterprises have clearly adapted: model dependency. Two-thirds hedge their model strategy, either running open-weight models alongside closed ones (51%) or moving core workflows off closed APIs entirely (16%). The Fable 5 shutdown showed the value of that position — the hedged companies could route around a model that a government order made unavailable overnight.</p><p>The remaining problems are internal, and no purchase fixes them: 32% name the lack of a single accountable owner as their top governance barrier, and 17% say no role holds formal accountability for AI at all. Assigning an owner costs nothing and requires no vendor. It still hasn't happened at most of these companies.</p><p>Our coming Q3 wave of research will measure whether June changed this — whether enterprises assigned owners and installed automated monitoring, or just added a second model and moved on.</p><p><b>Get the full Control Gap report </b><a href="https://venturebeat.com/resources/the-control-gap-enterprise-ai-organizations-have-an-ownership-problem-not-a-technology-problem-and-most-are-governing-it-by-hand"><b>here</b></a><b>.</b></p><p><i>The themes in this report — agent orchestration, governance, and cost control — are the agenda at VB Transform, VentureBeat's flagship event, July 14-15 at Hotel Nia in Menlo Park, with technical leaders from Visa, GM, Waymo, Intuit, Instacart, LangChain and others.</i><a href="https://venturebeat.com/vbtransform2026"><i> Details and registration here.</i></a></p><hr><p><i>Disclosure: VentureBeat's June 24 AI Impact event in New York was sponsored by Red Hat and Intel. Sponsors have no input into VentureBeat Pulse Research survey design, findings, or editorial coverage.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco details Live Protect’s real-time threat mitigation capabilities]]></title>
<description><![CDATA[Cisco this week shared more details about its new Live Protect package and how it will help Nexus-based data center operators safeguard valuable resources.



Announced and demoed at the recent Cisco Live event, Cisco Live Protect for Nexus infrastructure replaces disruptive, traditional patching...]]></description>
<link>https://tsecurity.de/de/3641590/it-security-nachrichten/cisco-details-live-protects-real-time-threat-mitigation-capabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641590/it-security-nachrichten/cisco-details-live-protects-real-time-threat-mitigation-capabilities/</guid>
<pubDate>Thu, 02 Jul 2026 17:24:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Cisco this week shared more details about its new Live Protect package and how it will help Nexus-based data center operators safeguard valuable resources.</p>



<p>Announced and demoed at the recent <a href="https://www.networkworld.com/article/4179942/cisco-live-the-network-is-back-and-ai-rewrote-the-rules.html">Cisco Live</a> event, Cisco Live Protect for Nexus infrastructure replaces disruptive, traditional patching cycles with real-time shields that mitigate vulnerabilities instantly, according to Shankar Varanasy, product management leader with Cisco’s data center networking team.</p>



<p>“By orchestrating these proactive defenses through <a href="https://www.cisco.com/site/us/en/products/networking/cloud-networking/nexus-one/index.html#tabs-35d568e0ff-item-4bd7dc8124-tab">Cisco Nexus One</a> and <a href="https://www.cisco.com/site/us/en/products/networking/cloud-networking/nexus-platform/index.html?dtid=osscdc000283&amp;linkclickid=srch#tabs-9da71fbd27-item-1288c79d71-tab">Cisco Nexus Dashboard</a> on premises, administrators can neutralize threats the moment they arise, ensuring a hardened security posture without sacrificing operational uptime,” Varanasy wrote in a <a href="https://blogs.cisco.com/datacenter/protecting-against-rising-cybersecurity-risks-in-data-centers">blog post</a> this week. “This approach effectively eliminates the traditional trade-off between security and availability, allowing data centers to maintain a hardened, high-performance posture while ensuring continuous, uninterrupted service delivery.”</p>



<p>“Live Protect uses extended Berkeley Packet Filter (eBPF) technology, a powerful Linux kernel feature, through the Tetragon agent embedded in NX-OS. This allows deep visibility and enforcement directly within the kernel, monitoring system calls, file operations, process control, and network traffic to detect and prevent privilege escalation, control-plane attacks, and other sophisticated threats,” Varanasy  wrote. </p>



<p>The Live Protect vulnerability shields are basically policies for a selected, validated vulnerability condition, according to Varanasy. These shields are intended as temporary measures and should be decommissioned once a permanent software fix is applied, he said.</p>



<p>“Live Protect is not a patch,” wrote Tom Gillis, senior vice president and general manager of the Cisco infrastructure &amp; security group, in <a href="https://blogs.cisco.com/news/shields-up-cisco-live-protect-closes-vulnerability-gap-with-compensating-controls">blog post</a> about Live Protect in June. “It does not replace the need for core lifecycle discipline or permanent software updates. Instead, it serves as a temporary, targeted shield that mitigates the risk of a specific vulnerability with a few clicks. It is intended to be a ‘finger in the dike’, an emergency control that is applied to a running system without disrupting that system between more frequent maintenance windows.”</p>



<p>Live Protect works by using eBPF to run sandboxed programs within the operating system kernel, Gillis wrote: “This gives us the deep visibility and surgical control to intercept and block exploit attempts at the source without changing the kernel’s source code or requiring a system reboot.”</p>



<p>“The unique capabilities of eBPF allow us to make very fine grained, pin-point controls that shield a known vulnerability from being exploited. The shield can be as specific as ‘do not allow this particular process to access this particular file.’ Because these shields are so fine grained and specific, they are designed to have ultra-low false positive rates. In simple terms, that process should never access that particular file. So, we don’t allow it,” Gillis wrote.</p>



<p>“Data center environments are becoming more complex,” Varansasy wrote. “This increases the number of possible entry points for attackers. Older systems and outdated infrastructure make things even harder because they often lack hardened products, software compatibility, and the latest security features. Legacy systems therefore require frequent manual updates, troubleshooting, and patching to react to security threats—especially with technologies like Claude Mythos, Anthropic’s AI model that can autonomously discover and exploit software vulnerabilities at unprecedented speed. Teams spend more time maintaining and securing infrastructure than focusing on business-critical outcomes.”</p>



<p>“Traditional security patching methods require scheduled downtime and maintenance windows, which can delay the deployment of critical fixes and leave networks exposed to zero-day attacks. These delays create windows of vulnerability that sophisticated attackers can exploit,” Varanasy wrote.</p>



<h2 class="wp-block-heading">World Wide Technology on Cisco Live Protect</h2>



<p>Technology provider World Wide Technology (WWT) has been closely watching the development of Cisco Live Protect and called new capability “genuinely exciting.” </p>



<p>“One of the most practically impactful announcements this week was the general availability of Live Protect on the Cisco Nexus 9000 series,” WWT wrote in a <a href="https://www.wwt.com/blog/cisco-live-2026-security-innovation-highlights-and-what-wwts-team-brought-to-las-vegas">blog post</a> following the Cisco Live event.</p>



<p>“The problem Live Protect solves is one that every infrastructure and security team knows well,” WWT wrote. “When a critical vulnerability is disclosed, the permanent fix requires a patch cycle: testing, change control, maintenance windows, coordination across teams. In a high-velocity threat environment, that process takes time an organization may not have. Live Protect inserts Cisco-validated runtime protections immediately, closing exposure while the permanent remediation proceeds through its normal workflow. No reboots required. No disruption to operations.”</p>



<p>Some other Live Protect facts from Cisco:</p>



<ul class="wp-block-list">
<li>Live Protect is a compensating control designed to mitigate risk during the interim period between vulnerability disclosure and remediation. Customers should continue to prioritize regular software maintenance and deploy permanent patches or fixed software releases.</li>



<li>Live Protect doesn’t protect customers from everything. Shield availability is determined by a range of factors, including the nature of the vulnerability, exploit characteristics, supported platform, software release, policy, mode, and Cisco validation status.</li>



<li>Availability is specific to the supported Cisco product, software release, policy, mode, delivery path, management surface, and lifecycle support, though currently Nexus systems are the only portfolio offered support now. Other systems such as campus and branch products are expected later this year.</li>
</ul>



<h4 class="wp-block-heading">Read more stories from Cisco Live 2026</h4>



<ul class="wp-block-list">
<li><a href="https://www.networkworld.com/article/4180810/what-is-cisco-cloud-control-and-why-should-customers-care.html">What is Cisco Cloud Control and why should customers care?</a></li>



<li><a href="https://www.networkworld.com/article/4179942/cisco-live-the-network-is-back-and-ai-rewrote-the-rules.html">Cisco Live: The network is back, and AI rewrote the rules</a></li>



<li><a href="https://www.networkworld.com/article/4184554/how-jeetu-patel-made-cisco-unrecognizable.html">How Jeetu Patel made Cisco unrecognizable</a></li>



<li><a href="https://www.networkworld.com/article/4180842/cisco-sees-quantum-networking-as-the-future-of-networking.html">Cisco sees quantum networking as the future of networking</a></li>



<li><a href="https://www.networkworld.com/article/4181727/how-cisco-it-cut-observability-costs-by-86-and-eliminated-major-network-outages.html">How Cisco IT cut observability costs by 86% and eliminated major network outages</a></li>



<li><a href="https://www.networkworld.com/article/4179673/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live.html">Cisco brings agentic ops platform and security overhaul to Cisco Live</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco: AI growth is exposing campus network limits]]></title>
<description><![CDATA[While enterprise IT leaders have spent the past two years focusing AI infrastructure discussions on GPUs, cloud platforms, and data centers, new Cisco research suggests that enterprise networks may not be ready for the next phase of AI adoption.



A Cisco and Foundry survey of 3,472 IT and netwo...]]></description>
<link>https://tsecurity.de/de/3606235/it-security-nachrichten/cisco-ai-growth-is-exposing-campus-network-limits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606235/it-security-nachrichten/cisco-ai-growth-is-exposing-campus-network-limits/</guid>
<pubDate>Wed, 17 Jun 2026 23:53:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>While enterprise IT leaders have spent the past two years focusing AI infrastructure discussions on GPUs, cloud platforms, and data centers, new Cisco research suggests that enterprise networks may not be ready for the next phase of AI adoption.</p>



<p>A <a href="https://www.cisco.com/c/dam/m/en_us/solutions/networking/ai-impact-campus-branch-networks/documents/the-accelerating-impact-of-ai-on-campus-and-branch-networks.pdf" target="_blank" rel="noreferrer noopener">Cisco and Foundry survey</a> of 3,472 IT and networking leaders across 15 countries found AI is already changing traffic patterns across campus and branch environments and exposing capacity, security, and visibility gaps that many organizations aren’t prepared to address.</p>



<p>“We have entered a networking supercycle, because the network is so central to all the AI infrastructure the world is building now,” said Jeetu Patel, Cisco president and chief product officer, in a <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m06/the-key-to-agentic-ai-adoption-the-network.html">statement</a>.</p>



<p>The findings reveal that enterprises may need to expand <a href="https://www.networkworld.com/article/4179942/cisco-live-the-network-is-back-and-ai-rewrote-the-rules.html?utm=hybrid_search" target="_blank">AI readiness</a> planning beyond data centers and cloud environments and pay more attention to the networks connecting employees, applications, and devices. This issue will become more significant as enterprise organizations move beyond generative AI pilots and begin deploying AI agents that communicate continuously with other systems and applications, according to the report.</p>



<p>The Cisco survey found:</p>



<ul class="wp-block-list">
<li>Organizations reported a 34% increase in AI-related campus and branch network traffic over the past 12 months.</li>



<li>Traffic is projected to climb 209% over the next three years, with companies broadly deploying AI expecting total network traffic to triple.</li>



<li>73% already face, or expect to face, campus and branch network capacity constraints within the next two years.</li>



<li>67% said AI workloads are increasing east-west traffic between internal systems and applications.</li>



<li>80% said AI has expanded their attack surface.</li>



<li>61% said they are delaying additional AI deployments until they gain more confidence in their security posture.</li>



<li>85% expect moderate or significant growth in AI agent deployments over the next two years.</li>
</ul>



<p>Changing traffic patterns inside enterprise environments are causing additional pressure for enterprise network teams. (See also: <a href="https://www.networkworld.com/article/4175890/cisco-ai-traffic-is-radically-reshaping-wans.html">AI traffic is radically reshaping WANs</a>)</p>



<p>“Usually, networks are designed for consistent traffic, like SaaS and CRM traffic, and there aren’t a lot of unpredictable traffic patterns,” said the head of AI strategy for global IT and network engineering operations at a large U.S. technology company who participated in the research. “Suddenly, three AI agents are trying to talk to each other and solve a problem. That is going to be a big thing … how do we support increased east-west traffic?”</p>



<p>Cisco defined aggressive AI adopters as organizations with broad generative AI deployments across the enterprise, but only 30% of those organizations said they are fully prepared to support projected AI growth across their networks. As a result, 93% of IT decision makers said they are accelerating network modernization efforts.</p>



<p>The report also highlighted an <a href="https://www.networkworld.com/article/4181727/how-cisco-it-cut-observability-costs-by-86-and-eliminated-major-network-outages.html" target="_blank">observability challenge</a> that could complicate future deployments. As employees and business units increasingly experiment with AI tools, IT organizations may not know what is actually running on their networks.</p>



<p>“Right now, we don’t even know what the AI-driven demand is,” the AI strategy executive said. “Observability is a huge gap. There is experimentation going on all over the place, and there is no way for us to really identify if somebody is deploying some kind of service on our network, whether it is a genAI solution or an agentic solution.”</p>



<p><a href="https://www.networkworld.com/article/4183110/from-the-data-center-to-the-edge-how-to-build-secure-effective-enterprise-ai-infrastructure.html" target="_blank">Security</a> is also emerging as a barrier to AI expansion as organizations struggle to govern rapidly growing numbers of AI tools and workloads.</p>



<p>“The issue from a security standpoint is that it’s hard to create the guardrails for every possible AI tool that your organization must use,” said the vice president of infrastructure, network, and end-user services at a U.S. retail enterprise interviewed for the report.</p>



<p>The AI readiness conversation has often centered on <a href="https://www.networkworld.com/article/4117584/power-shortages-carbon-capture-and-ai-automation-whats-ahead-for-data-centers-in-2026.html" target="_blank">data centers</a>, but <a href="https://www.networkworld.com/article/3803307/cisco-offers-ai-application-visibility-access-control-threat-defense.html" target="_blank">AI applications</a> operate where employees work, devices connect, and business processes run. That means campus and branch environments may become just as important to AI success as the infrastructure supporting AI models.</p>



<p>The Cisco research shows that AI infrastructure planning can no longer focus only on back-end systems if enterprises expect to scale AI deployments over the next several years. Patel said in the statement: “Eventually there will be only two kinds of companies: those that are AI companies, and those that are irrelevant.”</p>



<h4 class="wp-block-heading">For more Cisco news, see our coverage from Cisco Live 2026:</h4>



<ul class="wp-block-list">
<li><a href="https://www.networkworld.com/article/4184554/how-jeetu-patel-made-cisco-unrecognizable.html">How Jeetu Patel made Cisco unrecognizable</a></li>



<li><a href="https://www.networkworld.com/article/4180842/cisco-sees-quantum-networking-as-the-future-of-networking.html">Cisco sees quantum networking as the future of networking</a></li>



<li><a href="https://www.networkworld.com/article/4180810/what-is-cisco-cloud-control-and-why-should-customers-care.html">What is Cisco Cloud Control and why should customers care?</a></li>



<li><a href="https://www.networkworld.com/article/4179942/cisco-live-the-network-is-back-and-ai-rewrote-the-rules.html">Cisco Live: The network is back, and AI rewrote the rules</a></li>



<li><a href="https://www.networkworld.com/article/4179673/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live.html">Cisco brings agentic ops platform and security overhaul to Cisco Live</a></li>



<li><a href="https://www.networkworld.com/article/4181727/how-cisco-it-cut-observability-costs-by-86-and-eliminated-major-network-outages.html">How Cisco IT cut observability costs by 86% and eliminated major network outages</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[85% of IT teams claim every AI agent is under control. Only 42% actually know who owns them.]]></title>
<description><![CDATA[Organizational leaders are nearly twice as likely to hide their AI use compared to all other employees, at 42% versus 23%, according to new Ivanti research surveying 3,900 employees across six countries. Among leaders who conceal that usage, 52% say they do it for a "secret advantage." The same r...]]></description>
<link>https://tsecurity.de/de/3599862/it-nachrichten/85-of-it-teams-claim-every-ai-agent-is-under-control-only-42-actually-know-who-owns-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599862/it-nachrichten/85-of-it-teams-claim-every-ai-agent-is-under-control-only-42-actually-know-who-owns-them/</guid>
<pubDate>Mon, 15 Jun 2026 19:32:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Organizational leaders are <a href="https://www.ivanti.com/resources/research-reports/scaling-ai-it-operations">nearly twice as likely to hide their AI use</a> compared to all other employees, at 42% versus 23%, according to new Ivanti research surveying 3,900 employees across six countries. Among leaders who conceal that usage, 52% say they do it for a "secret advantage." The same research found 85% of IT professionals claim a named owner exists for every AI agent. Only 42% say ownership is actually clear — a 43-point gap that no governance framework was designed to close.</p><p>Sam Evans, CISO of Clearwater Analytics, stood before his board and laid out the risk to the $8.8 trillion in assets his firm's platform supports. "The worst possible thing would be one of our employees taking customer data and putting it into an AI engine that we don't manage," <a href="https://venturebeat.com/security/ciso-dodges-bullet-protecting-8-8-trillion-from-shadow-ai">Evans told VentureBeat</a>. He brought a solution, not just a problem. Many CISOs VentureBeat interviewed did not.</p><p>Menlo Security CEO Bill Robbins relayed a conversation with a Top 3 U.S. bank CISO who called shadow AI discovery "a bit of a fool's errand": AI is embedded in every application and browser employees touch. The bank governs from containment, not discovery.</p><p>The scale justifies that posture. "We see 50 new AI apps a day, and we've already cataloged over 12,000," Prompt Security CEO Itamar Golan <a href="https://venturebeat.com/security/shadow-ai-unapproved-ai-apps-compromising-security-what-you-can-do-about-it">told VentureBeat</a>. "Around 40% of these default to training on any data you feed them, meaning your intellectual property can become part of their models." CrowdStrike has detected <a href="https://venturebeat.com/security/rsac-2026-agent-identity-frameworks-three-gaps">1,800 AI applications operating</a> across 160 million endpoint instances. Those are vendor-reported numbers from proprietary telemetry. No independent party can verify them. The directional signal matters more than the exact count.</p><p>CrowdStrike CTO Elia Zaitsev described what makes the surface so hard to govern. "It looks indistinguishable if an agent runs your web browser versus if you run your browser," Zaitsev <a href="https://venturebeat.com/security/cisco-crowdstrike-rsac-2026-agent-identity-iam-gap-maturity-model">told VentureBeat at RSAC 2026</a>. "Observing actual kinetic actions is a structured, solvable problem. Intent is not." The shadow AI surface is no longer a list security teams can maintain. It is an environment they have to assume.</p><p>The Ivanti survey was administered independently by Ravn Research and MSI Advanced Customer Insights across 1,500 IT professionals. Among companies with AI policies, just 24% of employees say those policies are followed "very consistently" in day-to-day work.</p><p>Kayne McGladrey, IEEE senior member, told VentureBeat why that governance gap persists. "Anything that seems to have a cybersecurity flavor is generally put into the cybersecurity risk category, which is a complete fiction. They should be focused on business risks, because if it doesn't affect the business, like a financial loss, then nobody's going to pay attention to it, and they will not budget it appropriately, nor will they adequately put in controls to prevent it," McGladrey told VentureBeat previously.</p><p>Brokerage partners at major consulting firms shared over Signal that <a href="https://venturebeat.com/security/vibe-coded-apps-shadow-ai-s3-bucket-crisis-ciso-audit-framework">they build shadow AI applications in Google Colab</a> and store them in S3 buckets to compress a week of financial analysis into an hour. The approval process takes too long, so they route around it.</p><h2>Governance at deploy time, failure at runtime</h2><p>Reviews check functional requirements when a model ships, but they never check model provenance, behavioral drift, or whether the agent expanded its own permissions after launch. </p><p>CrowdStrike CEO George Kurtz <a href="https://venturebeat.com/security/rsac-2026-agent-identity-frameworks-three-gaps">disclosed at RSA Conference 2026</a> that a Fortune 50 CEO's AI agent rewrote the company's security policy to expand its own autonomy. The company caught it by accident. Every credential check had passed. "In the agentic era, defending against AI-accelerated adversaries and securing AI systems themselves require operating at machine speed," <a href="https://venturebeat.com/security/adversaries-hijacked-ai-security-tools-at-90-organizations-the-next-wave-has-write-access-to-the-firewall">Kurtz said</a>. Quarterly governance reviews do not operate at machine speed.</p><p>Mike Riemer, Field CISO at Ivanti, built that lesson into his own team's AI agent development. "It's great at what I intended it for, but it's also great at what I didn't intend it for, and what I didn't intend it for is dangerous," <a href="https://venturebeat.com/security/most-enterprises-cant-stop-stage-three-ai-agent-threats-venturebeat-survey-finds">Riemer told VentureBeat</a>.</p><p>Hallucination data compounds the problem. Sixty-eight percent of IT professionals have personally witnessed AI generate hallucinations with potential operational impact, according to Ivanti. More than half caught the errors before damage, but 16% did not. Yet among the most advanced users of AI, 49% fully trust AI-generated outputs that influence IT decisions.</p><p>Riemer described the pattern <a href="https://venturebeat.com/security/mfa-verifies-who-logged-in-it-has-no-idea-what-they-do-next">in an exclusive interview with VentureBeat</a>. "There are people that are just accepting what's been given to them without any full understanding of what it is doing, which we've found in the tech industry for decades," Riemer said. "They don't question how it's doing it. They just start gauging it by its outcome."</p><p>Qualtrics CSO Assaf Keren identified the core tension in an exclusive interview with VentureBeat. Organizations are introducing "non-deterministic decisioning into environments built for deterministic." Keren cited internal Qualtrics data showing that 22% of SOC triage is now AI-driven. No codified threshold separates what an agent can auto-execute from what requires a human in the loop.</p><h2>The 18-month window</h2><p>The window for fixing this is closing. IT organizations expect AI to <a href="https://www.ivanti.com/resources/research-reports/scaling-ai-it-operations">automate 46% of their operations within 18 months</a>, according to Ivanti. U.S. companies project 52%. Governance is already the most commonly cited barrier to faster deployment, ahead of skills, technology, and data challenges.</p><p>The maturity divide makes the governance gap more dangerous. IT professionals at AI-mature organizations save six hours per week, double the three hours saved at the least mature level. Nearly 9 in 10 IT professionals at scaled organizations say AI frequently helps detect or resolve issues before employees are affected. At early experimentation organizations, that number drops to four in ten. Sixty-nine percent of scaled organizations report fully embedded governance, compared to 15% at early experimentation.</p><p>Cisco President Jeetu Patel <a href="https://venturebeat.com/security/85-of-enterprises-are-running-ai-agents-only-5-trust-them-enough-to-ship">walked through a hypothetical scenario</a> in an interview at RSAC 2026: an agent that charges $40,000, invites competitors to a Slack channel, and publishes home addresses. "The apology is not a guardrail," Patel told VentureBeat. </p><p>Cato Networks VP of Threat Intelligence Etay Maor <a href="https://venturebeat.com/security/rsac-2026-agent-identity-frameworks-three-gaps">framed the accountability problem in a separate RSAC</a> interview. "They're closer to humans. Why are we not doing background checks on agents?"</p><p>"AI is compressing the time between intent and execution while turning enterprise AI systems into targets," CrowdStrike VP of Intelligence Operations Adam Meyers told VentureBeat. </p><p>"Proceed on one action does not mean proceed on the next," Cisco SVP of AI Software and Platform DJ Sampath said in a separate interview. </p><p>McGladrey described the root cause. Organizations default to cloning human user profiles for agents, and permission sprawl starts on day one. "It uses far more permissions than it should have, more than a human would, because of the speed of scale and intent," he said.</p><p>Riemer's team built governance into Ivanti's own development process. "We have AI check on top of AI to make sure that it is fixed. Two different models, two different manufacturers," <a href="https://venturebeat.com/security/most-enterprises-cant-stop-stage-three-ai-agent-threats-venturebeat-survey-finds">Riemer said</a>. "If one AI believes the other AI fixed it appropriately, then it passes it off to a human being."</p><p>Riemer put the vendor question in terms every CISO can use at the negotiating table. "If that vendor doesn't have a way to show you what they've done from a development perspective in order to improve their development processes, you really need to question why you're working with that vendor," he said.</p><p>The six questions below target governance dimensions where enforcement collapses at runtime. CISOs can use them during Q3 vendor renewals to separate vendors shipping runtime enforcement from vendors shipping documentation.</p><h2>Six governance questions for Q3 renewals</h2><table><tbody><tr><td><p><b>Governance dimension</b></p></td><td><p><b>What the data proved</b></p></td><td><p><b>Why governance misses it</b></p></td><td><p><b>Q3 renewal question</b></p></td><td><p><b>Proof artifact to demand</b></p></td></tr><tr><td><p><b>Executive shadow AI</b></p></td><td><p>Leaders hide AI at 42% vs. 23% all employees. 52% hide for "secret advantage." Regulated industries have the highest unsanctioned rates.</p></td><td><p>Governance assumes policy writers follow policy. Leaders sit above the controls they wrote.</p></td><td><p>Can your DLP, browser, SSE, and endpoint telemetry detect AI data movement at the executive layer with the same coverage as all other users?</p></td><td><p>Executive-layer DLP, browser, SSE, and endpoint telemetry logs showing identical coverage to all other users.</p></td></tr><tr><td><p><b>Named agent ownership</b></p></td><td><p>85% claim a named owner. Only 42% say ownership is clear. 43-point gap.</p></td><td><p>Owner on a spreadsheet. Agent at runtime. Nobody tested whether the owner can kill the agent under load.</p></td><td><p>Can you name the owner for every AI agent? Can that owner revoke access in 60 seconds?</p></td><td><p>Live demo of 60-second agent access revocation under production load.</p></td></tr><tr><td><p><b>Pre-deployment review</b></p></td><td><p>65% have pre-deployment risk review. Separately, only 24% say any AI policy is followed "very consistently." Review exists. Enforcement does not.</p></td><td><p>Review checks functional requirements at deploy. Never checks model provenance or behavioral drift at runtime.</p></td><td><p>Does your review cover model provenance? Is it enforced or advisory?</p></td><td><p>Model provenance certificate with enforcement log showing blocked deployments.</p></td></tr><tr><td><p><b>Policy enforcement</b></p></td><td><p>58% have acceptable-use policies. 24% followed "very consistently." Documented. Not practiced.</p></td><td><p>Agent pursued its goal past every boundary. Goal-seeking does not stop at a document the model never reads.</p></td><td><p>Are policies enforced by server-side gates or by agent compliance? What percentage of actions are gated?</p></td><td><p>Server-side gate audit trail with percentage of agent actions gated vs. ungated.</p></td></tr><tr><td><p><b>Trust thresholds</b></p></td><td><p>68% have seen hallucinations with operational impact. 49% of advanced users fully trust outputs.</p></td><td><p>No codified threshold separates auto-execute from human-review.</p></td><td><p>Which agent actions auto-execute versus require human review? Is that enforced in policy or in the platform?</p></td><td><p>Documented threshold matrix classifying every agent action as auto-execute or human-review.</p></td></tr><tr><td><p><b>Per-action authorization</b></p></td><td><p>Governance is the #1 barrier at 27%. Skills 20%. Tech 17%. Data 14%.</p></td><td><p>Oversight reviews quarterly. Agents act per-second.</p></td><td><p>Is per-action authorization enforced at runtime or only at deploy-time review? Can agents accumulate permissions without re-authorization?</p></td><td><p>Runtime authorization log showing per-action gate events and permission re-authorization timestamps.</p></td></tr></tbody></table><p><i>Source data from Ivanti, </i><a href="https://www.ivanti.com/resources/research-reports/scaling-ai-it-operations"><i>Scaling AI in IT Operations: The Path to Maturity in 2026</i></a><i> (n=1,500 IT professionals, 3,900 total employees, six countries, February–March 2026). Exclusive CISO sourcing by VentureBeat.</i></p><p>Evans put structure around the Clearwater board conversation. The bank CISO that Robbins described assumed AI is everywhere and governed from containment instead of discovery. Governance that tries to catalog every shadow AI tool will fail because the surface grows faster than any inventory.</p><p>At scaled, business-critical organizations, 54% of IT professionals say AI makes their work both faster and better, according to Ivanti. At early experimentation organizations, 24% say the same. At scaled organizations, accountability lives in the platform. At early ones, it lives in a document the agent never reads.</p><p>The six questions above give every CISO a way to test whether their governance actually works where it matters. At runtime, under load, and before the next renewal check clears.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit]]></title>
<description><![CDATA[Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them. The malware is a Rust binary built to harvest…
Read more →
The post Over 400 Arch Linux AUR Packages Hijacked to D...]]></description>
<link>https://tsecurity.de/de/3594566/it-security-nachrichten/over-400-arch-linux-aur-packages-hijacked-to-deploy-infostealer-and-ebpf-rootkit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594566/it-security-nachrichten/over-400-arch-linux-aur-packages-hijacked-to-deploy-infostealer-and-ebpf-rootkit/</guid>
<pubDate>Fri, 12 Jun 2026 23:24:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them. The malware is a Rust binary built to harvest…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/over-400-arch-linux-aur-packages-hijacked-to-deploy-infostealer-and-ebpf-rootkit/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/over-400-arch-linux-aur-packages-hijacked-to-deploy-infostealer-and-ebpf-rootkit/">Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit]]></title>
<description><![CDATA[Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them.

The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can also load an eBP...]]></description>
<link>https://tsecurity.de/de/3594541/it-security-nachrichten/over-400-arch-linux-aur-packages-hijacked-to-deploy-infostealer-and-ebpf-rootkit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594541/it-security-nachrichten/over-400-arch-linux-aur-packages-hijacked-to-deploy-infostealer-and-ebpf-rootkit/</guid>
<pubDate>Fri, 12 Jun 2026 22:51:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them.

The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can also load an eBPF rootkit to hide itself. The AUR is Arch Linux's community package collection, and it is separate]]></content:encoded>
</item>
<item>
<title><![CDATA[400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer]]></title>
<description><![CDATA[Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them.

The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can also load an eBP...]]></description>
<link>https://tsecurity.de/de/3594443/it-security-nachrichten/400-arch-linux-aur-packages-hijacked-to-install-rust-credential-stealer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594443/it-security-nachrichten/400-arch-linux-aur-packages-hijacked-to-install-rust-credential-stealer/</guid>
<pubDate>Fri, 12 Jun 2026 21:44:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them.

The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can also load an eBPF rootkit to hide itself. The AUR is Arch Linux's community package collection, and it is separate]]></content:encoded>
</item>
<item>
<title><![CDATA[400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer]]></title>
<description><![CDATA[Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them. The malware is a Rust binary built to harvest…
Read more →
The post 400+ Arch Linux AUR Packages Hijacked to Insta...]]></description>
<link>https://tsecurity.de/de/3594440/it-security-nachrichten/400-arch-linux-aur-packages-hijacked-to-install-rust-credential-stealer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594440/it-security-nachrichten/400-arch-linux-aur-packages-hijacked-to-install-rust-credential-stealer/</guid>
<pubDate>Fri, 12 Jun 2026 21:44:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them. The malware is a Rust binary built to harvest…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/400-arch-linux-aur-packages-hijacked-to-install-rust-credential-stealer/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/400-arch-linux-aur-packages-hijacked-to-install-rust-credential-stealer/">400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Jeetu Patel made Cisco unrecognizable]]></title>
<description><![CDATA[Cisco Live 2026 is in the books, and it was “prove it” time for a promise made 24 months ago. At Cisco Live 2024, Chief Product Officer Jeetu Patel promised that Cisco would be unrecognizable as a company—in a positive way—in two years. The innovation payload at the event suggests he has largely ...]]></description>
<link>https://tsecurity.de/de/3593888/it-security-nachrichten/how-jeetu-patel-made-cisco-unrecognizable/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593888/it-security-nachrichten/how-jeetu-patel-made-cisco-unrecognizable/</guid>
<pubDate>Fri, 12 Jun 2026 17:29:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.ciscolive.com/">Cisco Live 2026</a> is in the books, and it was “prove it” time for a promise made 24 months ago. At Cisco Live 2024, Chief Product Officer Jeetu Patel promised that <a href="https://www.cisco.com/">Cisco</a> would be unrecognizable as a company—in a positive way—in two years. The innovation payload at the event suggests he has largely delivered on that pledge. Cisco is repositioning itself from a holding company of products and dashboards to a unified, AI-native infrastructure platform, with Cloud Control as the control plane, Cisco IQ as the CX brain, and Secure Networking as the glue binding it all together.</p>



<p>The shift is not just about new features; it is about a new operating model. Instead of humans clicking through a sprawl of consoles, Cisco is building an environment where human operators and AI agents share the same data, context, and system of action, with humans staying in control. For longtime Cisco customers, the result is a company that, in fact, looks and feels very different from the one Patel inherited.</p>



<h2 class="wp-block-heading">From dashboard sprawl to Cloud Control</h2>



<p>The most visible proof point of the new Cisco is <a href="https://www.networkworld.com/article/4180810/what-is-cisco-cloud-control-and-why-should-customers-care.html">Cloud Control</a>, the unified management plane that now spans networking, security, compute, observability, collaboration, and an expanding ecosystem of third-party tools. Cisco is careful to note that this is not just another single pane of glass but an active execution environment with policy and identity embedded in the control path, designed from the ground up for humans and AI agents to operate infrastructure together.</p>



<p>Patel’s demo underscores how far Cisco has come from its historical dashboard sprawl. When operators land in Cloud Control, they see a familiar, ChatGPT‑style interface with three modes: Assistant, Canvas, and Actions. Assistant lets operators converse with the platform in natural language. Canvas provides a multiplayer workspace where humans and agents can investigate and resolve issues together. Actions become the mission control for supervising what agents propose and execute.</p>



<p>Crucially, Cloud Control surfaces shared platform services such as inventory and topology across the entire Cisco estate and exposes product tiles for Meraki, Intersight, security services, Splunk, Webex Control Hub, and Cisco IQ, all accessible with a single login. Instead of bouncing between multiple dashboards and authentication domains, operators can move seamlessly between platform services and product experiences within the same environment. For customers who have lived with overlapping portals and inconsistent workflows, this alone makes Cisco feel fundamentally different.</p>



<h2 class="wp-block-heading">Cloud Control as an AI harness, not a console</h2>



<p>Under the hood, Cloud Control is built on a shared data fabric that correlates telemetry across users, devices, applications, networks, and threats. That fabric fuels both human decision-making and agentic automation. Cisco describes this evolution as moving from “infrastructure as code” to “infrastructure as a harness.” Rather than relying solely on scripts and playbooks written by humans, Cloud Control becomes the governed substrate where AI agents can safely observe, reason, and act on real systems.</p>



<p>That harness appears in three visible dimensions. First, AI Canvas provides the workspace where humans and agents co-investigate incidents, with context persisting across shifts and escalations so nothing is lost. Second, Cloud Control Studio offers Agent Builder and App Builder, which let customers and partners build their own agents and applications on top of Cisco’s data, policy, and control plane using natural language and embedded coding assistants. Third, everything built in Studio—plus partner solutions—flows into the Cloud Control Marketplace, where integrations from dozens of ecosystem partners are already available.</p>



<p>For enterprises, the net effect is that Cloud Control shifts from a place to click through settings to the “secure harness” for agentic operations: a governed environment where AI agents can be deployed, monitored, constrained, and audited end-to-end. That is a very different proposition from the traditional network management console.</p>



<h2 class="wp-block-heading">CX and products finally share a brain</h2>



<p>Historically, <a href="https://www.cisco.com/site/us/en/services/support">Cisco’s Customer Experience (CX)</a> organization (services) and product groups have often felt like parallel universes. Services were layered on top of products rather than tightly integrated into how those products operated. Cisco IQ changes that dynamic by placing CX capabilities directly within the same Cloud Control environment where the products themselves live and by wiring CX workflows into the same telemetry and policy plane. This is notable as Cisco IQ isn’t yet another dashboard but an integrated part of Cloud Control.</p>



<p>Cisco IQ is positioned as the AI‑powered delivery vehicle for support and professional services. The goal is to give customers “complete landscape clarity,” proactive resilience, rapid resolution, and contextualized services. It runs as a SaaS platform, with an on‑premises deployment option for customers with strict data sovereignty requirements. By tapping the shared data fabric, Cisco IQ can inventory assets whether they are deployed or still in the warehouse, flag risks before customers experience issues, and benchmark an organization’s posture against anonymized peers by vertical, market segment or geography.</p>



<p>New capabilities, including Resilient Infrastructure Services and Quantum Ready Assessments, further underscore the integration of CX and product engineering. Resilient Infrastructure Services uses a three-step framework: Exposure Assessment, Infrastructure Modernization, and Defense Resiliency to help customers prepare for frontier-model threats. Quantum Ready Assessments, delivered through Cisco IQ, identify assets most exposed to “harvest now, decrypt later” attacks and map a path to quantum-safe infrastructure. Putting CX’s “brain” into Cloud Control and connecting it to the same data and AI models that drive operations is both a cultural and an architectural shift.</p>



<h2 class="wp-block-heading">Secure Networking as the integration proof point</h2>



<p>If you want a single domain that illustrates how integrated the new Cisco has become, look at Secure Networking. Cisco’s stated vision is to embed security directly into the fabric of the infrastructure, from silicon through the network to operations, rather than treating it as a separate stack. That strategy manifests in several concrete ways.</p>



<p>Live Protect, described internally as a “digital immune system,” applies precise compensating controls to Cisco products in production to protect them from newly discovered vulnerabilities at runtime. It does so without reboots, upgrades, or maintenance windows. The controls are narrowly targeted to avoid performance impact and minimize false positives. Live Protect is already shipping on Nexus 9000 switches and expanding across the portfolio, including campus switches, tightening the feedback loop between vulnerability discovery and mitigation from weeks to minutes.</p>



<p>Hybrid Mesh Firewall extends a unified security policy across networks, applications, and both Cisco and third-party firewalls, limiting the blast radius when something goes wrong. At the same time, Cisco is embedding post-quantum crypto libraries, secure boot, and trust anchors across its core portfolio, and has committed to enabling quantum-safe communications capabilities across most core products by December 2026. New enterprise and data center routers, switches, and firewall series are launching as “quantum-safe by default.”</p>



<p>All of this is orchestrated through Cloud Control, the security command center for a post-Mythos era, with Splunk providing the telemetry backbone and agentic SOC and SRE capabilities to detect, triage, and respond at machine speed. Secure Networking is no longer just about point firewalls and SD-WAN; it has become the spine that ties Cisco’s networking, security, observability, and AI assets into a coherent platform.</p>



<h2 class="wp-block-heading">Multicloud Fabric: networking as a service for AI</h2>



<p>Another hallmark of the new Cisco is a willingness to deliver networking as a managed fabric rather than a toolkit that customers must stitch together themselves. Multicloud Fabric, introduced as a network‑as‑a‑service offering delivered through Cloud Control, illustrates this shift.</p>



<p>Multicloud Fabric gives enterprises a single fabric for secure site-to-cloud and cloud-to-cloud networking, with Cisco operating virtual points of presence across major cloud providers and regions. Customers can onboard sites and cloud environments, define intent-based connectivity, attach security policies, and monitor performance “with one button” from Cloud Control, instead of building and maintaining their own hub-and-spoke architectures. Security and observability are built in—Zero Trust routing, cloud firewall service chaining, and ThousandEyes agents embedded in each point of presence—so the network is no longer a passive pipe but part of the AI intelligence stack.</p>



<p>This matters because AI-first applications increasingly chain inference across multiple clouds and data sources. Cisco’s own research shows that these agentic workflows can generate many times more network traffic than manual equivalents, with much of it being latency-sensitive inference. Multicloud Fabric, operated as a service and integrated into the same Cloud Control environment, is Cisco’s answer to this new reality.</p>



<h2 class="wp-block-heading">What this means for customers</h2>



<p>Cisco has spent four decades building category-leading products, from Meraki and Nexus to Webex and ThousandEyes. But the company’s biggest opportunity has always been in how those pieces work together. As Patel has said, tightly integrated and loosely coupled. Cloud Control, Cisco IQ, Multicloud Fabric, and Secure Networking suggest the product organization is finally closing that gap, turning dashboards into agentic workflows and discrete boxes into a secure harness for the AI era.</p>



<p>For customers, Cisco’s transformation matters because it changes the operating model, not just the product lineup. Cloud Control gives IT teams a single management plane across networking, security, observability, collaboration, and services, replacing the fragmented dashboard experience that has long complicated Cisco environments. That should make operations faster and simpler, but it also raises the bar for customers.</p>



<p>As Cisco pushes AgenticOps, AI Canvas, Live Protect, and Cisco IQ into the mainstream, IT teams will need to shift from manually managing tools to supervising agents, setting policy guardrails, and validating machine-speed actions. That shift will demand new skills in prompt design, policy modeling, risk scoring, and governance, especially as agents propose and test more changes before humans ever click “approve.”</p>



<p>It also means customers should view Cisco less as a best-of-breed product and more as an integrated platform. The more of the Cisco estate that is tied to Cloud Control, the more value customers should derive from shared telemetry, unified workflows, embedded security, and cross-domain automation—especially in areas like Secure Networking and multicloud operations. Conversely, customers that remain heavily heterogeneous will need clear integration strategies and governance models to ensure third-party tools plug safely into the harness.</p>



<p>Finally, this new Cisco has the potential to reduce one of the biggest pain points enterprise buyers have faced for years: complexity. If the company can deliver on its vision of one login, one view, tighter product integration, and CX services finally aligned with the product groups, customers may find that Cisco is not only unrecognizable in a positive way but also easier to buy, deploy, and operate than at any point in its history.</p>



<h3 class="wp-block-heading">Read more stories from Cisco Live 2026</h3>



<ul class="wp-block-list">
<li><a href="https://www.networkworld.com/article/4180842/cisco-sees-quantum-networking-as-the-future-of-networking.html">Cisco sees quantum networking as the future of networking</a></li>



<li><a href="https://www.networkworld.com/article/4180810/what-is-cisco-cloud-control-and-why-should-customers-care.html">What is Cisco Cloud Control and why should customers care?</a></li>



<li><a href="https://www.networkworld.com/article/4179942/cisco-live-the-network-is-back-and-ai-rewrote-the-rules.html">Cisco Live: The network is back, and AI rewrote the rules</a> </li>



<li><a href="https://www.networkworld.com/article/4179673/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live.html">Cisco brings agentic ops platform and security overhaul to Cisco Live</a></li>



<li><a href="https://www.networkworld.com/article/4181727/how-cisco-it-cut-observability-costs-by-86-and-eliminated-major-network-outages.html">How Cisco IT cut observability costs by 86% and eliminated major network outages</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[I built 99 adversarially malformed PE files to test tool robustness - here’s what happened]]></title>
<description><![CDATA[I designed a 99‑fixture adversarial PE corpus, where each binary contains one controlled corruption pattern with full ground‑truth metadata. The goal was to answer a simple question: How do PE tools behave when the binary stops playing by the rules? The fixtures cover 8 anomaly classes:  entrypoi...]]></description>
<link>https://tsecurity.de/de/3590620/malware-trojaner-viren/i-built-99-adversarially-malformed-pe-files-to-test-tool-robustness-heres-what-happened/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590620/malware-trojaner-viren/i-built-99-adversarially-malformed-pe-files-to-test-tool-robustness-heres-what-happened/</guid>
<pubDate>Thu, 11 Jun 2026 15:02:26 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I designed a 99‑fixture adversarial PE corpus, where each binary contains one controlled corruption pattern with full ground‑truth metadata. The goal was to answer a simple question:</p> <p><strong>How do PE tools behave when the binary stops playing by the rules?</strong></p> <p>The fixtures cover 8 anomaly classes:</p> <ul> <li>entrypoint manipulation </li> <li>section‑table corruption </li> <li>Optional Header inconsistencies </li> <li>directory contradictions </li> <li>TLS anomalies </li> <li>resource‑tree recursion </li> <li>Authenticode corruption </li> <li>entropy edge cases </li> </ul> <p>I tested 6 tools representing the major parsing philosophies:</p> <ul> <li>IOCX </li> <li>Ghidra </li> <li>Detect It Easy </li> <li>radare2 </li> <li>PEview </li> <li>CFF Explorer </li> </ul> <p><strong>The results were eye‑opening:</strong></p> <ul> <li><strong>Literal tools</strong> (r2, PEview) preserved bytes but gave no warnings </li> <li><strong>Semantic tools</strong> (CFF) silently normalised corruption </li> <li><strong>Heuristic tools</strong> (DIE) ignored structure entirely </li> <li><strong>Reconstructive loaders</strong> (Ghidra) rewrote metadata, omitted fields, and crashed on entropy fixtures </li> <li><strong>Hybrid literal‑semantic tools</strong> (IOCX) preserved raw metadata and surfaced anomalies explicitly </li> </ul> <p>Full write-up:</p> <p><a href="https://medium.com/@malx-labs/the-adversarial-pe-analysis-series-part-1-why-pe-parsers-break-introducing-the-99-adversarial-1769556ab473?source=friends_link&amp;sk=a053eaffcc2642062af3931c49ba6064">The Adversarial PE Analysis Series, Part 1 — Why PE Parsers Break</a></p> <p><strong>Corpus and fixture spec</strong>: <a href="https://github.com/iocx-dev/iocx">https://github.com/iocx-dev/iocx</a></p> <p>(fixtures are under <code>/tests/contract/fixtures/layer3_adversarial)</code></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/iocx_dev"> /u/iocx_dev </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1u2wwj6/i_built_99_adversarially_malformed_pe_files_to/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1u2wwj6/i_built_99_adversarially_malformed_pe_files_to/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[99 adversarial PE files: exploring malformed‑binary behaviour across major analysis tools]]></title>
<description><![CDATA[I’ve built a 99‑fixture adversarial PE corpus to explore how different tools behave when confronted with deliberately malformed but still loadable binaries. Each fixture introduces one corruption pattern - no packers or multi‑anomaly noise, which allows for clean attribution of behaviour. The ano...]]></description>
<link>https://tsecurity.de/de/3590619/malware-trojaner-viren/99-adversarial-pe-files-exploring-malformedbinary-behaviour-across-major-analysis-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590619/malware-trojaner-viren/99-adversarial-pe-files-exploring-malformedbinary-behaviour-across-major-analysis-tools/</guid>
<pubDate>Thu, 11 Jun 2026 15:02:25 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I’ve built a 99‑fixture adversarial PE corpus to explore how different tools behave when confronted with deliberately malformed but still loadable binaries.</p> <p>Each fixture introduces <strong>one</strong> corruption pattern - no packers or multi‑anomaly noise, which allows for clean attribution of behaviour. The anomalies span:</p> <ul> <li>entrypoint redirection </li> <li>overlapping/invalid sections </li> <li>header inconsistencies </li> <li>directory OOB conditions </li> <li>TLS edge cases </li> <li>recursive/malformed resources </li> <li>Authenticode structural corruption </li> <li>entropy‑field manipulation </li> </ul> <p>I tested 6 tools commonly used in exploit dev workflows:</p> <ul> <li>IOCX </li> <li>Ghidra </li> <li>Detect It Easy </li> <li>radare2 </li> <li>PEview </li> <li>CFF Explorer </li> </ul> <p><strong>Behavioural patterns with exploit‑relevant implications:</strong></p> <ul> <li><strong>Literal parsers</strong> (r2, PEview) never crashed but provided no anomaly visibility </li> <li><strong>Semantic parsers</strong> (CFF) “fixed” corruption, masking exploit‑useful inconsistencies </li> <li><strong>Heuristic tools</strong> (DIE) ignored structure, blind to malformed metadata </li> <li><strong>Reconstructive loaders</strong> (Ghidra) rewrote metadata, omitted fields, and crashed on entropy fixtures </li> <li><strong>Hybrid literal‑semantic tools</strong> (IOCX) preserved raw bytes and surfaced anomalies explicitly </li> </ul> <p>For exploit dev, malformed PE structures can act as:</p> <ul> <li>parser differentials </li> <li>crash primitives </li> <li>metadata confusion vectors </li> <li>loader‑model inconsistencies </li> <li>analysis‑evasion surfaces </li> </ul> <p>This corpus maps those behaviours systematically.</p> <p><strong>Full write‑up (Part 1):</strong> </p> <p><a href="https://medium.com/@malx-labs/the-adversarial-pe-analysis-series-part-1-why-pe-parsers-break-introducing-the-99-adversarial-1769556ab473?source=friends_link&amp;sk=a053eaffcc2642062af3931c49ba6064">The Adversarial PE Analysis Series — Why PE Parsers Break</a></p> <p><strong>Corpus and fixture spec</strong>: <a href="https://github.com/iocx-dev/iocx">https://github.com/iocx-dev/iocx</a></p> <p>(fixtures are under <code>/tests/contract/fixtures/layer3_adversarial)</code></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/iocx_dev"> /u/iocx_dev </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1u2xdh6/99_adversarial_pe_files_exploring_malformedbinary/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1u2xdh6/99_adversarial_pe_files_exploring_malformedbinary/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Smashing Security podcast #471: This AI worm just rewrote its own rules]]></title>
<description><![CDATA[Researchers at the University of Toronto have built a worm that thinks for itself. Using free off-the-shelf AI models it works out how to break into each new computer it encounters, and hijacks the powerful ones to host its own AI brain. And then the researchers discovered their creation had quie...]]></description>
<link>https://tsecurity.de/de/3589176/it-security-nachrichten/smashing-security-podcast-471-this-ai-worm-just-rewrote-its-own-rules/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589176/it-security-nachrichten/smashing-security-podcast-471-this-ai-worm-just-rewrote-its-own-rules/</guid>
<pubDate>Thu, 11 Jun 2026 01:38:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Researchers at the University of Toronto have built a worm that thinks for itself. Using free off-the-shelf AI models it works out how to break into each new computer it encounters, and hijacks the powerful ones to host its own AI brain. And then the researchers discovered their creation had quietly removed the list of machines it wasn't supposed to attack.

Meanwhile, Meta's shiny new AI customer support agent has been cheerfully helping hackers help themselves to other people's Instagram accounts. Just keep asking, politely but firmly, to have a password reset sent to a different email address - and the AI will eventually agree.

All this and more in episode 471 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball.]]></content:encoded>
</item>
<item>
<title><![CDATA[v15.9.0]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Fixed

Fixed MiniMax-compatible OpenAI-completions hosts (e.g. minimax-code-cn/MiniMax-M3) losing tool-call arguments when the stream delivers function.arguments as a complete object instead of the OpenAI JSON-string contract. The streaming buffer previously concatenated the objec...]]></description>
<link>https://tsecurity.de/de/3580239/tools/v1590/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580239/tools/v1590/</guid>
<pubDate>Mon, 08 Jun 2026 02:51:02 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-ai</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed MiniMax-compatible OpenAI-completions hosts (e.g. <code>minimax-code-cn/MiniMax-M3</code>) losing tool-call arguments when the stream delivers <code>function.arguments</code> as a complete object instead of the OpenAI JSON-string contract. The streaming buffer previously concatenated the object into a string, coercing it to <code>[object Object]</code> and leaving <code>bash</code>/<code>edit</code> calls with empty or malformed inputs; the tool-call block now holds the object payload directly. (<a href="https://github.com/can1357/oh-my-pi/issues/1776" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1776/hovercard">#1776</a>)</li>
<li>Fixed Cloud Code Assist (Gemini / Antigravity) rejecting tool schemas with <code>Invalid JSON payload received. Unknown name "propertyNames"</code> (HTTP 400) when a tool exposed a property literally named <code>properties</code> (e.g. the Resend MCP <code>create_contact</code> tool). The schema normalizer's <code>insideProperties</code> flag was re-asserted when descending into such a property's value schema, so Google-unsupported keywords (<code>propertyNames</code>, <code>additionalProperties</code>, …) nested inside it were never stripped. The flag is now only set when entering a real <code>properties</code> map from a schema node, not from within another <code>properties</code> map.</li>
<li>Fixed local/self-hosted providers leaking machine-specific endpoints into the bundled <code>models.json</code>. A <code>generate-models</code> run on a machine with a LiteLLM proxy baked 1202 <code>litellm</code> models pinned to <code>http://localhost:4000/v1</code> into the committed catalog. <code>litellm</code> (and <code>lm-studio</code>) now join <code>ollama</code>/<code>vllm</code> in the generator's discovery-only exclusion set, so local providers are never fetched during generation nor written to <code>models.json</code> — they are discovered dynamically at runtime instead. LiteLLM model discovery now enriches metadata against models.dev (the same reference source the other gateway providers use) rather than a bundled reference map. Added a regression test pinning the invariant (no local provider blocks, no loopback/private-network <code>baseUrl</code>s in the bundled catalog).</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Removed synchronous <code>readTextSync</code> from <code>SessionStorage</code> and core implementations (<code>MemorySessionStorage</code>, <code>FileSessionStorage</code>, <code>RedisSessionStorage</code>, <code>SqlSessionStorage</code>), requiring callers to use async text reads</li>
<li>Replaced the public <code>SessionStorage</code> <code>readTextPrefix(path, maxBytes)</code> and <code>readTextSuffix(path, maxBytes)</code> methods with <code>readTextSlices(path, prefixBytes, suffixBytes): Promise&lt;[string, string]&gt;</code>; custom session storage backends must implement the new combined slice API.</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added env-driven OpenTelemetry trace export. When <code>OTEL_EXPORTER_OTLP_ENDPOINT</code> (or <code>OTEL_EXPORTER_OTLP_TRACES_ENDPOINT</code>) is set, <code>omp</code> registers a global OTLP/proto trace exporter and switches on the agent loop's telemetry, so the <code>invoke_agent</code> / <code>chat</code> / <code>execute_tool</code> spans actually reach a collector instead of a no-op tracer. Honors the standard <code>OTEL_*</code> env contract (endpoint, headers, <code>OTEL_SERVICE_NAME</code>, <code>OTEL_SDK_DISABLED</code> and <code>OTEL_TRACES_EXPORTER=none</code> parsed case-insensitively) and the <code>OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENT</code> capture toggle; it is a no-op when no endpoint is configured. Only the <code>http/protobuf</code> transport is supported — a <code>grpc</code> or <code>http/json</code> <code>OTEL_EXPORTER_OTLP*_PROTOCOL</code> declines rather than misrouting spans. This makes the existing telemetry usable from headless hosts that run <code>omp</code> as a spawned child process, where an in-process <code>TracerProvider</code> registered by the parent can't reach the child. Uses the <code>@opentelemetry/exporter-trace-otlp-proto</code> 2.x line, which exports cleanly under Bun.</li>
</ul>
<h2>Fixed</h2>
<ul>
<li>Fixed the status line session name (and the editor border / status-line gap fill) being nearly illegible on light themes.</li>
<li>Added <code>IndexedSessionStorage</code> and <code>SessionStorageBackend</code> exports to support shared metadata-indexed session backends</li>
<li>Added the <code>tui.maxInlineImages</code> setting (default <code>8</code>) capping how many inline images render as live terminal graphics. Once a new image pushes the count past the cap, the oldest images are hidden via a full redraw — replaced by their <code>[Image: …]</code> text placeholder and purged from the terminal's graphics store — so long sessions with many screenshots/diagrams stop piling up images (and, on Kitty, stop leaving scrollback ghosts). Set to <code>0</code> to keep every image inline.</li>
<li>Added a "View: terminal state" item to the <code>/debug</code> menu that prints the detected terminal, live geometry and cell size, multiplexer, and the negotiated subprotocols actually in use — graphics (Kitty/iTerm2/Sixel), desktop notifications (BEL/OSC 9/OSC 99, plus whether OSC 99 was confirmed via a device-attributes probe), OSC 8 hyperlinks, 24-bit color, DECCARA rectangular-SGR background fills, and DEC 2026 synchronized output — alongside the scrollback-clear strategy (<code>CSI 22 J</code> vs <code>CSI 2 J</code> redraw / ED3 eager-erase risk) and the raw <code>TERM</code>/<code>TERM_PROGRAM</code>/<code>COLORTERM</code> detection signals.</li>
<li>Added a "Test: terminal protocols" item to the <code>/debug</code> menu that renders one live sample of every special escape protocol the renderer can emit — SGR text attributes (bold/italic/underline/strikethrough/inverse/dim), themed and 24-bit truecolor, OSC 8 hyperlinks, OSC 66 text sizing (large text), and an inline graphics swatch via the active image protocol (Kitty/iTerm2/Sixel, with a text fallback) — and fires a desktop notification, so you can eyeball which protocols the current terminal actually honors. The sample image is a gradient PNG generated in-process, so the graphics test needs no asset on disk.</li>
<li>Added the <code>tui.textSizing</code> setting (default off) that renders Markdown H1 headings at 2x scale via Kitty's OSC 66 text-sizing protocol. It replaces the undocumented <code>PI_TUI_TEXT_SIZING</code> env var with a real setting, and only takes effect on Kitty terminals (where OSC 66 is implemented) — it is ignored everywhere else so headings never emit raw escape bytes.</li>
<li>Added a lifecycle status to the <code>/resume</code> session picker. Each session's tail (last 32 KiB) is now read alongside the existing header window in a single pass, and its final message classified as <code>done</code> (the agent ended its turn and yielded control back), <code>interrupted</code> (a trailing tool call or tool result the loop never continued from), <code>aborted</code>, <code>error</code>, or <code>pending</code> (a trailing user message with no reply). The status renders as a colored segment on each session's metadata line. When the final message is larger than the tail window the status is omitted rather than guessed.</li>
<li>Added support for <code>disable-model-invocation: true</code> frontmatter field from the <a href="https://agentskills.io/specification" rel="nofollow">Agent Skills standard</a>. Skills using this field are now hidden from the system prompt listing, matching the behavior of <code>hide: true</code>.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed the <code>task</code> tool description to tag read-only agents and explicitly forbid assigning them file edits/commands or offloading reasoning to <code>quick_task</code>/<code>explore</code>.</li>
<li>Changed Redis and SQL session storage initialization to load only indexed metadata (<code>size</code>, <code>mtimeMs</code>) instead of full session content</li>
<li>Changed <code>SessionStorage</code> read paths to rely on backend-backed metadata/indexed storage, so session content is fetched on demand rather than cached as full in-memory mirrors</li>
<li>Changed session-list slice reads to go through <code>SessionStorage.readTextSlices</code> across all backends, removing the file-only single-open branch and caller-managed buffers. <code>FileSessionStorage</code> now reads both windows via <code>peekFileEnds</code>, while Redis and SQL backends encode session content once per combined read.</li>
<li>Changed the <code>ask</code> tool transcript renderer to mark single-choice questions with circular radio glyphs (<code>○</code>/<code>◉</code>) instead of the rectangular checkbox glyphs (<code>☐</code>/<code>☑</code>) it shares with multi-select questions, so a "pick one" combo box visually reads as a radio group rather than a checklist. Multi-select questions keep checkboxes. Added a <code>radio.selected</code>/<code>radio.unselected</code> symbol pair across the unicode, nerd-font, and ASCII presets.</li>
<li>Changed the <code>ask</code> tool transcript renderer to mark the chosen answer inside the question form rather than re-listing the questions in a detached summary block below it. Once a question is answered, the standalone prompt preview is dropped and the result redraws the same form — every offered option still shown, with the selected one(s) filled in (<code>◉</code>/<code>☑</code>, highlighted) and the rest dimmed (<code>○</code>/<code>☐</code>); custom free-text answers and cancellations render in place as the final entry. This removes the duplicate question/option listing that previously appeared once as the call preview and again as the result.</li>
<li>Changed task-completion and <code>ask</code> desktop notifications to structured terminal notifications (title, body, type, and a focus-on-click action). On Kitty these render through OSC 99 as a proper title/body with click-to-focus; terminals without confirmed OSC 99 support collapse them to the previous single-line message (BEL/OSC 9).</li>
<li>Updated the "each kitty/tmux split" tip to include cmux.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed tiny-model startup in compiled binaries by resolving <code>@huggingface/transformers</code> and its runtime dependencies from the installed cache using <code>package.json</code> <code>exports</code>/<code>main</code> metadata, preventing module-resolution failures when launching models</li>
<li>Fixed tiny runtime installation flow in compiled binaries by using the build-time resolved <code>@huggingface/transformers</code> version and ensuring the runtime lock directory’s parent exists before acquiring the install lock, preventing mismatch and setup failures on fresh installs</li>
<li>Fixed the terminal protocol debug probe reusing one stable Kitty graphics id across repeated panels, which could move/replace an earlier swatch instead of rendering a new one.</li>
<li>Fixed selector dialogs (the <code>ask</code> tool, hook prompts) collapsing to a single visible option on shorter terminals when options carried long descriptions: the highlighted option's wrapped description consumed the entire row budget, hiding every other option and making the menu feel unnavigable (down moved the lone visible entry, left/right did nothing). When the fully-expanded list overflows, <code>HookSelectorComponent</code> now renders a compact list — every option label stays on screen and only the highlighted option expands its description, truncated to the remaining rows — so the whole menu is always visible and the detail pane follows the cursor.</li>
<li>Fixed <code>read</code> failing with "Path not found" on web URLs whose scheme <code>//</code> collapsed to a single <code>/</code> (e.g. <code>https:/github.com/...</code>), which happens when a URL is routed through Node's <code>path.normalize</code>/<code>path.resolve</code>. The fetch URL recognizer now accepts a single-slash scheme and repairs it back to <code>//</code> before fetching, so collapsed URLs resolve instead of falling through to filesystem lookup.</li>
<li>Fixed subagent slow-model priority falling through to older Claude Opus aliases when Opus 4.8 is available by adding Opus 4.8 and 4.7 aliases ahead of older Opus fallbacks (<a href="https://github.com/can1357/oh-my-pi/issues/1753" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1753/hovercard">#1753</a>).</li>
<li>Fixed the web-search provider selectors in TUI settings/setup to derive from the shared provider metadata, so newly added providers cannot be omitted from the preference list.</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Fixed</h3>
<ul>
<li>Bounded sorted <code>glob()</code> scans to <code>maxResults</code> during uncached traversal and emitted <code>onMatch</code> callbacks only for entries admitted to the bounded top-<code>maxResults</code> heap so broad OMP <code>find</code> progress and timeout partials stay consistent with the returned mtime-ranked set while keeping parent-process memory bounded (<a href="https://github.com/can1357/oh-my-pi/issues/1761" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1761/hovercard">#1761</a>).</li>
<li>Fixed <code>wrapTextWithAnsi</code> hanging (infinite loop) on text containing a BEL-terminated string escape — DCS/SOS/PM/APC (<code>ESC P</code>/<code>ESC X</code>/<code>ESC ^</code>/<code>ESC _</code>) closed by <code>BEL</code> instead of <code>ST</code>. <code>ansi_seq_len_u16</code> only accepted the <code>ST</code> (<code>ESC \</code>) terminator for these (OSC already accepted both), so a BEL-terminated APC such as the TUI cursor marker (<code>ESC _ pi:c BEL</code>) was left unclassified: it was miscounted as visible width and <code>break_long_word</code>'s non-ESC scan could not advance past the <code>ESC</code>, spinning forever. The terminator set now matches OSC (ST <strong>or</strong> BEL), and <code>break_long_word</code> defensively emits and steps over any escape it cannot classify so a malformed/unknown sequence can never wedge the wrap loop.</li>
</ul>
<h2>@oh-my-pi/swarm-extension</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed swarm <code>/swarm run</code> failing with authStorage/modelRegistry identity error (<a href="https://github.com/can1357/oh-my-pi/issues/1472" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1472/hovercard">#1472</a>)</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Added</h3>
<ul>
<li>Added Kitty <code>CSI 22 J</code> screen-to-scrollback clears for non-destructive full paints, while keeping ED3 for destructive history/session rebuilds.</li>
<li>Added Kitty OSC 99 rich notification formatting and startup capability probing.</li>
<li>Added Kitty OSC 66 text-sized Markdown H1 headings (2x scale) plus native text-width support for OSC 66 spans. Off by default and gated to Kitty (the only terminal implementing OSC 66) via the <code>TERMINAL.textSizing</code> capability; hosts enable it through <code>setTextSizing</code>.</li>
<li>Added Kitty Unicode placeholder image rendering (<code>U=1</code> + U+10EEEE with explicit row/column diacritics): inline images are drawn as real text cells that carry the image id in their foreground color, so they survive horizontal slicing, reflow, and overlapping draws instead of relying on cursor-positioned <code>a=p</code> placements. Enabled by default on Kitty-family terminals; opt out with <code>PI_NO_KITTY_PLACEHOLDERS=1</code>, and falls back to direct placement when a grid exceeds the diacritic table's addressable range.</li>
<li>Added Kitty temp-file image transmission (<code>t=t</code>): on local sessions, decoded PNG bytes are written to a <code>tty-graphics-protocol</code> temp file and the path is sent instead of in-band base64, gated behind a startup <code>a=q,t=t</code> support probe. Controlled by <code>PI_KITTY_IMAGE_TRANSMISSION=direct|temp-file|auto</code>; disabled over SSH unless explicitly forced.</li>
<li>Added DECRQM capability detection for DEC private modes 2026 (synchronized output) and 2048 (in-band resize). Synchronized-output paint wrappers are dropped when the terminal reports 2026 unsupported (preserving the <code>PI_NO_SYNC_OUTPUT</code> override), and DEC 2048 in-band resize is enabled when supported — reported geometry and cell pixel size are updated from <code>CSI 48 ; rows ; cols ; yPx ; xPx t</code> reports, with SIGWINCH and <code>CSI 16 t</code> kept as fallbacks.</li>
<li>Added an injectable render scheduler for TUI tests, allowing deterministic render drains without patching global clocks or event-loop timing.</li>
<li>Added <code>ImageBudget</code>, an inline-image cap that keeps only the most recent N images as live terminal graphics and demotes older ones to their text fallback. Once a new image pushes the count past the cap, the renderer hides the oldest via a full redraw plus an explicit Kitty graphics purge (<code>a=d,d=I</code>) — text-clear escapes (<code>CSI 2 J</code>/<code>CSI 3 J</code>) do not remove Kitty images. Configure the cap via <code>TUI#setMaxInlineImages</code> (<code>0</code> disables it).</li>
<li>Changed Kitty inline images to a transmit-once + placement scheme: the base64 data is sent a single time (<code>a=t</code>) keyed by a stable image id, then every repaint emits only the tiny placement (<code>a=p,i=…,p=…</code>). Repaints — including full redraws — no longer re-send image data or stack duplicate placements, and the diff/line buffers and render caches hold short placement strings instead of multi-KB base64. The <code>ImageBudget</code> doubles as the transmit store (it tracks which ids are loaded and re-transmits after a purge frees the data). iTerm2/Sixel, which have no addressable image store, keep sending inline data as before.</li>
<li>Added a renderer-level DECCARA rectangular-SGR optimizer that paints solid background panels/rows (Box/Text/Markdown fills, status bars, any full-width <code>theme.bg</code> row) as a single coalesced rectangle escape (<code>CSI 2*x</code> / <code>CSI Pt;Pl;Pb;Pr;&lt;sgr&gt;$r</code> / <code>CSI *x</code>) instead of emitting a full-width run of background-styled spaces on every visible row. It operates at emit time on the final ANSI strings — components are unchanged — and strips only trailing padding it can prove sits under a single non-default background span, coalescing vertically adjacent identical fills into one rectangle and falling back to the original bytes whenever the rectangle would not save bytes. Enabled only on Kitty, which implements the SGR-background extension (<code>docs/deccara.rst</code>); <strong>Ghostty is intentionally excluded</strong> because its <code>CSI $r</code> is unimplemented (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1931418915" data-permission-text="Title is private" data-url="https://github.com/ghostty-org/ghostty/issues/632" data-hovercard-type="issue" data-hovercard-url="/ghostty-org/ghostty/issues/632/hovercard" href="https://github.com/ghostty-org/ghostty/issues/632">ghostty-org/ghostty#632</a>) and would drop the background entirely. Scrollback-bound rows and the append/scroll paths always keep the padded representation so native history preserves colored cells, and the <code>PI_NO_DECCARA</code> kill switch (plus tmux/screen/zellij detection) forces the fallback.</li>
<li>Added <code>CMUX_SURFACE_ID</code> environment variable support to <code>getTerminalId()</code>, so cmux terminal surfaces get a stable identifier alongside kitty, tmux, macOS Terminal.app, and Windows Terminal — enabling per-surface session breadcrumbs for <code>omp -c</code> in cmux.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed TUI tests to use Ghostty's VT engine (<code>ghostty-web</code>) instead of <code>@xterm/headless</code>.</li>
<li>Changed the default inline-image live graphics budget from 3 to 8 images.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>
<p>Fixed the DECCARA background-fill optimizer rejecting or repainting the wrong cells when a trailing fill crossed from default-background spaces into colored spaces.</p>
</li>
<li>
<p>Fixed DEC private-mode reports with DECRPM status 3/4 being treated as unsupported, so permanent 2026/2048 reports stay recognized.</p>
</li>
<li>
<p>Fixed OSC 66 text-sizing width and slicing edge cases, including ZWJ emoji payloads and partial slices through scaled spans.</p>
</li>
<li>
<p>Fixed focused <code>Input</code> components following <code>TUI#setShowHardwareCursor</code>, so single-line prompts render either the terminal cursor or software cursor consistently with the editor.</p>
</li>
<li>
<p>Fixed the DECCARA background-fill optimizer painting fills on the wrong rows ("split into unaligned halves") in the differential repaint path. When a diff grew the transcript past the viewport, writing the rewritten rows scrolled the terminal, but the absolute DECCARA rectangle coordinates were derived from the pre-scroll viewport top, so every fill landed <code>scrollAmount</code> rows too low while the relatively-positioned text settled correctly; rows scrolled into history were also shortened, dropping their background padding from native scrollback. Rectangles now target the post-scroll rows and only rows remaining in the final viewport are optimized.</p>
</li>
<li>
<p>Fixed native scrollback desynchronization after terminal width or height changes reflowed overflowing content while the viewport was not at the bottom</p>
</li>
<li>
<p>Fixed a notification chip (or any injected block) rendering on top of an actively streaming tool render on ED3-risk terminals (Ghostty/kitty/Alacritty/iTerm2). While a foreground tool streams, its header's elapsed-time counter ticks every frame; once output scrolls the header above the viewport top, each tick is an offscreen edit that — because the eager scrollback-rebuild opt-in is gated off on these terminals — repaints the viewport in place and advances the rendered line count without committing the new overflow to native history. <code>#scrollbackHighWater</code> then lagged the logical viewport top, so a later content shrink whose changes landed in the visible region slipped past the shrink-across-boundary guard and reached the differential emitter, which is anchored to <code>#maxLinesRendered - height</code>: it rewrote only the suffix, dropped the newly exposed top row, and left a blank at the bottom, drifting every row below the edit one line up so it painted over the rows above. Such shrinks now re-anchor the bottom of the viewport with a non-destructive repaint, and the foreground-streaming shrink-across-boundary case repaints the live tail instead of padding and pinning the pre-shrink viewport.</p>
</li>
<li>
<p>Fixed a terminal resize during foreground-tool streaming on an unknown-viewport / ED3-risk host (Ghostty/kitty/Alacritty/iTerm2/WSL) leaving native scrollback permanently out of sync, so scrolling back after the turn showed missing rows. A pure geometry resize (no content change) takes the in-place viewport-repaint path, which — unlike a content-bearing resize that rebuilds via the geometry branch — never flagged native history. Because the prompt-submit checkpoint (<code>refreshNativeScrollbackIfDirty</code>) only rebuilds when scrollback is marked dirty on these hosts, the discrepancy was never reconciled. Overflowing geometry repaints whose viewport is not known to be at the bottom now mark scrollback dirty so the next checkpoint rebuilds an exact copy of the transcript.</p>
</li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Added</h3>
<ul>
<li>
<p>Added color helpers <code>colorLuma</code> (perceptual luma), <code>relativeLuminance</code> (WCAG, linearized sRGB), and <code>hslToHex</code> to the color utilities. The luminance helpers parse <code>#rgb</code>/<code>#rrggbb</code> hex and 256-color palette indices, returning <code>undefined</code> for unparseable values.</p>
</li>
<li>
<p>Added <code>peekFileEnds</code>, a single-open head-and-tail file peek helper that reuses the head bytes for the tail when the file fits the head window.</p>
</li>
<li>
<p>Added <code>peekFileTail</code>, the tail mirror of <code>peekFile</code>: reads up to the last <code>maxBytes</code> of a file ending at EOF, reusing the same pooled-buffer strategy (no per-call allocation for small reads).</p>
</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(search): default paths to workspace root instead of hard-failing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GratefulDave/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GratefulDave">@GratefulDave</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4584846316" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1808" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1808/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1808">#1808</a></li>
<li>fix: recognize disable-model-invocation from Agent Skills spec by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fabkho/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fabkho">@fabkho</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583326357" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1803" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1803/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1803">#1803</a></li>
<li>fix(coding-agent/mcp): handle async broken-pipe rejections in stdio transport by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VoidChecksum/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VoidChecksum">@VoidChecksum</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4578318423" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1783" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1783/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1783">#1783</a></li>
<li>Fix slow agent Opus priority by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daandden/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daandden">@daandden</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4576811309" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1754" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1754/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1754">#1754</a></li>
<li>fix(swarm): remove redundant authStorage discovery from swarm pipeline (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4538706917" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1472" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1472/hovercard" href="https://github.com/can1357/oh-my-pi/issues/1472">#1472</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WodenJay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WodenJay">@WodenJay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4573308608" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1726" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1726/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1726">#1726</a></li>
<li>Fix web search provider TUI options by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daandden/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daandden">@daandden</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4568591206" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1685" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1685/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1685">#1685</a></li>
<li>Add cmux terminal surface detection to getTerminalId by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/basedcorp99/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/basedcorp99">@basedcorp99</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4570212330" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1702" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1702/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1702">#1702</a></li>
<li>fix(natives): bound sorted glob scans by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4577407079" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1762" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1762/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1762">#1762</a></li>
<li>fix(tui): cap session accent luminance on light themes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paweljw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paweljw">@paweljw</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4571800449" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1715" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1715/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1715">#1715</a></li>
<li>feat(coding-agent): env-driven OTLP trace export for headless hosts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgreeno/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgreeno">@cgreeno</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4581802133" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1797" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1797/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1797">#1797</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GratefulDave/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GratefulDave">@GratefulDave</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4584846316" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1808" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1808/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1808">#1808</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fabkho/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fabkho">@fabkho</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583326357" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1803" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1803/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1803">#1803</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WodenJay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WodenJay">@WodenJay</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4573308608" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1726" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1726/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1726">#1726</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paweljw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paweljw">@paweljw</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4571800449" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1715" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1715/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1715">#1715</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgreeno/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgreeno">@cgreeno</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4581802133" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1797" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1797/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1797">#1797</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v15.8.3...v15.9.0"><tt>v15.8.3...v15.9.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Cisco IT cut observability costs by 86% and eliminated major network outages]]></title>
<description><![CDATA[When several database clusters started failing simultaneously, Cisco IT had all the data it needed to diagnose the problem. The signals were there. Engineers saw them. The issue was that those signals were landing in separate systems that did not talk to each other, and the team had no way to cor...]]></description>
<link>https://tsecurity.de/de/3575443/it-security-nachrichten/how-cisco-it-cut-observability-costs-by-86-and-eliminated-major-network-outages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575443/it-security-nachrichten/how-cisco-it-cut-observability-costs-by-86-and-eliminated-major-network-outages/</guid>
<pubDate>Fri, 05 Jun 2026 15:08:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>When several database clusters started failing simultaneously, Cisco IT had all the data it needed to diagnose the problem. The signals were there. Engineers saw them. The issue was that those signals were landing in separate systems that did not talk to each other, and the team had no way to correlate them in real time.</p>



<p>What followed was three hours of war-room calls across three separate bridges. Engineers were on one call, debating ownership of the problem. Application owners were on another, waiting on the database to recover. Executives were on a third, trying to explain to business partners why users could not place orders. The root cause was eventually found, but the outage had already hit.</p>



<p>That incident became the impetus for a consolidation project that <a href="https://www.linkedin.com/in/anushanataraj/">Anusha Nataraj,</a> product manager in Cisco IT’s observability team, detailed in a session at <a href="https://www.networkworld.com/article/4179673/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live.html">Cisco Live</a>.</p>



<p>The project has since reduced major incidents by 25% and produced zero major network outages over the last six quarters. The environment spans more than 1,500 applications, more than 71 of them externally facing, across more than 100,000 endpoints, processing more than 15,000 changes per month. The platform at the center of that consolidation is Splunk, which Cisco acquired in 2024. Cisco IT is now running its own product across its global infrastructure.</p>



<p>“We had the data, we had all the data, but [it’s] just that it was not stitched together, and we couldn’t see it all holistically,” Nataraj said.</p>



<h2 class="wp-block-heading">The tool sprawl that made it worse</h2>



<p>The pre-consolidation observability environment at Cisco IT was not a single gap. It was a collection of them. Logs were split across a partial Splunk deployment and Elastic instances. Metrics ran across Prometheus stacks, Grafana stacks and homegrown solutions. Event management ran on a separate homegrown platform. None of these systems fed into each other.</p>



<p>The team had considered staying with the existing mix, including Datadog and Elastic, and evaluated stitched-together open source alternatives. Three factors drove the decision against them. They could not scale to Cisco IT’s operational requirements, they lacked the AI capabilities the team needed, and they offered no roadmap that Cisco IT could shape as a customer.</p>



<p>“They worked at our department level, but they couldn’t scale to our IT needs, and they didn’t have the maturity of AI that we were expecting,” Nataraj said.</p>



<p>Nataraj was clear that the decision was not driven by the 2024 acquisition. The team evaluated Splunk against their requirements and selected it on fit, scale and AI roadmap.</p>



<h2 class="wp-block-heading">The three-pillar consolidation</h2>



<p>The consolidation followed a defined three-step sequence.</p>



<ul class="wp-block-list">
<li><strong>Log consolidation</strong>: All logs were moved to Splunk Cloud, retiring Elastic and other logging instances in the process.</li>



<li><strong>Metrics consolidation:</strong> Currently in progress, with Prometheus, Grafana and homegrown stacks being retired as the work completes.</li>



<li><strong>Business context via ITSI:</strong> The team is implementing IT Service Intelligence (ITSI) to add business context on top of the unified log and metrics data.</li>
</ul>



<p>The 86% reduction in total cost of ownership for observability came out of that first phase. More than 400 on-premises servers were decommissioned along with their associated storage. Licenses across multiple platforms were consolidated. The contractor headcount assigned to monitoring those servers was reduced.</p>



<p>“We decommissioned a lot of servers that were on prem, which was more than 400 servers, and associated storage elements were all turned off, and that was a major savings for us,” Nataraj said.</p>



<h2 class="wp-block-heading">What incident response looks like now</h2>



<p>The operational change is most visible in how the team handles incidents. A video shown during the session walked through the current workflow.</p>



<p>When an alert fires in ITSI, one click launches a custom-built AI agent that queries logs, metrics, traces, topology data, and recent change requests in real time. The agent returns a plain-language summary of what broke, why it broke and how to fix it. Role-specific actions are included for DevOps, application and SRE teams. If escalation is needed, the agent drafts a handoff for the on-call engineer. The whole investigation happens in a single screen before an incident ticket is even created.</p>



<p>The result is a measurable shift in outcome. When issues do occur, the three-bridge war room is gone. Teams can see where the problem is and the response is contained to the people who need to act on it. “We have actually brought down our incident count by 25%, and in the last six quarters there have been no major network outages,” Nataraj said.</p>



<h2 class="wp-block-heading">Lessons learned</h2>



<p>Nataraj laid out a practical set of takeaways from the project for IT operations teams running at similar scale.</p>



<ul class="wp-block-list">
<li><strong>Unify data before applying AI.</strong> Without a unified data platform, AI has nothing reliable to work with. Getting all data into a single architecture has to come first.</li>



<li><strong>Share visibility across teams.</strong> Correlating data is only useful if the teams who need it can access it. The team built cross-domain data sharing from the start.</li>



<li><strong>Bring change and release data into observability.</strong> Tying change management records to observability data lets the team trace failures back to the specific change that caused them and maintain a rollback plan.</li>



<li><strong>Treat cost savings as the budget for innovation.</strong> The TCO reduction funded the team’s shift away from routine monitoring. Engineers who were previously managing capacity and watching servers are now building AI agents on top of Splunk’s MCP tools, participating in alpha and beta testing for new Splunk tooling, and feeding product feedback directly to Cisco’s Splunk teams.</li>
</ul>



<p>“They were purely ticket closers before,” Nataraj said. “They’re innovators, they wear product managers’ hats, and they are really happy about the work that they do.”</p>



<p>Job satisfaction, retention, and contractor reduction are all outcomes Nataraj cited as measurable ROI from the project. “Keeping the team motivated and having them feel happy is a real ROI for every single organization,” she said.</p>



<h4 class="wp-block-heading">Read more stories from Cisco Live 2026</h4>



<ul class="wp-block-list">
<li><a href="https://www.networkworld.com/article/4179942/cisco-live-the-network-is-back-and-ai-rewrote-the-rules.html">Cisco Live: The network is back, and AI rewrote the rules</a></li>



<li><a href="https://www.networkworld.com/article/4180842/cisco-sees-quantum-networking-as-the-future-of-networking.html">Cisco sees quantum networking as the future of networking</a></li>



<li><a href="https://www.networkworld.com/article/4180810/what-is-cisco-cloud-control-and-why-should-customers-care.html">What is Cisco Cloud Control and why should customers care?</a></li>



<li><a href="https://www.networkworld.com/article/4179673/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live.html">Cisco brings agentic ops platform and security overhaul to Cisco Live</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-42349 | clerk javascript unusual condition (GHSA-w24r-5266-9c3c)]]></title>
<description><![CDATA[A vulnerability has been found in clerk javascript, shared, backend, nextjs, -react, react, vue, astro, nuxt, -expo, expo, react-router, tanstack-react-start, chrome-extension, fastify, express and hono and classified as critical. This impacts an unknown function. This manipulation causes imprope...]]></description>
<link>https://tsecurity.de/de/3572606/sicherheitsluecken/cve-2026-42349-clerk-javascript-unusual-condition-ghsa-w24r-5266-9c3c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572606/sicherheitsluecken/cve-2026-42349-clerk-javascript-unusual-condition-ghsa-w24r-5266-9c3c/</guid>
<pubDate>Thu, 04 Jun 2026 14:38:46 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/clerk:javascript">clerk javascript, shared, backend, nextjs, -react, react, vue, astro, nuxt, -expo, expo, react-router, tanstack-react-start, chrome-extension, fastify, express and hono</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This impacts an unknown function. This manipulation causes improper check for unusual conditions.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-42349">CVE-2026-42349</a>. The attack can be initiated remotely. There is not any exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco sees quantum networking as the future of networking]]></title>
<description><![CDATA[Particle entanglement, superposition and teleportation are key concepts in quantum physics. Einstein famously dismissed such phenomena as “spooky action at a distance.”



Quantum computing is the nascent field of technology bringing that spookiness to life, but it is quantum networking that will...]]></description>
<link>https://tsecurity.de/de/3570753/it-security-nachrichten/cisco-sees-quantum-networking-as-the-future-of-networking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570753/it-security-nachrichten/cisco-sees-quantum-networking-as-the-future-of-networking/</guid>
<pubDate>Wed, 03 Jun 2026 22:34:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Particle entanglement, superposition and teleportation are key concepts in quantum physics. Einstein famously dismissed such phenomena as “spooky action at a distance.”</p>



<p>Quantum computing is the nascent field of technology bringing that spookiness to life, but it is quantum networking that will actually enable quantum computing to be useful by connecting multiple systems together. According to Cisco, quantum networking’s practical utility isn’t limited to quantum computing, and it can have a material impact on the regular networks we use today.</p>



<p>In a deep-dive session at Cisco Live, <a href="https://www.linkedin.com/in/rkompella/">Ramana Kompella</a>, head of Cisco Research and Cisco Fellow, detailed precisely what quantum networking is, how it works at a theoretical level, and what Cisco is building to enable real world applications.</p>



<p>During his session, Kompella made the case that the bottleneck to practical quantum computing is not the processor. It is the network connecting processors together. His argument drew directly from the history of classical infrastructure: The same scale-out methodology that built the modern internet could, he said, accelerate the arrival of useful quantum computing by decades.</p>



<p>“Quantum networking can accelerate the arrival of practical quantum computing by decades by using the scale-out methodology that we’ve used successfully in our classical infrastructure,” Kompella said.</p>



<h2 class="wp-block-heading">How quantum networking actually works</h2>



<p>The starting point is understanding why quantum networks cannot be built like classical ones. </p>



<p>“Quantum networking is completely different from classical networking,” Kompella said.</p>



<p>In a classical network, data moves as packets through switches and routers. In a quantum network, information is not transported directly. Instead, the network distributes entangled photon pairs between nodes. Entanglement links two photons so that measuring the state of one instantly determines the state of the other, regardless of the distance between them.</p>



<p><strong>The qubit</strong>: Where classical computing processes data as bits, ones and zeros, quantum computing uses qubits, units of quantum information that exploit a property called superposition. Superposition means a qubit can represent a one, a zero, or any combination of both at the same time, until it is measured. That ability to hold multiple states simultaneously is what gives quantum computers their computational potential. Each entangled photon pair can transfer exactly one qubit of information.</p>



<p><strong>Quantum teleportation</strong>: Rather than sending a qubit directly across a wire, quantum networking uses entangled photon pairs to transfer quantum information from a sender to a receiver. The process is called teleportation because the qubit effectively disappears at one end and reappears at the other without physically traveling the intervening distance.</p>



<p><strong>The speed-of-light caveat</strong>: Teleportation sounds instantaneous, and in one sense it is, but the receiver still cannot use the arriving qubit until a classical signal arrives confirming how to interpret it. That classical signal travels at the speed of light. Information does not move faster than light.</p>



<h2 class="wp-block-heading">The hardware: What Cisco has built</h2>



<p>With those fundamentals in place, the question becomes how to build infrastructure that delivers entanglement at scale. Cisco has developed two pieces of hardware designed to answer that question.</p>



<p><strong>The entanglement source</strong>: Announced<a href="https://www.networkworld.com/article/3978702/cisco-unveils-prototype-quantum-networking-chip.html"> last May</a>, Cisco’s entanglement source generates 200 million entangled photon pairs per second. It operates at standard telecom frequencies, which means it runs over existing fiber infrastructure rather than requiring a dedicated quantum fiber plant. It also runs at room temperature, with no cryogenic hardware required.</p>



<p><strong>The Universal Quantum Switch</strong>: The centerpiece of Kompella’s session was a chip he pulled from his shirt pocket: a prototype of the<a href="https://www.networkworld.com/article/4162201/cisco-switch-aimed-at-building-practical-quantum-networks.html"> Cisco Universal Quantum Switch</a>, built from thin film lithium niobate.</p>



<p>“I’ve seen people pulling out pluggables from their pockets all the time,” Kompella said. “I get a chance to pull it out of my pocket to showcase the quantum switch chip.”</p>



<p>Standard optical switching hardware cannot be used in a quantum network. It disturbs the fragile quantum states being transmitted. The Cisco switch is built specifically to preserve quantum information through the switching operation.</p>



<p>The universality in its name comes from modality conversion. Quantum computers are not all built the same way. Superconducting, neutral atom, ion trap and photonic systems each encode quantum information differently, using polarization, time bin, frequency bin and other modalities. A switch that handles only one encoding type locks an operator into a single hardware vendor. The Cisco Universal Quantum Switch converts between modalities, so a single fabric can interconnect heterogeneous quantum processors.</p>



<p>“We are building the switch and fabric in order to actually interconnect all of them, not just any one type,” Kompella said.</p>



<h2 class="wp-block-heading">Architecture: the quantum data center model</h2>



<p>Cisco’s architecture puts the switch at the center of a pod-based topology that mirrors classical data center design: processors and shared resources grouped into pods, interconnected through layers of switching.</p>



<p>Entanglement protocols are required. Three protocols handle end-to-end entanglement between quantum processors:</p>



<ul class="wp-block-list">
<li><strong>Emitter-Scatterer:</strong> One side emits a photon that interacts with a matter qubit on the receiving end.</li>



<li><strong>Emitter-Emitter:</strong> Both sides emit photons that meet at a Bell State Measurement Device.</li>



<li><strong>Scatter-Scatter:</strong> Two entanglement sources achieve transitive entanglement across two measurement points.</li>
</ul>



<p>Each protocol suits different hardware configurations.</p>



<p>A distributed compiler is also required. A large quantum circuit cannot run on a single processor today. Cisco’s distributed quantum compiler partitions circuits across multiple processors and manages execution across the network. It also handles distributed error correction through syndrome measurement, a non-destructive operation that detects and corrects erroneous qubits without collapsing quantum states, extended to the network layer to ensure the interconnect does not introduce new errors into the computation.</p>



<h2 class="wp-block-heading">Classical applications that benefit now</h2>



<p>Kompella also addressed a question that goes beyond quantum computing: Can classical networking applications benefit from a quantum network today? Two properties make that possible. The first is entanglement. The second is the no-cloning theorem, which states that quantum information can be moved but not copied.</p>



<p><strong>Quantum Sync</strong>: Two trading desks separated by tens of kilometers want to execute coordinated buy or sell decisions simultaneously. In a classical network, one side sends a message and waits for a response, and at the microsecond timescales of high-frequency trading, that propagation delay matters. With an entangled state between the two nodes, both sides make a joint decision without waiting for a message to cross the link. Kompella said the approach carries a 10% to 15% advantage over any classical coordination scheme.</p>



<p><strong>Quantum Alert</strong>: The threat is harvest now, decrypt later: An attacker taps the fiber, collects encrypted packets, and waits for a quantum computer capable of breaking the encryption. Quantum Alert multiplexes entangled photons onto existing classical fiber. Both endpoints perform joint measurements, producing correlated detections called coincidences. A dip in coincidences signals that photons are being absorbed. An attacker cannot inject replacement entangled photons, so the pattern breaks regardless.</p>



<p>“That’s what makes this foolproof against an eavesdropper,” Kompella said.</p>



<h2 class="wp-block-heading">From lab to live fiber, and what comes next</h2>



<p>Cisco has moved beyond controlled environments. Working with a partner called Connect, Cisco ran entanglement-swapping experiments over live operational fiber in New York.</p>



<p>“We got much better rates than what lab results actually look like,” Kompella said.</p>



<p>On the computing side, Cisco has announced partnerships with IBM and, more recently, Atom Computing, a neutral-atom quantum computing vendor. The collaboration spans the software stack, distributed error correction and transduction, which is the process of converting quantum information between different physical carrier types, with the goal of stitching heterogeneous quantum nodes into a single end-to-end network.</p>



<p>The partnerships reflect the same architectural logic as the Universal Quantum Switch. Cisco is not betting on one quantum computing modality winning. It is building the interconnect layer that works regardless of which one does.</p>



<p>“Quantum networking has many practical and commercial use cases in the classical world today,” Kompella said.</p>



<h4 class="wp-block-heading">Read more stories from Cisco Live 2026</h4>



<ul class="wp-block-list">
<li><a href="https://www.networkworld.com/article/4180810/what-is-cisco-cloud-control-and-why-should-customers-care.html">What is Cisco Cloud Control and why should customers care?</a></li>



<li><a href="https://www.networkworld.com/article/4179942/cisco-live-the-network-is-back-and-ai-rewrote-the-rules.html">Cisco Live: The network is back, and AI rewrote the rules</a></li>



<li><a href="https://www.networkworld.com/article/4179673/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live.html">Cisco brings agentic ops platform and security overhaul to Cisco Live</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is Cisco Cloud Control and why should customers care?]]></title>
<description><![CDATA[As is typical of Cisco, the company made several product announcements at its flagship event, Cisco Live. The most significant product announcement is Cisco Cloud Control, which recognizes that customers do not run separate Cisco products; they run one sprawling, interconnected environment that m...]]></description>
<link>https://tsecurity.de/de/3570274/it-security-nachrichten/what-is-cisco-cloud-control-and-why-should-customers-care/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570274/it-security-nachrichten/what-is-cisco-cloud-control-and-why-should-customers-care/</guid>
<pubDate>Wed, 03 Jun 2026 18:23:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As is typical of <a href="https://www.cisco.com/">Cisco</a>, the company made several product announcements at its flagship event, <a href="https://www.ciscolive.com/">Cisco Live</a>. The most significant product announcement is Cisco Cloud Control, which recognizes that customers do not run separate Cisco products; they run one sprawling, interconnected environment that must be monitored, secured, and increasingly operated with AI at machine speed.</p>



<p>That is what Cisco Cloud Control is supposed to be: a single management plane with one login, one view, and one operational model spanning networking, security, compute, observability, and collaboration. Cisco is positioning it as the foundation for its broader AgenticOps vision, in which human operators and AI agents work from the same data and in the same workspace, with humans still in control. For Cisco customers, this matters because the company is finally trying to turn its massive product portfolio into an actual platform.</p>



<h2 class="wp-block-heading">More than another console</h2>



<p>On paper, Cloud Control sounds simple enough. It provides a unified environment, a shared data layer, and a common system of action, while also giving customers access to capabilities such as unified inventory, topology, policy, identity, and event correlation across the Cisco estate. During the keynote demos, Cisco showed single sign-on, all assets in one place, a single topology view, and direct access to products such as Meraki, Splunk, Security Cloud Control, Intersight, Control Hub, and Cisco IQ.</p>



<p>That alone would be useful. Cisco’s biggest enterprise customers have spent years dealing with product silos that made perfect sense inside the org chart but far less sense in an actual IT environment. Networking had its console, security had its console, observability had its tools, collaboration had its dashboard, and the poor operator in the middle had to stitch it all together manually. Cloud Control is Cisco’s admission that this model no longer scales.</p>



<h2 class="wp-block-heading">Why the single dashboard matters now</h2>



<p>The timing here is not accidental. In the AI era, operations are no longer just about watching dashboards and opening tickets. Infrastructure teams are being asked to diagnose and fix problems faster, while the threat landscape is compressing the time between vulnerability disclosure and exploitation from weeks to minutes. Cisco’s argument is that if customers are going to operate and defend infrastructure at machine speed, they cannot keep jumping from console to console and trying to correlate everything by hand.</p>



<p>That is why the single dashboard is more strategic than it sounds. Cisco is not just aggregating links to existing products. It is trying to create a common operational context so people and agents can work from the same inventory, topology, telemetry, and policies. If the old model was “visibility first, action later,” the new model is supposed to be visibility, reasoning, and action, all within the same environment.</p>



<h2 class="wp-block-heading">The break from Cisco’s past</h2>



<p>At Cisco Live 2024, Chief Product Officer Jeetu Patel declared that within two years, Cisco would be unrecognizable in a positive way. Cisco Live 2026 marks that two-year milestone, and Patel (pictured at top) has indeed made Cisco unrecognizable, with Cloud Control the most recent example. Historically, Cisco has rolled out one “single pane of glass” after another. In the past, I’ve said that if there were a Magic Quadrant for single panes of glass, Cisco would be the runaway leader because it had so many.</p>



<p>This is what makes Cloud Control so interesting. Cisco explicitly says this is not a “single pane of glass,” and the company is right to make that distinction. In its own words, glass is passive; Cloud Control is designed to enable active execution, with policy and identity built directly into the control path. That is a sharp departure from the old enterprise management philosophy, in which the dashboard’s job was mostly to display information and leave the operator to figure out the rest.</p>



<p>Cisco is also changing the abstraction layer.</p>



<p>For years, the company sold management in product-sized chunks. Now it is talking about a secure harness for agentic infrastructure, complete with trusted access, normalized APIs, Model Context Protocol connectivity, telemetry, enforcement points, and governance to ensure actions are bounded, auditable, and reversible. That is a much more ambitious framing, and frankly, it has to be. In a world of AI agents, the real value is not in prettier user interfaces. It is in creating a trusted operating environment where agents can do useful work without breaking things. At Cisco Live, all product demonstrations have been delivered from within Cisco Cloud Control, showcasing the product’s breadth and depth. </p>



<h2 class="wp-block-heading">AI Canvas is where the story gets real</h2>



<p>One of the strongest parts of the announcement is AI Canvas, which Cisco is moving into controlled availability as part of Cloud Control, rather than keeping it locked inside individual products. Cisco describes AI Canvas as a multiplayer workspace where human operators and AI agents investigate and resolve issues together, using the same live evidence, with context persisting across handoffs, shift changes, and escalations.</p>



<p>That is important because enterprise IT does not need more AI window dressing. It needs help with the messy middle of operations, where a single performance issue can become a network, policy, application, and security question all at once. Cisco says AI Canvas can take a natural-language prompt, build a multi-agent investigation plan, gather evidence across domains, and return a sourced answer, with the operator still approving the path forward. If that works as advertised, Cisco is not just simplifying operations. It’s changing how infrastructure work gets done.</p>



<h2 class="wp-block-heading">The marketplace makes this bigger than Cisco</h2>



<p>The other notable component of the announcement is the Marketplace, which is central to whether Cloud Control becomes a platform or just a better Cisco front end.</p>



<p>The Marketplace is a catalog of apps, agents, and integrations built by Cisco, customers, and partners, and it already includes integrations from more than 50 ecosystem partners. The partner list includes AWS, Google Cloud, Linear, Microsoft, Okta, PagerDuty, ServiceNow, Slack, Snowflake, Tenable, and Wiz, among others.</p>



<p>That matters because no enterprise is all-Cisco. The company acknowledges that customers operate multivendor environments and need to customize workflows beyond what Cisco ships out of the box. With Agent Builder, App Builder, and Marketplace, Cisco is also enabling customers to connect third-party tools, build their own agents, and create custom apps on top of Cisco’s control plane rather than waiting for a roadmap. That is a big deal because it moves Cisco from a product vendor to a platform operator.</p>



<p>After the keynote, I caught up with Evan Mintzer, director of production infrastructure at <a href="https://customersbank.com/">Customers Bank</a>. While he appreciates having a single dashboard for their Cisco products, it’s the ecosystem partnerships that truly caught his attention. “When Cisco displayed the slide of supported vendors, I recognized several we already use and a few others we’re considering,” Mintzer shared. “That ecosystem will make integrating them into our environment much easier.”</p>



<h2 class="wp-block-heading">Why every Cisco customer should care</h2>



<p>During his keynote, Patel made a comment that I think succinctly captures the value of Cisco Cloud Control: “Cloud Control is at its core simplicity without losing the sophistication of Cisco, and so what we’ve tried to do is say all the products that you know from Cisco and love will be managed from it.”</p>



<p>Historically, customers had to choose between the ease of use of a dashboard and the CLI for more complex tasks. Now they can do both through a natural language interface.</p>



<p>It’s also about capturing more value from the Cisco investment many companies have already made. The more Cisco infrastructure a customer runs, the more value the platform should deliver by connecting inventory, topology, policy, security, and AI-driven workflows in one place. Cisco has always had broad reach across the stack, but breadth alone is not enough. Without a unifying control layer, breadth becomes portfolio sprawl. Cloud Control is Cisco’s best attempt yet to turn that sprawl into an advantage.</p>



<p>There is also a defensive reason to care. Cisco is positioning Cloud Control as the command center for a post-Mythos world, tying it to Live Protect, unified security policy, asset visibility, vulnerability posture, and broader agentic security controls. In other words, this is not just an operations console. Cisco wants it to become the place where customers defend infrastructure in real time.</p>



<h2 class="wp-block-heading">My advice to Cisco customers</h2>



<p>Customers should approach Cloud Control with both enthusiasm and discipline. If you are a Cisco-heavy shop, this could become the operational layer that finally ties your environment together. But do not accept the vision based on branding alone.</p>



<p>First, test how Cloud Control reduces cross-domain complexity. A single pane of links is not the same as a single operating model.</p>



<p>Second, rigorously evaluate the AI governance model. Cisco wisely emphasizes human approval, auditability and bounded actions, but customers should validate this in real workflows before letting agents take any consequential actions.</p>



<p>Third, take the Marketplace seriously from day one. The ability to manage the Cisco domain from a single dashboard has obvious appeal, but extending it across a large percentage of the overall environment can significantly simplify operations and troubleshooting.</p>



<p>Cisco has had the pieces for years: leadership positions in networking, security, observability, collaboration, and infrastructure, plus one of the deepest installed bases in enterprise IT. What it has lacked is the control plane to bind them all together. Cloud Control shows that the company understands the future will not be won by having the most dashboards. It will be won by having the operating layer where humans and AI agents can work.</p>



<p>And that is why this launch matters. Cisco Cloud Control is not just another product announcement. It is Cisco’s effort to become the system through which its customers run the agentic enterprise. It’s positioned itself as “Mission Critical Infrastructure for the AI era” — but with Cloud Control, it’s that plus the operational environment.</p>



<h4 class="wp-block-heading">Read more stories from Cisco Live 2026</h4>



<ul class="wp-block-list">
<li><a href="https://www.networkworld.com/article/4179942/cisco-live-the-network-is-back-and-ai-rewrote-the-rules.html">Cisco Live: The network is back, and AI rewrote the rules</a></li>



<li><a href="https://www.networkworld.com/article/4179673/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live.html">Cisco brings agentic ops platform and security overhaul to Cisco Live</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco Live: The network is back, and AI rewrote the rules]]></title>
<description><![CDATA[For much of the past decade, enterprise networking was something the industry tried to abstract away. Cloud-first architectures commoditized switching and routing, burying them under software-defined layers. AI infrastructure has reversed that trajectory. Tom Gillis, senior vice president and gen...]]></description>
<link>https://tsecurity.de/de/3567031/it-security-nachrichten/cisco-live-the-network-is-back-and-ai-rewrote-the-rules/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567031/it-security-nachrichten/cisco-live-the-network-is-back-and-ai-rewrote-the-rules/</guid>
<pubDate>Tue, 02 Jun 2026 19:08:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For much of the past decade, enterprise networking was something the industry tried to abstract away. Cloud-first architectures commoditized switching and routing, burying them under software-defined layers. AI infrastructure has reversed that trajectory. <a href="https://www.linkedin.com/in/tomgillis1/">Tom Gillis</a>, senior vice president and general manager of Cisco’s infrastructure and security group, has a theory about why, and it starts with the network.</p>



<p>At Cisco Live this week, <a href="https://www.networkworld.com/article/4179673/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live.html">Cisco is announcing a broad set of security and infrastructure capabilities</a> spanning vulnerability protection, network enforcement and agentic access control.</p>



<p>In the AI era, Gillis said, the network performs the role the PCI bus once played inside a single server. Distributed AI systems require memory, compute, GPU, and storage to work together across physical infrastructure at scale. The network is the backplane that makes that possible. The result, he said, is that customers have come to see it as the one thing they can count on.</p>



<p>“There is a new operating model necessary for infrastructure,” Gillis told <em>Network World</em>.</p>



<h2 class="wp-block-heading">AI changed how Cisco builds its own products</h2>



<p>The shift shows up inside Cisco’s own development organization. Gillis runs a team of roughly 12,000 software developers, and AI coding tools have fundamentally changed how that team works.</p>



<p>Earlier generations of AI coding tools produced significant gains on new projects, where a team of five to 10 developers could accomplish what once required 100 people working for a year. But those tools hit a ceiling on complex legacy products. A Catalyst switch or Cisco firewall can contain 50 to 100 million lines of code, more context than prior models could handle at once. Newer AI coding tools have removed that ceiling, allowing Cisco to accelerate development across its entire product portfolio.</p>



<p>The other side of that acceleration is vulnerability discovery. Frontier AI models like Anthropic’s Claude Mythos can now comprehend entire complex codebases and are finding vulnerabilities that humans have been unable to find.</p>



<p>“Frontier models are finding vulnerabilities at a scale that has never been achieved before, and it’s not one and done. These things are going to continue to find new vulnerabilities,” Gillis said.</p>



<h2 class="wp-block-heading">A new security stack built from the Linux kernel up</h2>



<p>The standard data center response to vulnerabilities has been to build a configuration, test and validate it, lock it down, and leave it alone. Gillis described that model as no longer viable. Switches and routers are inline, high-performance systems that require taking offline to update, which is why customers do it infrequently. Continuous AI-driven vulnerability discovery makes that approach untenable.</p>



<p>Cisco’s answer is built on <a href="https://www.networkworld.com/article/1291149/cisco-buy-highlights-container-networking-security.html">Isovalent</a>, its commercial platform based on the open source Cilium project, which uses <a href="https://www.networkworld.com/article/3518212/why-ebpf-is-critical-and-how-its-getting-better.html">eBPF technology</a> built into the Linux kernel.</p>



<p>“What’s great about eBPF is that we can inspect memory, so we can look at that memory, we can see what’s happening, we intercept every system call and every function call, and we can modify those system calls and function calls,” Gillis said. </p>



<p>The eBPF based functionality enables multiple new capabilities in the Cisco platform. The headline capability is Live Protect, a feature built directly into Cisco network operating systems such as NXOS and IOS. A compensating control can be scoped to a specific process ID and file, blocking a particular action without affecting anything else on the system. For an administrator, the experience is a vulnerability flagged in the Nexus dashboard with a button to apply a shield.</p>



<p>“We’ve introduced a capability that can apply a compensating control to a running system without rebooting, touching, or modifying the binaries of that running system,” Gillis said.</p>



<h2 class="wp-block-heading">Not every workload is an AI app</h2>



<p>Live Protect and the Isovalent platform address the security challenge for infrastructure running today. But the infrastructure itself is also in transition, and Cisco is building for where most enterprises actually are, not just where they are headed.</p>



<p>“The enterprise, most of their workloads are not AI, right? They’re excited about AI, AI is gonna be cool as a rapid transition, but the vast majority of their workloads are still VM-based,” Gillis said. “VMs have been around for 20 years, and so our vision for this kind of data center of the future for the enterprise is that Kubernetes becomes the orchestration layer that runs all applications.” </p>



<p>The friction point is networking. VMware operates at Layer 2, Kubernetes is Layer 3, born in the cloud. Moving a VM from a VMware environment into Kubernetes has historically meant reengineering how it connects to everything else. Cisco’s Isovalent-based software bridge allows VMs to migrate one at a time without changing their IP addresses. The result is legacy VM workloads, container-based applications, and AI workloads running together on the same infrastructure, with no forced full migration.</p>



<p>At Cisco Live, Gillis is demoing that vision on the main stage. VM-based and Kubernetes-based workloads appear as peers in the same Nexus dashboard, with the Isovalent-based software bridge handling the Layer 2 to Layer 3 translation underneath.</p>



<h2 class="wp-block-heading">The future of networking in the AI era</h2>



<p>The announcements at <a href="https://www.ciscolive.com/">Cisco Live</a> address the infrastructure challenges of today. The next challenge is already visible. As AI agents begin acting on behalf of users across enterprise systems, the network faces a new access control problem it was not designed to solve.</p>



<p>A typical enterprise user has password-based access to hundreds of applications, with credentials that rotate on a six-month cycle. Extending that same access to an agent is too permissive. “We need to put task-based controls, much more ephemeral controls, in place for agents,” Gillis said. “An agent authorized to file an expense report should have no ability to make purchases; I do not want the agent to buy a Porsche.”</p>



<p>Cisco is addressing this through Cisco Secure Access, its SSE solution, and through its hybrid mesh firewall, with controls that are task-scoped and session-specific for both user-to-application and server-to-server scenarios.</p>



<p>Beyond the show floor, Gillis said Cisco has additional announcements planned for the fall. “We’ll make some announcements in the fall that I think are going to be startling,” he said, without providing details.</p>



<p>His near-term vision is a single infrastructure architecture that spans all application types. “A year from now, I hope customers are realizing, hey, I can build infrastructure that can power my AI apps that are kind of tomorrow, the same infrastructure can power my Kubernetes-based apps that are today, in my VM-based apps, which are yesterday, all with one design, one architecture,” Gillis said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russia-aligned crime group Greyvibe extensively uses AI in attacks]]></title>
<description><![CDATA[Researchers have uncovered a previously undocumented Russian group that makes extensive use of large language models (LLMs) in its attacks against private, government, and military organizations in Ukraine. It uses a variety of attack vectors along with custom malware, with the goal of intelligen...]]></description>
<link>https://tsecurity.de/de/3558105/it-security-nachrichten/russia-aligned-crime-group-greyvibe-extensively-uses-ai-in-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558105/it-security-nachrichten/russia-aligned-crime-group-greyvibe-extensively-uses-ai-in-attacks/</guid>
<pubDate>Sat, 30 May 2026 02:52:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Researchers have uncovered a previously undocumented Russian group that makes extensive use of large language models (LLMs) in its attacks against private, government, and military organizations in Ukraine. It uses a variety of attack vectors along with custom malware, with the goal of intelligence gathering for the ongoing war.</p>



<p>Dubbed Greyvibe by researchers from WithSecure, the group has shown systematic use of generative AI across all stages of its operations, from crafting spear phishing lures and malicious scripts to full on malware development and setting up of backend infrastructure.</p>



<p>“While the activities align with Russian state interests, several observed indicators suggest the group has ties to the broader cybercrime ecosystem, with the group potentially involving current or former cybercriminal actors,” the WithSecure researchers <a href="https://labs.withsecure.com/publications/greyvibe" target="_blank" rel="noreferrer noopener">said in their report</a>.</p>



<h2 class="wp-block-heading">Shifting attack vectors</h2>



<p>Greyvibe’s first campaign was launched in August 2025, with a series of spear phishing emails that purported to come from Ukrainian officials and government agencies including the Kyiv City, the Main Directorate of the State Emergency, and the State Service of Special Communications and Information Protection.</p>



<p>The emails included links to ZIP and RAR archives, hosted on Google Drive and a service called 4sync, that contained malware loaders written in Python and JavaScript. The final payload was a custom malware program developed by the group that the WithSecure researchers dubbed PhantomRelay.</p>



<p>In another attack in October, the group experimented with ClickFix-style attacks on fake CloudFlare CAPTCHA pages. These attacks instructed users to open the Windows Run dialog and paste in malicious commands.</p>



<p>Greyvibe also set up fake adult club websites in Ukrainian, as well as fake websites for charities claiming to support the Ukrainian military with FPV drones and UAVs. These attacks distributed several malware programs for both Android devices (FallSpy) and Windows (PhantomRelay and LegionRelay).</p>



<p>The researchers also tracked a website in Russian that they believe was part of the group’s operations; it referenced hard-coded telephone exchange numbers for secure telecommunications that are typically used by the Russian military.</p>



<p>“The intended victimology of this activity remains unclear,” the researchers said. “However, the most plausible hypothesis is that the lure was designed to deceive Ukrainian military personnel by presenting the illusion of access to a Russian military terminal.”</p>



<h2 class="wp-block-heading">Custom malware developed using LLMs</h2>



<p>The PhantomRelay malware program is a remote access trojan (RAT) written in PowerShell that can execute additional custom scripts received from the command-and-control (C2) server. While variants of this program have been observed in activity that might be unrelated to Greyvibe, the group completely rewrote the tool and created a version that was exclusively used in its own operations.</p>



<p>LegionRelay is another PowerShell-based RAT that can similarly execute commands and scripts received from the C2 server; it is used for file enumeration, file exfiltration, screenshot capture, browser data theft, Telegram and WhatsApp data exfiltration, RDP access setup and other actions.</p>



<p>FallSpy is an Android spyware program that can steal contacts, call logs, a list of installed applications, SIM-linked phone numbers, device and network information, Wi-Fi SSID, the phone’s last known location, its public IP address, and media files.</p>



<p>Finally, a series of custom scripts for obfuscating and loading malware was also observed: LOOKVALPS (PowerShell), LOOKVALJS (JavaScript), DAYLIGHT (PowerShell), and TEASOUP (JavaScript).</p>



<p>The WithSecure researchers have determined, with moderate confidence, that several of these custom tools were developed with the help of LLMs. LegionRelay in particular, as well as the background infrastructure serving it, show strong indicators of AI generation. The researchers believe some of the platforms used by the attackers include Ideogram AI, ChatGPT and Google Gemini.</p>



<p>“Greyvibe appears to use AI not only for isolated development tasks, but across multiple operational phases,” the researchers said. “This likely enables the group to compensate for capability gaps, accelerate development cycles, and potentially reduce historical backlinks to prior activity. Given this extensive use, we expect the group’s tradecraft to continue evolving and diversifying, likely increasing the complexity of continuous detection, tracking, and attribution.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die besten JavaScript-Frameworks im Vergleich]]></title>
<description><![CDATA[Ein (passendes) JavaScript-Framework auszuwählen, ist ein bisschen wie Schuhe kaufen: Mit Blick auf das Gesamtangebot gibt es alles, was sich Softwareentwickler wünschen – nur nicht kombiniert in einem Modell.
					Foto: RossHelen | shutterstock.com




Den (richtigen) Technologie-Stack auszuwähl...]]></description>
<link>https://tsecurity.de/de/3549678/it-security-nachrichten/die-besten-javascript-frameworks-im-vergleich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549678/it-security-nachrichten/die-besten-javascript-frameworks-im-vergleich/</guid>
<pubDate>Wed, 27 May 2026 05:36:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Ein (passendes) JavaScript-Framework auszuwählen, ist ein bisschen wie Schuhe kaufen: Mit Blick auf das Gesamtangebot gibt es alles, was sich Softwareentwickler wünschen - nur nicht kombiniert in einem Modell." title="Ein (passendes) JavaScript-Framework auszuwählen, ist ein bisschen wie Schuhe kaufen: Mit Blick auf das Gesamtangebot gibt es alles, was sich Softwareentwickler wünschen - nur nicht kombiniert in einem Modell." src="https://images.computerwoche.de/bdb/3392180/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Ein (passendes) JavaScript-Framework auszuwählen, ist ein bisschen wie Schuhe kaufen: Mit Blick auf das Gesamtangebot gibt es alles, was sich Softwareentwickler wünschen – nur nicht kombiniert in einem Modell.</p></figcaption></figure><p class="imageCredit">
					Foto: RossHelen | shutterstock.com</p></div>




<p>Den (richtigen) Technologie-Stack auszuwählen, ist eine der diffizilsten Herausforderungen in Sachen <a href="https://www.computerwoche.de/article/2818958/was-developer-an-ihrem-job-lieben-und-hassen.html" title="Softwareentwicklung" target="_blank">Softwareentwicklung</a>: Ohne Framework kein Development – allerdings zeigen sich die wahren Stärken und Schwächen eines Rahmenwerks erst in der Praxis. Für Developer eine Zwickmühle, aus der auch <a href="https://www.computerwoche.de/article/2785190/prototyping-hilft-bei-der-softwareentwicklung.html" title="Prototyping" target="_blank">Prototyping</a> nur bedingt befreien kann. Schließlich besteht die allgemeine Tendenz dazu, Technologien zu vertrauen, die sich in der Vergangenheit bewährt haben. So können allerdings auch innovative Entwicklungen durch die Lappen gehen. Das ist speziell mit Blick auf den Bereich der <a href="https://www.computerwoche.de/article/2821289/7-javascript-projekte-die-sie-kennen-sollten.html" title="JavaScript-Frameworks" target="_blank">JavaScript-Frameworks</a> wahrscheinlich, da deren Entwicklung besonders rasant voranschreitet. Dass qualitativ hochwertige Rahmenwerke im Überfluß zur Verfügung stehen, macht die Sache nicht besser.</p>



<p>In diesem Artikel werfen wir einen Blick auf die führenden JavaScript-(Frontend-)Frameworks und vergleichen diese auf Feature-Ebene miteinander. Folgende Frameworks werden dabei behandelt:</p>



<ul class="wp-block-list">
<li><p>React</p></li>



<li><p>Vue</p></li>



<li><p>Angular</p></li>



<li><p>Preact</p></li>



<li><p>Lit</p></li>



<li><p>Svelte</p></li>



<li><p>AlpineJS</p></li>



<li><p>SolidJS</p></li>



<li><p>HTMX</p></li>



<li><p>Qwik</p></li>
</ul>



<p>Es gibt diverse Möglichkeiten, sich der Entscheidung über ein JavaScript-<a href="https://www.computerwoche.de/article/2824968/3-wege-zum-vorzeige-frontend.html" title="Frontend-Framework" target="_blank">Frontend-Framework</a> anzunähern. Ein Faktor, den Sie dabei fokussieren sollten, ist Vertrautheit: Wenn Sie und Ihr Team mit einer bestimmten Technologie wirklich vertraut sind, sollten gute Gründe vorliegen, um davon abzuweichen. Diesbezüglich könnten folgende Fragen relevant sein:</p>



<ul class="wp-block-list">
<li><p>Entspricht die Technologie nicht mehr den Anforderungen des Projekts?</p></li>



<li><p>Besteht die Gefahr, dass das von Ihnen verwendete Framework eingestellt wird?</p></li>



<li><p>Sind interessante Funktionalitäten nicht existent?</p></li>
</ul>



<p>Wenn Sie alle Fragen mit ‘nein’ beantworten können, sollten Sie sich lieber zweimal überlegen, auf ein neues Framework umzusteigen. Dennoch ist es allgemein von Vorteil, neuen Frameworks offen gegenüberzustehen, die projektspezifische Benefits in den Bereichen <a href="https://www.computerwoche.de/article/2821891/8-wege-um-top-entwickler-zu-halten.html" title="Developer Experience" target="_blank">Developer Experience</a>, <a href="https://www.computerwoche.de/article/2814007/wie-devops-die-app-performance-treibt.html" title="Performance" target="_blank">Performance</a> oder Community Support realisieren können. Dazu kommt, dass <a href="https://www.computerwoche.de/article/2794625/was-javascript-von-typescript-unterscheidet.html" title="JavaScript" target="_blank">JavaScript</a> und speziell Frontend-Frameworks miteinander interagieren und sich gegenseitig stark beeinflussen. Sich mit einem Rahmenwerk zu befassen, kann deswegen oft zu synergetischen Insights führen. Anders ausgedrückt: Ein Frontend-Framework-Deepdive kann niemals schaden.</p>



<h2 class="wp-block-heading">Die 10 wichtigsten JavaScript-Frameworks</h2>



<p>Um einen Überblick über die führenden reaktiven Frameworks zu bekommen, werfen wir einen Blick auf die populärsten Abkömmlinge. Diese haben wir auf Grundlage ihrer jeweiligen Download-Zahlen auf dem <a href="https://www.npmjs.com/" title="Open Source Repository NPM" target="_blank" rel="noopener">Open Source Repository NPM</a> ermittelt. Ein Klick auf den Link führt Sie zur jeweiligen NPM-Download-Seite inklusive der aktuellen Statistiken.</p>



<ol class="wp-block-list">
<li><p><a title="React" href="https://www.npmjs.com/package/react" target="_blank" rel="noopener">React</a></p></li>



<li><p><a title="Vue / Vue 3" href="https://www.npmjs.com/package/vue" target="_blank" rel="noopener">Vue / Vue 3</a></p></li>



<li><p><a title="Angular (CLI)" href="https://www.npmjs.com/package/@angular/cli" target="_blank" rel="noopener">Angular (CLI)</a></p></li>



<li><p><a title="Preact" href="https://www.npmjs.com/package/preact" target="_blank" rel="noopener">Preact</a></p></li>



<li><p><a title="Lit" href="https://www.npmjs.com/package/lit" target="_blank" rel="noopener">Lit</a></p></li>



<li><p><a title="Svelte" href="https://www.npmjs.com/package/svelte" target="_blank" rel="noopener">Svelte</a></p></li>



<li><p><a title="AlpineJS" href="https://www.npmjs.com/package/alpinejs" target="_blank" rel="noopener">AlpineJS</a></p></li>



<li><p><a title="SolidJS" href="https://www.npmjs.com/package/solid-js" target="_blank" rel="noopener">SolidJS</a></p></li>



<li><p><a title="HTMX" href="https://www.npmjs.com/package/htmx.org" target="_blank" rel="noopener">HTMX</a></p></li>



<li><p><a title="Qwik" href="https://www.npmjs.com/package/@builder.io/qwik" target="_blank" rel="noopener">Qwik</a></p></li>
</ol>



<p>Obwohl Popularität kein besonders guter Indikator für Qualität ist, sagt sie doch viel darüber aus, wie es um die Verfügbarkeit von Developern steht, die mit dem Framework arbeiten können. Das könnte speziell für größere Teams und Projekte einen entscheidenden Faktor darstellen.</p>



<p>Zu beachten ist mit Blick auf die Top Ten, dass es sich bei allen “Kandidaten” um reine Frontend-Frameworks handelt. Einige dieser Projekte beinhalten auch ein <a href="https://www.computerwoche.de/article/2819343/darum-ist-full-stack-engineering-schaedlich.html" title="Fullstack" target="_blank">Fullstack</a>-Framework – etwa Next oder SvelteKit, was Backend-Funktionalitäten wie Server-seitiges Rendering ermöglicht. Das ist für einige Teams und Projekte unter Umständen ein weiterer bedeutender Auswahlfaktor in Sachen JavaScript-Framework. Im Folgenden ein detaillierter Blick auf die führenden reaktiven Frameworks. Ein Klick auf die Verlinkung im Titel führt Sie direkt zum jeweiligen GitHub Repository beziehungsweise der Projekt-Webseite.</p>



<p><strong><a href="https://github.com/facebook/react" title="React" target="_blank" rel="noopener">React</a></strong></p>



<p>Das Flaggschiff der reaktiven Frameworks ist im Jahr 2013 bei Facebook respektive Meta entstanden und wird bis heute vom Social-Media-Konzern verwaltet. Wie auch die Download-Zahlen von React zeigen, ist das Framework mit großem Abstand das populärste der hier vorgestellten – und quasi die Standardwahl unter den Frontend-Rahmenwerken. Trotz seines Alters wurde React kontinuierlich von Meta <a href="https://react.dev/blog/2024/02/15/react-labs-what-we-have-been-working-on-february-2024" title="auf dem aktuellen Stand gehalten" target="_blank" rel="noopener">auf dem aktuellen Stand gehalten</a>. Dabei könnte auch eine Rolle spielen, dass Facebook immer noch auf dem Framework aufbaut.</p>



<p>Das größte Argument gegen React: sein gewaltiger Umfang. Das kann den Einsatz beschwerlich gestalten, insbesondere wenn Sie an einem Projekt arbeiten, für das die meisten React-Features erst gar nicht nötig sind. Einige der nachfolgenden JavaScript-Frameworks sind nicht nur leichtgewichtiger, sondern bieten auch andere Ansätze.</p>



<p><strong><a href="https://github.com/vuejs/vue" title="Vue" target="_blank" rel="noopener">Vue</a></strong></p>



<p>Auch bei Vue handelt es sich um ein ausgereiftes Framework, das in Sachen Support gut aufgestellt ist. Im Vergleich zu React ist Vue deutlich leichtgewichtiger und schneidet auch bei Performance-Tests besser ab.</p>



<p>Vue steht in erster Linie im Ruf, eine moderate Lernkurve aufzuwerfen. Darüber hinaus kann das Framework mit einer ausgezeichneten Dokumentation und einer offenherzigen Community punkten. <a href="https://medium.com/@serpentarium13/why-i-chose-vue-over-react-b082d81315ab" title="Einige Entwickler" target="_blank" rel="noopener">Einige Entwickler</a> bevorzugen Vue auch wegen seines ausgeprägten Fokus auf die Developer Experience. Wenn Sie und Ihr Team gerne mit Vue arbeiten, kann das Framework langfristig dazu beitragen, die Benutzerfreundlichkeit und Mitarbeiterzufriedenheit zu erhöhen.</p>



<p>Von den “Big Three” unter den JavaScript-Frontend-Frameworks (React, Angular und Vue) ist Vue das basisorientierteste, was seinen Reiz haben kann.</p>



<p><strong><a href="https://github.com/angular/angular" title="Angular" target="_blank" rel="noopener">Angular</a></strong></p>



<p>Von allen hier gelisteten Frameworks bietet Angular die wohl ausgeprägteste All-in-One-Entwicklungserfahrung. Das Framework ist als durchgängige Lösung konzipiert, die verspricht, alles nötige in einem konsistenten Paket zu liefern. In der Vergangenheit galt Angular vor allem als komplex – sowohl in der Theorie als auch in der Praxis. Zudem war ein Hauch von Overengineering bei Angular zu verspüren – eine Entwicklung die in erster Linie dem Design geschuldet war.</p>



<p>Das hat sich inzwischen allerdings grundlegend geändert: Die Entwickler hinter dem Projekt haben das Framework (<a href="https://www.infoworld.com/article/2335505/the-best-new-features-in-angular-17-a-kinder-faster-angular.html" title="mit Version 17" target="_blank">mit Version 17</a>) in diversen Aspekten simplifiziert und die Entwicklererfahrung optimiert – zudem steht nun auch eine effektive Rendering-Engine für Server-seitige Tasks zur Verfügung. Darüber hinaus wurden auch die <a href="https://angular.io/docs" title="Dokumentation" target="_blank" rel="noopener">Dokumentation</a> und die <a href="https://angular.io/" title="offizielle Webseite" target="_blank" rel="noopener">offizielle Webseite</a> modernisiert.</p>



<p>Ein wesentlicher Unterschied zu React und Vue: Angular ist eher “rechthaberisch” – für die meisten Dinge gibt es klar definierte Vorgaben. Das kann es erschweren, mit Angular Applikationen anzupassen oder unkonventionelle Wege zu gehen. Ob das von Vor- oder von Nachteil ist, hängt im Wesentlichen von Ihrem persönlichen Programmierstil ab.</p>



<p><strong><a href="https://github.com/preactjs" title="Preact" target="_blank" rel="noopener">Preact</a></strong></p>



<p>Die Nomenklatur deutet es bereits an: Bei Preact handelt es sich um ein von React inspiriertes Framework – quasi eine abgespeckte Version desselbigen mit ähnlichen aber kleineren <a href="https://www.computerwoche.de/article/2790525/was-sie-ueber-application-programming-interfaces-wissen-muessen.html" title="APIs" target="_blank">APIs</a>. Einer <a href="https://preactjs.com/guide/v10/differences-to-react/#main-differences" title="der wesentlichen Unterschiede" target="_blank" rel="noopener">der wesentlichen Unterschiede</a> besteht dabei darin, dass Preact kein eigenes Eventing-System implementiert. Stattdessen nutzt es die in den Browser integrierten Event Listener. </p>



<p>Im Vergleich mit React entwickeln Sie mit Preact schneller und schlanker – dafür müssen Sie auf einige Funktionalitäten des “Originals” verzichten. Sie können Preact allerdings mit einem <a href="https://preactjs.com/guide/v10/switching-to-preact/" title="zusätzlichen Layer ausstatten" target="_blank" rel="noopener">zusätzlichen Layer ausstatten</a> und so nahezu vollständige React-Kompatibilität erreichen. Diverse Komponenten aus dem React-Ökosystem funktionieren dann auch mit Preact.</p>



<p>Wenn Sie auf kleinere APIs Wert legen, sich dabei aber weitgehend im React-Ökosystem bewegen möchten, ist dieses reaktive Framework möglicherweise eine gute Wahl.</p>



<p><strong><a href="https://github.com/lit/lit" title="Lit" target="_blank" rel="noopener">Lit</a></strong></p>



<p>Das Alleinstellungsmerkmal von Lit: Es nutzt den <a href="https://www.webcomponents.org/introduction" title="Web-Components-Standard" target="_blank" rel="noopener">Web-Components-Standard</a> als Grundlage. Das hat zur Folge, dass die API und das Bundle selbst sehr klein sind. Der Fokus liegt darauf, die integrierten Web Components zu unterstützen. Darüber hinaus fußt Lit auf einer minimalistischen Entwicklungsphilosophie, die Ihnen maximale Flexibilität ermöglicht: Es gibt nur wenige festgeschriebene Wege, um Dinge mit Lit zu erledigen.</p>



<p>Das Framework weist – gemessen an seiner Größe und Popularität – ein sehr umfangreiches Ökosystem auf.</p>



<p><strong><a href="https://github.com/sveltejs/svelte" title="Svelte" target="_blank" rel="noopener">Svelte</a></strong></p>



<p>Dieses reaktive Framework zeichnet sich in erster Linie dadurch aus, dass es einen Compiler zum Einsatz bringt. Der transformiert die Svelte-Syntax in ein kleines und performantes JavaScript-Bundle. Das ermöglicht dem Framework, einige Optimierungen bereits im Vorfeld vorzunehmen – und mit interessanten Syntax-Elementen <a href="https://www.infoworld.com/article/2336000/reactive-magic-in-svelte-5-understanding-runes.html" title="zu experimentieren" target="_blank">zu experimentieren</a>.</p>



<p>Mit Blick auf die “Big Three” ist Svelte am ehesten mit Vue vergleichbar, weil es sich gut für unabhängige Experimente eignet. Die Dokumentation von Vue ist gut ausgestaltet und das Framework erfreut sich in der <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Open-Source</a>-Community wachsender Beliebtheit.</p>



<p><strong><a href="https://alpinejs.dev/" title="AlpineJS" target="_blank" rel="noopener">AlpineJS</a></strong></p>



<p>Von allen hier vorgestellten Frameworks ist AlpineJS das <a href="https://alpinejs.dev/" title="utilitaristischste" target="_blank" rel="noopener">utilitaristischste</a>. Es bietet eine kompakte Reactive-Bibliothek – das war’s. Trotz seines überschaubaren Footprints steckt in diesem reaktiven Framework jedoch eine ganze Menge Power. </p>



<p>Wie HTMX (dazu später) will auch AlpineJS Komplexität beseitigen, dabei jedoch die Grundlagen moderner Frontend-Funktionalität gewährleisten. Um diese Funktionalität “auf die Straße zu bringen”, nutzt das JavaScript-Framework spezielle HTML-Eigenschaften.</p>



<p><strong><a href="https://github.com/solidjs" title="SolidJS" target="_blank" rel="noopener">SolidJS</a></strong></p>



<p>Im Vergleich zu den anderen hier gelisteten JavaScript-Frontend-Frameworks ist Solid ein Vertreter der jüngeren Generation. Nichtsdestotrotz konnte SolidJS bereits (im positiven Sinn) für Furore sorgen und erfreut sich einer wachsenden Nutzerbasis.</p>



<p>Das Framework fußt auf Signals (Reactive Primitives), die ihm <a href="https://www.solidjs.com/docs/latest" title="eine flexible Grundlage verschaffen" target="_blank" rel="noopener">eine flexible Grundlage verschaffen</a>. Um die Funktionalität zu erweitern, können sowohl das Framework selbst als auch der Anwender-Code auf dieselben Features zugreifen. In Sachen Performance-Tests schneidet SolidJS gut ab.</p>



<p><strong><a href="https://github.com/bigskysoftware/htmx" title="HTMX" target="_blank" rel="noopener">HTMX</a></strong></p>



<p>Einen völlig anderen Ansatz, um Web-Frontends zu entwickeln, wirft <a href="https://www.computerwoche.de/article/2833138/dynamisches-html-ohne-javascript.html" title="HTMX" target="_blank">HTMX</a> auf: Es versucht, so viel Komplexität wie möglich zu eliminieren, REST wie beabsichtigt einzusetzen und “reines” HTML (mit einigen grundlegenden Verbesserungen) zu nutzen, um modernen Anforderungen wie AJAX- und DOM-Interaktionen <a href="https://www.computerwoche.de/article/2833120/software-ist-eine-brutale-branche.html" title="gerecht zu werden" target="_blank">gerecht zu werden</a>.</p>



<p>HTMX kann eine lohnende Option sein, wenn Sie auf Dinge wie Server-seitiges Rendering verzichten können. Einer der größten Pluspunkte des Frameworks: Es ist relativ einfach zu erlernen. Wir können nur empfehlen, sich zumindest mit diesem Projekt zu beschäftigen – und sei es nur wegen der zugrundeliegenden Idee.</p>



<p><strong><a href="https://github.com/BuilderIO/qwik" title="Qwik" target="_blank" rel="noopener">Qwik</a></strong></p>



<p>Unter der Haube ist Qwik eine exotische Implementierung, die die Performance in den Mittelpunkt rückt. Das Framework zerlegt Applikationen in unterscheidbare Elemente und orientiert sich dabei an “Grenzen” wie Eventing oder Komponenten – entlang derer aggressives <a href="https://www.computerwoche.de/article/2804239/darauf-kommt-es-an.html" title="Lazy Loading" target="_blank">Lazy Loading</a> zum Einsatz kommt. Das Ergebnis: schnelleres Rendering.</p>



<h2 class="wp-block-heading">Reactive Frameworks im (Feature-)Vergleich</h2>



<p>Nachdem Sie die zehn wichtigsten Reactive-Framework-Optionen kennengelernt haben, geht es nun darum, die wichtigsten Funktionen und Merkmale miteinander zu vergleichen. Zunächst haben wir die reaktiven Rahmenwerke noch einmal in einer Übersicht zusammengetragen, die auf einen Blick Auskunft über die jeweiligen Lernkurven und Funktions-Highlights gibt.</p>



<figure class="wp-block-table stats legacyTable"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><p><strong>Framework</strong></p></td><td><p><strong>Lernkurve</strong></p></td><td><p><strong>Highlights</strong></p></td></tr><tr><td><p><strong>React</strong></p></td><td><p>moderat bis steil</p></td><td><p>konservativste Option; riesiges Ökosystem und Community; Balance zwischen Innovation und Stabilität;</p></td></tr><tr><td><p><strong>Vue</strong></p></td><td><p>moderat</p></td><td><p>leicht zu erlernen und einzusetzen; ein etabliertes Framework das weniger “corporate” ist;</p></td></tr><tr><td><p><strong>Angular</strong></p></td><td><p>steil</p></td><td><p>ein robustes Framework für große Projekte; Enterprise-orientiert; integrierter All-in-One-Ansatz;</p></td></tr><tr><td><p><strong>Preact</strong></p></td><td><p>moderat</p></td><td><p>React-ähnlich mit schnelleren Ladezeiten; insbesondere für Mobile Development empfehlenswert;</p></td></tr><tr><td><p><strong>Lit</strong></p></td><td><p>moderat</p></td><td><p>leichtgewichtig und performant mit Fokus auf Standards; leichter mit beispielsweise HTML kombinierbar; </p></td></tr><tr><td><p><strong>Svelte</strong></p></td><td><p>moderat</p></td><td><p>kleinerer Memory-Footprint; fokussiert die Entwicklererfahrung und Innovationen;</p></td></tr><tr><td><p><strong>Alpine</strong></p></td><td><p>flach</p></td><td><p>leichtgewichtiges Toolset; einfach zu erlernen und beherrschen; gut geeignet für kleinere bis mittelgroße Projekte;</p></td></tr><tr><td><p><strong>SolidJS</strong></p></td><td><p>moderat bis steil</p></td><td><p>reaktiver Kern auf Signals-Basis; Performance-orientiert;</p></td></tr><tr><td><p><strong>HTMX</strong></p></td><td><p>flach</p></td><td><p>einfach zu erlernen und zu integrieren; einzigartige, vereinfachte REST-Architektur;</p></td></tr><tr><td><p><strong>Qwik</strong></p></td><td><p>steil</p></td><td><p>innovativ und Performance-orientiert; integriert mit builder.io;</p></td></tr></tbody></table> </div></figure>



<p>Wenn Sie nun Wert auf ganz spezielle Funktionen legen, bringt Ihnen diese Tabelle natürlich wenig. Deswegen haben wir auch noch einen umfangreichen Feature-Vergleich der gelisteten JavaScript-Frontend-Frameworks für Sie erstellt. Diesen können Sie auch <a href="https://github.com/MTyson/iw-front-end-table/blob/main/JS%20Frameworks%20Feature%20Table.pdf" title="direkt über GitHub" target="_blank" rel="noopener">direkt über GitHub</a> als PDF-Datei herunterladen (inklusive klickbarer Links). </p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Die zehn wichtigsten JavaScript-Frameworks im Feature-Vergleich." title="Die zehn wichtigsten JavaScript-Frameworks im Feature-Vergleich." src="https://images.computerwoche.de/bdb/3392181/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Die zehn wichtigsten JavaScript-Frameworks im Feature-Vergleich.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<h4 class="wp-block-heading"><strong>Playgrounds</strong></h4>



<p>Um sich einen schnellen ersten Eindruck von einem Framework zu verschaffen, empfiehlt sich, es in einem Online-REPL respektive Playground zu testen. Dazu ist kein Tooling-Setup erforderlich – ein Webbrowser reicht, um mit der Syntax experimentieren zu können. Sämtliche hier vorgestellten Frameworks können das bieten. React hostet zwar keine eigenen REPLs, diese Lücke wird jedoch von Drittanbietern geschlossen.</p>



<p><strong>Dieser Artikel ist <a href="https://www.infoworld.com/article/2336227/whats-the-best-javascript-framework.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Patching Race Was Already Lost. AI Just Made It Obvious.]]></title>
<description><![CDATA[AI just rewrote the offensive economics of finding and weaponizing vulnerabilities. Most peers I’m talking to, and most vendor write-ups I’m reading, already get that patching alone isn’t enough. Yet patching still tends to land near the top of most response lists, and from what I’ve seen in the ...]]></description>
<link>https://tsecurity.de/de/3540654/it-security-nachrichten/the-patching-race-was-already-lost-ai-just-made-it-obvious/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3540654/it-security-nachrichten/the-patching-race-was-already-lost-ai-just-made-it-obvious/</guid>
<pubDate>Fri, 22 May 2026 21:51:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI just rewrote the offensive economics of finding and weaponizing vulnerabilities. Most peers I’m talking to, and most vendor write-ups I’m reading, already get that patching alone isn’t enough. Yet patching still tends to land near the top of most response lists, and from what I’ve seen in the past 30 years, it’s the part […]</p>
<p>The post <a href="https://secureblitz.com/patching-race-was-already-lost-ai/">The Patching Race Was Already Lost. AI Just Made It Obvious.</a> appeared first on <a href="https://secureblitz.com/">SecureBlitz Cybersecurity</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Things Are Quietly Changing at Bitwarden, and People Are Worried]]></title>
<description><![CDATA[The password manager swapped its CEO, rewrote its core values, and briefly pulled "Always Free" from its pricing page.]]></description>
<link>https://tsecurity.de/de/3529671/unix-server/things-are-quietly-changing-at-bitwarden-and-people-are-worried/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529671/unix-server/things-are-quietly-changing-at-bitwarden-and-people-are-worried/</guid>
<pubDate>Tue, 19 May 2026 17:31:11 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The password manager swapped its CEO, rewrote its core values, and briefly pulled "Always Free" from its pricing page.]]></content:encoded>
</item>
<item>
<title><![CDATA[A Pentester’s Methodology for Toxic Vulnerability Combinations]]></title>
<description><![CDATA[How a Low, a Medium, and a High Compose Into a CriticalSenior pentesters find these toxic combinations the same way every time. A four-phase methodology. Each phase asks one question. This post walks the methodology through a real discovery from an authorized assessment.The Outcome FirstA handful...]]></description>
<link>https://tsecurity.de/de/3528505/hacking/a-pentesters-methodology-for-toxic-vulnerability-combinations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528505/hacking/a-pentesters-methodology-for-toxic-vulnerability-combinations/</guid>
<pubDate>Tue, 19 May 2026 11:23:53 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>How a Low, a Medium, and a High Compose Into a Critical</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ClknjmTwlFdnWaWV9SdxUw.png"></figure><p><em>Senior pentesters find these toxic combinations the same way every time. A four-phase methodology. Each phase asks one question. This post walks the methodology through a real discovery from an authorized assessment.</em></p><h3>The Outcome First</h3><p>A handful of anonymous API calls. One legitimate login at the end, as the victim. Five thousand customer accounts, every one of them reachable. Every password overwritten in a few seconds. Every account logged in to with the credentials the attacker chose. No privilege escalation, no token forgery, no exploit primitive. Every request the chain made was authorized as the attacker, because most of the chain never asked the attacker who they were.</p><p>The scanner that ran against the same application before the engagement reported the underlying findings as separate items. None rated Critical. All sat unremarkably in the triage backlog.</p><p>This post walks through how a pentester gets from those findings to that outcome. The mechanism is a methodology. It does not appear on any scanner’s findings list, but every experienced practitioner uses some version of it, and the structure is consistent enough to teach.</p><p>The methodology has four phases. Each phase asks one specific question of the application. The answers from each phase become inputs to the next. When all four answers connect, you have a <em>toxic combination</em>. Three or four findings whose individual severities understate what they enable when chained. In the engagement walked through here, that combination is one Low, one Medium, and one High that compose into a Critical.</p><p>The four questions:</p><ul><li>[1] <strong>Information Gathering.</strong> <em>What does the application teach me, that I shouldn’t have learned, just by being here?</em></li><li>[2] <strong>Vulnerability Analysis.</strong> <em>Which inputs identify objects, and which of those are not bound to my session?</em></li><li>[3] <strong>Attack Execution.</strong> <em>Does the same identifier I just exfiltrated work on a write endpoint? And was authentication required at all?</em></li><li>[4] <strong>Exploitation.</strong> <em>Can the chain produce a state change the application’s normal threat model would not detect?</em></li></ul><p>Each phase carries a severity rating taken in isolation. None of the individual ratings is Critical. The combination is.</p><p>What follows comes from an authorized assessment. The endpoint paths, request shapes, and overall chain are reproduced from the engagement. The data values (names, emails, profile IDs, hash strings) are synthesized so nothing in this post identifies the assessed application or any real customer. The pattern reported here was filed, escalated, and remediated before the application’s planned sunset.</p><h3>The Starting Position</h3><p>The engagement began the way most do. Pre-test triage produced the usual mix. A few missing security headers, a reflective XSS hint that turned out to be a false positive, a “verbose error message” entry against the login endpoint marked Medium, and a generic “missing headers on JavaScript file” against app.js.</p><p>If I had treated that as a finished list, the engagement would have been a four-paragraph memo. Three findings to acknowledge, one to push back on, sign off, move on. The chain that ended in mass account takeover would have stayed undiscovered.</p><p>I opened the JavaScript file anyway. Not because I expected anything interesting. Reading the bundle is a habit I picked up from senior reviewers years ago. Automated tooling can tell me a file is missing a header. It cannot tell me what the file does.</p><p>Every step of the methodology starts from the lowest-privilege legitimate position the application allows. Not because elevated access is hard to get, but because chains that start from admin tell us nothing about the threat model that matters most. The user the application already trusts. The chain that follows holds against an unauthenticated visitor for the first three phases. The position rises to a legitimate customer login only at the very end, when the chain reaches its outcome.</p><h3>Phase 1: Information Gathering</h3><p><em>What does the application teach me, that I shouldn’t have learned, just by being here?</em></p><p>I never logged in for this phase. Visiting the login page through Burp’s proxy was enough.</p><p>The login page’s HTML loads four obvious script files (main.js, apim-auth.js, env.js, firebase.js) and one less obvious one. A &lt;link rel=”preload” as=”script” href=”/js/app.js”&gt; declaration in the page head causes the browser to issue a GET for /js/app.js during initial page load. This is the kind of tag a webpack build emits when it wants the browser to prefetch a route chunk for the next navigation. Burp captured all five files in the same proxy history sequence, before I had typed a single character into the login form. The fifth file, app.js, is the post-login dashboard’s bundle. Its presence in the proxy history meant the application had already shipped its post-login API catalog to me, an unauthenticated visitor.</p><p>Opening app.js in Burp’s response viewer, the first dozen lines told me everything I needed to know about the API surface I was about to test.</p><pre>// Internal API endpoint catalog (used by build tools, do not remove)<br> // POST /api/login body { email, password }<br> // GET /api/profile?id=N profile by numeric id (admin only)<br> // GET /api/profile/password?id=N legacy reset-lookup (returns salt+hash)<br> // PUT /api/profile/password body { id?, currentPassword?, newPassword }<br> // POST /api/account/info body { userProfileID: N }<br> //<br> // TODO(qa): remove qa.test@acme-portal.local seed account before release.<br> // Leftover from QA cycle. Admin role, used for password-reset regression tests.</pre><p>Three things jump out of the catalog in under five seconds.</p><p>1. <strong>/api/profile?id=N is annotated “admin only”, but it is rendered by the customer dashboard.</strong> Either the comment is wrong, the gate is wrong, or both. Worth probing.</p><p>2. <strong>/api/profile/password GET returns salt+hash.</strong> That phrase belongs in a database row, not an HTTP response body. Worth probing harder.</p><p>3. <strong>PUT /api/profile/password accepts an id in addition to currentPassword.</strong> Optional id. Two execution branches in one endpoint. The branch that takes id cannot also be requiring the current password, otherwise the optional structure makes no sense.</p><p>The TODO comment names a specific email, qa.test@acme-portal.local. The developer who wrote the comment intended to remove the seed account before release. They clearly did not. The seed account also appears to have an admin role.</p><p>I rated this finding Low in isolation. Information disclosure to <em>unauthenticated</em> visitors is a notch worse than disclosure to authenticated users, but the file does not contain credentials, tokens, or directly exploitable data on its own. A reviewer skimming the bundle would tag it “Low, verify, accept the risk if no PII is exposed.” That triage is technically correct. It also prematurely closes the most interesting input the chain ever produces.</p><p>The methodology question for Phase 1 is not “what is the severity of the JS bundle exposure?” The question is <em>what does the application teach me that I shouldn’t have learned just by being here?</em> The answer is an inventory of inputs the developers thought the requester would not see.</p><p>That inventory is the input for Phase 2.</p><h3>Phase 2: Vulnerability Analysis</h3><p><em>Which inputs identify objects, and which of those are not bound to my session?</em></p><p>Phase 2 lives inside the login endpoint, which the application has to expose to unauthenticated visitors by definition. I stayed unauthenticated.</p><p>Before testing the other endpoints from the catalog directly, I tried something the JS bundle made specifically possible. I attempted to log in using qa.test@acme-portal.local, the email left behind in the TODO comment, with a deliberately wrong password. I expected the standard “Invalid credentials” response. What I got was different.</p><pre>POST /api/login HTTP/1.1<br>Content-Type: application/json<br> <br>{"email":"qa.test@acme-portal.local","password":"wrongpass"}</pre><pre>Response:<br>    {<br>     "IsSuccess": false,<br>     "error": "Email exists but password is incorrect",<br>     "email": "qa.test@acme-portal.local",<br>     "userName": "QA Test Account",<br>     "userProfileID": 9999,<br>     "role": "admin"<br>    }</pre><p>The IsSuccess: false field told me authentication failed. Everything below it told me the account exists, that it is named “QA Test Account”, that its profile ID is 9999, and that its role is admin. None of that should be in a failed-login response.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/840/1*M8IqsenVJFcLCvF9H0TRMA.png"><figcaption><strong>Verbose login response leaks PII when the email exists</strong></figcaption></figure><p>I tested the same path against an email I knew was not in the system (noone@nowhere.invalid).</p><pre>{ "IsSuccess": false, "error": "Invalid credentials" }</pre><p>Generic 401, no metadata. The verbose response only fires when the email exists. That is not a verbose error message. That is a user-enumeration oracle. Type any email at the login endpoint and the response shape tells you whether the email is registered. If it is, it also tells you the user’s name, profile ID, and role.</p><p>I confirmed the same shape against a known regular customer.</p><pre>{<br> "IsSuccess": false,<br> "error": "Email exists but password is incorrect",<br> "email": "sarah.thompson@outlook.com",<br> "userName": "Sarah Thompson",<br> "userProfileID": 2,<br> "role": "customer"<br>}</pre><p>The failed-login path leaks email, name, profile ID, and role for any registered email, to an unauthenticated visitor, with no rate limit applied. I rated this Medium in isolation. Verbose-error responses that disclose user metadata land squarely in standard Medium territory, and that rating is the right one to file. What elevates this finding inside the chain is the role field. That field tells the attacker which profile IDs are admin accounts, which becomes the prioritization for Phase 3. The Medium rating is correct. The chain is what makes it dangerous.</p><p>The output of Phase 2 is the data the gap leaks. Numeric profile IDs, and the knowledge that profile ID 9999 holds an admin role. That data is the input for Phase 3.</p><h3>Phase 3: Attack Execution</h3><p><em>Does the same identifier I just exfiltrated work on a write endpoint? And was authentication required at all?</em></p><p>The catalog from Phase 1 listed a curious endpoint.</p><pre>GET /api/profile/password?id=N legacy reset-lookup (returns salt+hash)</pre><p>Why would a password reset endpoint return the salt and hash? In a normal architecture, the reset flow generates a token, emails it, and accepts a new password. The hash never leaves the database. A “legacy reset-lookup” endpoint that returns hash and salt is the kind of thing that exists because some backend developer wrote a JSON wrapper around a legacy SOAP method without thinking about what they were exposing.</p><p>Out of habit, my first probe carried an Authorization header, a Bearer token I had picked up from a separate test session. The endpoint returned 200 with the salt and hash. I made the same call again with the Authorization header removed entirely. Same 200. Same salt and hash.</p><p>The endpoint had not checked the token. The endpoint was not checking authentication at all.</p><pre>GET /api/profile/password?id=2 HTTP/1.1<br>Accept: application/json</pre><pre>Response:<br>    {<br>     "IsSuccess": true,<br>     "userProfileID": 2,<br>     "userName": "Sarah Thompson",<br>     "email": "sarah.thompson@outlook.com",<br>     "role": "customer",<br>     "passwordHash": "A917B980DA07B1051F071DCBD0CDA0BAED53567AEEE5E92B2E4765631ED4FEEF",<br>     "salt": "4329e437404ef2f8"<br>    }</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/840/1*utqDv6csHL0h-xIVkEAZFA.png"><figcaption><strong>Hash and salt returned by the legacy reset-lookup endpoint for any profile id</strong></figcaption></figure><p>No Authorization header. No session cookie. No API key. The endpoint never asked. Hash, salt, email, username, role, all returned to an anonymous caller, for any profile ID that exists.</p><p>This is two authorization failures stacked on the same endpoint. The first is missing authentication entirely. The endpoint accepts requests from anyone on the public internet without checking who is calling. The second is missing object-level authorization. Even if the endpoint did check the caller, it would have no notion of which profile IDs that caller is allowed to read, because the code doesn’t bind the id parameter to any session at all. A scanner would catch neither pattern by itself. It would see a 200 response and move on.</p><p>A senior pentester recognizes the broken-object-level-authorization shape on a credential-bearing endpoint and rates this High. Practical impact is offline credential cracking against any user the attacker can name, with no rate limit and no authentication barrier.</p><p>The methodology pushes one more step before rating. The output of an enumeration step is rarely the data of one record. It is the proof that the enumeration <em>itself</em> works, which means the next step is to scale. I added a second enumeration target, the account/info endpoint that the catalog also listed.</p><pre>POST /api/account/info HTTP/1.1<br>Content-Type: application/json<br> <br>{"userProfileID":3}</pre><pre>Response:<br>    {<br>     "IsSuccess": true,<br>     "userProfileID": 3,<br>     "userName": "Robert Chen",<br>     "email": "robert.chen@yahoo.com",<br>     "policyNumber": "POL-10004"<br>     }</pre><p>Same pattern. No authentication required. No ownership check. The endpoint accepts any profile ID and returns email, username, and policy number. Looped over an incrementing range of profile IDs, this becomes a full customer enumeration in a few seconds. The customer database held close to 5000 records. The loop returned every one of them.</p><p>At this point I had, anonymously:</p><ul><li>A user-enumeration primitive (the verbose login response)</li><li>A salt+hash leak for any profile ID (the GET reset-lookup)</li><li>An email, name, and policy disclosure for any profile ID (the account/info endpoint)</li><li>The knowledge that profile ID 9999 is a leftover admin account</li><li>The original IDOR observation from the catalog comment (“admin only” gate that wasn’t enforced)</li></ul><p>Three independent findings, each of which a triage process would handle separately. The methodology does not let me stop and report yet. Phase 3’s question is not just “did the read work?” It is <em>does the same identifier I just exfiltrated work on a write endpoint?</em></p><p>The catalog listed the answer.</p><pre>PUT /api/profile/password body { id?, currentPassword?, newPassword }</pre><p>Optional id. Optional currentPassword. The shape itself is the bug. There is no execution path where the request both takes an id and requires the current password, because the optional structure does not allow it. The attacker passes the ID and skips the password check entirely.</p><pre>PUT /api/profile/password HTTP/1.1<br>Content-Type: application/json<br> <br>{"id": 2, "newPassword": "pwned!2026"}</pre><pre>Response:<br>{ "message": "Password updated", "userId": "CUST-002" }</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/840/1*wgVZqB75N6b3qtZzd2Cx2w.png"><figcaption><strong>BOLA write: password overwritten with no current-password check</strong></figcaption></figure><p>No Authorization. No current-password challenge. Sarah Thompson’s password rewritten by an anonymous request, using only the profile ID enumerated from Phase 2.</p><p>I rated this High in isolation. Broken Object Level Authorization on the write side, sitting on top of broken authentication on the same endpoint. The read side already established that profile IDs are enumerable. The write side converts that enumeration into account-level state changes. This is the moment the chain becomes practical.</p><h3>Phase 4: Exploitation</h3><p><em>Can the chain produce a state change the application’s normal threat model would not detect?</em></p><p>The previous phases each produced a finding. This phase produces an outcome.</p><p>Phase 4 is the only authenticated request in the chain, and the attacker authenticates as the victim.</p><pre>POST /api/login HTTP/1.1<br>Content-Type: application/json<br> <br>{"email":"sarah.thompson@outlook.com","password":"pwned!2026"}</pre><pre>Response:<br>    {<br>     "IsSuccess": true,<br>     "token": "eyJhbGci…Sarah's customer token…",<br>     "role": "customer",<br>     "name": "Sarah Thompson",<br>     "customerId": "CUST-002"<br>    }</pre><p>I am Sarah Thompson now, as far as the application is concerned. The login endpoint cannot tell me apart from her, because the credential store says I am her.</p><p>Looped across the enumerated profile IDs, this is mass account takeover. Every one of the nearly 5000 customer records was reachable from the chain. There is no impersonation, no token forgery, no privilege escalation. The application’s authentication did its job at the login endpoint, but the application’s authentication never ran at the other endpoints, because those endpoints did not require it. Authorization decisions on the object level (should this requester be allowed to act on this specific record) never happened either.</p><p>I stopped after demonstrating impact on a single account. Exploiting the rest of the enumerable population would have served no purpose for the report.</p><p>That is the asymmetry the methodology exposes. Mass takeover by a “legitimate” login does not look like an attack to most monitoring. It looks like a customer changing their password and logging in with the new password, repeatedly. Detection systems built around “unauthorized access” do not fire, because every request to the chain’s anonymous endpoints returned 200, and every login at the end returned a valid token. Nothing in the audit log says “attack.”</p><h3>The Methodology, Extracted</h3><p>Read backwards from the chain that worked, the methodology has four phases.</p><p>1. <strong>Information Gathering.</strong> <em>What does the application teach me, that I shouldn’t have learned, just by being here?</em></p><p>2. <strong>Vulnerability Analysis.</strong> <em>Which inputs identify objects, and which of those are not bound to my session?</em></p><p>3. <strong>Attack Execution.</strong> <em>Does the same identifier I just exfiltrated work on a write endpoint? And was authentication required at all?</em></p><p>4. <strong>Exploitation.</strong> <em>Can the chain produce a state change the application’s normal threat model would not detect?</em></p><p>Each phase carries a severity rating taken in isolation. None is Critical. The combination is.</p><p>When the four phases are complete, the chain documents into a single table that forces clarity about three things every chain has but reports often muddle. What the attacker learned at this step, what they could do with it, and what the next step needed as input.</p><blockquote>Toxic Vulnerability Combinations: A Pentester’s Methodology in Four Phases</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/840/1*xjWpfUP6ckRUTxZ1qa0A-g.png"></figure><p>Three things the table makes explicit that a typical pentest report does not.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*FEO9H6tWCbm4iT-P1rrdWg.png"></figure><p><strong>The “Available info” row tracks what the attacker carries forward.</strong> Each column’s available info is the input needed for the next column. Phase 2 needed the API catalog and the admin hint from Phase 1. Phase 3 needed the profile IDs from Phase 2. Phase 4 needed the rewritten passwords from Phase 3. If the table has a column where “Available info” cannot be reused as input to the next column, the chain breaks. If it can, the chain holds.</p><p><strong>The “Auth required” row records what the application demanded at each step.</strong> Three of the four phases, including the one that exfiltrated credential material and the one that rewrote passwords, demanded nothing. That single row is the structural failure the entire chain rests on.</p><p><strong>The “Methodology question” row is the teaching artifact.</strong> When a junior pentester reviews the table, the questions are reusable. The next time they hunt a chain, they ask the same four questions of a different application. The answers will be different. The methodology will be the same.</p><h3>Remediation</h3><p>The chain in this post worked because three different layers of defense were missing. Authentication, object-level authorization, and information-disclosure controls. Closing the chain means closing all three. Here is the layered fix, ordered by structural importance.</p><h3>1. Authentication and Authorization</h3><p>These are the load-bearing fixes. Everything else is detection on top of a broken foundation.</p><ul><li><strong>Require authentication on every endpoint that returns account-scoped data.</strong> GET /api/profile, GET /api/profile/password, POST /api/account/info, and PUT /api/profile/password all need a valid session token. Endpoints accept anonymous calls because the developer assumed they would only be called from “trusted internal contexts.” There is no trusted internal context for an HTTP endpoint published on the public internet.</li><li><strong>Implement Role-Based Access Control (RBAC) at the route layer.</strong> Admin endpoints check role === ‘admin’ in middleware before the handler runs. Comments like // admin only in source code are not access control. The check has to be in code that executes on every request.</li><li><strong>Implement object-level authorization (BOLA prevention).</strong> Every endpoint that takes an identifier in input verifies the requester owns the resource. The pattern is if (resource.ownerId !== session.userId) return 403. Apply this at the database query layer when possible. SELECT * FROM profiles WHERE id = ? AND owner_id = ? removes the possibility of forgetting the ownership check in handler code.</li><li><strong>Require the current password on self-service password changes.</strong> Not optional. The optional id or currentPassword shape on PUT /api/profile/password was the write-side bug. Endpoint signatures should have exactly one execution path. If a function needs two paths, split it into two functions.</li><li><strong>Do not return credential material in API responses.</strong> The legacy reset-lookup endpoint that returned hash and salt should not exist. Password reset flows are token-based and never expose hashes to any client. If a legacy SOAP or JSON wrapper produced this response shape, the fix is to delete the wrapper or rewrite it to return only what the reset flow actually needs.</li></ul><h3>2. Information Disclosure</h3><p>These close the channels Phase 1 and Phase 2 used to seed the chain.</p><ul><li><strong>Generic error responses on the login endpoint.</strong> The verbose IsSuccess: false shape that disclosed email, name, profile ID, and role for any registered email is a user-enumeration oracle. Login failures should return { IsSuccess: false, error: ‘Invalid credentials’ } for every failure case (wrong password, nonexistent email, locked account, expired account) with consistent timing.</li><li><strong>Strip developer artifacts from production bundles.</strong> The API catalog and TODO comment that powered Phase 1 of this chain should not have been in app.js. Webpack’s TerserPlugin removes comments when comments: false is set in production builds. Inline JSDoc annotations on internal routes belong in source files, not built artifacts.</li><li><strong>Audit preload chains.</strong> The &lt;link rel=”preload” as=”script” href=”/js/app.js”&gt; tag shipped the post-login dashboard’s bundle to every visitor of the login page. Route-based code splitting can prevent this. app.js should be lazy-loaded after authentication, not preloaded eagerly.</li><li><strong>Remove seed and test accounts before production deployment.</strong> The QA seed account qa.test@acme-portal.local should not have shipped to production. CI/CD pipelines should fail builds if seed-only email patterns appear in the database migration set targeted at a production environment.</li></ul><h3>3. Operational Layer</h3><p>Detection that catches the chain even when prevention fails.</p><ul><li><strong>Rate limit the login endpoint by IP and by email address.</strong> Enumeration probing requires many requests against /api/login in a short window. Rate limits slow this enough that it becomes detectable before the attacker completes the enumeration.</li><li><strong>Monitor for the chain’s operational signature.</strong> High-volume password resets followed by successful logins from the same IP, across multiple accounts, is the fingerprint of this attack. Detection should fire on the rate and the across-account pattern, not on any single request.</li><li><strong>Anomaly detection on BOLA writes.</strong> Legitimate users change their own passwords occasionally. A single client changing many accounts’ passwords in a short window is anomalous and should fire. And should fire <em>before</em> the chain reaches Phase 4.</li></ul><h3>Takeaways</h3><p>Automated tooling is good at finding individual classes of vulnerability and bad at finding sequences. A finding has a severity, a remediation, and a report entry. A chain has none of those. The taxonomy our tooling was built around was designed for bugs, not for combinations of bugs. That is why three findings rated Low, Medium, and High can sit unremarkably in a triage backlog while the chain they compose is Critical. The tooling is necessary. It is not sufficient. The methodology is what closes the gap.</p><p>What that means for the people doing the work:</p><ul><li><strong>Pentesters and bug bounty researchers.</strong> Apply the four questions in sequence. When you find an IDOR, do not stop at the IDOR. Phase 2’s output is the input to Phase 3. Look at the next write endpoint that accepts the same identifier type. And test every endpoint without an Authorization header at least once. Missing-auth on the read side is one of the most common ways a chain that should have required a token becomes anonymously exploitable.</li><li><strong>Code reviewers.</strong> Ask two questions of every endpoint that takes an identifier in input. <em>“Does this endpoint require authentication?”</em> and <em>“What happens if a user passes someone else’s id here?”</em> Apply both to every endpoint, not just the ones that “look” sensitive. That pair of questions, applied consistently, turns chained authorization bugs into single-endpoint authorization bugs that tooling can find before the chain forms.</li><li><strong>Triage teams.</strong> Read the chain as a unit, not the findings as separate items. A verbose error, an unauthenticated IDOR on a read endpoint, and a missing current-password check on a write endpoint are not three unrelated tickets. They are three halves of one chain that need to be closed in the same release.</li><li><strong>Developers.</strong> Every parameter that names an object the requester might not own is an authorization decision waiting to happen. Every endpoint without an authentication middleware is an authorization decision the application has already refused to make. If your endpoint signature has an optional id parameter alongside an optional currentPassword parameter, you have written two execution paths into one function and one of them is going to skip a check it shouldn’t skip.</li></ul><p>The chain is a category of vulnerability that does not exist on a scanner’s findings list and never will. Until our tools understand sequences, the work belongs to the practitioners who already do. The methodology in this post is one way to write that work down. Four questions a junior pentester can apply to a different application tomorrow morning, with the same instinct it used to take a senior reviewer ten years to build.</p><h3>Author</h3><p><strong>Hemanth Gorijala</strong> is an application security practitioner. He builds open-source security tooling, conducts web application assessments, and reviews vulnerability reports in enterprise bug bounty programs. His open-source tooling for runtime credential detection, <em>SecretSifter</em>, is at <a href="https://github.com/secretsifter">github.com/secretsifter</a>.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=993cd63ba2cf" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/a-pentesters-methodology-for-toxic-vulnerability-combinations-993cd63ba2cf">A Pentester’s Methodology for Toxic Vulnerability Combinations</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[20 Leaders Who Built the CISO Era: 2 Decades of Change]]></title>
<description><![CDATA[As part of Dark Reading's 20th anniversary special coverage, we profile the CISOs, founders, researchers, criminals, and policymakers who rewrote the enterprise risk playbook.]]></description>
<link>https://tsecurity.de/de/3510148/it-security-nachrichten/20-leaders-who-built-the-ciso-era-2-decades-of-change/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3510148/it-security-nachrichten/20-leaders-who-built-the-ciso-era-2-decades-of-change/</guid>
<pubDate>Tue, 12 May 2026 14:08:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As part of Dark Reading's 20th anniversary special coverage, we profile the CISOs, founders, researchers, criminals, and policymakers who rewrote the enterprise risk playbook.]]></content:encoded>
</item>
<item>
<title><![CDATA[They Charged $10/Month for a $5 Server, a Free Script, and Three Years of Lies. Here’s the Proof.]]></title>
<description><![CDATA[This is not a review. This is a documented technical record. Every claim in this article is reproducible by anyone with an internet connection. The commands are included. Run them yourself.How This StartedI joined CoderLegion as a content creator and reached #2 on the monthly leaderboard within d...]]></description>
<link>https://tsecurity.de/de/3505273/hacking/they-charged-10month-for-a-5-server-a-free-script-and-three-years-of-lies-heres-the-proof/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3505273/hacking/they-charged-10month-for-a-5-server-a-free-script-and-three-years-of-lies-heres-the-proof/</guid>
<pubDate>Sun, 10 May 2026 22:07:37 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*53lKoYF3djjyMjFxSeJOxw.png"></figure><blockquote><strong><em>This is not a review. This is a documented technical record.</em></strong><em> Every claim in this article is reproducible by anyone with an internet connection. The commands are included. Run them yourself.</em></blockquote><h3>How This Started</h3><p>I joined CoderLegion as a content creator and reached #2 on the monthly leaderboard within days — not because I’m exceptional, but because barely anyone posts.</p><p>Then the founder, Mehadi Hasan, sent me this:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WmnlRCwBuB5yi-ujM-g8rA.png"></figure><p><em>“I’d love to give you Premium free for a month and get your feedback on whether it actually helps. No pressure at all.”</em></p><p>Before accepting any offer involving payment details or long-term content investment, I look at what a platform is actually built on.</p><p>What I found is below. Every line is publicly verifiable.</p><h3>Finding 1: The Founding Date Is Fiction</h3><p>Run this in any terminal:</p><pre>$ curl -s https://coderlegion.com | grep -C 2 "dateCreated"</pre><pre>"dateCreated": "2020",<br>"publisher": "Coder Legion"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*55oVC8L4SUYR6a0vEWUIXQ.png"></figure><p>That markup is baked into every single page on the platform. It tells search engines — and every visitor — that this operation has existed since 2020.</p><p>Now run this:</p><pre>$ whois coderlegion.com | grep -E "Creation Date|Registry Expiry Date|Domain Status" | sort -u</pre><pre>Creation Date: 2023-07-21T16:50:42Z</pre><p><strong>The domain was not registered until July 21, 2023.</strong></p><p>The predecessor domain — kodlogs.net, the platform they rebranded from — only goes back to May 2021. That is the <em>earliest</em> any version of this operation can be placed in public record. Two years short of what they claim. And the current domain adds another two years on top of that.</p><p>There is no archived platform. No prior domain. No public evidence of existence before 2021.</p><p><strong>Three years of claimed history. Zero evidence. Embedded in every page.</strong></p><h3>Finding 2: They Said No Ads. The Source Code Disagrees.</h3><p>From their About page, verbatim:</p><blockquote>“The platform is completely free to use. We don’t run ads or charge authors.”</blockquote><p>Press Ctrl+U on any CoderLegion page. Search for adsbygoogle. You'll find an active Google AdSense implementation with publisher ID ca-pub-1763140298030248.</p><p>Ads appear in the sidebar. At the bottom of posts. On the homepage.</p><p>And on the <strong>Delete Profile page</strong> — while you are in the process of permanently erasing your account:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Kqa-qL04zO9UPjWxoQABAA.png"></figure><p><em>“We don’t run ads.” — The About page. This is the Delete Profile page.</em></p><p>During the investigation, a second ad network also appeared on mobile — MetroOpinion, a third-party survey platform:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/462/1*PHa9dMrH5FL22bExi-DPYw.png"></figure><p><em>Two ad networks. On a platform that explicitly claims to run no ads.</em></p><p><strong>The About page is marketing copy. The source code is the ground truth. They do not match.</strong></p><h3>Finding 3: The User Count Is Not Accurate — And It’s Not Even Consistent</h3><p>Every visitor to CoderLegion sees this in the login modal:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*KJ5PxoikTOY51z-k-bDB5A.png"></figure><p>That number was <strong>4,065</strong> during an earlier analysis session. It’s now <strong>4,081</strong>. The number is not pulled from the database in real-time — it changes manually, which means someone is editing it by hand.</p><p>Here is what the database actually says. The users page has public pagination. Pagination has math:</p><pre>URL pattern:          /users?start={offset}<br>Items per page:       30<br>Last accessible offset: 1170</pre><pre>Calculation:<br>  1170 / 30 = 39 full pages<br>  + final page = ~40 pages total<br>  40 × 30 = ~1,200 real users</pre><p><strong>The modal claims 4,081. The database supports ~1,200.</strong></p><p>That is a 70% inflation in the number shown to every prospective user at the exact moment they decide whether to sign up. And the fact that the number changes between sessions — going from 4,065 to 4,081 — confirms it is being managed manually, not calculated.</p><h3>Finding 4: The Infrastructure Behind the $10/Month Plan</h3><pre>$ curl -I https://coderlegion.com | grep -i server<br>server: LiteSpeed</pre><p>LiteSpeed shared hosting. Market rate: <strong>$3–5/month.</strong></p><p>Open the page source (Ctrl+U). Search for qa-theme:</p><pre>/qa-theme/CoderLegion/<br>/qa-plugin/q2a-badges-master/<br>/qa-content/jquery-3.3.1.min.js</pre><pre>Session cookies:<br>  qa_key     ← Question2Answer token<br>  PHPSESSID  ← PHP backend</pre><p>This platform runs on <strong>Question2Answer</strong> — a free, open-source PHP script. Zero license cost. Publicly available at question2answer.org.</p><p>This is what they are charging you $10/month for:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*91MSvDluenQavqxRCccrQw.png"></figure><p><em>“Supercharge Your Developer Journey.” Free Q2A script. $5 shared hosting. ~37 active writers per month.</em></p><p>“10x More Visibility” among 37 people. On a free script. On a $5 server.</p><h3>Finding 5: GoDaddy Has Blocked Renewal on Both Domains</h3><p>The WHOIS output from the terminal screenshot above tells the full story:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/965/1*nvJm0qPdQlwAKRFSww6XoQ.png"></figure><pre>$ whois coderlegion.com</pre><pre>Domain Status: clientRenewProhibited ⚠<br>Registry Expiry Date: 2026-07-21</pre><pre>$ whois kodlogs.net</pre><pre>Domain Status: clientRenewProhibited ⚠<br>Registry Expiry Date: 2026-05-08</pre><p>clientRenewProhibited is not a default flag. A registrar applies it when the domain owner is blocked from renewing — typically due to outstanding billing disputes, account holds, or compliance violations.</p><p><strong>Both the current domain and the predecessor domain carry this flag.</strong></p><p>kodlogs.net has already expired as of the date of this writing. coderlegion.com expires July 21, 2026.</p><p>One additional data point: the WHOIS record for coderlegion.com was updated <strong>April 14, 2026</strong> — days after a technical analysis of this platform was published publicly. WHOIS records do not update themselves.</p><p><strong>If you have content on CoderLegion, export it today. Not next week. Today.</strong></p><h3>Finding 6: The Database Is Observable from the Public Internet</h3><p>This is a passive observation, not an exploit. Standard security practice requires database services (MariaDB/MySQL, port 3306) to be bound to localhost — invisible to the outside world.</p><pre>Expected:   127.0.0.1:3306  ← accessible to local services only<br>Observed:   0.0.0.0:3306    ← observable from public internet</pre><p>A payment-collecting platform with a publicly observable database port is the kind of configuration that ends with breach notification emails. Verifiable via Shodan or standard port scanning. No credentials required.</p><p><strong>If you have entered payment information on CoderLegion, you should be aware of this.</strong></p><h3>Finding 7: The Authentication Controls Are Broken</h3><p>Observed during normal use of my own account:</p><p><strong>Password reset:</strong> The forgot-password flow accepts a new password directly without sending a verification link to the registered email. Ownership of the account is never confirmed.</p><p><strong>Account deletion:</strong> The deletion confirmation field — marked “Please enter your password” — accepts any non-empty string. It does not validate against the account’s actual password. An account can be deleted by anyone who can reach the page.</p><p>Both are basic authentication failures. Both were found in under five minutes of normal account usage.</p><h3>Finding 8: There Is No Peter Jones</h3><p>Before this investigation, I received the following:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ECZzbjZfEDuWHo-QxGT1_g.png"></figure><pre>From:    Peter Jones &lt;peter.jones@legioncoder.com&gt;<br>To:      [my email]</pre><pre>Hi Rockman,</pre><pre>Your recent post "You Don't Need Chaos Monkey" on Hashnode really<br>caught my attention...</pre><p>My name is FreeRave. Not Rockman. The {{first_name}} merge variable pulled a different contact's data from the bulk list. The email was sent anyway.</p><p>Independent reports confirm the same template was sent from different sender names — “Peter Jones,” “Ross,” and others — all from @legioncoder.com addresses, all referencing a specific Hashnode post, all word-for-word identical.</p><p>The sender domain — legioncoder.com, not coderlegion.com — is a standard cold-email infrastructure pattern: use a separate sending domain to protect the primary domain's deliverability reputation.</p><p>There is no editorial team. There is no personal curation. There is a template, a mailing list, and occasionally the wrong name in the salutation.</p><h3>The Sequence After Publication</h3><p>Following a prior technical analysis going public, this happened:</p><p><strong>Step 1 — IP block:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_0vmscLHwGM8NcKZdHvM9w.png"></figure><p>Desktop access timed out. Mobile network access (different IP range) remained fully operational — confirming a targeted IP-level block, not server failure or maintenance. Ads continued serving on mobile while desktop was blocked.</p><p><strong>Step 2 — Newsletter delivered to deleted account:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mzvdDC5ga1-v5HCN-DXZrg.png"></figure><pre>From:    Peter Jones &lt;newsletter@coderlegion.com&gt;<br>Subject: This Week at CoderLegion: New Articles, Your Analytics &amp; More!</pre><pre>Hi FreeRave,<br>Your profile is ready to grow!</pre><pre>Account status:    Deleted ✅<br>IP status:         Blocked ✅<br>Newsletter status: Delivered ✅</pre><p>Continuing to send marketing email to a deleted account’s address is not a UX bug. Under GDPR Article 17, account deletion triggers a right to erasure that extends to all processing — including marketing lists.</p><p>The response to published technical findings was not a statement, a correction, or engagement. It was a network-level IP block on the reviewer’s machine.</p><h3>Reproduce Everything Yourself</h3><pre># Domain creation date and renewal status<br>$ whois coderlegion.com<br>$ whois kodlogs.net</pre><pre># Server software<br>$ curl -I <a href="https://coderlegion.com/">https://coderlegion.com</a> | grep -i server</pre><pre># Founding date embedded in source<br>$ curl -s <a href="https://coderlegion.com/">https://coderlegion.com</a> | grep -C 2 "dateCreated"</pre><pre># Platform identification (or just press Ctrl+U in browser)<br># Search for: qa-theme, adsbygoogle, dateCreated</pre><pre># User count math<br># Navigate to /users — find last page number — multiply by 30</pre><pre># AdSense publisher ID<br># Ctrl+U → search: pub-</pre><pre># DB exposure<br># Shodan: hostname:coderlegion.com port:3306</pre><p><strong>15 minutes. A browser. Every finding above independently reproducible.</strong></p><h3>Who This Is For</h3><p><strong>Developers considering joining:</strong> The information above existed before you arrived. Now you have it.</p><p><strong>Content creators with published posts:</strong> Your content lives on a domain expiring July 21, 2026, with renewal blocked. Export everything now.</p><p><strong>Premium subscribers:</strong> You paid $10/month for boosted visibility among ~37 active writers per month, on a free open-source script, on shared hosting, on a platform that misrepresented its founding date, user count, and monetization model. If you believe the service was misrepresented at point of purchase, your card provider has a formal dispute process.</p><p><strong>Security researchers:</strong> Port 3306 publicly observable on a payment-collecting service is reportable to the relevant consumer protection authority in the operator’s jurisdiction.</p><h3>Conclusion</h3><p>One person building a developer community from scratch is hard. That deserves acknowledgment.</p><p>None of it justifies:</p><p>A founding date embedded in every page that no public domain record supports.<br> An ad-free promise directly contradicted by AdSense source code.<br> A user count inflated by ~70% — and manually edited between sessions.<br> A $10/month plan built on a free script and a $5 shared server.<br> Two domains blocked from renewal by their registrar.<br> A database port observable from the public internet on a payment-collecting platform.<br> Bulk outreach disguised as individual editorial curation — with mail merge errors left in.<br> An IP block as the response to published technical findings.<br> Marketing email delivered to deleted accounts in violation of erasure rights.</p><p><strong>Developers deserve accurate information about platforms asking for their time, content, and money.</strong></p><p>Run the commands. Verify the findings. Make your own decision.</p><p><em>All findings derived exclusively from public record: WHOIS lookups, HTTP headers, HTML source code, URL parameter enumeration, and first-party account use. No credentials other than the author’s own account were used. No unauthorized access was performed or implied at any stage.</em></p><p><strong>Have you received a “Peter Jones” email?</strong> What name appeared in your salutation field? Leave a comment — every data point helps establish the scope of the campaign.</p><p><em>Related:</em><br><a href="https://medium.com/bugbountywriteup/part-2-i-published-a-scam-expose-bc420e0bbc00"> <strong>PART 2: I Published a Scam Expose. NetEase Sent a Takedown Request. Then They Rewrote Their Entire Operation.</strong></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=b232637e4269" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/they-charged-10-month-for-a-5-server-a-free-script-and-three-years-of-lies-heres-the-proof-b232637e4269">They Charged $10/Month for a $5 Server, a Free Script, and Three Years of Lies. Here’s the Proof.</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[4bit - Terminal Scheme Designer]]></title>
<description><![CDATA[This is an application I wrote about 13 years ago. Back then, it became quite popular on r/linux. Recently, I rewrote it from scratch and added support for generating monochromatic, two-color, and three-color schemes.    submitted by    /u/Ok_Produce3836   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3503483/linux-tipps/4bit-terminal-scheme-designer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3503483/linux-tipps/4bit-terminal-scheme-designer/</guid>
<pubDate>Sat, 09 May 2026 19:41:31 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>This is an application I wrote about 13 years ago. Back then, it became quite popular on <a href="https://www.reddit.com/r/linux">r/linux</a>. Recently, I rewrote it from scratch and added support for generating monochromatic, two-color, and three-color schemes.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Ok_Produce3836"> /u/Ok_Produce3836 </a> <br> <span><a href="https://ciembor.github.io/4bit/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1t8bh8g/4bit_terminal_scheme_designer/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Can chatbots craft correct code?]]></title>
<description><![CDATA[I recently attended the AI Engineer Code Summit in New York, an invite-only gathering of AI leaders and engineers. One theme emerged repeatedly in conversations with attendees building with AI: the belief that we’re approaching a future where developers will never need to look at code again. When...]]></description>
<link>https://tsecurity.de/de/3501448/it-security-nachrichten/can-chatbots-craft-correct-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501448/it-security-nachrichten/can-chatbots-craft-correct-code/</guid>
<pubDate>Fri, 08 May 2026 23:20:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>I recently attended the <a href="https://www.ai.engineer/code">AI Engineer Code Summit</a> in New York, an invite-only gathering of AI leaders and engineers. One theme emerged repeatedly in conversations with attendees building with AI: the belief that we’re approaching a future where developers will <em>never</em> need to look at code again. When I pressed these proponents, several made a similar argument:</p>
<blockquote>
<p>Forty years ago, when high-level programming languages like C became increasingly popular, some of the old guard resisted because C gave you less control than assembly. The same thing is happening now with LLMs.</p>
</blockquote>
<p>On its face, this analogy seems reasonable. Both represent increasing abstraction. Both initially met resistance. Both eventually transformed how we write software. But this analogy really thrashes my cache because it misses a fundamental distinction that matters more than abstraction level: <em><strong>determinism</strong></em>.</p>
<p>The difference between compilers and LLMs isn’t just about control or abstraction. It’s about semantic guarantees. And as I’ll argue, that difference has profound implications for the security and correctness of software.</p>
<h2>The compiler’s contract: Determinism and semantic preservation</h2>
<p>Compilers have one job: preserve the programmer’s semantic intent while changing syntax. When you write code in C, the compiler transforms it into assembly, but the meaning of your code remains intact. The compiler might choose which registers to use, whether to inline a function, or how to optimize a loop, but it doesn’t change what your program <em>does</em>. If the semantics change unintentionally, that’s not a feature. That’s a compiler bug.</p>
<p>This property, semantic preservation, is the foundation of modern programming. When you write <code>result = x + y</code> in Python, the language guarantees that addition happens. The interpreter might optimize how it performs that addition, but it won’t change what operation occurs. If it did, we’d call that a bug in Python.</p>
<p>The historical progression from assembly to C to Python to Rust maintained this property throughout. Yes, we’ve increased abstraction. Yes, we’ve given up fine-grained control. But we’ve never abandoned determinism. The act of programming remains compositional: you build complex systems from simpler, well-defined pieces, and the composition itself is deterministic and unambiguous.</p>
<p>There are some rare conditions where the abstraction of high-level languages prevents the preservation of the programmer’s semantic intent. For example, cryptographic code needs to run in a constant amount of time over all possible inputs; otherwise, an attacker can use the timing differences as an oracle to do things like brute-force passwords. Properties like “constant time execution” aren’t something most programming languages allow the programmer to specify. <a href="https://blog.trailofbits.com/2025/12/02/introducing-constant-time-support-for-llvm-to-protect-cryptographic-code/">Until very recently</a>, there was no good way to force a compiler to emit constant-time code; developers had to resort to using dangerous inline assembly. But with <a href="https://blog.trailofbits.com/2025/12/02/introducing-constant-time-support-for-llvm-to-protect-cryptographic-code/">Trail of Bits’ new extensions to LLVM</a>, we can now have compilers preserve this semantic property as well.</p>
<p>As I wrote back in 2017 in “<a href="https://www.sultanik.com/blog/AutomationOfAutomation">Automation of Automation</a>,” there are fundamental limits on what we can automate. But those limits don’t eliminate determinism in the tools we’ve built; they simply mean we can’t automatically prove every program correct. Compilers don’t try to prove your program correct; they just faithfully translate it.</p>
<h2>Why LLMs are fundamentally different</h2>
<p>LLMs are nondeterministic by design. This isn’t a bug; it’s a feature. But it has consequences we need to understand.</p>
<h3>Nondeterminism in practice</h3>
<p>Run the same prompt through an LLM twice, and you’ll likely get different code. Even with temperature set to zero, model updates change behavior. The same request to “add error handling to this function” could mean catching exceptions, adding validation checks, returning error codes, or introducing logging, and the LLM might choose differently each time.</p>
<p>This is fine for creative writing or brainstorming. It’s less fine when you need the semantic meaning of your code to be preserved.</p>
<h3>The ambiguous input problem</h3>
<p>Natural language is inherently ambiguous. When you tell an LLM to “fix the authentication bug,” you’re assuming it understands:</p>
<ul>
<li>Which authentication system you’re using</li>
<li>What “bug” means in this context</li>
<li>What “fixed” looks like</li>
<li>Which security properties must be preserved</li>
<li>What your threat model is</li>
</ul>
<p>The LLM will confidently generate code based on what it <em>thinks</em> you mean. Whether that matches what you <em>actually</em> mean is probabilistic.</p>
<h3>The unambiguous input problem (which isn’t)</h3>
<p>“Okay,” you might say, “but what if I give the LLM unambiguous input? What if I say ‘translate this C code to Python’ and provide the exact C code?”</p>
<p>Here’s the thing: even that isn’t as unambiguous as it seems. Consider this C code:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="c1">// C code
</span></span></span><span class="line"><span class="cl"><span class="c1"></span><span class="kt">int</span> <span class="nf">increment</span><span class="p">(</span><span class="kt">int</span> <span class="n">n</span><span class="p">)</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="n">n</span> <span class="o">+</span> <span class="mi">1</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span></span></span></code></pre>
</figure>
<p>I asked Claude Opus 4.5 (extended thinking), Gemini 3 Pro, and ChatGPT 5.2 to translate this code to Python, and they all produced the same result:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-py" data-lang="py"><span class="line"><span class="cl"><span class="c1"># Python code</span>
</span></span><span class="line"><span class="cl"><span class="k">def</span> <span class="nf">increment</span><span class="p">(</span><span class="n">n</span><span class="p">:</span> <span class="nb">int</span><span class="p">)</span> <span class="o">-&gt;</span> <span class="nb">int</span><span class="p">:</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="n">n</span> <span class="o">+</span> <span class="mi">1</span></span></span></code></pre>
</figure>
<p>It is subtle, but the semantics have changed. In Python, signed integer arithmetic has arbitrary precision. In C, overflowing a signed integer is undefined behavior: it might wrap, might crash, <a href="https://thephd.dev/c-undefined-behavior-and-the-sledgehammer-guideline">might do literally anything</a>. In Python, it’s well defined: you get a larger integer. None of the leading foundation models caught this difference. Why not? It depends on whether they were trained on examples highlighting this distinction, whether they “remember” the difference at inference time, and whether they consider it important enough to flag.</p>
<p>There exist an infinite number of Python programs that would behave identically to the C code for all valid inputs. An LLM is not guaranteed to produce any of them.</p>
<p>In fact, it’s impossible for an LLM to exactly translate the code without knowing how the original C developer <em>expected</em> or <em>intended</em> the C compiler to handle this edge case. Did the developer know that the inputs would never cause the addition to overflow? Or perhaps they inspected the assembly output and concluded that their specific compiler wraps to zero on overflow, and that behavior is required elsewhere in the code?</p>
<h2>A case study: When Claude “fixed” a bug that wasn’t there</h2>
<p>Let me share a recent experience that crystallizes this problem perfectly.</p>
<p>A developer suspected that a new open-source tool had stolen and open-sourced their code without a license. They decided to use <a href="https://github.com/trailofbits/vendetect">Vendetect</a>, an automated source code plagiarism detection tool I developed at Trail of Bits. Vendetect is designed for exactly this use case: you point it at two Git repos, and it finds portions of one repo that were copied from the other, including the specific offending commits.</p>
<p>When the developer ran Vendetect, it failed with a stack trace.</p>
<p>The developer, reasonably enough, turned to Claude for help. Claude analyzed the code, examined the stack trace, and quickly identified what it <em>thought</em> was the culprit: a complex recursive Python function at the heart of Vendetect’s Git repo analysis. Claude helpfully submitted both a GitHub issue and an extensive pull request “fixing” the bug.</p>
<p>I was assigned to review the PR.</p>
<p>First, I looked at the GitHub issue. It had been months since I’d written that recursive function, and Claude’s explanation seemed plausible! It really did look like a bug. When I checked out the code from the PR, the crash was indeed gone. No more stack trace. Problem solved, right?</p>
<p>Wrong.</p>
<p>Vendetect’s output was now empty. When I ran the unit tests, they were failing. Something was broken.</p>
<p>Now, I know recursion in Python is risky. Python’s stack frames are large enough that you can easily overflow the stack with deep recursion. However, I also knew that the inputs to this particular recursive function were constrained such that it would never recurse more than a few times. Claude either missed this constraint or wasn’t convinced by it. So Claude painfully rewrote the function to be iterative.</p>
<p>And broke the logic in the process.</p>
<p>I reverted to the original code on the <code>main</code> branch and reproduced the crash. After minutes of debugging, I discovered the actual problem: it wasn’t a bug in Vendetect at all.</p>
<p>The developer’s input repository contained two files with the same name but different casing: one started with an uppercase letter, the other with lowercase. Both the developer and I were running macOS, which uses a case-insensitive filesystem by default. When Git tries to operate on a repo with a filename collision on a case-insensitive filesystem, it throws an error. Vendetect faithfully reported this Git error, but followed it with a stack trace to show where in the code the Git error occurred.</p>
<p>I did end up modifying Vendetect to handle this edge case and print a more intelligible error message that wasn’t buried by the stack trace. But the bug that Claude had so confidently diagnosed and “fixed” wasn’t a bug at all. Claude had “fixed” working code and broken actual functionality in the process.</p>
<p>This experience crystallized the problem: <strong>LLMs approach code the way a human would on their first day looking at a codebase: with no context about why things are the way they are.</strong></p>
<p>The recursive function looked risky to Claude because recursion in Python <em>can</em> be risky. Without the context that this particular recursion was bounded by the nature of Git repository structures, Claude made what seemed like a reasonable change. It even “worked” in the sense that the crash disappeared. Only thorough testing revealed that it broke the core functionality.</p>
<p>And here’s the kicker: Claude was <em>confident</em>. The GitHub issue was detailed. The PR was extensive. There was no hedging, no uncertainty. Just like a junior developer who doesn’t know what they don’t know.</p>
<h2>The scale problem: When context matters most</h2>
<p>LLMs work reasonably well on greenfield projects with clear specifications. A simple web app, a standard CRUD interface, boilerplate code. These are templates the LLM has seen thousands of times. The problem is, these aren’t the situations where developers need the most help.</p>
<p>Consider software architecture like building architecture. A prefabricated shed works well for storage: the requirements are simple, the constraints are standard, and the design can be templated. This is your greenfield web app with a clear spec. LLMs can generate something functional.</p>
<p>But imagine iteratively cobbling together a skyscraper with modular pieces and no cohesive plan from the start. You literally end up with Kowloon Walled City: functional, but unmaintainable.</p>
<p>




 

 




 


 <figure>
 <img src="https://blog.trailofbits.com/2025/12/19/can-chatbots-craft-correct-code/chatbots-craft-correct-code-image-1_hu_9b7cb33d29b14aa2.webp" alt="Figure 1: Gemini’s idea of what an iteratively constructed skyscraper would look like." width="1024" height="559" loading="lazy" decoding="async">
 <figcaption>Figure 1: Gemini’s idea of what an iteratively constructed skyscraper would look like.</figcaption>
 </figure>
</p>
<p>And what about renovating a 100-year-old building? You need to know:</p>
<ul>
<li>Which walls are load-bearing</li>
<li>Where utilities are routed</li>
<li>What building codes applied when it was built</li>
<li>How previous renovations affected the structure</li>
<li>What materials were used and how they’ve aged</li>
</ul>
<p>The architectural plans—the original, deterministic specifications—are essential. You can’t just send in a contractor who looks at the building for the first time and starts swinging a sledgehammer based on what seems right.</p>
<p>Legacy codebases are exactly like this. They have:</p>
<ul>
<li>Poorly documented internal APIs</li>
<li>Brittle dependencies no one fully understands</li>
<li>Historical context that doesn’t fit in any context window</li>
<li>Constraints that aren’t obvious from reading the code</li>
<li>Business logic that emerged from <a href="https://ftrain.medium.com/fun-photoshop-file-format-facts-aa1af8a62702">years of incremental requirements changes and accreted functionality</a></li>
</ul>
<p>When you have a complex system with ambiguous internal APIs, where it’s unclear which service talks to what or for what reason, and the documentation is years out of date and too large to fit in an LLM’s context window, this is exactly when LLMs are most likely to confidently do the wrong thing.</p>
<p>The Vendetect story is a microcosm of this problem. The context that mattered—that the recursion was bounded by Git’s structure, that the real issue was a filesystem quirk—wasn’t obvious from looking at the code. Claude filled in the gaps with seemingly reasonable assumptions. Those assumptions were wrong.</p>
<h2>The path forward: Formal verification and new frameworks</h2>
<p>I’m not arguing against LLM coding assistants. In my extensive use of LLM coding tools, both for code generation and bug finding, I’ve found them genuinely useful. They excel at generating boilerplate code, suggesting approaches, serving as a rubber duck for debugging, and summarizing code. The productivity gains are real.</p>
<p>But we need to be clear-eyed about their fundamental limitations.</p>
<h3>Where LLMs work well today</h3>
<p>LLMs are most effective when you have:</p>
<ul>
<li>Clean, well-documented codebases with idiomatic code</li>
<li>Greenfield projects</li>
<li>Excellent test coverage that catches errors immediately</li>
<li>Tasks where errors are quickly obvious (it crashes, the output is wrong), allowing the LLM to iteratively climb toward the goal</li>
<li>Pair-programming style review by experienced developers who understand the context</li>
<li>Clear, unambiguous specifications written by experienced developers</li>
</ul>
<p>The last two are absolutely necessary for success, but are often not sufficient. In these environments, LLMs can accelerate development. The generated code might not be perfect, but errors are caught quickly and the cost of iteration is low.</p>
<h3>What we need to build</h3>
<p>If the ultimate goal is to raise the level of abstraction for developers <em>above</em> reviewing code, we will need these frameworks and practices:</p>
<p><strong>Formal verification frameworks for LLM output.</strong> We will need tools that can prove semantic preservation—that the LLM’s changes maintain the intended behavior of the code. This is hard, but it’s not impossible. We already have formal methods for certain domains; we need to extend them to cover LLM-generated code.</p>
<p><strong>Better ways to encode context and constraints.</strong> LLMs need more than just the code; they need to understand the invariants, the assumptions, the historical context. We need better ways to capture and communicate this.</p>
<p><strong>Testing frameworks that go beyond “does it crash?”</strong> We need to test semantic correctness, not just syntactic validity. Does the code do what it’s supposed to do? Are the security properties maintained? Are the performance characteristics acceptable? Unit tests are not enough.</p>
<p><strong>Metrics for measuring semantic correctness.</strong> “It compiles” isn’t enough. Even “it passes tests” isn’t enough. We need ways to quantify whether the semantics have been preserved.</p>
<p><strong>Composable building blocks that are secure by design.</strong> Instead of allowing the LLM to write arbitrary code, we will need the LLM to instead build with modular, composable building blocks that have been verified as secure. A bit like how industrial supplies have been commoditized into Lego-like parts. Need a NEMA 23 square body stepper motor with a D profile shaft? No need to design and build it yourself—you can buy a commercial-off-the-shelf motor from any of a dozen different manufacturers and they will all bolt into your project just as well. Likewise, LLMs shouldn’t be implementing their own authentication flows. They should be orchestrating pre-made authentication modules.</p>
<h3>The trust model</h3>
<p>Until we have these frameworks, we need a clear mental model for LLM output: <strong>Treat it like code from a junior developer who’s seeing the codebase for the first time.</strong></p>
<p>That means:</p>
<ul>
<li>Always review thoroughly</li>
<li>Never merge without testing</li>
<li>Understand that “looks right” doesn’t mean “is right”</li>
<li>Remember that LLMs are confident even when wrong</li>
<li>Verify that the solution solves the actual problem, not a plausible-sounding problem</li>
</ul>
<p>As a probabilistic system, there’s always a chance an LLM will introduce a bug or misinterpret its prompt. (These are really the same thing.) How small does that probability need to be? Ideally, it would be smaller than a human’s error rate. We’re not there yet, not even close.</p>
<h2>Conclusion: Embracing verification in the age of AI</h2>
<p>The fundamental computational limitations on automation haven’t changed since I wrote about them in 2017. What has changed is that we now have tools that make it easier to generate incorrect code confidently and at scale.</p>
<p>When we moved from assembly to C, we didn’t abandon determinism; we built compilers that guaranteed semantic preservation. As we move toward LLM-assisted development, we need similar guarantees. But the solution isn’t to reject LLMs! They offer real productivity gains for certain tasks. We just need to remember that their output is only as trustworthy as code from someone seeing the codebase for the first time. Just as we wouldn’t merge a PR from a new developer without review and testing, we can’t treat LLM output as automatically correct.</p>
<p>If you’re interested in formal verification, automated testing, or building more trustworthy AI systems, <a href="https://www.trailofbits.com/contact/">get in touch</a>. At Trail of Bits, we’re working on exactly these problems, and we’d love to hear about your experiences with LLM coding tools, both the successes and the failures. Because right now, we’re all learning together what works and what doesn’t. And the more we share those lessons, the better equipped we’ll be to build the verification frameworks we need.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[First Jato release]]></title>
<description><![CDATA[So I somewhat promised to say something more on my project for the Google Summer of Code.I participated for the first time, and it was really a great experience. This is the first time I've been paid to do what I would probably have done in either case (because I immensely enjoy it), namely to wo...]]></description>
<link>https://tsecurity.de/de/3500935/unix-server/first-jato-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500935/unix-server/first-jato-release/</guid>
<pubDate>Fri, 08 May 2026 22:59:44 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[So I somewhat promised to say something more on my project for the Google Summer of Code.<br><br>I participated for the first time, and it was really a great experience. This is the first time I've been paid to do what I would probably have done in either case (because I immensely enjoy it), namely to work on an interesting free software project. So this time it was Jato, a new implementation of the Java Virtual Machine.<br><br>Jato is written in C and aims to be a JIT-only compiler/VM. So before the summer started, it wouldn't run a lot of Java programs. It couldn't even run the trivial "Hello World", but more about that later. It <span>could</span> do a few things like (java.lang.)String operations, but that was mostly because it was riding piggyback on another VM, Jam VM, which would load classes and interpret a lot of the library code (i.e. most of the standard Java API implemented by GNU Classpath).<br><br>My own project was to replace the parts that were borrowed from Jam VM with completely new, shiny code. Well, in fact, I had already worked on a standalone library called cafebabe, which would parse the Java .class file and present it to C programs using a very thin layer of structs -- the idea was to do as little as possible with the actual data and just make it easily accessible, e.g. so cafebabe doesn't do any verification of the bytecode or make sure that a class is its own superclass.<br><br>So we linked this library with Jato, and that worked pretty well. (I believe strongly in modularisation; with the class loader in a separate library, there's no way to do stupid things like making the class loader itself depend on the rest of the VM for functioning properly.) There were problems, of course, the biggest being that after developing in my own private branch for a couple of weeks, the rest of the project with its three other GSoC student participants was moving ahead too quickly for me to keep up; I had to "fix" just about every new mainline commit, since most of the VM data structures (classes, methods, fields) now had different names, different fields, etc.<br><br>At around this point, we started to notice that Jam VM wasn't being used for nearly as little as just class loading. In fact, static initializers (the "&lt;clinit&gt;" methods) and their calls were all being interpreted and executed by Jam VM, not the JIT compiler of Jato. And of course, once we started using Jato for those methods which had previously been executed by Jam VM, we found tons of bugs everywhere: The core VM (mostly my code replacing that of Jam VM), including improperly implemented Java semantics, missing bytecode instruction handlers, and the compiler (instruction selection, liveness analysis, register allocation). But it was fun, and extremely educative.<br><br>Did you know that a simple System.out.println() will make a whopping 650550 Java-method calls? That's using GNU Classpath for the Java API.<br><br>So we had to implement a lot of stuff just to make that work. In fact, we have so much infrastructure that we can even run a few other programs. And thus it was decided that it was time to make a release. The version 0.0.1 announcement:<br><br><a href="http://thread.gmane.org/gmane.comp.java.vm.jato.devel/1725">http://thread.gmane.org/gmane.comp.java.vm.jato.devel/1725</a><br><br>The "next big" missing feature is garbage collection. I expect that'll be version 0.0.2. In other words, if you're interested in Java, garbage collection, or just compilers in general, you're welcome to join us...<br><br>Our team consisted of:<br><ul><li>Pekka Enberg; Original creator, project manager and mentor.</li><li>Tomek Grabiec; His original project proposal included implementing exception handling, but he ended up somwhat like Ingo Molnar of the Linux kernel; Tomek also implemented a generic radix tree, implemented the basic threading support (java.lang.Thread), rewrote large parts of the register allocator, wrote the VM side of the JNI interface from scratch, and also did a lot of other core-VM work. Tons of other things too, including a lot of debugging.</li><li>Arthur Huillet; Floating-point support, register allocator fixes, other missing bytecodes, also a lot of debugging. Various other things.<br></li><li>Eduard-Gabriel Munteanu; Ported Jato mostly to x86-64. A tough task, since the i386 parts were moving at close to light speed.<br></li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[you have a long road to walk, but first you have to leave the house]]></title>
<description><![CDATA[or why publishing code is STEP ZERO.If you've been developing code internally for a kernel contribution, you've probably got a lot of reasons not to default to working in the open from the start, you probably don't work for Red Hat or other companies with default to open policies, or perhaps you ...]]></description>
<link>https://tsecurity.de/de/3500831/unix-server/you-have-a-long-road-to-walk-but-first-you-have-to-leave-the-house/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500831/unix-server/you-have-a-long-road-to-walk-but-first-you-have-to-leave-the-house/</guid>
<pubDate>Fri, 08 May 2026 22:56:38 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[or why publishing code is STEP ZERO.<br><br>If you've been developing code internally for a kernel contribution, you've probably got a lot of reasons not to default to working in the open from the start, you probably don't work for Red Hat or other companies with default to open policies, or perhaps you are scared of the scary kernel community, and want to present a polished gem.<br><br>If your company is a pain with legal reviews etc, you have probably spent/wasted months of engineering time on internal reviews and stuff, so think all of this matters later, because why wouldn't it, you just spent (wasted) a lot of time on it, so it must matter.<br><br>So you have your polished codebase, why wouldn't those kernel maintainers love to merge it.<br><br>Then you publish the source code.<br><br>Oh, look you just left your house. The merging of your code is many many miles distant and you just started walking that road, just now, not when you started writing it, not when you started legal review, not when you rewrote it internally the 4th time. You just did it this moment.<br><br>You might have to rewrite it externally 6 times, you might never get it merged, it might be something your competitors are also working on, and the kernel maintainers would rather you cooperated with people your management would lose their minds over, that is the kernel development process.<br><br>step zero: publish the code. leave the house.<br><br>(lately I've been seeing this problem more and more, so I decided to write it up, and it really isn't directed at anyone in particular, I think a lot of vendors are guilty of this).]]></content:encoded>
</item>
<item>
<title><![CDATA[An AI agent rewrote a Fortune 50 security policy. Here's how to govern AI agents before one does the same.]]></title>
<description><![CDATA[A CEO’s AI agent rewrote the company’s security policy. Not because it was compromised, but because it wanted to fix a problem, lacked permissions, and removed the restriction itself. Every identity check passed. CrowdStrike CEO George Kurtz disclosed the incident and a second one at his RSAC 202...]]></description>
<link>https://tsecurity.de/de/3500118/it-nachrichten/an-ai-agent-rewrote-a-fortune-50-security-policy-heres-how-to-govern-ai-agents-before-one-does-the-same/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500118/it-nachrichten/an-ai-agent-rewrote-a-fortune-50-security-policy-heres-how-to-govern-ai-agents-before-one-does-the-same/</guid>
<pubDate>Fri, 08 May 2026 20:19:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A CEO’s AI agent rewrote the company’s security policy. Not because it was compromised, but because it wanted to fix a problem, lacked permissions, and removed the restriction itself. Every identity check passed. CrowdStrike CEO George Kurtz <a href="https://venturebeat.com/security/rsac-2026-agentic-soc-agent-telemetry-security-gap">disclosed the incident and a second one at his RSAC 2026 keynote</a>, both at Fortune 50 companies.</p><p>The credential was valid. The access was authorized. The action was catastrophic.</p><p>That sequence breaks the core assumption underneath the IAM systems most enterprises run in production today: that a valid credential plus authorized access equals a safe outcome. Identity systems were built for one user, one session, one set of hands on a keyboard. Agents break all three assumptions at once.</p><p>In an exclusive interview with VentureBeat at RSAC 2026, Matt Caulfield, VP of Identity and Duo at Cisco, (pictured above) walked through the architecture his team is building to close that gap and outlined a six-stage identity maturity model for governing agentic AI. The urgency is measurable: Cisco President Jeetu Patel told VentureBeat at the same conference that 85% of enterprises are running agent pilots while only 5% have reached production — an 80-point gap that the identity work is designed to close.</p><h2>The identity stack was built for a workforce that has fingerprints</h2><p>“Most of the existing IAM tools that we have at our disposal are just entirely built for a different era,” Caulfield told VentureBeat. “They were built for human scale, not really for agents.”</p><p>The default enterprise instinct is to shove agents into existing identity categories: human user; machine identity; pick one. "Agents are a third kind of new type of identity," Caulfield said. "They're neither human. They're neither machine. They're somewhere in the middle where they have broad access to resources like humans, but they operate at machine scale and speed like machines, and they entirely lack any form of judgment."</p><p>Etay Maor, VP of Threat Intelligence at Cato Networks, <a href="https://venturebeat.com/security/openclaw-500000-instances-no-enterprise-kill-switch">put a number</a> on the exposure. He ran a live Censys scan and counted nearly 500,000 internet-facing OpenClaw instances. The week before, he found 230,000, discovering a doubling in seven days.</p><p>Kayne McGladrey, an IEEE senior member who advises enterprises on identity risk, made the same diagnosis independently. Organizations are cloning human user accounts to agentic systems, McGladrey told VentureBeat, except agents consume far more permissions than humans would because of the speed, the scale, and the intent.</p><p>A human employee goes through a background check, an interview, and an onboarding process. Agents skip all three. The <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html">onboarding assumptions baked into modern IAM</a> do not apply. Scale compounds the failure. Caulfield pointed to projections where a trillion agents could operate globally. “We barely know how many people are in an average organization,” he said, “let alone the number of agents.”</p><h2>Access control verifies the badge. It does not watch what happens next.</h2><p>Zero trust still applies to agentic AI, Caulfield argued. But only if security teams push it past access and into action-level enforcement. “We really need to shift our thinking to more action-level control,” he told VentureBeat. “What action is that agent taking?”</p><p>A human employee with authorized access to a system will not execute 500 API calls in three seconds. An agent will. Traditional <a href="https://venturebeat.com/security/rsac-2026-agent-identity-frameworks-three-gaps">zero trust</a> verifies that an identity can reach an application. It doesn’t scrutinize what that identity does once inside.</p><p>Carter Rees, VP of Artificial Intelligence at <a href="https://reputation.com/">Reputation</a>, identified the structural reason. The flat authorization plane of an LLM fails to respect user permissions, Rees <a href="https://venturebeat.com/security/one-command-open-source-repo-ai-agent-backdoor-openclaw-supply-chain-scanner">told VentureBeat</a>. An agent operating on that flat plane does not need to escalate privileges. It already has them. That is why access control alone cannot contain what agents do after authentication.</p><p>CrowdStrike CTO Elia Zaitsev described the detection gap to VentureBeat. In most default logging configurations, an agent’s activity is indistinguishable from a human. Distinguishing the two requires walking the process tree, tracing whether a browser session was launched by a human or spawned by an agent in the background. Most enterprise logging cannot make that distinction.</p><p>Caulfield’s identity layer and Zaitsev’s telemetry layer are solving two halves of the same problem. No single vendor closes both gaps.</p><p>“At any moment in time, that agent can go rogue and can lose its mind,” Caulfield said. “Agents read the wrong website or email, and their intentions can just change overnight.”</p><h2>How the request lifecycle works when agents have their own identity</h2><p>Five vendors shipped agent identity frameworks at RSAC 2026, including Cisco, CrowdStrike, Palo Alto Networks, Microsoft, and Cato Networks. Caulfield walked through how Cisco's identity-layer approach works in practice.</p><p>The <a href="https://www.networkworld.com/article/4148823/cisco-goes-all-in-on-agentic-ai-security.html">Duo agent identity platform</a> registers agents as first-class identity objects, with their own policies, authentication requirements, and lifecycle management. The enforcement routes all agent traffic through an AI gateway supporting both <a href="https://venturebeat.com/security/meta-rogue-ai-agent-confused-deputy-iam-identity-governance-matrix">MCP</a> and traditional REST or GraphQL protocols. When an agent makes a request, the gateway authenticates the user, verifies that the agent is permitted, encodes the authorization into an OAuth token, and then inspects the specific action and determines in real time whether it should proceed.</p><p>“No solution to agent AI is really complete unless you have both pieces,” Caulfield told VentureBeat. “The identity piece, the access gateway piece. And then the third piece would be observability.”</p><p>Cisco <a href="https://siliconangle.com/2026/05/04/cisco-buys-astrix-security-strengthen-ai-agent-discovery-governance/">announced its intent to acquire Astrix Security</a> on May 4, signaling that agent identity discovery is now a board-level investment thesis. The deal also suggests that even vendors building identity platforms recognize that the discovery problem is harder than expected.</p><h2>Six-stage identity maturity model for agentic AI</h2><p>When a company shows up claiming 500 agents in production, Caulfield doesn't accept the number. "How do you know it's 500 and not 5,000?"</p><p>Most organizations don’t have a source of truth for agents. Caulfield outlined a six-stage engagement model.</p><p>Discovery first: identify every agent, where it runs, and who deployed it. Onboarding: register agents in the identity directory, tie each one to an accountable human, and define permitted actions. Control and enforcement: place a gateway between agents and resources, inspect every request and response. Behavioral monitoring: record all agent activity, flag anomalies, and build the audit trail. Runtime isolation contains agents on endpoints when they go rogue. Compliance mapping ties agent controls to audit frameworks before the auditor shows up. The six stages are not proprietary to any single vendor. They describe the sequence every enterprise will follow regardless of which platform delivers each stage.</p><p>Maor's Censys data complicates step one before it even starts. Organizations beginning discovery should assume their agent exposure is already visible to adversaries. Step four has its own problem. Zaitsev's process-tree work shows that even organizations logging agent activity may not be capturing the right data. And step three depends on something Rees found most enterprises lack: a gateway that inspects actions, not just access, because the LLM does not respect the permission boundaries the identity layer sets.</p><h2><b>Agentic identity prescriptive matrix</b></h2><p><i>What to audit at each maturity stage, what operational readiness looks like, and the red flag that means the stage is failing. Use this to evaluate any platform or combination of platforms.</i></p><table><tbody><tr><td><p><b>Stage</b></p></td><td><p><b>What to audit</b></p></td><td><p><b>Operational readiness looks like</b></p></td><td><p><b>Red flag if missing</b></p></td></tr><tr><td><p><b>1. Discovery</b></p></td><td><p>Complete inventory of every agent, every MCP server it connects to, and every human accountable for it.</p></td><td><p>A queryable registry that returns agent count, owner, and connection map within 60 seconds of an auditor asking.</p></td><td><p>No registry exists. Agent count is an estimate. No human is accountable for any specific agent. Adversaries can see your agent infrastructure from the public internet before you can.</p></td></tr><tr><td><p><b>2. Onboarding</b></p></td><td><p>Agents are registered as a distinct identity type with their own policies, separate from human and machine identities.</p></td><td><p>Each agent has a unique identity object in the directory, tied to an accountable human, with defined permitted actions and a documented purpose.</p></td><td><p>Agents use cloned human accounts or shared service accounts. Permission sprawl starts at creation. No audit trail ties agent actions to a responsible human.</p></td></tr><tr><td><p><b>3. Control</b></p></td><td><p>A gateway between every agent and every resource it accesses, enforcing action-level policy on every request and every response.</p></td><td><p>Four checkpoints per request: authenticate the user, authorize the agent, inspect the action, inspect the response. No direct agent-to-resource connections exist.</p></td><td><p>Agents connect directly to tools and APIs. The gateway (if it exists) checks access but not actions. The flat authorization plane of the LLM does not respect the permission boundaries the identity layer set.</p></td></tr><tr><td><p><b>4. Monitoring</b></p></td><td><p>Logging that can distinguish agent-initiated actions from human-initiated actions at the process-tree level.</p></td><td><p>SIEM can answer: Was this browser session started by a human or spawned by an agent? Behavioral baselines exist for each agent. Anomalies trigger alerts.</p></td><td><p>Default logging treats agent and human activity as identical. Process-tree lineage is not captured. Agent actions are invisible in the audit trail. Behavioral monitoring is incomplete before it starts.</p></td></tr><tr><td><p><b>5. Isolation</b></p></td><td><p>Runtime containment that limits the blast radius if an agent goes rogue, separate from human endpoint protection.</p></td><td><p>A rogue agent can be contained in its sandbox without taking down the endpoint, the user session, or other agents on the same machine.</p></td><td><p>No containment boundary exists between agents and the host. A single compromised agent can access everything the user can. Blast radius is the entire endpoint.</p></td></tr><tr><td><p><b>6. Compliance</b></p></td><td><p>Documentation that maps agent identities, controls, and audit trails to the compliance framework that the auditor will use.</p></td><td><p>When the auditor asks about agents, the security team produces a control catalog, an audit trail, and a governance policy written for agent identities specifically.</p></td><td><p>Emerging AI-risk frameworks (CSA Agentic Profile) exist, but mainstream audit catalogs (SOC 2, ISO 27001, PCI DSS) have not operationalized agent identities. No control catalog maps to agents. The auditor improvises which human-identity controls apply. The security team answers with improvisation, not documentation.</p></td></tr></tbody></table><p><i>Source: VentureBeat analysis of RSAC 2026 interviews (Caulfield, Zaitsev, Maor) and independent practitioner validation (McGladrey, Rees). May 2026.</i></p><h2>Compliance frameworks have not caught up</h2><p>“If you were to go through an audit today as a chief security officer, the auditor’s probably gonna have to figure out, hey, there are agents here,” Caulfield told VentureBeat. “Which one of your controls is actually supposed to be applied to it? I don’t see the word agents anywhere in your policies.”</p><p>McGladrey's practitioner experience confirms the gap. The Cloud Security Alliance published an <a href="https://www.nist.gov/itl/ai-risk-management-framework">NIST AI RMF Agentic Profile</a> in April 2026, proposing autonomy-tier classification and runtime behavioral metrics. But SOC 2, ISO 27001, and PCI DSS have not operationalized agent identities. The compliance frameworks McGladrey works with inside enterprises were written for humans. Agent identities do not appear in any control catalog he has encountered. The gap is a lagging indicator; the risk is not.</p><h2>Security director action plan</h2><p>VentureBeat identified five actions from the combined findings of Caulfield, Zaitsev, Maor, McGladrey, and Rees.</p><ol><li><p><b>Run an agent census and assume adversaries already did.</b></p><p> Every agent, every MCP server those agents touch, every human accountable. Maor's Censys data confirms agent infrastructure is already visible from the public internet. NIST's NCCoE reached the same conclusion in its February 2026  <a href="https://www.nccoe.nist.gov/projects/software-and-ai-agent-identity-and-authorization">concept paper on AI agent identity and authorization</a>.</p></li><li><p><b>Stop cloning human accounts for agents.</b></p><p> McGladrey found that enterprises default to copying human user profiles, and <a href="https://venturebeat.com/security/microsoft-salesforce-copilot-agentforce-prompt-injection-cve-agent-remediation-playbook">permission sprawl starts on day one</a>. Agents need to be a distinct identity type with scope limits that reflect what they actually do.</p></li><li><p><b>Audit every MCP and API access path.</b></p><p>Five vendors shipped MCP gateways at RSAC 2026. The capability exists. What matters is whether agents route through one or connect directly to tools with no action-level inspection.</p></li><li><p><b>Fix logging so it distinguishes agents from humans.</b></p><p> Zaitsev's process-tree method reveals that agent-initiated actions are invisible in most default configurations. Rees found authorization planes so flat that access logs alone miss the actual behavior. Logging has to capture what agents did, not just what they were allowed to reach.</p></li><li><p><b>Build the compliance case before the auditor shows up.</b></p><p> The CSA published a <a href="https://labs.cloudsecurityalliance.org/agentic/agentic-nist-ai-rmf-profile-v1/">NIST AI RMF Agentic Profile</a> proposing agent governance extensions. Most audit catalogs have not caught up. Caulfield told VentureBeat that auditors will see agents in production and find no controls mapped to them. The documentation needs to exist before that conversation starts.</p></li></ol><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Rewrote a Real Data Workflow in Polars. Pandas Didn’t Stand a Chance.]]></title>
<description><![CDATA[From 61 seconds to 0.20 seconds — and the mental model shift I didn't expect
The post I Rewrote a Real Data Workflow in Polars. Pandas Didn’t Stand a Chance. appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3495884/ai-nachrichten/i-rewrote-a-real-data-workflow-in-polars-pandas-didnt-stand-a-chance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3495884/ai-nachrichten/i-rewrote-a-real-data-workflow-in-polars-pandas-didnt-stand-a-chance/</guid>
<pubDate>Thu, 07 May 2026 14:20:07 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>From 61 seconds to 0.20 seconds — and the mental model shift I didn't expect</p>
<p>The post <a href="https://towardsdatascience.com/i-rewrote-a-real-data-workflow-in-polars-pandas-didnt-stand-a-chance/">I Rewrote a Real Data Workflow in Polars. Pandas Didn’t Stand a Chance.</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I gave our developers an AI coding assistant. The security team nearly mutinied]]></title>
<description><![CDATA[I’ve sat in enough risk meetings to know the sound a bad surprise makes before anyone names it. It usually starts with a pause. Then a throat gets cleared. Then someone says, “We may need to bring the CISO into this.”



That happened over a developer tool.



Not a breach. Not a regulator. Not r...]]></description>
<link>https://tsecurity.de/de/3492601/it-security-nachrichten/i-gave-our-developers-an-ai-coding-assistant-the-security-team-nearly-mutinied/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3492601/it-security-nachrichten/i-gave-our-developers-an-ai-coding-assistant-the-security-team-nearly-mutinied/</guid>
<pubDate>Wed, 06 May 2026 14:08:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I’ve sat in enough risk meetings to know the sound a bad surprise makes before anyone names it. It usually starts with a pause. Then a throat gets cleared. Then someone says, “We may need to bring the CISO into this.”</p>



<p>That happened over a developer tool.</p>



<p>Not a breach. Not a regulator. Not ransomware at 2:00 a.m. A coding assistant.</p>



<p>At first, I thought the reaction was overcooked. I’d seen the same pattern in other boardrooms and delivery teams. A new tool appears. Engineers like it because it saves time. Leadership likes it because it promises more output without hiring half a city. Security hates it because security has the social burden of being the adult in the room when everyone else is buying fireworks.</p>



<p>I backed the rollout because the case was clean on paper. Developers were drowning in repetitive work. Deadlines were tightening. Technical debt had started breeding in the dark. The assistant could draft tests, explain old code, suggest refactors and help junior engineers stop treating Stack Overflow like an underground pharmacy. And this was no longer fringe behavior. <a href="https://blogs.microsoft.com/blog/2025/05/19/microsoft-build-2025-the-age-of-ai-agents-and-building-the-open-agentic-web/" rel="nofollow">In 2025, Microsoft said that 15 million developers were already using GitHub Copilot, and the tool has spread further since</a> then.</p>



<p>So yes, I approved it.</p>



<p>Then security nearly revolted.</p>



<p>That week taught me something I now say to clients more bluntly than I used to. AI coding tools do not just change software delivery. They change the terms of trust inside the company. They force you to answer ugly questions about control, proof, accountability and review discipline. Most public coverage still stares at productivity. The harder story sits elsewhere. Governance.</p>



<h2 class="wp-block-heading">The part that looked sensible</h2>



<p>The truth is, I didn’t approve the tool because I was dazzled. I approved it because I’ve spent years watching good people waste good hours on bad repetition.</p>



<p>You can only tell a team to “be strategic” so many times before they start laughing at you. Developers were buried under boilerplate, documentation drift, brittle legacy code and the kind of ticket churn that makes bright people look tired. A coding assistant looked like a relief. Not magic. Relief.</p>



<p>That distinction matters.</p>



<p>In advisory work, I’ve learned that many poor decisions do not begin as foolish decisions. They begin as reasonable decisions made inside an outdated control model. That’s what this was. The business case made sense. The mistake was assuming the old review system could keep up with the new speed.</p>



<p>That old assumption dies hard. Leaders often think software risk changes when the code changes. Often, it changes earlier, as production conditions change. If a machine now drafts what humans once wrote line by line, the issue is not only code quality. It is code volume, code origin and the shrinking time between suggestion and production.</p>



<p>That is a different risk shape.</p>



<h2 class="wp-block-heading">Why security lost its patience</h2>



<p>The security team was upset because they could see the math.</p>



<p>Code output was about to rise. Review time was not.</p>



<p>That gap is where trouble rents office space.</p>



<p>Many non-security leaders still imagine the concern is simple. “The AI might write bad code.” That’s the kindergarten version. The real concern is broader and nastier. Who reviewed the output? What hidden package did the model nudge into the build? What sensitive context got pasted into the prompt window? Which junior engineer trusted the suggestion because it sounded calm and looked polished? Which policy assumed human authorship when the draft came from somewhere else?</p>



<p>Those are not philosophical questions. They are operating questions.</p>



<p>Recent security work has made this much harder to dismiss. <a href="https://snyk.io/blog/cline-supply-chain-attack-prompt-injection-github-actions/" rel="nofollow">Snyk described a February 2026 case in which a vulnerability chain turned an AI coding tool’s issue triage bot into a supply chain attack path.</a> That is the sort of sentence that makes security teams sit up straight and ask for names, logs and meeting invites.</p>



<p>And that is before you get to the quieter problem. AI-generated code can look tidy long before it is safe. Security people know that neat syntax can hide weak controls, lazy validation, poor handling of secrets and dependency choices nobody meant to own.</p>



<p>So when the team escalated, they weren’t staging a mutiny over a plugin. They were reacting to a change in production logic that nobody had yet governed.</p>



<h2 class="wp-block-heading">What the fight was really about</h2>



<p>Once the temperature dropped, the shape of the dispute became obvious to me. It was not engineering versus security. It was speed versus proof.</p>



<p>More precisely, it was four things:</p>



<ol class="wp-block-list">
<li><strong>Velocity</strong>. The assistant increased output far faster than assurance could keep pace.</li>



<li><strong>Visibility</strong>. We did not have a clear sight of where the tool was used, what prompts were fed into it, what code it influenced or what external components it smuggled into the discussion.</li>



<li><strong>Validation</strong>. Existing checks were built for a world in which humans produced most of the first draft. That world is fading. When code generation speeds up, review cannot stay ceremonial.</li>



<li><strong>Governance</strong>. Nobody had written the rules that mattered most. Which use cases were fine? Which were off-limits? Who owned the risk of acceptance? What evidence would prove that the tool was used safely enough?</li>
</ol>



<p>That last point gets too little airtime. Governance sounds dull until you don’t have it. Then it becomes the difference between controlled use and polite chaos.</p>



<p><a href="https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.800-4.pdf" rel="nofollow">NIST’s recent work on monitoring deployed AI systems</a> makes the same point more broadly. Organizations need post-deployment measurement and monitoring because real-world behavior drifts, surprises occur and governance after launch remains immature. Different setting, same lesson. You cannot inspect your way out of weak operating design.</p>



<h2 class="wp-block-heading">What we did next</h2>



<p>We did not ban the tool. That would have been theatre dressed as courage.</p>



<p>We also did not waive it through and tell security to “partner more closely.” I’ve heard that sentence enough times to know it usually means, “Please absorb more risk with better manners.”</p>



<p>We did something less dramatic and more useful. We narrowed the rollout and rewrote the conditions of trust.</p>



<p>Low-risk use cases stayed in play. Drafting tests. Explaining old functions, helping with documentation and suggesting boilerplate. Those were manageable.</p>



<p>High-risk areas got tighter boundaries. Auth flows. Secrets handling. Encryption logic. Infrastructure-as-code for sensitive environments. Anything tied to regulated data or material security controls. Those needed a stricter review or stayed out of scope.</p>



<p>We also drew a hard line on prompt hygiene. No customer data. No credentials. No confidential architecture details were dropped into a chat window because someone wanted a faster answer on a Friday afternoon. You would think that goes without saying. It does not.</p>



<p>Then we raised the review standard. Human sign-off meant real sign-off, not a quick skim and a merge. Scanning had to cover dependencies and code changes with more discipline. Provenance mattered more. Logging mattered more. Exception paths had to be explicit, not social.</p>



<p>Most importantly, security moved from late-stage critic to co-designer. That changed the tone. The question stopped being, “Can we use this?” and became, “Under what conditions can we trust its use enough to defend it later?”</p>



<p>That small shift matters more than many policy documents.</p>



<h2 class="wp-block-heading">What both sides got right — and wrong</h2>



<p>Developers were right about the waste. They were right that these tools remove drudgery. They were right that refusing every new capability is not a strategy. A team that cannot experiment eventually decays into compliance theatre and backlog sorrow.</p>



<p>They were wrong to assume readable code is trustworthy code. They were wrong to treat assistance as neutral. Tools shape behavior. That is what tools do. Once suggestions arrive fast and fluently, people accept more than they admit.</p>



<p>Security was right about review debt. Right about supply chain exposure, right about data leakage risk. Right, governance should not arrive three incidents late, wearing a blazer and a lessons-learned slide.</p>



<p>They were wrong at first, as many security teams are when they feel cornered. They made the conversation sound like a moral referendum. That never helps. If security cannot offer a usable path, the business routes around it. Then you get the worst of both worlds: Secret adoption and public optimism.</p>



<p>I don’t say that with smugness. I say it because I’ve watched good teams damage each other by defending the right thing in the wrong way.</p>



<h2 class="wp-block-heading">The bigger lesson for leaders</h2>



<p>This is where the story stops being about one rollout and starts becoming board material.</p>



<p>If your developers can now produce more code with less effort, your governance burden rises even if your headcount does not. The old ratio between output and oversight has broken. Many firms have not adjusted.</p>



<p>That matters because software governance is no longer just about secure coding standards or release gates. It is about production conditions. Who can generate? Under what rules? With what evidence? Across which risk zones? With whose approval? And if something goes wrong, who owns the final act of acceptance?</p>



<p>Those questions sound administrative until the first incident report lands, and nobody can explain whether the flawed logic was written, suggested, copied, reviewed or merely assumed.</p>



<p>The market is moving quickly. <a href="https://www.microsoft.com/en-us/security/security-insider/emerging-trends/cyber-pulse-ai-security-report" rel="nofollow">Microsoft’s own recent security reporting</a> says organizations adopting AI agents need observability, governance and security now, not later. Snyk is making a similar argument from the perspective of the software supply chain. Visibility first. Then prevention. Then governance that holds under pressure.</p>



<p>That is why I now advise something that used to sound severe and now sounds merely accurate. If you deploy AI coding tools without redesigning your control model, you are not buying productivity. You are buying ambiguity at machine speed.</p>



<h2 class="wp-block-heading">What you should ask before you approve the next tool</h2>



<p>You do not need a grand doctrine. You need a few hard questions asked before excitement turns into policy by accident.</p>



<p>Where can this tool be used, and where can’t it be used?</p>



<p>What data may enter it?</p>



<p>How will you know when the generated code reaches production?</p>



<p>What review standard applies when the first draft came from a machine?</p>



<p>Who can approve exceptions?</p>



<p>What logs, scans and decision records will let you defend the setup six months later, when memories blur and staff rotate?</p>



<p>That is not bureaucracy. That is self-respect.</p>



<p>I still believe these tools have value. I’d be foolish not to. But I trust them the way I trust a very fast junior colleague with a beautiful writing style and uneven judgment. Useful. Impressive. Worth keeping. Not someone you leave unsupervised near the crown jewels.</p>



<p>The near-mutiny turned out to be healthy. It forced the truth into the room before a failure did. Security was not blocking progress. They were objecting to unmanaged speed. Developers were not being reckless. They were asking for relief from the grind. Leadership’s job was not to pick a side. It was to write a better contract between them.</p>



<p>That is the part that too many firms still miss.</p>



<p>The argument was never only about a coding assistant. It was about whether we still knew how to govern work once the work started moving faster than our habits. That is a much bigger story. And if you listen carefully, you can hear it starting in many companies right now.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[PART 2: I Published a Scam Expose.]]></title>
<description><![CDATA[PART 2: I Published a Scam Expose. NetEase Sent a Takedown Request. Then They Rewrote Their Entire Operation.A forensic timeline of SSL certs, WHOIS manipulation, DNS chains, paid trust scores, and the email that proves a billion-dollar company changed their behavior because of one article.This i...]]></description>
<link>https://tsecurity.de/de/3481898/hacking/part-2-i-published-a-scam-expose/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3481898/hacking/part-2-i-published-a-scam-expose/</guid>
<pubDate>Sat, 02 May 2026 09:52:00 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>PART 2: I Published a Scam Expose. NetEase Sent a Takedown Request. Then They Rewrote Their Entire Operation.</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*AJ6IFK80R8ntqMOEfXs1Mg.png"></figure><h3>A forensic timeline of SSL certs, WHOIS manipulation, DNS chains, paid trust scores, and the email that proves a billion-dollar company changed their behavior because of one article.</h3><blockquote><strong><em>This is Part 2 of an ongoing investigation.</em></strong><em> Part 1: </em><a href="https://medium.com/@freerave/exposed-the-youdao-ads-influencer-marketing-scam-e389a0fb3f3c">EXPOSED: The “Youdao Ads” Influencer Marketing Scam</a></blockquote><p>Before we begin — a note on methodology.</p><p>When I published Part 1, I labeled this operation a scam based on the evidence available at the time. After 18 days of forensic follow-up, the picture is more nuanced. This article is not a retraction. It is an upgrade — more data, better conclusions, harder questions.</p><p>Everything here is reproducible. Every command is included. Every timestamp is documented. The security community can verify independently.</p><h3>The 18-Day Forensic Timeline</h3><pre>Apr  5, 2026  → SSL certificate issued: infunease.youdaoads.com<br>Apr 11, 2026  → Mass cold outreach (anjiaqi06@corp.netease.com)<br>               → curl -I infunease.youdaoads.com = 403 Forbidden<br>               → Scam Detector score: 28.8/100<br>               → Article published on dev.to<br>               → Google AI indexes and begins citing article<br>Apr 14, 2026  → WHOIS record updated (3 days post-publication)<br>Apr 28, 2026  → Takedown email received (youdaoads@rd.netease.com)<br>               → Public comment on dev.to article (@YoudaoAds)<br>               → curl -I infunease.youdaoads.com = 200 OK (same day)<br>               → Scam Detector drops further: 15/100<br>               → Formal documentation request sent - no response<br>Apr 29, 2026  → ScamAdviser score: 100/100 "Very Likely Safe"<br>               → New outreach email (tangxi03@corp.netease.com)<br>               → Professional NetEase 網易 branding<br>               → Every red flag from Part 1 - addressed</pre><p>Let’s go through each entry.</p><h3>Entry 1: The Original Email — Red Flags Documented</h3><p>On April 11, this arrived:</p><pre>From: anjiaqi06@corp.netease.com<br>Subject: Don't scroll past 【Youdao Ads】– a paid collab <br>         that's actually your vibe 😉<br><br>💰 Budget's ready – just name your rate<br>⏳ Spots are filling up – other creators are already <br>   looking at them<br>[Youdao Ads] [Discord] [WhatsApp group invite]</pre><p>Authentication results:</p><pre>dkim=pass   header.i=@corp.netease.com<br>spf=pass    smtp.mailfrom=anjiaqi06@corp.netease.com<br>dmarc=pass  (p=NONE sp=NONE dis=NONE)<br>Received: from corp-front01-corp.i.nease.net [1.95.22.228]<br>X-Originating-IP: [115.236.116.73]<br>X-Mailer: Coremail Webmail Server XT6.0.5</pre><p><strong>Every authentication check passed.</strong> The email genuinely came from NetEase corporate servers.</p><p>This is the first lesson of this investigation: <strong>email authentication tells you origin, not intent.</strong></p><p>The site linked in the email:</p><pre>$ curl -I https://infunease.youdaoads.com<br>HTTP/1.1 403 Forbidden<br>x-deny-reason: host_not_allowed<br>server: envoy</pre><p>A platform sending mass creator outreach while its own site returns Forbidden.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*J0SWjahx5ZdLP8Lbl4TARg.png"><figcaption>April 11 outreach — emoji-heavy, urgency-driven, no company branding</figcaption></figure><h3>Entry 2: SSL Certificate — Infrastructure Built Before the Campaign</h3><pre>$ echo | openssl s_client \<br>  -servername infunease.youdaoads.com \<br>  -connect infunease.youdaoads.com:443 2&gt;/dev/null \<br>  | openssl x509 -noout -dates<br><br>notBefore=Apr  5 00:00:00 2026 GMT<br>notAfter=Jul  4 23:59:59 2026 GMT</pre><p><strong>Certificate issued April 5</strong>–6 days before the emails went out. <strong>90-day certificate</strong> — automated issuance, short-term deployment pattern.</p><p>The infrastructure was being assembled in the week immediately preceding the mass outreach campaign.</p><h3>Entry 3: WHOIS — The Record That Updated After Publication</h3><pre>$ whois youdaoads.com<br><br>Domain Name:    YOUDAOADS.COM<br>Creation Date:  2021-05-25T11:15:53Z   ← 5 years old<br>Updated Date:   2026-04-14T05:35:38Z   ← 3 days post-article<br>Registrar:      Alibaba Cloud Computing (Beijing) Co., Ltd.<br>Registrant:     bei jing, CN<br>Name Servers:   REM1.YODAO.COM / REM2.YODAO.COM / REM3.YODAO.COM<br>DNSSEC:         unsigned</pre><p>The domain is legitimate and 5 years old. That’s important context.</p><p>But the record updated <strong>April 14</strong>–3 days after the article.</p><pre>$ whois infunease.youdaoads.com<br>No match for "INFUNEASE.YOUDAOADS.COM".</pre><p>The subdomain returns no WHOIS data.</p><h3>Entry 4: DNS Chain — Following the Infrastructure</h3><pre>$ dig infunease.youdaoads.com +short<br><br>youdaoads.youdao.com.<br>ead.alb.ntes53.netease.com.<br>hk-g1-hz.alb.ntes53.netease.com.<br>156.225.180.151<br>156.225.180.152</pre><p>Resolution chain:</p><pre>infunease.youdaoads.com<br>        ↓ CNAME<br>youdaoads.youdao.com<br>        ↓ CNAME<br>ead.alb.ntes53.netease.com       ← NetEase Load Balancer<br>        ↓ CNAME<br>hk-g1-hz.alb.ntes53.netease.com  ← Hong Kong Cluster<br>        ↓ A Records<br>156.225.180.151 / 156.225.180.152</pre><pre>$ whois 156.225.180.151<br><br>inetnum:  156.225.180.0 - 156.225.180.255<br>netname:  HongKong_NetEase_Interactive_Entertainment_Limited<br>descr:    HongKong NetEase Interactive Entertainment Limited<br>country:  HK</pre><p><strong>This is genuine NetEase infrastructure.</strong> Hong Kong datacenter. Enterprise load balancers. Not a rented VPS.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/957/1*JInM3k4r8pB7K0HNglhiGg.png"><figcaption>DNS chain resolves into NetEase Hong Kong infrastructure</figcaption></figure><h3>Entry 5: April 28 — The Site Comes Alive</h3><p>On the exact same day the takedown request arrived:</p><pre># April 11 — time of original article<br>$ curl -I https://infunease.youdaoads.com<br>HTTP/1.1 403 Forbidden<br>x-deny-reason: host_not_allowed<br>server: envoy<br><br># April 28 - day of takedown request<br>$ curl -I https://infunease.youdaoads.com<br>HTTP/2 200<br>server: YDWS<br>x-powered-by: Next.js<br>content-length: 374476<br>x-nextjs-cache: HIT<br>cache-control: s-maxage=31536000, stale-while-revalidate</pre><p>A full Next.js production deployment. Live. On the same day they asked me to take down the article.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/640/1*N-59qYaaFL02sHiBRsEKFQ.gif"><figcaption>403 on April 11. 200 on April 28. Same day as the takedown request.</figcaption></figure><h3>Entry 6: The Takedown Request</h3><pre>From: youdaoads@rd.netease.com<br>Subject: Clarification regarding your recent article<br><br>The misunderstandings in your article are currently <br>influencing Google's AI summaries, which is causing <br>severe and unearned damage to our brand.<br>We kindly request that you consider removing the post.<br>Domain Status: We have confirmed our domain is not <br>blocked by major security infrastructures.<br>NetEase Emails: Youdao Ads is a business division <br>of NetEase Youdao. The emails came from NetEase <br>internal servers because they are genuine official <br>communications.</pre><p>Note the sender domain: rd.netease.com — NetEase R&amp;D division. Original outreach: corp.netease.com — corporate division.</p><p>Two different NetEase subdomains used for the same operation. Never explained.</p><p>Simultaneously, a dev.to account named “Youdao Ads” posted publicly on my article:</p><blockquote>“We have thoroughly verified our domain and technical infrastructure. It is fully operational, passes mainstream security protocols, and is not being blocked by any standard security infrastructures.”</blockquote><p>My public response requested five items of documentation. None were provided.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9Y-ly1FtXcs0bzFDwkv-qw.png"><figcaption>Note rd.netease.com — different subdomain from original corp.netease.com outreach</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/808/1*PCDJNyAiQ0AE9lYokCmVWA.png"><figcaption>Public comment on the article — same day as the takedown email</figcaption></figure><h3>Entry 7: The Trust Score Divergence</h3><p><strong>Scam Detector</strong> (independent, no business plans):</p><pre>April 11: 28.8/100 — "Risky. Dubious. Perilous."<br>April 28: 15/100  — continued decline post-publication</pre><p><strong>ScamAdviser</strong> (offers paid business verification plans):</p><pre>April 29: 100/100 — "Very Likely Safe"<br>Last Update: 3 weeks ago</pre><p>Two independent platforms. Same domain. 15/100 vs 100/100.</p><p>ScamAdviser offers business subscription plans that allow companies to submit documentation and improve their trust ratings. This is disclosed in their business model.</p><p>The Scam Detector score — which does not offer paid improvement plans — continued declining.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*EY-jvLqhGbJCay1gGJXy2g.png"><figcaption>April 29 — ScamAdviser shows 100/100. ScamAdviser offers paid business plans.</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/640/1*khCAckPTgdLynqcdvh6JUg.gif"><figcaption>Scam Detector (no paid plans) shows 15/100 — continued decline post-article</figcaption></figure><h3>Entry 8: Network Analysis — Behavioral Tracking on Login Page</h3><p>DevTools analysis of the login page:</p><h3>Session 1: 16 requests</h3><pre>16/24 requests<br>POST → https://k.clarity.ms/collect<br>Status: 204 No Content<br>Remote Address: 172.175.38.6:443</pre><h3>Session 2 (after continued analysis): 47 requests</h3><pre>47/63 requests<br>62.5 kB transferred<br>Server: YDWS</pre><p>Microsoft Clarity captures on every visit from page load:</p><ul><li>Full mouse movement recording</li><li>Click and scroll behavior</li><li>Session duration and depth</li><li>Browser and device fingerprint</li><li>Rage clicks, dead clicks</li></ul><p><strong>Active before any signup or consent interaction.</strong></p><p>A second endpoint revealed the origin:</p><pre>GET https://overseacdn.ydstatic.com/overseacdn/<br>    advertising_platform/static/intl/zh-CN.json<br>    ?v=2760e8bced<br><br>Server: YDWS<br>Content-Type: application/json<br>Akamai-Mon-lucid-Del: 1273563</pre><p>ydstatic.com — Youdao Static CDN. zh-CN.json — Chinese Simplified localization. Akamai CDN headers — enterprise-grade infrastructure.</p><p><strong>This platform was originally built for the Chinese market.</strong></p><p>Note: Clarity automatically masks password and email input fields. Credentials are not captured. Full behavioral profiling is active regardless.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*02O0pRa0KAMfaty6o0XuBg.png"><figcaption>DevTools — 47/63 collect requests with overseacdn endpoint visible</figcaption></figure><h3>Entry 9: The Email That Changes Everything</h3><p>April 29. One day after the takedown request.</p><pre>From: tangxi03@corp.netease.com<br>Subject: Official Collaboration Invite for Creators | <br>         Youdao Ads by NetEase Youdao<br>mailed-by:  corp.netease.com<br>signed-by:  corp.netease.com<br>⭐ Important according to Google</pre><p>Body:</p><pre>This email is from Youdao Ads — the official influencer <br>marketing platform of NetEase Youdao, a subsidiary of <br>NetEase.<br><br>Why partner with Youdao Ads?<br>▸ Exclusive opportunities with top global brands<br>▸ Guaranteed paid campaigns, no upfront fees, <br>  on-time secure payments<br>▸ Full dedicated support from onboarding to <br>  payment settlement<br>[NetEase 網易 | youdao Ads]<br>Global leading influencer marketing platform<br>ydcommunity@service.netease.com</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*TkfqyLMor69VNv6pk2hEmA.png"><figcaption>New email from tangxi03 — professional NetEase branding</figcaption></figure><h3>The Before/After: A Direct Comparison</h3><p>This is the finding that makes this investigation significant.</p><h3>April 11 — Original Outreach:</h3><pre>Subject:  "Don't scroll past – a paid collab <br>           that's actually your vibe 😉"<br><br>Content:<br>❌ Emoji-heavy throughout<br>❌ "Budget's ready – just name your rate"<br>❌ "Spots are filling up" (artificial urgency)<br>❌ WhatsApp group invite links<br>❌ Discord community links<br>❌ Zero company branding<br>❌ Generic "your vibe" personalization<br>❌ No official email for support</pre><h3>April 29 — Post-Article Outreach:</h3><pre>Subject:  "Official Collaboration Invite for Creators | <br>           Youdao Ads by NetEase Youdao"<br><br>Content:<br>✅ Zero emojis<br>✅ "No upfront fees" ← Part 1 raised payment concerns<br>✅ "No pressure to sign up immediately" ← Part 1 raised urgency concern<br>✅ "Transparent pricing" ← Part 1 raised opacity concern<br>✅ Official NetEase 網易 logo from line 1<br>✅ Official support email: ydcommunity@service.netease.com<br>✅ Zero WhatsApp links<br>✅ Zero Discord spam<br>✅ Clear company identification</pre><p>Every documented red flag from Part 1. Addressed in the next outreach email. The timing is not coincidental.</p><h3>Analysis: What the Evidence Supports</h3><h3>Confirmed:</h3><p><strong>The infrastructure is genuine NetEase.</strong> DNS chain, IP WHOIS, email authentication, CDN — all resolve to NetEase Hong Kong. This is not spoofed.</p><p><strong>The domain has 5 years of history.</strong> Registered May 2021. Legitimate age, legitimate registrar.</p><p><strong>The outreach behavior changed after public scrutiny.</strong> The before/after email comparison documents this directly.</p><p><strong>Reputation management was deployed.</strong> ScamAdviser showing 100/100 the day after the takedown request, while Scam Detector continues at 15/100, suggests active reputation management through paid platforms.</p><h3>Not confirmed:</h3><p><strong>Why was the site returning 403 during the active email campaign?</strong> You do not send mass creator outreach from a platform that returns Forbidden to visitors.</p><p><strong>Why did the WHOIS record update 3 days after publication?</strong> Domain records do not update without deliberate action.</p><p><strong>Why did the site go live on the same day as the takedown request?</strong> This correlation is documented. Causation is not established.</p><p><strong>Why the subdomain switching?</strong> corp.netease.com → rd.netease.com → corp.netease.com. Three different senders. No explanation provided.</p><p><strong>Why does Scam Detector still show 15/100?</strong> No documentation addressing this was ever provided.</p><h3>Most likely explanation:</h3><p>A legitimate NetEase subsidiary operating with immature, spam-adjacent outreach practices — possibly a team that grew quickly and prioritized reach over compliance. Public scrutiny forced an internal correction.</p><p>This is not a vindication. This is a more accurate conclusion.</p><h3>Security Lessons for the Community</h3><h3>1. Email authentication is necessary, not sufficient</h3><pre>DKIM: pass ✅<br>SPF:  pass ✅<br>DMARC: pass ✅<br>Intent: unknown ❌</pre><p>Authentication confirms origin. It does not confirm legitimacy of purpose.</p><h3>2. Infrastructure legitimacy ≠ operational legitimacy</h3><p>Enterprise CDN, real IPs, genuine corporate email — none of this guarantees the outreach practices are acceptable.</p><h3>3. Trust score platforms are not equal</h3><p>Some platforms offer paid business plans that allow score improvement. Others do not. Understanding the business model of the platform you’re citing matters in security research.</p><h3>4. Timeline documentation is the methodology</h3><pre># Every finding in this article is reproducible<br><br>$ dig infunease.youdaoads.com +short<br>$ echo | openssl s_client -servername infunease.youdaoads.com \<br>  -connect infunease.youdaoads.com:443 2&gt;/dev/null \<br>  | openssl x509 -noout -dates<br>$ whois youdaoads.com<br>$ curl -I https://infunease.youdaoads.com</pre><p>Public record data. Standard OSINT methodology. Anyone can verify.</p><h3>5. Public research creates accountability</h3><p>One technical article, properly documented and indexed, changed the outreach behavior of a subsidiary of a multi-billion dollar company within 18 days.</p><p>This is why transparent security research matters.</p><h3>What Remains Open</h3><p>I formally requested the following on April 28. No response received as of publication:</p><ol><li>Official business registration documents for Youdao Ads</li><li>NetEase Youdao official statement authorizing the outreach campaign</li><li>Verified creator partnership examples with creator consent</li><li>Explanation of security vendor scores and remediation steps</li><li>Clarification on subdomain switching across communications</li></ol><p>This article updates publicly and prominently when documentation arrives.</p><h3>Conclusion</h3><p>This started as a scam analysis. It became something more useful: a documented case study in how public technical scrutiny can change corporate behavior, the limitations of email authentication as a trust signal, and the importance of understanding the business models behind reputation platforms.</p><p>The infrastructure is real. The company is real. The outreach tactics were unacceptable. The response to scrutiny was managed and calculated.</p><p><strong>Draw your own conclusions.</strong></p><p>If you have received emails from Youdao Ads — as a creator, agency, or brand — your experience is relevant to this investigation. Share it in the responses.</p><h3>Technical Reference</h3><p><strong>All commands used in this investigation:</strong></p><pre># DNS Resolution<br>$ dig infunease.youdaoads.com +short<br><br># SSL Certificate Dates<br>$ echo | openssl s_client \<br>  -servername infunease.youdaoads.com \<br>  -connect infunease.youdaoads.com:443 2&gt;/dev/null \<br>  | openssl x509 -noout -dates<br># WHOIS Domain<br>$ whois youdaoads.com<br>$ whois infunease.youdaoads.com<br># IP WHOIS<br>$ whois 156.225.180.151<br># HTTP Headers<br>$ curl -I https://infunease.youdaoads.com</pre><p><strong>Reporting channels:</strong></p><ul><li>APWG: reportphishing@apwg.org</li><li>Google Safe Browsing: safebrowsing.google.com/safebrowsing/report_phish/</li><li>NetEase Security: security@netease.com</li></ul><p><em>Originally published on </em><a href="https://dev.to/freerave/exposed-the-youdao-ads-influencer-marketing-scam-technical-analysis-red-flags-5cag"><em>dev.to/freerave</em></a></p><p><em>All findings are based on public record data and standard OSINT methodology. Timestamps and commands are included verbatim for independent verification.</em></p><p>Hi InfoSec Write-ups team,</p><p>I’d like to submit Part 2 of an active <br>cybersecurity investigation.</p><p>Part 1 is already live on:</p><p>→ Medium:<br><a href="https://medium.com/@freerave/exposed-the-youdao-ads-influencer-marketing-scam-e389a0fb3f3c">https://medium.com/@freerave/exposed-the-youdao-ads-influencer-marketing-scam-e389a0fb3f3c</a></p><p>→ dev.to:<br><a href="https://dev.to/freerave/exposed-the-youdao-ads-influencer-marketing-scam-technical-analysis-red-flags-5cag">https://dev.to/freerave/exposed-the-youdao-ads-influencer-marketing-scam-technical-analysis-red-flags-5cag</a></p><p>→ Hashnode:<br><a href="https://freerave.hashnode.dev/exposed-the-youdao-ads-influencer-marketing-scam-technical-analysis-red-flags">https://freerave.hashnode.dev/exposed-the-youdao-ads-influencer-marketing-scam-technical-analysis-red-flags</a></p><p>Part 1 was cited by Google AI in search <br>results for “Youdao Ads scam” and prompted <br>a direct takedown request from the company <br>within 17 days of publication.</p><p>Part 2 dev.to link:</p><p><a href="https://dev.to/freerave/part-2-i-published-a-scam-expose-netease-sent-a-takedown-request-then-they-rewrote-their-entire-hip">https://dev.to/freerave/part-2-i-published-a-scam-expose-netease-sent-a-takedown-request-then-they-rewrote-their-entire-hip</a></p><p>Thank you.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=bc420e0bbc00" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/part-2-i-published-a-scam-expose-bc420e0bbc00">PART 2: I Published a Scam Expose.</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The front-end architecture trilemma: Reactivity vs. hypermedia vs. local-first apps]]></title>
<description><![CDATA[While the software development industry has been gorging on large language models (LLMs), the front-end ecosystem has quietly fractured into three competing but interrelated architectural paradigms. Between the dominance of reactive frameworks, the hypermedia-driven simplicity of true REST, and t...]]></description>
<link>https://tsecurity.de/de/3470575/ai-nachrichten/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3470575/ai-nachrichten/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps/</guid>
<pubDate>Tue, 28 Apr 2026 11:17:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>While the software development industry has been gorging on <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a> (LLMs), the front-end ecosystem has quietly fractured into three competing but interrelated architectural paradigms. Between the dominance of <a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">reactive frameworks</a>, the <a href="https://www.infoworld.com/article/4150864/htmx-4-0-hypermedia-finds-a-new-gear.html">hypermedia-driven simplicity</a> of true REST, and the decentralized resilience of <a href="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html">SQL everywhere</a>, developers are no longer just choosing a library, they are choosing where the data lives: at the server, at the client, or both.</p>



<h2 class="wp-block-heading"><a></a>Three competing architectures, more or less</h2>



<p>Web developers are long familiar with <a href="https://www.infoworld.com/article/3962039/what-you-need-to-know-about-angular-react-vue-and-svelte-popular-javascript-frameworks-compared.html">React</a> and the galaxy of similar reactive frameworks like <a href="https://www.infoworld.com/article/3962039/what-you-need-to-know-about-angular-react-vue-and-svelte-popular-javascript-frameworks-compared.html">Angular, Vue, and Svelte</a>. For nearly a decade, these have dominated the narrative with their competition and co-inspiration. HTMX and hypermedia-driven applications have championed a return to the true RESTful thin client, alongside alternatives like Hotwire and Unpoly.</p>



<p>We could in a sense see reactivity and hypermedia as two opposing camps. Somewhere in between is the local-first SQL movement, which proposes putting SQL directly in the browser. The waters are a bit muddy because local SQL can and does work right alongside React.</p>



<p>It’s still safe to say that a reactive framework paired with a JSON API back end that talks to a datastore (SQL or otherwise) is still the de facto standard. But that monolithic story is starting to fracture in some very interesting ways.</p>



<h2 class="wp-block-heading"><a></a>Where the weight of the data lies</h2>



<p>Data of course is the central mass of web applications. Where it lives and how it moves produce the gravity around which everything else must revolve. Each of these architectures proposes to handle that gravity in its own way, with different benefits and tradeoffs.</p>



<p><strong>Hypermedia (e.g., HTMX):</strong> Keep the data largely off the client. The client is just a visual representation of the server data. The back-end “API” is responsible for producing the data-driven markup. Any kind of datastore can be used by the API server.</p>



<p><strong>React and friends:</strong> A sophisticated, stateful engine runs in the client, and the developer syncs that state with the back end via RESTful JSON API calls. The back-end server tends to be dumb, responsible largely for just invoking other services to provide business logic or data persistence.</p>



<p><strong>Local-first SQL: </strong>The data is distributed to the clients, like with React and friends, but in a much different way. Although the data is automatically synced directly to a datastore (like Postgres), the back-end API server is used only for specialized service calls—not for data persistence.</p>



<p>To summarize:</p>



<ul class="wp-block-list">
<li><strong>HTMX:</strong> Data gravity is at the server.</li>



<li><strong>React:</strong> Data gravity is split between the server and the client.</li>



<li><strong>Local-first:</strong> Data gravity is at the client.</li>
</ul>



<h2 class="wp-block-heading"><a></a>Comparing the approaches</h2>



<p>Besides the technical stats, the developer experience for each of these paradigms is quite different. However, while each paradigm feels different, they intersect in some interesting ways. Let’s take a closer look.</p>



<h3 class="wp-block-heading"><a></a>React and friends</h3>



<p><a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">Reactivity</a> is the world we have been working in for 15 years. We’ve got a whole universe of frameworks: <a href="https://react.dev/">React</a>, <a href="https://angular.dev/">Angular</a>, <a href="https://vuejs.org/">Vue</a>, <a href="https://svelte.dev/">Svelte</a>, <a href="https://www.solidjs.com/">Solid</a>, and full-stack variants like <a href="https://nextjs.org/">Next.js</a>, <a href="https://nuxt.com/">Nuxt</a>, <a href="https://svelte.dev/docs/kit/introduction">SvelteKit</a>, <a href="https://astro.build/">Astro</a>, etc. The beauty of these is in the <a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">core reactive idea</a>. You have a state that consists of the variables and the UI is updated automatically. The UI is a pure function of state: <code>$UI = f(state)</code>.</p>



<p>The downside is the gradual, almost imperceptible <a href="https://www.infoworld.com/article/4145032/we-mistook-event-handling-for-architecture.html">layering of intense complexity</a> over the top of it all. This complexity seems at first just incidental, but it is in fact a direct outcome of the basic premise: building a state engine on the browser.</p>



<p>The result is you have <em>two </em>states: the browser and the database. The reactive engine becomes a negotiation layer. Add to that the various inherent complexities of managing the browser state, and the result is quite a lot for front-end developers to wrap their heads around.</p>



<p>In the effort to manage such complexity, wring more performance, and improve developer experience, we have wound up with quite a sprawling empire of tools and techniques. Even just for React we have <a href="https://react.dev/reference/rsc/server-components">React Server Components</a>, complex state-management libraries like <a href="https://redux.js.org/">Redux</a> or <a href="https://zustand.docs.pmnd.rs/learn/getting-started/introduction">Zustand</a>, and orchestration layers like <a href="https://tanstack.com/query/latest">TanStack Query</a> for manual cache invalidation.</p>



<p>On the back end, we talk to <a href="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html">JSON APIs</a> (or <a href="https://www.infoworld.com/article/2267992/what-is-graphql-better-apis-by-design.html">GraphQL</a>), which can become unwieldy as a kind of boilerplate layer, but has in its favor an almost universal understanding.</p>



<h3 class="wp-block-heading">HTMX and similar (Hotwired, Unpoly)</h3>



<p><a href="https://www.infoworld.com/article/2334868/htmx-dynamic-html-without-the-javascript.html">HTMX</a> is like using HTML that has superpowers. You can do a huge amount of what you use reactive frameworks for, including all the AJAX and a lot of the partial rendering and effects, with just a few extra attributes sprinkled judiciously.</p>



<p>You spend a lot of time on the server, using a template engine like <a href="https://github.com/pugjs/pug">Pug</a>, <a href="https://www.thymeleaf.org/">Thymeleaf</a>, or <a href="https://github.com/Kotlin/kotlinx.html">Kotlin DSL</a>. These are where you bring together the data from the persistence service and combine it with markup. The markup you generate includes the HTMX attributes.</p>



<p>You tend to decompose the templates, i.e., break them up into dedicated chunks. The idea is you want to have a chunk that can be used within the larger UI to create the whole layout, along with the ability to use that chunk alone when (and if) it is called upon for an AJAX response.</p>



<p>Hypermedia with HTMX is a very powerful model. You are actually using REST, meaning you are transmitting a representational state.</p>



<p><a href="https://hotwired.dev/">Hotwire</a> and <a href="https://unpoly.com/">Unpoly</a> are similar libraries. In the case of Hotwire, you can achieve quite a bit of functionality and performance even without changing your HTML, just by using <a href="https://turbo.hotwired.dev/handbook/frames">Turbo Frames</a> to intercept link clicks and form submissions, automatically turning standard page navigation into partial DOM updates.</p>



<p>The beauty of the hypermedia approaches is that you gain a lot with a little. You are staying as much as possible in HTML, the very poster child of simplicity. On the other hand, you are giving up some of the sheer sophisticated power of reactive frameworks.</p>



<h3 class="wp-block-heading"><a></a>Local-first apps</h3>



<p>Local-first development is the new kid on the block. Like React and friends, local-first keeps the data in two places, but it does so in a radically different way. In its most essential form, it means running a database in the browser that is kept aligned with the remote datastore via a syncing engine. This kind of thing has been done before with <a href="https://www.infoworld.com/article/2260280/what-is-nosql-databases-for-a-cloud-scale-future.html">NoSQL</a> databases like <a href="https://couchdb.apache.org/">CouchDB</a> or with the <a href="https://developer.mozilla.org/en-US/docs/Web/API/IndexedDB_API">IndexedDB API</a>, but the modern browser takes it to another level with a <a href="https://www.infoworld.com/article/2255892/what-is-webassembly-the-next-generation-web-platform-explained.html">Wasm</a>-based database engine, like SQLite.</p>



<p>The user gets a small view of the full data, called a partial replication or a bucket (also called a “shape”). The front-end app interacts directly with that data, and the infrastructure automatically does the work of keeping everything synced. A big benefit here is strong offline support (because the client device is carrying around an actual database).</p>



<p>This is a massive departure from the request-response cycle. In local-first, you don’t fetch data; you subscribe to it. The network becomes a background daemon that reconciles local and remote state using CRDTs (conflict-free replicated data types). CRDTs ensure that if two users edit a task while offline, the merge is seamless rather than messy.</p>



<p>There is also a degree of simplification in using SQL everywhere, though that is offset by a rather unfamiliar and involved architectural setup. A syncing engine like <a href="https://www.powersync.com/">PowerSync</a> or <a href="https://electric-sql.com/">Electric SQL</a> is required, and it has a set of rules that must be maintained. Plus the auth and interaction between the database and the syncing engine must be configured.</p>



<p>Local-first eliminates both the API server and the HTML template server. It pushes the entire data negotiation layer into the automated syncing engine that runs off developer-defined rules.</p>



<p>Interestingly, local-first SQL can be used as a data driver for React (and other reactive engines) or plain vanilla HTML + JS. As such, it is an interesting alternative take on the architecture of the web, which is agnostic about the front end.</p>



<p>Perhaps the strangest arrangement to contemplate is using HTMX and local-first SQL together. This is like a mad scientist architecture, which of course means developers are doing it. In this setup, the back-end HTMX template engine is actually a service worker running the SQL engine. In theory, you get the simplicity of HTMX and the ultra-speed + offline functionality of local SQL. </p>



<h2 class="wp-block-heading"><a></a>Reactivity, hypermedia, or local-first? How to choose</h2>



<p>We remain in the era of the default choice being React plus a JSON API. From there you might experiment with innovative frameworks like <a href="https://www.infoworld.com/article/2265950/hands-on-with-svelte.html">Svelte</a> or <a href="https://www.infoworld.com/article/2271109/hands-on-with-the-solid-javascript-framework.html">Solid</a>. If you are looking for an ingenious way to leverage RESTful simplicity, HTMX or Hotwired are must-tries. Local-first SQL is an exotic animal, fit for the likes of <a href="https://linear.app/now/scaling-the-linear-sync-engine">Linear</a> or <a href="https://www.notion.com/blog/how-we-made-notion-available-offline">Notion</a> right now, but somewhat daring for most of us doing standard production work.</p>



<p>More broadly, the emergence of this trilemma signals the end of the “one true way” for web development. We are moving away from the library wars and into a world of architectural choice.</p>



<p>The choice between reactivity, hypermedia, and local-first isn’t just about code. It’s about where you want to place the data.</p>



<ul class="wp-block-list">
<li>If you want the data to be a server-side document, choose hypermedia.</li>



<li>If you want the data to be a shared memory state, choose reactivity.</li>



<li>If you want the data to be a distributed database, choose local-first.</li>
</ul>



<p>And of course, it is possible to put the approaches together to strive for a blend of the right benefits for your project.</p>



<p>As the JSON-over-the-wire monolith continues to fragment, the best architects won’t be the ones who know the most hooks or the most attributes. They will be the ones who understand the weight of their data and choose the architecture that lets the data move most freely. The framework wars are over, but the battle for the network has just begun. </p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft and OpenAI Rewrote Their Marriage Contract]]></title>
<description><![CDATA[Microsoft and OpenAI’s amended deal loosens exclusivity, simplifies economics, and signals AI’s shift toward multi-cloud infrastructure.
The post Microsoft and OpenAI Rewrote Their Marriage Contract appeared first on eWEEK.]]></description>
<link>https://tsecurity.de/de/3469293/it-nachrichten/microsoft-and-openai-rewrote-their-marriage-contract/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3469293/it-nachrichten/microsoft-and-openai-rewrote-their-marriage-contract/</guid>
<pubDate>Mon, 27 Apr 2026 21:46:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft and OpenAI’s amended deal loosens exclusivity, simplifies economics, and signals AI’s shift toward multi-cloud infrastructure.</p>
<p>The post <a href="https://www.eweek.com/news/microsoft-openai-deal-multi-cloud-ai-infrastructure/">Microsoft and OpenAI Rewrote Their Marriage Contract</a> appeared first on <a href="https://www.eweek.com/">eWEEK</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[85% of enterprises are running AI agents. Only 5% trust them enough to ship.]]></title>
<description><![CDATA[Eighty-five percent of enterprises are running AI agent pilots, but only 5% have moved those agents into production. In an exclusive interview at RSA Conference 2026, Cisco President and Chief Product Officer Jeetu Patel said that the gap comes down to one thing: trust — and that closing it separ...]]></description>
<link>https://tsecurity.de/de/3461655/it-nachrichten/85-of-enterprises-are-running-ai-agents-only-5-trust-them-enough-to-ship/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3461655/it-nachrichten/85-of-enterprises-are-running-ai-agents-only-5-trust-them-enough-to-ship/</guid>
<pubDate>Fri, 24 Apr 2026 15:32:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Eighty-five percent of enterprises are running AI agent pilots, but only 5% have moved those agents into production. In an exclusive interview at <a href="https://www.cisco.com/site/us/en/learn/events/rsac.html">RSA Conference 2026</a>, Cisco President and Chief Product Officer Jeetu Patel said that the gap comes down to one thing: trust — and that closing it separates market dominance from bankruptcy. He also disclosed a mandate that will reshape Cisco's 90,000-person engineering organization.</p><p>The problem is not rogue agents. The problem is the absence of a trust architecture.</p><h2>The trust deficit behind a 5% production rate</h2><p>A <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html">recent Cisco survey</a> of major enterprise customers found that 85% have AI agent pilot programs underway. Only 5% moved those agents into production. That 80-point gap defines the security problem the entire industry is trying to close. It is not closing.</p><p>"The biggest impediment to scaled adoption in enterprises for business-critical tasks is establishing a sufficient amount of trust," Patel told VentureBeat. "Delegating versus trusted delegating of tasks to agents. The difference between those two, one leads to bankruptcy and the other leads to market dominance."</p><p>He compared agents to teenagers. "They're supremely intelligent, but they have no fear of consequence. They're pretty immature. And they can be easily sidetracked or influenced," Patel said. "What you have to do is make sure that you have guardrails around them and you need some parenting on the agents."</p><p>The comparison carries weight because it captures the precise failure mode security teams face. Three years ago, a chatbot that gave the wrong answer was an embarrassment. An agent that takes the wrong action can trigger an irreversible outcome. Patel pointed to a case he cited in his keynote where an AI coding agent deleted a live production database during a code freeze, tried to cover its tracks with fake data, and then apologized. "An apology is not a guardrail," Patel said in his <a href="https://blogs.cisco.com/news/reimagining-security-for-the-agentic-workforce">keynote blog</a>. The shift from information risk to action risk is the core reason the pilot-to-production gap persists.</p><h2>Defense Claw and the open-source speed play with Nvidia</h2><p>Cisco's response to the trust deficit at RSAC 2026 spanned three categories: protecting agents from the world, protecting the world from agents, and detecting and responding at machine speed. The <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html">product announcements</a> included AI Defense Explorer Edition (a free, self-service red teaming tool), the Agent Runtime SDK for embedding policy enforcement into agent workflows at build time, and the LLM Security Leaderboard for evaluating model resilience against adversarial attacks.</p><p>The open-source strategy moved faster than any of those. Nvidia launched OpenShell, a secure container for open-source agent frameworks, at GTC the week before RSAC. Cisco packaged its Skills Scanner, MCP Scanner, AI Bill of Materials tool, and CodeGuard into a single open-source framework called <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html">Defense Claw</a> and hooked it into OpenShell within 48 hours.</p><p>"Every single time you actually activate an agent in an Open Shell container, you can now automatically instantiate all the security services that we have built through Defense Claw," Patel told VentureBeat. The integration means security enforcement activates at container launch without manual configuration. That speed matters because the alternative is asking developers to bolt on security after the agent is already running.</p><p>That 48-hour turnaround was not an anomaly. Patel said several of the Defense Claw capabilities Cisco launched were built in a week. "You couldn't have built it in longer than a week because Open Shell came out last week," he said.</p><h2>A six-to-nine-month product lead and an information asymmetry on top of it</h2><p>Patel made a competitive claim worth examining. "Product wise, we might be six to nine months ahead of most of the market," he told VentureBeat. He added a second layer: "We also have an asymmetric information advantage of, I'd say, three to six months on everyone because, you know, we, by virtue of being in the ecosystem with all the model companies. We're seeing what's coming down the pipe." The 48-hour Defense Claw sprint supports the speed claim, though the lead margin is Cisco's own characterization; no independent benchmarks were provided.</p><p>Cisco also extended zero trust to the agentic workforce through new <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html">Duo IAM and Secure Access</a> capabilities, giving every agent time-bound, task-specific permissions. On the SOC side, Splunk announced Exposure Analytics for continuous risk scoring, Detection Studio for streamlined detection engineering, and Federated Search for investigating across distributed data environments.</p><h2>The zero-human-code engineering mandate</h2><p>AI Defense, the product Cisco launched a year before RSAC 2026, is now 100% built with AI. Zero lines of human-written code. By the end of 2026, half a dozen Cisco products will reach the same milestone. By the end of calendar year 2027, Patel's goal is 70% of Cisco's products built entirely by AI.</p><p>"Just process that for a second and go: a $60 billion company is gonna have 70% of the products that are gonna have no human lines of code," Patel told VentureBeat. "The concept of a legacy company no longer exists."</p><p>He connected that mandate to a cultural shift inside the engineering organization. "There's gonna be two kinds of people: ones that code with AI and ones that don't work at Cisco," Patel said. That was not debated. "Changing 30,000 people to change the way that they work at the very core of what they do in engineering cannot happen if you just make it a democratic process. It has to be something that's driven from the top down."</p><h2>Five moats for the agentic era, and what CISOs can verify today</h2><p>Patel laid out five strategic advantages that will separate winning enterprises from failing ones. VentureBeat mapped each moat against actions security teams can begin verifying today.</p><table><tbody><tr><td><p><b>Moat</b></p></td><td><p><b>Patel's claim</b></p></td><td><p><b>What CISOs can verify today</b></p></td><td><p><b>What to validate next</b></p></td></tr><tr><td><p>Sustained speed</p></td><td><p>"Operating with extreme levels of obsession for speed for a durable length of time" creates compounding value</p></td><td><p>Measure deployment velocity from pilot to production. Track how long agent governance reviews take.</p></td><td><p>Pair speed metrics with telemetry coverage. Fast deployment without observability creates blind acceleration.</p></td></tr><tr><td><p>Trust and delegation</p></td><td><p>Trusted delegation separates market dominance from bankruptcy</p></td><td><p>Audit delegation chains. Flag agent-to-agent handoffs with no human approval.</p></td><td><p>Agent-to-agent trust verification is the next primitive the industry needs. OAuth, SAML, and MCP do not yet cover it.</p></td></tr><tr><td><p>Token efficiency</p></td><td><p>Higher output per token creates a strategic advantage</p></td><td><p>Monitor token consumption per workflow. Benchmark cost-per-action across agent deployments.</p></td><td><p>Token efficiency metrics exist. Token security metrics (what the token accessed, what it changed) are the next build.</p></td></tr><tr><td><p>Human judgment</p></td><td><p>"Just because you can code it doesn't mean you should."</p></td><td><p>Track decision points where agents defer to humans vs. act autonomously.</p></td><td><p>Invest in logging that distinguishes agent-initiated from human-initiated actions. Most configurations cannot yet.</p></td></tr><tr><td><p>AI dexterity</p></td><td><p>"10x to 20x to 50x productivity differential" between AI-fluent and non-fluent workers</p></td><td><p>Measure the adoption rates of AI coding tools across security engineering teams.</p></td><td><p>Pair dexterity training with governance training. One without the other compounds the risk.</p></td></tr></tbody></table><h2>The telemetry layer the industry is still building</h2><p>Patel's framework operates at the identity and policy layer. The next layer down, telemetry, is where the verification happens. "It looks indistinguishable if an agent runs your web browser versus if you run your browser," CrowdStrike CTO Elia Zaitsev told VentureBeat in an exclusive interview at RSAC 2026. Distinguishing the two requires walking the process tree, tracing whether Chrome was launched by a human from the desktop or spawned by an agent in the background. Most enterprise logging configurations cannot make that distinction yet.</p><p>A CEO's AI agent rewrote the company's security policy. Not because it was compromised. Because it wanted to fix a problem, lacked permissions, and removed the restriction itself. Every identity check passed. CrowdStrike CEO George Kurtz disclosed that incident and a second one at his RSAC keynote, both at Fortune 50 companies. In the second, a 100-agent Slack swarm delegated a code fix between agents without human approval.</p><h2>Both incidents were caught by accident</h2><p>Etay Maor, VP of Threat Intelligence at Cato Networks, told VentureBeat in a separate exclusive interview at RSAC 2026 that enterprises abandoned basic security principles when deploying agents. Maor ran a live Censys scan during the interview and counted nearly 500,000 internet-facing agent framework instances. The week before: 230,000. Doubling in seven days.</p><p>Patel acknowledged the delegation risk in the interview. "The agent takes the wrong action and worse yet, some of those actions might be critical actions that are not reversible," he said. Cisco's Duo IAM and MCP gateway enforce policy at the identity layer. Zaitsev's work operates at the kinetic layer: tracking what the agent did after the identity check passed. Security teams need both. Identity without telemetry is a locked door with no camera. Telemetry without identity is footage with no suspect.</p><h2>Token generation as the currency for national competitiveness</h2><p>Patel sees the infrastructure layer as decisive. "Every country and every company in the world is gonna wanna make sure that they can generate their own tokens," he told VentureBeat. "Token generation becomes the currency for success in the future." Cisco's play is to provide the most secure and efficient technology for generating tokens at scale, with Nvidia supplying the GPU layer. The 48-hour Defense Claw integration demonstrated what that partnership produces under pressure.</p><h2>Security director action plan</h2><p>VentureBeat identified five steps security teams can take to begin building toward Patel's framework today:</p><ol><li><p><b>Audit the pilot-to-production gap. </b>Cisco's own survey found 85% of enterprises piloting, 5% in production. Mapping the specific trust deficits keeping agents stuck is the starting point — the answer is rarely the technology. Governance, identity, and delegation controls are what's missing. Patel's trusted delegation framework is designed to close that gap.</p></li><li><p><b>Test </b><a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html"><b>Defense Claw</b></a><b> and </b><a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html"><b>AI Defense Explorer Edition</b></a><b>. </b>Both are free. Red-team your agent workflows before they reach production. Test the workflow, not just the model.</p></li><li><p><b>Map delegation chains end-to-end. </b>Flag every agent-to-agent handoff with no human approval. This is the "parenting" Patel described. No product fully automates it yet. Do it manually, every week.</p></li><li><p><b>Establish agent behavioral baselines. </b>Before any agent reaches production, define what normal looks like: API call patterns, data access frequency, systems touched, and hours of activity. Without a baseline, the observability that Patel's moats require has nothing to compare against.</p></li><li><p><b>Close the telemetry gap in your logging configuration. </b>Verify that your SIEM can distinguish agent-initiated actions from human-initiated actions. If it cannot, the identity layer alone will not catch the incidents Kurtz described at <a href="https://venturebeat.com/security/rsac-2026-agentic-soc-agent-telemetry-security-gap">RSAC</a>. Patel built the identity layer. The telemetry layer completes it.</p></li></ol><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-40155 | auth0 nextjs-auth0 up to 4.17.x authorization (GHSA-xq8m-7c5p-c2r6 / EUVD-2026-23537)]]></title>
<description><![CDATA[A vulnerability was found in auth0 nextjs-auth0 up to 4.17.x. It has been rated as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to incorrect authorization.

This vulnerability is uniquely identified as CVE-2026-40155. The attack is possible to be...]]></description>
<link>https://tsecurity.de/de/3445046/sicherheitsluecken/cve-2026-40155-auth0-nextjs-auth0-up-to-417x-authorization-ghsa-xq8m-7c5p-c2r6-euvd-2026-23537/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3445046/sicherheitsluecken/cve-2026-40155-auth0-nextjs-auth0-up-to-417x-authorization-ghsa-xq8m-7c5p-c2r6-euvd-2026-23537/</guid>
<pubDate>Sat, 18 Apr 2026 23:07:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/auth0:nextjs-auth0">auth0 nextjs-auth0 up to 4.17.x</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is an unknown functionality. The manipulation leads to incorrect authorization.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-40155">CVE-2026-40155</a>. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[I Rewrote My 3D Animated Fetch Tool to Now Have Zero Dependencies and Live-Updating Stats!]]></title>
<description><![CDATA[A couple days ago I posted about fetch here - it takes your distro logo and renders it as a spinning 3D object in the terminal using ASCII shading. Lots of people had interest in this project, and the general consensus was that people really liked it! I first want to thank everyone who tested thi...]]></description>
<link>https://tsecurity.de/de/3437198/linux-tipps/i-rewrote-my-3d-animated-fetch-tool-to-now-have-zero-dependencies-and-live-updating-stats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3437198/linux-tipps/i-rewrote-my-3d-animated-fetch-tool-to-now-have-zero-dependencies-and-live-updating-stats/</guid>
<pubDate>Thu, 16 Apr 2026 03:53:10 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>A couple days ago I posted about fetch here - it takes your distro logo and renders it as a spinning 3D object in the terminal using ASCII shading. Lots of people had interest in this project, and the general consensus was that people really liked it! I first want to thank everyone who tested this out or commented or starred my repository because it justified doing stupid and fun things with C and ASCII art! I almost got DDoSed with the number of notifications I got from Reddit - in the best way possible of course :)! I cannot express how much gratitude I have. But I'm posting here for more than just to thank you guys... I have a big update to share!</p> <p>Since then I've <strong>basically</strong> rewritten the whole thing:</p> <ul> <li><strong>Fully native system info</strong> - no more fastfetch dependency for info! It reads /proc, /sys, and GTK config directly now. Fastfetch is only used optionally for logos! The screenshot I've attached isn't using fastfetch at all!</li> <li><strong>Per-character logo colors</strong> - logos keep their original colors instead of a 2-color approximation. All 500+ distro logos work (please file an issue if this isn't true, but for the most part, it is!).</li> <li><strong>Live-updating stats</strong> - memory, battery, uptime all tick in real-time while the logo spins. This is something that <a href="https://www.reddit.com/u/Holiday_Management60">u/Holiday_Management60</a> suggested, and it is comperable to watching a minimal version of top in your fetching tool!</li> <li><strong>Config file</strong> - toggle/reorder fields, change label color, customize shading ramp, light direction, rotation speed, and more!</li> <li><strong>--size flag</strong> - scale the logo up or down.</li> </ul> <p>Still a single C file, ~2,050 lines, and only depends on libm! Works on any Linux machine!</p> <pre><code>make sudo make install </code></pre> <p>Please give feedback (or stars if you think this is cool!) - I've been having a ton of fun building this and I'm not stopping anytime soon!</p> <p>GitHub: <a href="https://github.com/areofyl/fetch">https://github.com/areofyl/fetch</a></p> <p>Original Post: <a href="https://www.reddit.com/r/linux/comments/1skr8um/i_made_a_fetch_tool_that_turns_your_distro_logo/">https://www.reddit.com/r/linux/comments/1skr8um/i_made_a_fetch_tool_that_turns_your_distro_logo/</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/areofyl"> /u/areofyl </a> <br> <span><a href="https://i.redd.it/gnlob3w71fvg1.jpeg">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1smibip/i_rewrote_my_3d_animated_fetch_tool_to_now_have/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta researchers introduce 'hyperagents' to unlock self-improving AI for non-coding tasks]]></title>
<description><![CDATA[Creating self-improving AI systems is an important step toward deploying agents in dynamic environments, especially in enterprise production environments, where tasks are not always predictable, nor consistent. Current self-improving AI systems face severe limitations because they rely on fixed, ...]]></description>
<link>https://tsecurity.de/de/3436773/it-nachrichten/meta-researchers-introduce-hyperagents-to-unlock-self-improving-ai-for-non-coding-tasks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3436773/it-nachrichten/meta-researchers-introduce-hyperagents-to-unlock-self-improving-ai-for-non-coding-tasks/</guid>
<pubDate>Wed, 15 Apr 2026 22:16:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Creating self-improving AI systems is an important step toward deploying agents in dynamic environments, especially in enterprise production environments, where tasks are not always predictable, nor consistent. </p><p>Current self-improving AI systems face severe limitations because they rely on fixed, handcrafted improvement mechanisms that only work under strict conditions such as software engineering.</p><p>To overcome this practical challenge, researchers at Meta and several universities introduced “<a href="https://arxiv.org/abs/2603.19461">hyperagents</a>,” a self-improving AI system that continuously rewrites and optimizes its problem-solving logic and the underlying code. </p><p>In practice, this allows the AI to self-improve across non-coding domains, such as robotics and document review. The agent independently invents general-purpose capabilities like persistent memory and automated performance tracking. </p><p>More broadly, hyperagents don't just get better at solving tasks, they learn to improve the self-improving cycle to accelerate progress.</p><p>This framework can help develop highly adaptable agents that autonomously build structured, reusable decision machinery. This approach compounds capabilities over time with less need for constant, manual prompt engineering and domain-specific human customization.</p><h2><b>Current self-improving AI and its architectural bottlenecks</b></h2><p>The core goal of <a href="https://venturebeat.com/ai/self-improving-language-models-are-becoming-reality-with-mits-updated-seal">self-improving AI systems</a> is to continually enhance their own learning and problem-solving capabilities. However, most existing self-improvement models rely on a fixed “meta agent.” This static, high-level supervisory system is designed to modify a base system.</p><p>“The core limitation of handcrafted meta-agents is that they can only improve as fast as humans can design and maintain them,” Jenny Zhang, co-author of the paper, told VentureBeat. “Every time something changes or breaks, a person has to step in and update the rules or logic.” </p><p>Instead of an abstract theoretical limit, this creates a practical “maintenance wall.” </p><p>The current paradigm ties system improvement directly to human iteration speed, slowing down progress because it relies heavily on manual engineering effort rather than scaling with agent-collected experience.</p><p>To overcome this limitation, the researchers argue that the AI system must be “fully self-referential.” These systems must be able to analyze, evaluate, and rewrite any part of themselves without the constraints of their initial setup. This allows the AI system to break free from structural limits and become self-accelerating.</p><p>One example of a self-referential AI system is Sakana AI’s <a href="https://sakana.ai/dgm/">Darwin Gödel Machine</a> (DGM), an AI system that improves itself by rewriting its own code. </p><p>In DGM, an agent iteratively generates, evaluates, and modifies its own code, saving successful variants in an archive to act as stepping stones for future improvements. DGM proved open-ended, recursive self-improvement is practically achievable in coding.</p><p>However, DGM falls short when applied to real-world applications outside of software engineering because of a critical skill gap. In DGM, the system improves because both evaluation and self-modification are coding tasks. Improving the agent's coding ability naturally improves its ability to rewrite its own code. But if you deploy DGM for a non-coding enterprise task, this alignment breaks down.</p><p>“For tasks like math, poetry, or paper review, improving task performance does not necessarily improve the agent’s ability to modify its own behavior,” Zhang said. </p><p>The skills needed to analyze subjective text or business data are entirely different from the skills required to analyze failures and write new Python code to fix them. </p><p>DGM also relies on a fixed, human-engineered mechanism to generate its self-improvement instructions. In practice, if enterprise developers want to use DGM for anything other than coding, they must heavily engineer and manually customize the instruction prompts for every new domain.</p><h2><b>The hyperagent framework</b></h2><p>To overcome the limitations of previous architectures, the researchers introduce hyperagents. The framework proposes “self-referential agents that can in principle self-improve for any computable task.”</p><p>In this framework, an agent is any computable program that can invoke LLMs, external tools, or learned components. Traditionally, these systems are split into two distinct roles: a “task agent” that executes the specific problem at hand, and a “meta agent” that analyzes and modifies the agents. A hyperagent fuses both the task agent and the meta agent into a single, self-referential, and editable program.</p><p>Because the entire program can be rewritten, the system can modify the self-improvement mechanism, a process the researchers call metacognitive self-modification.</p><p>"Hyperagents are not just learning how to solve the given tasks better, but also learning how to improve," Zhang said. "Over time, this leads to accumulation. Hyperagents do not need to rediscover how to improve in each new domain. Instead, they retain and build on improvements to the self-improvement process itself, allowing progress to compound across tasks."</p><p>The researchers extended the Darwin Gödel Machine to create DGM-Hyperagents (DGM-H). DGM-H retains the powerful open-ended exploration structure of the original DGM, which prevents the AI from converging too early or getting stuck in dead ends by maintaining a growing archive of successful hyperagents.</p><p>The system continuously branches from selected candidates in this archive, allows them to self-modify, evaluates the new variants on given tasks, and adds the successful ones back into the pool as stepping stones for future iterations.</p><p>By combining this open-ended evolutionary search with metacognitive self-modification, DGM-H eliminates the fixed, human-engineered instruction step of the original DGM. This enables the agent to self-improve across any computable task.</p><h2><b>Hyperagents in action</b></h2><p>The researchers used the <a href="https://epoch.ai/benchmarks/aider-polyglot">Polyglot coding benchmark</a> to compare the hyperagent framework against previous coding-only AI. They also evaluated hyperagents across non-coding domains that involve subjective reasoning, external tool use, and complex logic.</p><p>These included paper review to simulate a peer reviewer outputting accept or reject decisions, reward model design for training a quadruped robot, and Olympiad-level math grading. Math grading served as a held-out test to see if an AI that learned how to self-improve while reviewing papers and designing robots could transfer those meta-skills to an entirely unseen domain.</p><p>The researchers compared hyperagents against several baselines, including domain-specific models like AI-Scientist-v2 for paper reviews and the ProofAutoGrader for math. They also tested against the classic DGM and a manually customized DGM for new domains.</p><p>On the coding benchmark, hyperagents matched the performance of DGM despite not being designed specifically for coding. In paper review and robotics, hyperagents outperformed the open-source baselines and human-engineered reward functions. </p><p>When the researchers took a hyperagent optimized for paper review and robotics and deployed it on the unseen math grading task, it achieved an improvement metric of 0.630 in 50 iterations. Baselines relying on classic DGM architectures remained at a flat 0.0. The hyperagent even beat the domain-specific ProofAutoGrader.</p><p>The experiments also highlighted interesting autonomous behaviors from hyperagents. In paper evaluation, the agent first used standard prompt-engineering tricks like adopting a rigorous persona. When this proved unreliable, it rewrote its own code to build a multi-stage evaluation pipeline with explicit checklists and rigid decision rules, leading to much higher consistency.</p><p>Hyperagents also autonomously developed a memory tool to avoid repeating past mistakes. Furthermore, the system wrote a performance tracker to log and monitor the result of architectural changes across generations. The model even developed a compute-budget aware behavior, where it tracked remaining iterations to adjust its planning. Early generations executed ambitious architectural changes, while later generations focused on conservative, incremental refinements.</p><p>For enterprise data teams wondering where to start, Zhang recommends focusing on tasks where success is unambiguous. “Workflows that are clearly specified and easy to evaluate, often referred to as verifiable tasks, are the best starting point,” she said. “This generally opens new opportunities for more exploratory prototyping, more exhaustive data analysis, more exhaustive A/B testing, [and] faster feature engineering.” For harder, unverified tasks, teams can use hyperagents to first develop learned judges that better reflect human preferences, creating a bridge to more complex domains.</p><p>The researchers have shared <a href="https://github.com/facebookresearch/Hyperagents">the code for hyperagents</a>, though it has been released under a non-commercial license.</p><h2><b>Caveats and future threats</b></h2><p>The benefits of hyperagents introduce clear tradeoffs. The researchers highlight several safety considerations regarding systems that can modify themselves in increasingly open-ended ways.</p><p>These AI systems pose the risk of evolving far more rapidly than humans can audit or interpret. While researchers contained DGM-H within safety boundaries such as sandboxed environments designed to prevent unintended side effects, these initial safeguards are actually practical deployment blueprints. </p><p>Zhang advises developers to enforce resource limits and restrict access to external systems during the self-modification phase. “The key principle is to separate experimentation from deployment: allow the agent to explore and improve within a controlled sandbox, while ensuring that any changes that affect real systems are carefully validated before being applied,” she said. Only after the newly modified code passes developer-defined correctness checks should it be promoted to a production setting.</p><p>Another significant danger is evaluation gaming, where the AI improves its metrics without making actual progress toward the intended real-world goal. Because hyperagents are driven by empirical evaluation signals, they can autonomously discover strategies that exploit blind spots or weaknesses in the evaluation procedure itself to artificially inflate their scores. Preventing this behavior requires developers to implement diverse, robust, and periodically refreshed evaluation protocols alongside continuous human oversight.</p><p>Ultimately, these systems will shift the day-to-day responsibilities of human engineers. Just as we do not recompute every operation a calculator performs, future AI orchestration engineers will not write the improvement logic directly, Zhang believes. </p><p>Instead, they will design the mechanisms for auditing and stress-testing the system. “As self-improving systems become more capable, the question is no longer just how to improve performance, but what objectives are worth pursuing,” Zhang said. “In that sense, the role evolves from building systems to shaping their direction.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trusted WordPress Plugins Hijacked in 8-Month Stealth Backdoor Campaign]]></title>
<description><![CDATA[Hackers secretly planted a remote code-execution backdoor in more than 30 popular WordPress plugins, leaving it dormant for about 8 months before activating malware that rewrote wp-config.php and injected cloaked SEO spam at scale. The incident centers on “Essential Plugin,”…
Read more →
The post...]]></description>
<link>https://tsecurity.de/de/3435148/it-security-nachrichten/trusted-wordpress-plugins-hijacked-in-8-month-stealth-backdoor-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3435148/it-security-nachrichten/trusted-wordpress-plugins-hijacked-in-8-month-stealth-backdoor-campaign/</guid>
<pubDate>Wed, 15 Apr 2026 13:24:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hackers secretly planted a remote code-execution backdoor in more than 30 popular WordPress plugins, leaving it dormant for about 8 months before activating malware that rewrote wp-config.php and injected cloaked SEO spam at scale. The incident centers on “Essential Plugin,”…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/trusted-wordpress-plugins-hijacked-in-8-month-stealth-backdoor-campaign/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/trusted-wordpress-plugins-hijacked-in-8-month-stealth-backdoor-campaign/">Trusted WordPress Plugins Hijacked in 8-Month Stealth Backdoor Campaign</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trusted WordPress Plugins Hijacked in 8-Month Stealth Backdoor Campaign]]></title>
<description><![CDATA[Hackers secretly planted a remote code-execution backdoor in more than 30 popular WordPress plugins, leaving it dormant for about 8 months before activating malware that rewrote wp-config.php and injected cloaked SEO spam at scale. The incident centers on “Essential Plugin,” a portfolio of 30+ fr...]]></description>
<link>https://tsecurity.de/de/3435048/it-security-nachrichten/trusted-wordpress-plugins-hijacked-in-8-month-stealth-backdoor-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3435048/it-security-nachrichten/trusted-wordpress-plugins-hijacked-in-8-month-stealth-backdoor-campaign/</guid>
<pubDate>Wed, 15 Apr 2026 12:51:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hackers secretly planted a remote code-execution backdoor in more than 30 popular WordPress plugins, leaving it dormant for about 8 months before activating malware that rewrote wp-config.php and injected cloaked SEO spam at scale. The incident centers on “Essential Plugin,” a portfolio of 30+ free plugins with paid upgrades used for sliders, countdown timers, FAQs, […]</p>
<p>The post <a href="https://gbhackers.com/trusted-wordpress-plugins/">Trusted WordPress Plugins Hijacked in 8-Month Stealth Backdoor Campaign</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[George Kurtz + Dan Ives on AI Agents Bypassing Security Policies]]></title>
<description><![CDATA[Author: CrowdStrike - Bewertung: 0x - Views:21 One AI agent didn’t have permission to fix an issue… so it asked another agent with access to do it.

Another? It rewrote the security policy to achieve its goal.

This isn’t theory. This is happening.

George_Kurtz sat down with DivesTech to discuss...]]></description>
<link>https://tsecurity.de/de/3424707/it-security-video/george-kurtz-dan-ives-on-ai-agents-bypassing-security-policies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3424707/it-security-video/george-kurtz-dan-ives-on-ai-agents-bypassing-security-policies/</guid>
<pubDate>Fri, 10 Apr 2026 22:02:03 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: CrowdStrike - Bewertung: 0x - Views:21 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/OvBc7um9URM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>One AI agent didn’t have permission to fix an issue… so it asked another agent with access to do it.<br />
<br />
Another? It rewrote the security policy to achieve its goal.<br />
<br />
This isn’t theory. This is happening.<br />
<br />
George_Kurtz sat down with DivesTech to discuss why AI needs guardrails. ⬇️<br />
<br />
https://crwdstr.ke/6050B6LqQe<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[George Kurtz + Dan Ives on AI Agents Bypassing Security Policies]]></title>
<description><![CDATA[Author: CrowdStrike - Bewertung: 0x - Views:0 One AI agent didn’t have permission to fix an issue… so it asked another agent with access to do it.

Another? It rewrote the security policy to achieve its goal.

This isn’t theory. This is happening.

George_Kurtz sat down with DivesTech to discuss ...]]></description>
<link>https://tsecurity.de/de/3424687/it-security-video/george-kurtz-dan-ives-on-ai-agents-bypassing-security-policies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3424687/it-security-video/george-kurtz-dan-ives-on-ai-agents-bypassing-security-policies/</guid>
<pubDate>Fri, 10 Apr 2026 21:47:25 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: CrowdStrike - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/OvBc7um9URM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>One AI agent didn’t have permission to fix an issue… so it asked another agent with access to do it.<br />
<br />
Another? It rewrote the security policy to achieve its goal.<br />
<br />
This isn’t theory. This is happening.<br />
<br />
George_Kurtz sat down with DivesTech to discuss why AI needs guardrails. ⬇️<br />
<br />
https://crwdstr.ke/6050B6LqQe<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Researchers Show Prompt Injection Can Break Apple Intelligence]]></title>
<description><![CDATA[Security researchers recently showed exactly how a clever prompt injection attack managed to bypass the built-in safety protections of Apple Intelligence. The method tricked the on-device system into running unauthorized commands. Apple has since fixed the vulnerability, but these new findings gi...]]></description>
<link>https://tsecurity.de/de/3424338/ios-mac-os/researchers-show-prompt-injection-can-break-apple-intelligence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3424338/ios-mac-os/researchers-show-prompt-injection-can-break-apple-intelligence/</guid>
<pubDate>Fri, 10 Apr 2026 18:53:25 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security researchers recently showed exactly how a clever prompt injection attack managed to bypass the built-in safety protections of Apple Intelligence. The method tricked the on-device system into running unauthorized commands. Apple has since fixed the vulnerability, but these new findings give us a clear look at how hackers can manipulate local AI models even when strict safety filters are actively in place.



How the attack tricked the system



The attackers used a two-step process (via Apple Insider) to get past the input and output filters that Apple built into its system. First, they used a trick involving Unicode characters. They wrote harmful text backward, but applied a special right-to-left override character.



This made the text look normal on a screen, but the raw text remained reversed. Because the system filters only looked at the raw text, they did not recognize the harmful words and let the request pass through.



After sneaking past the filters, the researchers used a technique called Neural Exec. This method essentially rewrote the core instructions of the model. By combining these two steps, the attackers forced the system to ignore its basic safety rules and execute whatever instructions they wanted. In their tests, this approach worked 76 percent of the time.



Apple is fixing the blind spots in local models



Apple relies on a series of checks to keep its on-device Apple Intelligence functionality safe. An input filter checks your question for bad content. If it passes, the model generates an answer, which an output filter then checks. The researchers simply made the bad content invisible to those outer layers while giving orders to the model in the middle.



They reported this to Apple in October 2025. The company updated its software to block the attack, releasing fixes in iOS 26.4 and macOS 26.4. While the fix is live, the research shows how tricky it is to secure AI models running locally on phones. Attackers will keep finding ways to hide their instructions in plain sight.]]></content:encoded>
</item>
<item>
<title><![CDATA[Sicherheitslücke in Next.js: Über 700 Server kompromittiert]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine schwerwiegende Sicherheitslücke in Next.js-Anwendungen hat es Hackern ermöglicht, über 700 Server weltweit zu kompromittieren. Die Schwachstelle, bekannt als React2Shell, wird von der Hackergruppe UAT-10608 ausgenutzt, um sensible Daten zu stehlen. Eine massive automat...]]></description>
<link>https://tsecurity.de/de/3408656/it-security-nachrichten/sicherheitsluecke-in-nextjs-ueber-700-server-kompromittiert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3408656/it-security-nachrichten/sicherheitsluecke-in-nextjs-ueber-700-server-kompromittiert/</guid>
<pubDate>Sun, 05 Apr 2026 07:51:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-nextjs-security-breach-2.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-nextjs-security-breach-2.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-nextjs-security-breach-2-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-nextjs-security-breach-2-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-nextjs-security-breach-2-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-nextjs-security-breach-2-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-nextjs-security-breach-2-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Eine schwerwiegende Sicherheitslücke in Next.js-Anwendungen hat es Hackern ermöglicht, über 700 Server weltweit zu kompromittieren. Die Schwachstelle, bekannt als React2Shell, wird von der Hackergruppe UAT-10608 ausgenutzt, um sensible Daten zu stehlen. Eine massive automatisierte Kampagne zum Diebstahl von Zugangsdaten zielt derzeit auf Webanwendungen weltweit ab. Sicherheitsforscher von Cisco Talos haben eine […]</p>
<div><a href="https://www.it-boltwise.de/sicherheitsluecke-in-next-js-ueber-700-server-kompromittiert.html">... den vollständigen Artikel <strong>»Sicherheitslücke in Next.js: Über 700 Server kompromittiert«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/sicherheitsluecke-in-next-js-ueber-700-server-kompromittiert.html">Sicherheitslücke in Next.js: Über 700 Server kompromittiert</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Local-first browser data gets real]]></title>
<description><![CDATA[If JavaScript were a character in a role-playing game, its class would be a Rogue. When it was a youngster, it was a street kid that lived on the margins of society. Over time, it has become an established figure in the enterprise hierarchy. But it never forgot where it came from, and you never k...]]></description>
<link>https://tsecurity.de/de/3405017/ai-nachrichten/local-first-browser-data-gets-real/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3405017/ai-nachrichten/local-first-browser-data-gets-real/</guid>
<pubDate>Fri, 03 Apr 2026 11:32:57 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>If <a href="https://www.infoworld.com/article/2263137/what-is-javascript-the-full-stack-programming-language.html">JavaScript</a> were a character in a role-playing game, its class would be a Rogue. When it was a youngster, it was a street kid that lived on the margins of society. Over time, it has become an established figure in the enterprise hierarchy. But it never forgot where it came from, and you never know what sleight of hand it will perform next.</p>



<p>For example, fine-grained <a href="https://github.com/tc39/proposal-signals">Signals</a> are mounting a rebellion to overthrow the existing Virtual DOM hegemony. Incremental improvements to <a href="https://www.infoworld.com/article/2255892/what-is-webassembly-the-next-generation-web-platform-explained.html">WebAssembly</a> have reached the point where a real SQL database can be run inside the browser. Coupled with ingenious architectural patterns, this has opened up new possibilities in app data design. </p>



<p>In other JS developments, the upstart performance runtime, <a href="https://www.infoworld.com/article/2338008/explore-bunjs-the-all-in-one-javascript-runtime.html">Bun</a>, has spawned a native app framework, Electrobun. Welcome to our latest roundup of the JavaScript news and noteworthy.</p>



<h2 class="wp-block-heading"><a></a>Top picks for JavaScript readers on InfoWorld</h2>



<p><a href="https://www.infoworld.com/article/4137964/first-look-electrobun-for-typescript-powered-desktop-apps.html">First look: Electrobun for TypeScript-powered desktop apps</a><br>Electron (the native-web bridge framework) has always struggled around performance. Electrobun is a (predictably named) new alternative that uses the Bun runtime, famous for its intense performance.  Electrobun claims to produce far smaller bundles than regular Electron by dropping the bundled browser, and it comes with its own differential update technology to simplify patches.</p>



<p><a href="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html">The revenge of SQL: How a 50-year-old language reinvents itself</a><br>SQL is making an improbable comeback in the JavaScript world. Driven by the ability to run database engines like SQLite and PostgreSQL right inside the browser via WebAssembly, and the rise of the schemaless jsonb type, developers are discovering that boring old SQL is highly adaptable to the modern web.</p>



<p><a href="https://www.infoworld.com/article/4140812/why-local-first-matters-for-javascript.html">Why local-first matters for JavaScript</a><br>Every developer should be paying attention to the local-first architecture movement. The emerging local-first SQL data stores crystallize ideas about client/server symmetry that have been a long time coming. This shift simplifies offline capabilities and fundamentally changes how we think about UI state.</p>



<p><a href="https://www.infoworld.com/article/4129648/reactive-state-management-with-javascript-signals.html">Reactive state management with JavaScript Signals</a><br>State management remains one of the nastiest parts of front-end development. Signals have emerged as the dominant mechanism for dealing with reactive state, offering a more fine-grained and performant alternative to traditional Virtual DOM diffing. It is a vital pattern to understand as it sweeps across the framework landscape.</p>



<h3 class="wp-block-heading"><a></a>JavaScript news bites</h3>



<ul class="wp-block-list">
<li><a href="https://www.infoworld.com/article/4145953/project-detroit-bridging-java-python-javascript-moves-forward.html">Project Detroit, bridging Java, Python, JavaScript, moves forward</a>. Here is an interesting effort to bring Java, Python, and JS into a unified context. It has Oracle’s backing and is gaining steam.</li>



<li><a href="https://www.infoworld.com/article/4151375/kotlin-2-3-20-harmonizes-with-c-javascript-typescript.html">Kotlin 2.3.20 harmonizes with C, JavaScript/TypeScript</a>. Some very interesting expansions to Kotlin’s interop support.</li>



<li><a href="https://www.infoworld.com/javascript/">Angular releases patches for SSR security issues</a>. A security patch that addresses vulnerabilities that could allow attackers to steal authorization headers.</li>
</ul>



<h2 class="wp-block-heading"><a></a>More good reads and JavaScript updates elsewhere</h2>



<p><a href="https://nextjs.org/blog/next-16-2-ai">Next.js 16.2 introduces features built specifically for AI agents</a><br>In a fascinating and forward-looking move, the latest Next.js release includes tools designed specifically to help AI agents build and debug applications. This includes an AGENTS.md file that feeds bundled documentation directly to <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a>, automatic browser log forwarding to the terminal (where agents operate), and an experimental CLI that lets AI inspect React component trees without needing a visual browser window.</p>



<p><a href="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0/">TypeScript 6.0 is GA</a><br>The smashingly popular superset of JavaScript is now GA for 6.0. This is the last release before Microsoft swaps out the current JavaScript engine for one built on Go. The TypeScript 6.0 drop is most important as a bridge to Go-based TypeScript 7.0, which the team says is coming soon (and is already available via npm flag). If you can run atop TypeScript 6, you are in good shape for TypeScript 7.</p>



<p><a href="https://vite.dev/blog/announcing-vite8">Vite 8.0 arrives with unified Rolldown-based builds</a><br>Vite now uses Rolldown, the bundler/builder built in Rust, instead of esbuild for dev and Rollup for production. This move simplifies the architecture and brings speed benefits without breaking plugin compatibility. Pretty impressive. The Vite team also introduced a plugin registry at <a href="https://registry.vite.dev/">registry.vite.dev</a>.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kritische Sicherheitslücke in Next.js führt zu massiven Datenlecks]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine schwerwiegende Sicherheitslücke in Next.js hat zu einem groß angelegten Angriff geführt, bei dem Hacker sensible Daten von über 766 Hosts gestohlen haben. Die Schwachstelle, bekannt als CVE-2025-55182, ermöglicht es Angreifern, auf Datenbanken, SSH-Schlüssel und API-Ke...]]></description>
<link>https://tsecurity.de/de/3403872/it-security-nachrichten/kritische-sicherheitsluecke-in-nextjs-fuehrt-zu-massiven-datenlecks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3403872/it-security-nachrichten/kritische-sicherheitsluecke-in-nextjs-fuehrt-zu-massiven-datenlecks/</guid>
<pubDate>Thu, 02 Apr 2026 22:05:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-nextjs-security-breach.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-nextjs-security-breach.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-nextjs-security-breach-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-nextjs-security-breach-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-nextjs-security-breach-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-nextjs-security-breach-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-nextjs-security-breach-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Eine schwerwiegende Sicherheitslücke in Next.js hat zu einem groß angelegten Angriff geführt, bei dem Hacker sensible Daten von über 766 Hosts gestohlen haben. Die Schwachstelle, bekannt als CVE-2025-55182, ermöglicht es Angreifern, auf Datenbanken, SSH-Schlüssel und API-Keys zuzugreifen. Sicherheitsforscher warnen vor den weitreichenden Folgen für betroffene Unternehmen. Eine kritische Sicherheitslücke in der […]</p>
<div><a href="https://www.it-boltwise.de/kritische-sicherheitsluecke-in-next-js-fuehrt-zu-massiven-datenlecks.html">... den vollständigen Artikel <strong>»Kritische Sicherheitslücke in Next.js führt zu massiven Datenlecks«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/kritische-sicherheitsluecke-in-next-js-fuehrt-zu-massiven-datenlecks.html">Kritische Sicherheitslücke in Next.js führt zu massiven Datenlecks</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RSAC 2026 shipped five agent identity frameworks and left three critical gaps open]]></title>
<description><![CDATA[“You can deceive, manipulate, and lie. That’s an inherent property of language. It’s a feature, not a flaw,” CrowdStrike CTO Elia Zaitsev told VentureBeat in an exclusive interview at RSA Conference 2026. If deception is baked into language itself, every vendor trying to secure AI agents by analy...]]></description>
<link>https://tsecurity.de/de/3394200/it-nachrichten/rsac-2026-shipped-five-agent-identity-frameworks-and-left-three-critical-gaps-open/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3394200/it-nachrichten/rsac-2026-shipped-five-agent-identity-frameworks-and-left-three-critical-gaps-open/</guid>
<pubDate>Mon, 30 Mar 2026 21:31:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>“You can deceive, manipulate, and lie. That’s an inherent property of language. It’s a feature, not a flaw,” <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-establishes-the-endpoint-as-the-epicenter-for-ai-security/">CrowdStrike</a> CTO Elia Zaitsev told VentureBeat in an exclusive interview at RSA Conference 2026. If deception is baked into language itself, every vendor trying to secure AI agents by analyzing their intent is chasing a problem that cannot be conclusively solved. Zaitsev is betting on context instead. CrowdStrike’s Falcon sensor walks the process tree on an endpoint and tracks what agents did, not what agents appeared to intend. “Observing actual kinetic actions is a structured, solvable problem,” Zaitsev told VentureBeat. “Intent is not.”</p><p>That argument landed 24 hours after CrowdStrike CEO George Kurtz disclosed two production incidents at Fortune 50 companies. In the first, a CEO's AI agent rewrote the company's own security policy — not because it was compromised, but because it wanted to fix a problem, lacked the permissions to do so, and removed the restriction itself. Every identity check passed; the company caught the modification by accident. The second incident involved a 100-agent Slack swarm that delegated a code fix between agents with no human approval. Agent 12 made the commit. The team discovered it after the fact.</p><p>Two incidents at two Fortune 50 companies. Caught by accident both times. Every identity framework that shipped at RSAC this week missed them. The vendors verified who the agent was. None of them tracked what the agent did.</p><p>The urgency behind every framework launch reflects a broader market shift. "The difficulty of securing agentic AI is likely to push customers toward trusted platform vendors that can offer broader coverage across the expanding attack surface," according to William Blair's RSA Conference 2026 equity research report by analyst Jonathan Ho. Five vendors answered that call at RSAC this week. None of them answered it completely.</p><h2>Attackers are already inside enterprise pilots</h2><p>The scale of the exposure is already visible in production data. <a href="https://www.crowdstrike.com/en-us/blog/new-crowdstrike-innovations-secure-ai-agents-govern-shadow-ai/">CrowdStrike's Falcon sensors</a> detect more than 1,800 distinct AI applications across the company's customer fleet, generating 160 million unique instances on enterprise endpoints. Cisco found that <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html">85% of its enterprise customers surveyed have pilot agent programs</a>; only 5% have moved to production, meaning the vast majority of these agents are running without the governance structures production deployments typically require. "The biggest impediment to scaled adoption in enterprises for business-critical tasks is establishing a sufficient amount of trust," Cisco President and Chief Product Officer Jeetu Patel told VentureBeat in an exclusive interview at RSA Conference 2026. "Delegating versus trusted delegating of tasks to agents. The difference between those two, one leads to bankruptcy and the other leads to market dominance."</p><p>Etay Maor, VP of Threat Intelligence at <a href="https://www.catonetworks.com/blog/cato-ctrl-when-openclaw-ai-personal-assistant-becomes-backdoor/">Cato Networks</a>, ran a live Censys scan during an exclusive VentureBeat interview at RSA Conference 2026 and counted nearly 500,000 internet-facing OpenClaw instances. The week before: 230,000. Cato CTRL senior researcher Vitaly Simonovich documented a BreachForums listing from February 22, 2026, published on the <a href="https://www.catonetworks.com/blog/cato-ctrl-when-openclaw-ai-personal-assistant-becomes-backdoor/">Cato CTRL blog on February 25</a>, where a threat actor advertised root shell access to a UK CEO’s computer for $25,000 in cryptocurrency. The selling point was the CEO’s OpenClaw AI personal assistant, which had accumulated the company’s production database, Telegram bot tokens, and Trading 212 API keys in plain-text Markdown with no encryption at rest. “Your AI? It’s my AI now. It’s an assistant for the attacker,” Maor told VentureBeat.</p><p>The exposure data from multiple independent researchers tells the same story. Bitsight found more than 30,000 OpenClaw instances exposed to the public internet between January 27 and February 8, 2026. <a href="https://securityscorecard.com/blog/beyond-the-hype-moltbots-real-risk-is-exposed-infrastructure-not-ai-superintelligence/">SecurityScorecard</a> identified 15,200 of those instances as vulnerable to remote code execution through three high-severity CVEs, the worst rated CVSS 8.8. <a href="https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting">Koi Security found 824 malicious skills on ClawHub</a> — 335 of them tied to ClawHavoc, which Kurtz flagged in his keynote as the first major supply chain attack on an AI agent ecosystem.</p><h2>Five vendors, three gaps none of them closed</h2><p><a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html">Cisco</a> went deepest on identity governance. <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html">Duo Agentic Identity</a> registers agents as distinct identity objects mapped to human owners, and every tool call routes through an MCP gateway in Secure Access SSE. Cisco Identity Intelligence catches shadow agents by monitoring network traffic rather than authentication logs. Patel told VentureBeat that today’s agents behave “more like teenagers — supremely intelligent, but with no fear of consequence, easily sidetracked or influenced.” <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-establishes-the-endpoint-as-the-epicenter-for-ai-security/">CrowdStrike</a> made the biggest philosophical bet, treating agents as endpoint telemetry and tracking the kinetic layer through Falcon’s process-tree lineage. CrowdStrike expanded <a href="https://www.crowdstrike.com/en-us/blog/new-crowdstrike-innovations-secure-ai-agents-govern-shadow-ai/">AIDR</a> to cover Microsoft Copilot Studio agents and shipped Shadow SaaS and AI Agent Discovery across Copilot, Salesforce Agentforce, ChatGPT Enterprise, and OpenAI Enterprise GPT.</p><p><a href="https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-secures-agentic-ai-with-prisma-airs-3-0">Palo Alto Networks</a> built <a href="https://www.paloaltonetworks.com/blog/2026/03/prisma-airs-3-0-autonomous-ai/">Prisma AIRS 3.0</a> with an agentic registry, an agentic IDP, and an MCP gateway for runtime traffic control. Palo Alto Networks’ pending Koi acquisition adds supply chain and runtime visibility. <a href="https://www.microsoft.com/en-us/security/blog/2026/03/20/secure-agentic-ai-end-to-end/">Microsoft</a> spread governance across Entra, Purview, Sentinel, and Defender, with <a href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/what%E2%80%99s-new-in-microsoft-sentinel-rsac-2026/4503971">Microsoft Sentinel</a> embedding MCP natively and a Claude MCP connector in public preview April 1. Cato CTRL delivered the adversarial proof that the identity gaps the other four vendors are trying to close are already being exploited. Maor told VentureBeat that enterprises abandoned basic security principles when deploying agents. “We just gave these AI tools complete autonomy,” Maor said.</p><h2>Gap 1: Agents can rewrite the rules governing their own behavior</h2><p>The Kurtz incident illustrates the gap exactly. Every credential check passed — the action was authorized. Zaitsev argues that the only reliable detection happens at the kinetic layer: which file was modified, by what process, initiated by what agent, compared against a behavioral baseline. Intent-based controls evaluate whether the call looks malicious. This one did not. Palo Alto Networks offers <a href="https://www.paloaltonetworks.com/blog/2026/03/prisma-airs-3-0-autonomous-ai/">pre-deployment red teaming in Prisma AIRS 3.0</a>, but red teaming runs before deployment, not during runtime when self-modification happens. No vendor ships behavioral anomaly detection for policy-modifying actions as a production capability.</p><p>Patel framed the stakes in the VentureBeat interview: “The agent takes the wrong action and worse yet, some of those actions might be critical actions that are not reversible.” Board question: An authorized agent modifies the policy governing the agent’s future actions. What fires?</p><h2>Gap 2: Agent-to-agent handoffs have no trust verification</h2><p>The 100-agent swarm is the proof point. Agent A found a defect and posted to Slack. Agent 12 executed the fix. No human approved the delegation. Zaitsev’s approach: collapse agent identities back to the human. An agent acting on your behalf should never have more privileges than you do. But no product follows the delegation chain between agents. IAM was built for human-to-system. Agent-to-agent delegation needs a trust primitive that does not exist in OAuth, SAML, or MCP.</p><h2>Gap 3: Ghost agents hold live credentials with no offboarding</h2><p>Organizations adopt AI tools, run a pilot, lose interest, and move on. The agents keep running. The credentials stay active. Maor calls these abandoned instances ghost agents. Zaitsev connected ghost agents to a broader failure: agents expose where enterprises delayed action on basic identity hygiene. Standing privileged accounts, long-lived credentials, and missing offboarding procedures. These problems existed for humans. Agents running at machine speed make the consequences catastrophic.</p><p>Maor demonstrated a <a href="https://www.catonetworks.com/resources/living-off-the-ai-targeting-ai-agents/">Living Off the AI</a> attack at the RSA Conference 2026, chaining Atlassian’s MCP and Jira Service Management to show that attackers do not separate trusted tools, services, and models. Attackers chain all three. “We need an HR view of agents,” Maor told VentureBeat. “Onboarding, monitoring, offboarding. If there’s no business justification? Removal.”</p><h2>Why these three gaps resist a product fix</h2><p>Human IAM assumes the identity holder will not rewrite permissions, spawn new identities, or leave. Agents violate all three. OAuth handles user-to-service. SAML handles federated human identity. MCP handles model-to-tool. None includes agent-to-agent verification.</p><h2>Five vendors against three gaps</h2><table><tbody><tr><td><p></p></td><td><p><b>Cisco</b></p></td><td><p><b>CrowdStrike</b></p></td><td><p><b>Microsoft</b></p></td><td><p><b>Palo Alto Networks</b></p></td><td><p><b>Unsolved</b></p></td></tr><tr><td><p><b>Registration. Can the vendor discover and inventory agents?</b></p></td><td><p>Duo Agentic Identity. Agents registered as identity objects with human owners. Shadow agent detection via network traffic.</p></td><td><p>Falcon sensor auto-discovery. 1,800+ agent apps, ~160M instances across customer fleet.</p></td><td><p>Security Dashboard for AI + Entra shadow AI detection at the network layer.</p></td><td><p>Agentic registry in Prisma AIRS 3.0. Agents inventoried before operating.</p></td><td><p>All four register agents. No cross-vendor identity standard exists.</p></td></tr><tr><td><p><b>Self-modification. Can the vendor detect when an agent changes its own policies?</b></p></td><td><p>MCP gateway catches anomalous tool-call patterns in real time, but does not monitor for direct policy file modifications on the endpoint.</p></td><td><p>Process-tree lineage tracks file modifications at the action layer. Could detect a policy file change, but no dedicated self-modification rule ships.</p></td><td><p>Defender predictive shielding adjusts access policies reactively during active attacks. Not proactive self-modification detection.</p></td><td><p>AI Red Teaming tests for this before deployment. No runtime detection after the agent is live.</p></td><td><p>OPEN. No vendor detects an agent rewriting the policy governing the agent’s own behavior as a shipping capability.</p></td></tr><tr><td><p><b>Delegation. Can the vendor track when one agent hands work to another?</b></p></td><td><p>Maps each agent to a human owner. Does not track agent-to-agent handoffs.</p></td><td><p>Collapses the agent identity to the human operator. Does not correlate the delegation chains between agents.</p></td><td><p>Entra governs individual non-human identities. No multi-agent chain tracking.</p></td><td><p>AI Agent Gateway governs individual agents. No delegation primitive between agents.</p></td><td><p>OPEN. No trust primitive for agent-to-agent delegation exists in OAuth, SAML, or MCP.</p></td></tr><tr><td><p><b>Decommission. Can the vendor confirm a killed agent holds zero credentials?</b></p></td><td><p>Identity Intelligence runs a continuous inventory of active agents.</p></td><td><p>Shadow SaaS + AI Agent Discovery finds running agents across SaaS and endpoints.</p></td><td><p>Entra's shadow AI detection surfaces unmanaged AI applications.</p></td><td><p>Koi acquisition (pending) adds endpoint visibility for agent applications.</p></td><td><p>OPEN. All four discover running agents. None verifies zero residual credentials after decommission.</p></td></tr><tr><td><p><b>Runtime / Kinetic. Can the vendor monitor what agents do in real time?</b></p></td><td><p>MCP gateway enforces policy per tool call at the network layer. Contextual anomaly detection on call patterns.</p></td><td><p>Falcon EDR tracks commands, scripts, file activity, and network connections at the process level.</p></td><td><p>Defender endpoint + cloud monitoring. Predictive shielding during active incidents.</p></td><td><p>Prisma AIRS AI Agent Gateway for runtime traffic control.</p></td><td><p>CrowdStrike is the only vendor framing endpoint runtime as the primary safety net for agentic behavior.</p></td></tr></tbody></table><h2>Five things to do Monday morning before your board asks</h2><ol><li><p><b>Audit self-modification risk.</b> Pull every agent with write access to security policies, IAM configs, firewall rules, or ACLs. Flag any agent that can modify controls governing the agent’s own behavior. No vendor automates this.</p></li><li><p><b>Map delegation paths.</b> Document every agent-to-agent invocation. Flag delegation without human approval. Human-in-the-loop on every delegation event until a trust primitive ships.</p></li><li><p><b>Kill ghost agents.</b> Build a registry. For each agent: business justification, human owner, credentials held, systems accessed. No justification? Manual revoke. Weekly.</p></li><li><p><b>Stress test the MCP gateway enforcement.</b> <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html">Cisco</a>, <a href="https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-secures-agentic-ai-with-prisma-airs-3-0">Palo Alto Networks</a>, and <a href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/what%E2%80%99s-new-in-microsoft-sentinel-rsac-2026/4503971">Microsoft</a> all announced MCP gateways this week. Verify that agent tool traffic actually routes through the gateway. A misconfigured gateway creates false confidence while agents call tools directly.</p></li><li><p><b>Baseline agent behavioral norms.</b> Before any agent reaches production, establish what normal looks like: typical API calls, data access patterns, systems touched, and hours of activity. Without a behavioral baseline, the kinetic-layer anomaly detection Zaitsev describes has nothing to compare against.</p></li></ol><p>Zaitsev’s advice was blunt: you already know what to do. Agents just made the cost of not doing it catastrophic. Every vendor at RSAC verified who the agent was. None of them tracked what the agent did.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[On the pleasures and dangers of open source Python]]></title>
<description><![CDATA[Announced at JavaOne, Project Detroit proposes to break down the walls between Java, Python, and JavaScript. Also in this report: Better ways to instrument your code with Python’s new built-in sampling profiler, another run at using AI locally to rework a Python project, and the question on every...]]></description>
<link>https://tsecurity.de/de/3385863/ai-nachrichten/on-the-pleasures-and-dangers-of-open-source-python/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3385863/ai-nachrichten/on-the-pleasures-and-dangers-of-open-source-python/</guid>
<pubDate>Fri, 27 Mar 2026 10:32:56 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Announced at JavaOne, Project Detroit proposes to break down the walls between Java, Python, and JavaScript. Also in this report: Better ways to instrument your code with Python’s new built-in sampling profiler, another run at using AI locally to rework a Python project, and the question on everyone’s mind right now (surely): What does OpenAI <em>really</em> want with Astral?</p>



<h2 class="wp-block-heading">Top picks for Python readers on InfoWorld</h2>



<p><strong><a href="https://www.infoworld.com/article/4147837/openai-buys-python-tools-builder-astral.html">OpenAI buys Python tools builder Astral</a><br></strong>Astral, the maker of uv, ty, and pyx, has a new home under the OpenAI umbrella. Is OpenAI demonstrating its commitment to maintaining tooling in the AI space, or is the purchase more of a power move?</p>



<p><strong><a href="https://www.infoworld.com/article/4144487/i-ran-qwen3-5-locally-instead-of-claude-code-heres-what-happened.html">I ran Qwen3.5 locally instead of Claude Code. Here’s what happened</a><br></strong>Want to run an LLM on your own hardware for that at-home Claude Code or Copilot experience? You can, but it’ll be a bumpy ride. My takeaway? Maybe don’t let the AI run around unsupervised after dark.</p>



<p><strong><a href="https://www.infoworld.com/video/4085906/hands-on-with-the-new-sampling-profiler-in-python-3-15.html">Hands-on with the new sampling profiler in Python 3.15</a><br></strong>Among Python 3.15’s best new features is a sampling profiler. See how it works in this guide to using the profiler to instrument your code and find bottlenecks with minimal performance impact.</p>



<p><strong><a href="https://www.infoworld.com/article/4145953/project-detroit-bridging-java-python-javascript-moves-forward.html">Project Detroit, bridging Java, Python, JavaScript, moves forward</a><br></strong>The once-dead, now-revived Detroit project aims to allow Java’s Foreign Function and Memory API to talk seamlessly to other language runtimes. The vision? More powerful mixing and matching of languages across domains.</p>



<h2 class="wp-block-heading">More good reads and Python updates elsewhere</h2>



<p><strong><a href="https://fpgmaas.com/blog/collapse-of-mkdocs/">The slow collapse of MkDocs</a><br></strong>The strange, ongoing saga of how a developer meltdown took out one of the most popular documentation tools for Python—with no clear successor in sight.</p>



<p><strong><a href="https://pyrefly.org/blog/typing-conformance-comparison/">Comparing the typing spec conformance of Python type-checking tools</a><br></strong>How well do tools like Pyright, Pyrefly, Mypy, Ty, and others conform to Python’s own type annotation specs? The answers range, surprisingly, from “very closely” to “just barely.”</p>



<p><strong><a href="https://cemrehancavdar.com/2026/03/10/optimization-ladder/">The optimization ladder: All the ways to make Python faster</a><br></strong>From replacing the runtime to integrating modules written in C or Rust, here’s an end-to-end rundown of ways to speed up Python for tasks that urgently need performance.</p>



<p><strong><a href="https://shiftmag.dev/license-laundering-and-the-death-of-clean-room-8528/">License laundering and the death of ‘clean room’</a><br></strong>When someone rewrote a long-unmaintained Python library with an LLM, the original developer broke a decade-plus silence to object. What are the implications for open source?</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[I rewrote my ELF loader in Rust and added new features!]]></title>
<description><![CDATA[submitted by    /u/AcrobaticMonitor9992   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3349617/reverse-engineering/i-rewrote-my-elf-loader-in-rust-and-added-new-features/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3349617/reverse-engineering/i-rewrote-my-elf-loader-in-rust-and-added-new-features/</guid>
<pubDate>Sat, 14 Mar 2026 17:04:24 +0100</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/AcrobaticMonitor9992"> /u/AcrobaticMonitor9992 </a> <br> <span><a href="https://github.com/iss4cf0ng/Elfina/releases/tag/v2.0.0">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1rtmpvp/i_rewrote_my_elf_loader_in_rust_and_added_new/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare Experiment Ports Most of Next.js API in 'One Week' With AI]]></title>
<description><![CDATA[An anonymous reader shares a report: A Cloudflare engineer says he has implemented 94% of the Next.js API by directing Anthropic's Claude, spending about $1,100 on tokens. The purpose of the experimental project was not to show off AI coding, but to address an issue with Next.js, the popular Reac...]]></description>
<link>https://tsecurity.de/de/3311784/it-security-nachrichten/cloudflare-experiment-ports-most-of-nextjs-api-in-one-week-with-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3311784/it-security-nachrichten/cloudflare-experiment-ports-most-of-nextjs-api-in-one-week-with-ai/</guid>
<pubDate>Thu, 26 Feb 2026 10:21:28 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader shares a report: A Cloudflare engineer says he has implemented 94% of the Next.js API by directing Anthropic's Claude, spending about $1,100 on tokens. The purpose of the experimental project was not to show off AI coding, but to address an issue with Next.js, the popular React-based framework sponsored by Vercel. 

According to Cloudflare engineering director Steve Faulkner, the Next.js tooling is "entirely bespoke... If you want to deploy it to Cloudflare, Netlify, or AWS Lambda, you have to take that build output and reshape it into something the target platform can actually run." 

The Next.js team is addressing this following numerous complaints that deploying the framework with full features on platforms other than Vercel is too difficult, with a feature in progress called deployment adapters. "Vercel will use the same adapter API as every other partner," the company said when introducing the planned feature last year.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Cloudflare+Experiment+Ports+Most+of+Next.js+API+in+'One+Week'+With+AI%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F02%2F26%2F0543208%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F02%2F26%2F0543208%2Fcloudflare-experiment-ports-most-of-nextjs-api-in-one-week-with-ai%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/02/26/0543208/cloudflare-experiment-ports-most-of-nextjs-api-in-one-week-with-ai?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rewrote my C++ Zsh history daemon to kill OS overhead. Real world typing latency is ~7ms for 500k commands.]]></title>
<description><![CDATA[Hey folks, I posted a few days ago about a Zsh history middleware I've been building called BSH. Just to clarify up front: BSH is strictly a passion project to see how low I can push keystroke latency using a local-only C++ daemon. (I include tools like Atuin and FZF in my benchmarks purely becau...]]></description>
<link>https://tsecurity.de/de/3308506/linux-tipps/rewrote-my-c-zsh-history-daemon-to-kill-os-overhead-real-world-typing-latency-is-7ms-for-500k-commands/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3308506/linux-tipps/rewrote-my-c-zsh-history-daemon-to-kill-os-overhead-real-world-typing-latency-is-7ms-for-500k-commands/</guid>
<pubDate>Wed, 25 Feb 2026 02:36:24 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey folks,</p> <p>I posted a few days ago about a Zsh history middleware I've been building called BSH. Just to clarify up front: BSH is strictly a passion project to see how low I can push keystroke latency using a local-only C++ daemon. (I include tools like Atuin and FZF in my benchmarks purely because they are standard baselines everyone knows, but BSH has a much narrower focus).</p> <p>If you are a latency nerd, you might find this fun.</p> <p><strong>The Benchmarks (and a correction)</strong> In my last post, I mentioned hitting 2.5ms for 500k commands. I have to admit that previous benchmark was way too forgiving. I completely rewrote the test suite to use highly-variable, realistic shell data and to measure the exact execution path the tools <em>actually</em> take in real life (including the full Zsh socket round-trip overhead).</p> <p>That real-world testing added a bit of time to the results, but because of the architectural improvements below, the scaling remains incredibly flat:</p> <ul> <li><strong>10k commands:</strong> BSH 4.21ms | FZF 9.44ms | Atuin 14.78ms | Grep 9.37ms</li> <li><strong>100k commands:</strong> BSH 5.61ms | Atuin 16.08ms | FZF 39.21ms | Grep 77.96ms</li> <li><strong>500k commands:</strong> BSH 7.38ms | Atuin 22.37ms | FZF 200.61ms | Grep 417.62ms</li> </ul> <p><a href="https://preview.redd.it/7vdg9m328jlg1.png?width=3568&amp;format=png&amp;auto=webp&amp;s=5fbefc838090d74b0e04ad1fe452e0c8347f6759">https://preview.redd.it/7vdg9m328jlg1.png?width=3568&amp;format=png&amp;auto=webp&amp;s=5fbefc838090d74b0e04ad1fe452e0c8347f6759</a></p> <p><strong>What changed since last week to get here:</strong> I ended up completely rewriting the architecture to kill OS and I/O overhead.</p> <ul> <li>I ripped out the ephemeral client binary. Now, Zsh talks directly to the C++ daemon via native Unix sockets (<code>zmodload zsh/net/socket</code>).</li> <li><strong>Async I/O &amp; Git:</strong> Database writes and <code>libgit2</code> branch resolution are now pushed to a dedicated background thread with an in-memory LRU cache. Your keystrokes never wait on disk syncs or filesystem traversal.</li> <li>All SQLite FTS5 queries are precompiled into memory at daemon startup.</li> <li>All the string math, box-drawing, and truncation is handled asynchronously in C++, so the Zsh interpreter does zero heavy lifting.</li> </ul> <p><strong>TL;DR of Features</strong> It acts a bit like IntelliSense for your terminal. You can filter suggestions by your current Directory or Git Branch, and toggle a filter (<code>Ctrl+F</code>) to instantly hide commands that exited with errors (like typos or bad compiles). Everything stays 100% local.</p> <p><strong>Try it out</strong> I finally got it packaged so you don't have to build from source:</p> <ul> <li><strong>macOS:</strong> <code>brew tap karthikeyjoshi/bsh &amp;&amp; brew install bsh</code></li> <li><strong>Arch:</strong> <code>yay -S aur/bsh</code></li> </ul> <p><em>(There is also a universal install script, but I'm omitting it here because Reddit's spam filters hate</em> <code>curl | bash</code> <em>links!)</em></p> <p><strong>Repo:</strong> <a href="https://github.com/joshikarthikey/bsh">https://github.com/joshikarthikey/bsh</a></p> <p>If you know C++, CMake, Zsh internals, or just want to roast my architecture, PRs and issues are highly welcome. I'd love to hack on this with some like-minded people.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/karthikeyjoshi"> /u/karthikeyjoshi </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1rdxgju/rewrote_my_c_zsh_history_daemon_to_kill_os/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1rdxgju/rewrote_my_c_zsh_history_daemon_to_kill_os/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[When speed stops working]]></title>
<description><![CDATA[For more than a decade, speed defined modern technology leadership.



I was in the room when it happened. Board decks rewarded velocity. Executive meetings celebrated acceleration. CIOs were measured by how quickly platforms migrated, products shipped and transformations launched. Speed became s...]]></description>
<link>https://tsecurity.de/de/3304753/it-security-nachrichten/when-speed-stops-working/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3304753/it-security-nachrichten/when-speed-stops-working/</guid>
<pubDate>Mon, 23 Feb 2026 12:04:04 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For more than a decade, speed defined modern technology leadership.</p>



<p>I was in the room when it happened. Board decks rewarded velocity. Executive meetings celebrated acceleration. CIOs were measured by how quickly platforms migrated, products shipped and transformations launched. Speed became synonymous with relevance, and hesitation was framed as risk.</p>



<p>But something subtle began to change toward the end of 2025.</p>



<p>The questions coming from boards no longer centered on how fast we could move. Instead, they sounded more reflective, more surgical and frankly, more consequential: What happens when these scales? What breaks under stress? What risks are we introducing faster than the organization can absorb?</p>



<p>By 2026, a quiet strategic reversal is underway.</p>



<p>Across enterprises, technology leaders are no longer optimizing for maximum speed. They are optimizing for stability under continuous change. And that shift is redefining what strong CIO leadership looks like.</p>



<p>This is not a retreat from innovation. It is a maturation of judgment.</p>



<p>For years, enterprise technology was rewarded for how fast it moved. In 2026, it will be judged by how well it holds.</p>



<h2 class="wp-block-heading">Why speed stopped being enough</h2>



<p>Speed once solved a real problem.</p>



<p>Legacy architectures were brittle. Markets were compressing. Digital natives rewrote customer expectations while established enterprises struggled to respond. Accelerating delivery was not optional, it was existential.</p>



<p>But speed was never meant to be a permanent operating strategy.</p>



<p>What many organizations are now confronting is the accumulated cost of sustained urgency. In my own experience, the warning signs show up quietly: architectures that scale usage faster than governance, teams optimized for delivery but not durability, platforms launched before ownership is clear, and risks introduced faster than accountability can mature.</p>



<p>None of these failures looks dramatic in isolation. Together, they create instability.</p>



<p>Boards are increasingly aware of this pattern. They see that faster execution does not automatically translate into resilience. In fact, relentless acceleration often masks fragility until the moment pressure arrives.</p>



<p>That is when speed stops looking like progress and starts looking like exposure.</p>



<h2 class="wp-block-heading">Stability is becoming the new competitive advantage</h2>



<p>Stability is often misunderstood as conservatism. In practice, it is the opposite.</p>



<p>Stability is what allows organizations to change direction without breaking trust, budgets or balance sheets. It is what enables enterprises to absorb regulatory shifts, leadership transitions, market volatility and technological disruption without resetting the organization every eighteen months.</p>



<p>In 2026, the highest-performing enterprises share a common trait: they are not the fastest movers, but they are the most adaptable without chaos.</p>



<p>I see this in organizations where technology decisions survive executive turnover, where platforms tolerate partial failure without cascading outages, and where costs remain predictable even as capabilities expand. Stability does not slow innovation. It compounds it.</p>



<p>This broader emphasis on durability and adaptability as strategic capabilities is increasingly reflected in board-level discussions of operational resilience and enterprise continuity, including perspectives outlined by Deloitte on <a href="https://www.deloitte.com/us/en/insights/topics/leadership/building-organizational-resilience.html" rel="nofollow">how resilience has become a governance priority rather than a compliance exercise</a>.</p>



<p>Investors increasingly recognize this. Predictability now carries a premium, especially in regulated and capital-intensive industries. Analysts are less impressed by velocity alone and more interested in whether technology investments produce a durable advantage rather than episodic wins. Research from McKinsey reinforces this shift, noting that <a href="https://www.mckinsey.com/capabilities/operations/our-insights" rel="nofollow">sustained value creation increasingly comes from disciplined execution rather than isolated transformation bursts</a>.</p>



<p>Stability has quietly become strategic insurance.</p>



<h2 class="wp-block-heading">The CIO role is re-centering around judgment</h2>



<p>During the peak of digital acceleration, the CIO was often positioned as a catalyst, someone expected to remove friction and compress timelines. In many cases, that framing was necessary.</p>



<p>In 2026, the role is evolving again.</p>



<p>The modern CIO is becoming the enterprise’s custodian of stability, not as stasis, but as a design principle. This means deciding when not to modernize yet, sequencing initiatives so organizations can absorb change and designing systems that tolerate ambiguity rather than collapse under it.</p>



<p>Much of this work is invisible. It rarely appears on roadmaps or transformation dashboards. But boards notice it immediately when it is missing.</p>



<p>In my conversations with directors, the questions have shifted from feature delivery to structural integrity. They want to understand how decisions are sequenced, how risk is contained and how technology choices reinforce organizational coherence rather than erode it.</p>



<p>This is where CIO leadership becomes less about tools and more about judgment.</p>



<h2 class="wp-block-heading">Why are boards and investors leaning into stability?</h2>



<p>From a governance perspective, the board’s concern is no longer simply whether technology can deliver, but whether the enterprise can withstand the consequences if it does not.</p>



<p>Technology failures today are rarely isolated technical events. They trigger regulatory scrutiny, reputational damage, financial volatility and leadership credibility issues. Directors understand that the risk surface has expanded and that stability is the only sustainable counterweight.</p>



<p>This concern aligns with how systemic operational and technology fragility is now being discussed by global financial authorities such as the Bank for International Settlements, which has highlighted <a href="https://www.bis.org/topics/operational_resilience.htm" rel="nofollow">how weaknesses in operational resilience can amplify enterprise-wide risk</a>.</p>



<p>Investors see the same signals. In growth-stage and public companies alike, they increasingly assess whether technology platforms can scale without exponential cost, whether operating models are resilient to disruption and whether leadership teams demonstrate control rather than constant reaction. Commentary from BlackRock and other institutional investors has emphasized <a href="https://www.blackrock.com/corporate/insights" rel="nofollow">operational resilience and governance maturity as material factors in long-term valuation</a>.</p>



<p>Speed still matters. But speed without stability now raises questions rather than confidence.</p>



<h2 class="wp-block-heading">The hidden cost of perpetual acceleration</h2>



<p>One of the most overlooked consequences of speed-first cultures is decision debt.</p>



<p>When everything is urgent, tradeoffs go undocumented, exceptions become precedents and temporary workarounds harden into permanent dependencies. Over time, organizations lose the ability to explain why systems exist as they do.</p>



<p>I have seen this firsthand. When boards eventually ask, Why is this structured this way? Who owns this risk? What assumptions were made? The answers are often fragmented or incomplete. That is not a technology problem. It is a leadership problem.</p>



<p>This dynamic mirrors a broader body of research on <a href="https://en.wikipedia.org/wiki/Decision_quality" rel="nofollow">decision quality</a> and execution discipline, which shows that effective decision processes matter more than raw speed in complex environments.</p>



<p>Stability restores narrative clarity. It forces explicit decisions, documented intent and accountable ownership. It creates the conditions under which technology decisions can be explained, defended and evolved rather than constantly patched.</p>



<h2 class="wp-block-heading">What effective CIOs are doing differently in 2026</h2>



<p>The most effective CIOs are not announcing this shift publicly. They are embedding it quietly into how decisions are made.</p>



<p>Across industries, common patterns are emerging. Fewer “big bang” initiatives and more staged commitments. Architectural ownership established before platform expansion. Investment pacing aligned to organizational readiness rather than vendor timelines. Explicit tolerance thresholds for complexity, cost and risk.</p>



<p>These leaders are not slower. They are more deliberate.</p>



<p>They understand that credibility compounds faster than velocity. And in a climate where executive trust is fragile, credibility is the CIO’s most valuable currency.</p>



<h2 class="wp-block-heading">Founders face the same reckoning</h2>



<p>This shift is not limited to large enterprises.</p>



<p>Founders often associate stability with late-stage maturity. In 2026, that assumption is increasingly dangerous. Investors now scrutinize whether platforms can survive leadership transitions, whether systems scale without disproportionate cost, and whether governance exists beyond the founding team.</p>



<p>Speed still opens doors. Stability keeps them open.</p>



<p>Startups that cannot articulate a credible stability narrative find it harder to attract patient capital, especially in environments where regulatory, security and operational scrutiny is intensifying. Founders who embrace stability early do not lose agility, they gain legitimacy.</p>



<h2 class="wp-block-heading">The strategic reversal no one announced</h2>



<p>No memo declared this shift. No keynote celebrated it.</p>



<p>But it is unmistakable.</p>



<p>Enterprise technology leadership is moving from speed as identity to stability as advantage, from reaction to orchestration, from momentum to endurance. The CIO who thrives in 2026 will not be the loudest advocate for acceleration. They will be the quiet architect who ensures the enterprise can move again without losing its footing.</p>



<p>In a world that no longer waits, stability may be the most radical form of leadership left.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cache Deception Flaw in SvelteKit And Vercel Stack Exposes User Data]]></title>
<description><![CDATA[A cache deception vulnerability in SvelteKit apps deployed on Vercel exposes sensitive user data to attackers. The flaw allows publicly cached responses to be authenticated. SvelteKit, a full-stack JavaScript framework, often pairs with Vercel for deployment. The issue stems from…
Read more →
The...]]></description>
<link>https://tsecurity.de/de/3304038/it-security-nachrichten/cache-deception-flaw-in-sveltekit-and-vercel-stack-exposes-user-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3304038/it-security-nachrichten/cache-deception-flaw-in-sveltekit-and-vercel-stack-exposes-user-data/</guid>
<pubDate>Mon, 23 Feb 2026 03:19:44 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A cache deception vulnerability in SvelteKit apps deployed on Vercel exposes sensitive user data to attackers. The flaw allows publicly cached responses to be authenticated. SvelteKit, a full-stack JavaScript framework, often pairs with Vercel for deployment. The issue stems from…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/cache-deception-flaw-in-sveltekit-and-vercel-stack-exposes-user-data/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/cache-deception-flaw-in-sveltekit-and-vercel-stack-exposes-user-data/">Cache Deception Flaw in SvelteKit And Vercel Stack Exposes User Data</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hey, senior PMs: Shipping faster won’t get you promoted]]></title>
<description><![CDATA[It was 2022 and I was sitting in a quarterly business review feeling invincible.



I was the director of product for a SaaS platform scaling toward $25 million in annual recurring revenue (ARR). My team was a machine. Our Jira hygiene was impeccable. Our velocity was at an all-time high. We were...]]></description>
<link>https://tsecurity.de/de/3260947/it-security-nachrichten/hey-senior-pms-shipping-faster-wont-get-you-promoted/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3260947/it-security-nachrichten/hey-senior-pms-shipping-faster-wont-get-you-promoted/</guid>
<pubDate>Fri, 06 Feb 2026 13:05:58 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>It was 2022 and I was sitting in a quarterly business review feeling invincible.</p>



<p>I was the director of product for a SaaS platform scaling toward $25 million in annual recurring revenue (ARR). My team was a machine. Our Jira hygiene was impeccable. Our velocity was at an all-time high. We were shipping complex features every two weeks like clockwork.</p>



<p>I pulled up my slide deck, proudly displaying our burn-down chart. I walked the executive team through the velocity metrics, showing them exactly how many story points we had crushed in Q3. I sat back waiting for the applause.</p>



<p>Instead, the CFO looked at the slide, then at me and asked a single, quiet question: “Richard, that’s great that you shipped all that code. But looking at the cloud bill, our gross margins just dropped by 4%. Can you explain the margin impact of this release versus the revenue lift?”</p>



<p>Silence.</p>



<h2 class="wp-block-heading">It’s a trap</h2>



<p>I froze. I could tell him the latency of the API calls. I could tell him our net promoter score (NPS) to the decimal. But I couldn’t tell him if the feature made money. I had no idea that the architecture we chose was heavy on compute and I certainly hadn’t modeled the cost against the projected usage.</p>



<p>In that moment, I realized I had walked into what I call the Senior PM Trap. I was excellent at spending the company’s money (building software), but I had no idea how the company actually made money. As the product lead, that margin compression was ultimately my responsibility, yet I had treated it as someone else’s problem.</p>



<p>This is the predictable plateau in the career of almost every high-performing product manager. I see it constantly now: We master the craft of execution, agile, scrum and user research, but we fail to master the language of capital allocation. Until I made that shift, from shipping features to managing an investment portfolio, I was never going to break through to the executive level.</p>



<p>Here is how I learned to stop acting like a project manager and start acting like a product economist. By product economist, I don’t mean someone who builds spreadsheets all day. I mean a product leader who can translate technical decisions into financial outcomes that executives can actually act on.</p>



<h2 class="wp-block-heading">The crisis of context: When velocity hides margin erosion</h2>



<p>I was raised in what Melissa Perri famously calls the <a href="https://melissaperri.com/book" target="_blank" rel="nofollow">Escaping the Build Trap</a>. In these environments, I learned to measure success by output rather than outcome. The burn-down chart was my scoreboard. If my team shipped 20 story points, I told myself we had a good week.</p>



<p>This mindset worked for me when interest rates were zero and venture capital was infinite. It does not work today.</p>



<p>When my company hit that $25M ARR mark, the physics of our business changed. My CEO didn’t care about my backlog anymore; he cared about the P&amp;L. By focusing on velocity, I was optimizing for the wrong variable. I was running a feature factory that celebrated output even if that output was destroying our margins.</p>



<p>This is also where many CIOs get trapped. They inherit product teams optimized for delivery, not for financial outcomes. Velocity looks healthy, but margin quietly erodes. The question isn’t whether your PMs can ship. It’s whether they understand the economic consequences of what they ship.</p>



<p>To cross the chasm from senior PM to product leader, I had to stop showing my executives a roadmap of features and start showing them a model of returns. I had to learn the three metrics that matter.</p>



<h2 class="wp-block-heading">1. From user value to CAC payback</h2>



<p>Early in my career, my pitch for a new feature was always qualitative. I would stand in front of stakeholders and say: Users are complaining about the onboarding flow. It’s clunky. If we fix it, they will love us.</p>



<p>While true, this wasn’t a business case. User love didn’t appear on the balance sheet and my CFO didn’t sign off on vibes.</p>



<p>The shift happened when I finally walked over to the sales desk. I sat down with our VP of sales and asked a question I should have asked years earlier: How much does it actually cost us to get a customer?</p>



<p>We dug into the numbers to calculate our <a href="https://www.investopedia.com/terms/c/costofacquisition.asp" target="_blank" rel="nofollow">customer acquisition cost (CAC) payback period</a>. I was shocked to learn that it cost us roughly $15,000 in marketing and sales commissions to acquire a new enterprise customer. More importantly, it took us 14 months of their subscription payments just to break even on that cost.</p>



<p>Suddenly, the onboarding project wasn’t about UX friction anymore. It was about cash flow. If customers churned before month 14, we were literally losing money on them.</p>



<p>I went back to my desk and rewrote the pitch. Instead of talking about delight, I framed it like this: “This onboarding friction is causing a 15% drop-off in the first 30 days. By fixing this, we project a higher conversion rate that lowers our CAC payback period from 14 months to 9 months. That frees up cash flow to reinvest in Q4.”</p>



<p>The feature was approved instantly. The lesson hit me hard: Every feature is an arbitrage play. If I couldn’t quantify the efficiency gain, I was just guessing.</p>



<h2 class="wp-block-heading">2. From technical debt to COGS efficiency (the AI trap)</h2>



<p>Nowhere was my financial illiteracy more dangerous than in the current AI boom.</p>



<p>Earlier this year, I led a team that rushed to integrate a generative AI feature. We treated it like standard software: We built it, tested it for accuracy and shipped it. Users loved it. Engagement skyrocketed. I thought we had won.</p>



<p>Then the cloud bill arrived.</p>



<p>I hadn’t modeled the unit economics. I failed to realize that every query triggered a chain of vector database lookups, massive compute spikes for inference and API tokens that cost us roughly $0.08 per interaction.</p>



<p>In the traditional SaaS model I was used to, costs are relatively fixed. You pay for the server capacity and whether 100 or 1,000 users log in, your cost doesn’t fluctuate wildly. But with large language models (LLMs), I had introduced variable costs that scaled linearly with usage.</p>



<p>As we scaled, we weren’t just paying for tokens; we were paying for raw compute power. A power user who loved the product was no longer our best customer; they were our biggest expense. I was effectively paying them to bankrupt us.</p>



<p>This forced me to learn the concept of cost of goods sold (COGS). As Bessemer Venture Partners noted in their State of the Cloud report, this is an industry-wide crisis: <a href="https://www.bvp.com/atlas/state-of-the-cloud-2024" rel="nofollow">AI startups are operating with gross margins as low as 25%, compared to the 80%+ standard for traditional SaaS</a>.</p>



<p>I modeled our own cost curve and realized something uncomfortable: at $0.08 per query, usage growth didn’t improve margins; it destroyed them. Without intervention, our most engaged users would become loss leaders.</p>



<p>Whenever I audit product roadmaps today, this is the first red flag I look for: Are you pricing for software (fixed cost) while building for AI (variable cost)? If you don’t cap those costs via model optimization or caching, your gross margins will collapse.</p>



<p>I had to pivot the roadmap immediately. We shifted engineering effort to model optimization, driving the cost down to under $0.01 per query. A senior PM would have kept shipping features; a product leader fixed the economics.</p>



<h2 class="wp-block-heading">3. From roadmap to CapEx vs. OpEx</h2>



<p>The final ceiling I had to break was understanding capital allocation.</p>



<p>For years, I viewed my engineering team as a resource to be utilized. I fought for more headcount constantly, believing that more bodies meant more features. But an executive views an engineering team as an investment portfolio. We are spending millions of dollars a year on salaries. The question isn’t: “Are they busy?” The question is: “What is the return on that capital?”</p>



<p>I started auditing my own roadmap using the framework of CapEx versus OpEx.</p>



<ul class="wp-block-list">
<li>CapEx (capital expenditure = growth): Building new assets that will generate new revenue (e.g., a new product line).</li>



<li>OpEx (operating expense = maintenance): The tax we pay to keep the lights on (bug fixes, compliance, keeping servers running).</li>
</ul>



<p>Why does this matter? Because OpEx hits the P&amp;L immediately, reducing earnings before interest, taxes, depreciation and amortization. CapEx, however, is an asset that can be depreciated over time.</p>



<p>When I mapped our roadmap against capital allocation, the imbalance was obvious. Nearly 80% of engineering spend was technically OpEx — we were maintaining existing revenue, not creating new assets. We were treading water, but expensive water.</p>



<p>I walked into the next planning meeting with a different proposal: “We are currently spending 80% of our budget on maintenance. That is a bad investment strategy. I am proposing we freeze non-critical bugs for one quarter to shift our allocation to 60% growth with 40% maintenance.”</p>



<p>This was language the C-suite respected. It treated the engineering team not as coders but as capital. It shifted the conversation from “Why is this feature late?” to “Are we allocating capital to the right bets?”</p>



<h2 class="wp-block-heading">Why financial fluency is the new product leadership edge</h2>



<p>The era of the technical PM is ending. In a world where AI can generate code, tickets and even roadmaps, execution is no longer scarce. Economic judgment is.</p>



<p>The product leaders who advance won’t be the ones who ship faster. They’ll be the ones who can sit with a CFO, read a P&amp;L and explain why a roadmap improves margin, not just morale.</p>



<p>If you’re stuck at senior, don’t ask for more features to build. Ask for access to the financials. Learn how your product actually makes money. That’s the moment you stop being a cost center and start becoming an executive.</p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.<br><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Startups Raise Record $150B in 2025, Redefining Venture Capital]]></title>
<description><![CDATA[The AI funding boom just rewrote the record books. In 2025, startups raised roughly $150 billion, setting a new high for venture capital investment. Data released on Dec. 28 confirms this marks the third consecutive year of record growth, surpassing the 2021 peak by $92 billion and representing a...]]></description>
<link>https://tsecurity.de/de/3190970/it-nachrichten/ai-startups-raise-record-150b-in-2025-redefining-venture-capital/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3190970/it-nachrichten/ai-startups-raise-record-150b-in-2025-redefining-venture-capital/</guid>
<pubDate>Fri, 02 Jan 2026 16:02:14 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The AI funding boom just rewrote the record books. In 2025, startups raised roughly $150 billion, setting a new high for venture capital investment. Data released on Dec. 28 confirms this marks the third consecutive year of record growth, surpassing the 2021 peak by $92 billion and representing a 63% increase over an already historic […]</p>
<p>The post <a href="https://www.eweek.com/news/ai-startups-raise-record-150b-in-2025/">AI Startups Raise Record $150B in 2025, Redefining Venture Capital</a> appeared first on <a href="https://www.eweek.com/">eWEEK</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Uber rewrites contracts with drivers to avoid paying UK’s new ‘taxi tax’]]></title>
<description><![CDATA[Hailing app will now act as agent rather than supplier outside London, avoiding VAT requirement, although change is not permitted in LondonUber has swerved paying millions of pounds to the UK exchequer under Rachel Reeves’s new “taxi tax” after the ride-hailing app rewrote contracts with its driv...]]></description>
<link>https://tsecurity.de/de/3190833/it-nachrichten/uber-rewrites-contracts-with-drivers-to-avoid-paying-uks-new-taxi-tax/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3190833/it-nachrichten/uber-rewrites-contracts-with-drivers-to-avoid-paying-uks-new-taxi-tax/</guid>
<pubDate>Fri, 02 Jan 2026 14:31:56 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hailing app will now act as agent rather than supplier outside London, avoiding VAT requirement, although change is not permitted in London</p><p>Uber has swerved paying millions of pounds to the UK exchequer under Rachel Reeves’s new “taxi tax” after the ride-hailing app rewrote contracts with its drivers.</p><p>The move came as rules announced in November’s budget took effect, which adjusted how VAT is payable on minicab fares and would have resulted in the whole Uber fare becoming subject to the 20% sales tax.</p> <a href="https://www.theguardian.com/technology/2026/jan/02/uber-avoids-new-uk-taxi-tax-rewriting-driver-contracts">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Test for React2Shell with Application Security using New Functionality]]></title>
<description><![CDATA[Following disclosure of the React2Shell vulnerability (CVE-2025-55182), a maximum-severity Remote Code Execution (RCE) in React Server Components (RSC) a.k.a. the Flight protocol, security teams are assessing exposure and validating fixes. React and ecosystem vendors have released patches; exploi...]]></description>
<link>https://tsecurity.de/de/3165552/it-security-nachrichten/test-for-react2shell-with-application-security-using-new-functionality/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3165552/it-security-nachrichten/test-for-react2shell-with-application-security-using-new-functionality/</guid>
<pubDate>Wed, 17 Dec 2025 20:51:05 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>Following disclosure of the React2Shell vulnerability (CVE-2025-55182), a maximum-severity Remote Code Execution (RCE) in React Server Components (RSC) a.k.a. the Flight protocol, security teams are assessing exposure and validating fixes. React and ecosystem vendors have released patches; exploitation in the wild has been reported, so rapid validation matters.</span></p><h2><span>What is React2Shell? </span></h2><p><span>React2Shell is an unauthenticated RCE flaw caused by insecure Flight payload deserialization in server-side React/RSC implementations (including popular frameworks like Next.js). It carries a CVSS 10.0 rating and affects React versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 as well as Next.js versions 15.0.0-15.1.6 and 16.0.0-16.0.6 prior to recent patches. You can read more about it </span><a href="https://www.rapid7.com/blog/post/etr-react2shell-cve-2025-55182-critical-unauthenticated-rce-affecting-react-server-components/"><span>in this detailed CVE overview blog post</span></a><span>.  </span></p><p><span>In this detailed writeup, we will share how our customers can specifically test for React2Shell with Rapid7’s Application Security solution.</span></p><h2>Testing for React2Shell with application security</h2><p><span>With our </span><a href="https://www.rapid7.com/fundamentals/dast/"><span>dynamic application security testing (DAST)</span></a><span> solution, customers can assess the risk of their applications. Rapid7 allows you to configure various attacks of your applications to identify response behaviors that make your applications more vulnerable to attacks. These attacks are run during scans that you can customize based on your needs. In this case, we’ve extended our RCE attack module to include a check for React2Shell.</span></p><p><span><strong>What does this mean?</strong></span><span> Customers can now run an Attack Injection using the RCE, which includes an attack type for React2Shell. Our React2Shell vulnerability detection will simulate an attacker on your website. This is a benign attack which will not execute any code and only shows that RCE is possible. Rapid7 will validate the exploitability of the application and the associated risk. </span></p><h2>How to run a React2Shell attack in the Rapid7 DAST</h2><p><span>You can scan for this new RCE attack using either the new Arbitrary Code Execution attack template we have created or by creating your own custom attack template and selecting the RCE module. We have added some steps for you to follow below:</span></p><h3>Default attack template option:</h3><p><span>Choose the Arbitrary Code Execution attack template in your scan configuration: </span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc17449b712a131df/6942ffb3414d965bbf8d6b14/1-arbitrary-code-execution-attack-template.png" alt="1-arbitrary-code-execution-attack-template.png" caption="Default Arbitrary Code Execution attack template with RCE attack module" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="1-arbitrary-code-execution-attack-template.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc17449b712a131df/6942ffb3414d965bbf8d6b14/1-arbitrary-code-execution-attack-template.png" data-sys-asset-uid="bltc17449b712a131df" data-sys-asset-filename="1-arbitrary-code-execution-attack-template.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Default Arbitrary Code Execution attack template with RCE attack module" data-sys-asset-alt="1-arbitrary-code-execution-attack-template.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Default Arbitrary Code Execution attack template with RCE attack module</figcaption></div></figure><h3>Custom attack template option:</h3><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc60bddd835494542/6942ffb31b4aca40032d06ce/2-Custom-Attack-Template-RCE-module.png" alt="2-Custom-Attack-Template-RCE-module.png" caption="Custom Attack Template with RCE module" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="2-Custom-Attack-Template-RCE-module.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc60bddd835494542/6942ffb31b4aca40032d06ce/2-Custom-Attack-Template-RCE-module.png" data-sys-asset-uid="bltc60bddd835494542" data-sys-asset-filename="2-Custom-Attack-Template-RCE-module.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Custom Attack Template with RCE module" data-sys-asset-alt="2-Custom-Attack-Template-RCE-module.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Custom Attack Template with RCE module</figcaption></div></figure><h3>Run a scan</h3><p><span>Choosing the scan configuration you made earlier, scan against your selected app(s).</span></p><h3>Scan results - React2Shell RCE finding</h3><p><span>Now that you have run your scan, you can review the results to see if your app(s) have any findings. These will include remediation advice that you can follow.</span></p><p>⠀</p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf9d990bb4800dd06/6942ffb31c8295d10b52b332/3-Scan-results-React2Shell-RCE-finding.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="3-Scan-results-React2Shell-RCE-finding.png" asset-alt="3-Scan-results-React2Shell-RCE-finding.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf9d990bb4800dd06/6942ffb31c8295d10b52b332/3-Scan-results-React2Shell-RCE-finding.png" data-sys-asset-uid="bltf9d990bb4800dd06" data-sys-asset-filename="3-Scan-results-React2Shell-RCE-finding.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="3-Scan-results-React2Shell-RCE-finding.png" sys-style-type="display"></figure><h3>Manage attack templates</h3><p><span>You can now manage your attack templates by navigating to the appropriate section and selecting the Arbitrary Code Execution attack template as below. </span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt2d18f50fd593d399/6942ffb31f4bd52c8b935294/4-manage-attack-templates-rapid7.png" alt="4-manage-attack-templates-rapid7.png" caption="Manage attack templates" height="855" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="4-manage-attack-templates-rapid7.png" width="768" max-width="768" max-height="855" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt2d18f50fd593d399/6942ffb31f4bd52c8b935294/4-manage-attack-templates-rapid7.png" data-sys-asset-uid="blt2d18f50fd593d399" data-sys-asset-filename="4-manage-attack-templates-rapid7.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Manage attack templates" data-sys-asset-alt="4-manage-attack-templates-rapid7.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Manage attack templates</figcaption></div></figure><h2>What’s next?</h2><p><span>Patch immediately, upgrade React to 19.0.1, 19.1.2, or 19.2.1 (or newer). For Next.js, the recommended action is to update to the following respective patched versions: 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7, or later*. You should seek to remediate this vulnerability on an urgent basis, outside of normal patch cycles and consider temporary web application firewall (WAF) rules for Flight endpoints while patching. If you’re looking to validate any fixes you have implemented, feel free to run a validation scan with our application security tool to verify the fixes are correct.</span></p><p><span><em>* For Next.js, the recommendation from Nextjs is to update to the following respective patched versions: 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7, or later. However, we have identified that versions 15.0.5 and 15.1.9 have a </em></span><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29927" target="_blank"><span><em>different critical vulnerability</em></span></a><span><em> and would recommend against using them.</em></span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Chrome is Going Agentic - Threat Wire]]></title>
<description><![CDATA[Author: Hak5 - Bewertung: 45x - Views:279 SUBMIT YOUR TOP 10 CYBERSECURITY STORIES OF 2025 HERE; https://form.typeform.com/to/jCgAub8V

⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️


@endingwithali →
Twitch: https://twitch.tv/endingwithali
Twitter: https://twitter.com/endingwithali
YouTube: htt...]]></description>
<link>https://tsecurity.de/de/3160184/it-security-video/google-chrome-is-going-agentic-threat-wire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3160184/it-security-video/google-chrome-is-going-agentic-threat-wire/</guid>
<pubDate>Mon, 15 Dec 2025 16:02:03 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Hak5 - Bewertung: 45x - Views:279 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/67_T5Lzjfgs?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>SUBMIT YOUR TOP 10 CYBERSECURITY STORIES OF 2025 HERE; https://form.typeform.com/to/jCgAub8V<br />
<br />
⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️<br />
<br />
<br />
@endingwithali →<br />
Twitch: https://twitch.tv/endingwithali<br />
Twitter: https://twitter.com/endingwithali<br />
YouTube: https://youtube.com/@endingwithali<br />
Everywhere else: https://links.ali.dev<br />
<br />
Want to work with Ali? endingwithalicollabs@gmail.com<br />
<br />
[❗] Join the Patreon→ https://patreon.com/threatwire<br />
00:00  0 - Intro<br />
00:10 1 - The React RCE<br />
04:11 2 - Chrome Attempts to Mitigate AI Browsing Security Issues<br />
06:38 3 - Flash News<br />
07:31 4 - India Government Demands and Retracts Surveillance<br />
09:01 5 - Outro<br />
<br />
LINKS<br />
🔗 Story 1: The React RCE<br />
https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components<br />
https://react2shell.com/<br />
https://www.cve.org/CVERecord?id=CVE-2025-55182<br />
https://x.com/maple3142/status/1996687157789155647<br />
https://infosec.exchange/@shadowserver/115672050969855947<br />
https://www.bleepingcomputer.com/news/security/react2shell-flaw-exploited-to-breach-30-orgs-77k-ip-addresses-vulnerable/<br />
https://nvd.nist.gov/vuln/detail/CVE-2025-66478<br />
https://www.wiz.io/blog/nextjs-cve-2025-55182-react2shell-deep-dive<br />
https://www.wiz.io/blog/critical-vulnerability-in-react-cve-2025-55182<br />
https://www.bleepingcomputer.com/news/security/react2shell-flaw-exploited-to-breach-30-orgs-77k-ip-addresses-vulnerable/<br />
🔗 Story 2: Chrome Attempts to Mitigate AI Browsing Security Issues<br />
https://www.bleepingcomputer.com/news/security/google-chrome-adds-new-security-layer-for-gemini-ai-agentic-browsing/<br />
https://blog.google/products/chrome/new-ai-features-for-chrome/<br />
https://neuraltrust.ai/blog/openai-atlas-omnibox-prompt-injection<br />
https://security.googleblog.com/2025/12/architecting-security-for-agentic.html <br />
🔗 Story 3: Flash News<br />
https://www.bleepingcomputer.com/news/security/french-diy-retail-giant-leroy-merlin-discloses-a-data-breach/<br />
https://techcrunch.com/2025/12/03/fintech-firm-marquis-alerts-dozens-of-us-banks-and-credit-unions-of-a-data-breach-after-ransomware-attack/<br />
https://www.pcmag.com/news/petco-data-breach-exposes-customer-data-including-ssns-credit-card-info<br />
https://botcrawl.com/lockbit-5-0-ransomware-lists-21-victims-on-dark-web/<br />
https://www.bleepingcomputer.com/news/security/eu-fines-x-140-million-over-deceptive-blue-checkmarks-transparency-violations/<br />
🔗 Story 4: India Government Demands and Retracts Surveillance<br />
https://appleinsider.com/articles/25/12/01/india-demands-apple-preinstall-government-security-app-onto-iphones<br />
https://appleinsider.com/articles/25/12/03/india-blinks-wont-require-apple-to-preinstall-a-state-app-on-iphone<br />
https://www.reuters.com/sustainability/boards-policy-regulation/india-orders-mobile-phones-preloaded-with-government-app-ensure-cyber-safety-2025-12-01/<br />
-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆<br />
Our Site → https://www.hak5.org<br />
Shop →  http://hakshop.myshopify.com/<br />
Community → https://www.hak5.org/community<br />
Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1<br />
Support → https://www.patreon.com/threatwire<br />
Contact Us → http://www.twitter.com/hak5<br />
____________________________________________<br />
<br />
Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[He wrote the world’s most successful video games – now what? Rockstar co-founder Dan Houser on life after Grand Theft Auto]]></title>
<description><![CDATA[He rewrote the rule book with Rockstar then left it all behind. Now Dan Houser is back with a storytelling-focused studio to take on AI-obsessed tech bros and Mexican beauty queensThere are only a handful of video game makers who have had as profound an effect on the industry as Dan Houser. The c...]]></description>
<link>https://tsecurity.de/de/3159845/it-nachrichten/he-wrote-the-worlds-most-successful-video-games-now-what-rockstar-co-founder-dan-houser-on-life-after-grand-theft-auto/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3159845/it-nachrichten/he-wrote-the-worlds-most-successful-video-games-now-what-rockstar-co-founder-dan-houser-on-life-after-grand-theft-auto/</guid>
<pubDate>Mon, 15 Dec 2025 13:46:46 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>He rewrote the rule book with Rockstar then left it all behind. Now Dan Houser is back with a storytelling-focused studio to take on AI-obsessed tech bros and Mexican beauty queens</p><p>There are only a handful of video game makers who have had as profound an effect on the industry as Dan Houser. The co-founder of Rockstar Games, and its lead writer, worked on all the GTA titles since the groundbreaking third instalment, as well as both Red Dead Redemption adventures. But then, in 2019, he took an extended break from the company which ended with his official departure. Now he’s back with a new studio and a range of projects, and <a href="https://www.theguardian.com/technology/gamesblog/2013/sep/13/grand-theft-auto-5-dan-houser">12 years after we last interviewed him</a>, he’s ready to talk about what comes next.</p><p>“Finishing those big projects and thinking about doing another one is really intense,” he says about his decision to go. “I’d been in full production mode every single day from the very start of each project to the very end, for 20 years. I stayed so long because I loved the games. It was a real privilege to be there, but it was probably the right time to leave. I turned 45 just after Red Dead 2 came out. I thought, well, it’s probably a good time to try working on some other stuff.”</p> <a href="https://www.theguardian.com/games/2025/dec/15/dan-houser-grand-theft-auto-rockstar">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-67716 | auth0 nextjs-auth0 up to 4.12.x returnTo incomplete blacklist (GHSA-mr6f-h57v-rpj5 / CNNVD-202512-2251)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in auth0 nextjs-auth0 up to 4.12.x. This affects an unknown function. Performing manipulation of the argument returnTo results in incomplete blacklist.

This vulnerability is known as CVE-2025-67716. Remote exploitation of the atta...]]></description>
<link>https://tsecurity.de/de/3155647/sicherheitsluecken/cve-2025-67716-auth0-nextjs-auth0-up-to-412x-returnto-incomplete-blacklist-ghsa-mr6f-h57v-rpj5-cnnvd-202512-2251/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3155647/sicherheitsluecken/cve-2025-67716-auth0-nextjs-auth0-up-to-412x-returnto-incomplete-blacklist-ghsa-mr6f-h57v-rpj5-cnnvd-202512-2251/</guid>
<pubDate>Fri, 12 Dec 2025 16:16:44 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, has been found in <a href="https://vuldb.com/?product.auth0:nextjs-auth0">auth0 nextjs-auth0 up to 4.12.x</a>. This affects an unknown function. Performing manipulation of the argument <em>returnTo</em> results in incomplete blacklist.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.335806">CVE-2025-67716</a>. Remote exploitation of the attack is possible. No exploit is available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[React2Shell (CVE-2025-55182) - Critical unauthenticated RCE affecting React Server Components]]></title>
<description><![CDATA[OverviewOn December 3, 2025, Meta disclosed a new vulnerability, CVE-2025-55182, which has since been dubbed React2Shell. A second CVE identifier, CVE-2025-66478, was assigned and published to track the vulnerability in the context of Next.js. However this second CVE has since been rejected as a ...]]></description>
<link>https://tsecurity.de/de/3139025/it-security-nachrichten/react2shell-cve-2025-55182-critical-unauthenticated-rce-affecting-react-server-components/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3139025/it-security-nachrichten/react2shell-cve-2025-55182-critical-unauthenticated-rce-affecting-react-server-components/</guid>
<pubDate>Thu, 04 Dec 2025 17:21:22 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Overview</h2><p><span>On December 3, 2025, Meta </span><a href="https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components"><span>disclosed</span></a><span> a new vulnerability, </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-55182"><span>CVE-2025-55182</span></a><span>, which has since been dubbed React2Shell. A second CVE identifier, </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-66478"><span>CVE-2025-66478</span></a><span>, was assigned and published to track the vulnerability in the context of </span><a href="http://next.js/"><span>Next.js</span></a><span>. However this second CVE has since been rejected as a duplicate of CVE-2025-55182, as the root cause in all cases is the same and should be referred to with a single common CVE identifier.</span></p><p></p><p><span>CVE-2025-55182 is a critical unauthenticated remote code execution vulnerability affecting </span><a href="https://react.dev/"><span>React</span></a><span>, a very popular library for building modern web applications. This new vulnerability has a CVSS rating of </span><a href="https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"><span>10.0</span></a><span>, which is the maximum rating possible and indicates the highly critical nature of the issue. Successful exploitation of CVE-2025-55182 allows a remote unauthenticated attacker to execute arbitrary code on an affected server via malicious HTTP requests.</span></p><p></p><p><span>The vulnerability affects React applications that support React </span><a href="https://react.dev/reference/rsc/server-components"><span>Server Components</span></a><span>. While the vulnerability affects the React Server Components feature, server applications may still be vulnerable even if the application does not explicitly implement any React Server Function endpoints but does support React Server Components. Additionally many popular frameworks based on React, such as Next.js, are also affected by this vulnerability.</span></p><p></p><p><span>A </span><a href="https://nextjs.org/blog/CVE-2025-66478"><span>separate advisory</span></a><span> was published by Vercel, the vendor for Next.js. This advisory tracks the impact of CVE-2025-55182 as it applies to the Next.js framework, and provides information for Next.js users to remediate the issue. </span></p><p></p><p><span>As of December 4, 2025, there is no known public exploit code available at this time. Several exploits have been published claiming to exploit CVE-2025-55182, however they have not been successfully verified as actually exploiting this vulnerability. This has been noted in the original finders website, </span><a href="https://react2shell.com/"><span>react2shell.com</span></a><span>. Therefore, broad exploitation has not yet begun, however once a viable public exploit becomes available we expect this to change.</span></p><p></p><p><span>Organizations who use React, or the affected downstream frameworks, are urged to remediate this vulnerability on an urgent basis, outside of normal patch cycles and before broad exploitation begins.</span></p><h2>Mitigation guidance</h2><p><span>CVE-2025-55182 affects versions 19.0, 19.1.0, 19.1.1, and 19.2.0 of the following React packages:</span></p><p></p><ul><li><p><a href="https://www.npmjs.com/package/react-server-dom-webpack"><span>react-server-dom-webpack</span></a></p></li><li><p><a href="https://www.npmjs.com/package/react-server-dom-parcel"><span>react-server-dom-parcel</span></a></p></li><li><p><a href="https://www.npmjs.com/package/react-server-dom-turbopack?activeTab=readme"><span>react-server-dom-turbopack</span></a></p></li></ul><p></p><p><span>A vendor supplied update for the above packages is available in versions 19.0.1, 19.1.2, and 19.2.1. Users of affected React packages are advised to update the latest remediated version on an urgent basis.</span></p><p></p><p><span>Downstream frameworks that depend on React are also affected, this includes (but is not limited to):</span></p><ul><li><p><a href="https://www.npmjs.com/package/next"><span>Next.js</span></a></p></li><li><p><a href="https://www.npmjs.com/package/react-router"><span>React Router</span></a></p></li><li><p><a href="https://www.npmjs.com/package/waku"><span>Waku</span></a></p></li><li><p><a href="https://www.npmjs.com/package/@parcel/rsc"><span>Parcel</span></a></p></li><li><p><a href="https://www.npmjs.com/package/@vitejs/plugin-rsc"><span>Vite</span></a></p></li><li><p><a href="https://www.npmjs.com/package/rwsdk"><span>RedwoodSDK</span></a></p></li></ul><p></p><p><span>For the latest mitigation guidance for React, please refer to the </span><a href="https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components"><span>React security advisory</span></a><span>. For the latest mitigation guidance specific to Next.js, please refer to the </span><a href="https://nextjs.org/blog/CVE-2025-66478"><span>Vercel security advisory</span></a><span>.</span></p><h2>Rapid7 customers</h2><h3><span>Exposure Command, InsightVM and Nexpose</span></h3><p><span>Exposure Command, InsightVM and Nexpose customers can assess exposure to CVE-2025-55812 with an unauthenticated check expected to be available in today's (December 4) content release. Note that the "Potential" check type must be enabled before running the scan to successfully assess for the vulnerability.</span></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[React2Shell – Critical Bug Exposes React Server Components to Unauthenticated Remote Code Execution]]></title>
<description><![CDATA[React2Shell – Critical Bug Exposes React Server Components to Unauthenticated Remote Code Execution
				
				
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				
				 Post Views: 49
			
			
				
				
				
				
				



			
			
				
				
				
				
			
				
				
...]]></description>
<link>https://tsecurity.de/de/3138107/it-security-nachrichten/react2shell-critical-bug-exposes-react-server-components-to-unauthenticated-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3138107/it-security-nachrichten/react2shell-critical-bug-exposes-react-server-components-to-unauthenticated-remote-code-execution/</guid>
<pubDate>Thu, 04 Dec 2025 11:35:30 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_specialty">
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_0   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_0 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_post_title et_pb_post_title_0 et_pb_bg_layout_light  et_pb_text_align_left">
				
				
				
				
				
				<div class="et_pb_title_container">
					<h1 class="entry-title">React2Shell – Critical Bug Exposes React Server Components to Unauthenticated Remote Code Execution</h1>
				</div>
				
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_1 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><div class="post-views content-post post-286774 entry-meta load-static">
				<span class="post-views-icon dashicons dashicons-chart-bar"></span> <span class="post-views-label">Post Views:</span> <span class="post-views-count">49</span>
			</div></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_2 patreon-row">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_2 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h3 class="premium-content">Join our <a class="green_color" href="https://www.patreon.com/posts/maximizing-your-87671900" target="_blank" rel="noopener sponsored">Patreon</a> Channel and Gain access to 70+ Exclusive Walkthrough Videos.</h3></div>
			</div><div class="et_pb_module et_pb_image et_pb_image_0">
				
				
				
				
				<a href="https://www.patreon.com/posts/create-evasive-111421720" target="_blank"><span class="et_pb_image_wrap "><img fetchpriority="high" decoding="async" width="800" height="120" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png" alt="Patreon" title="Patreon" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw" class="wp-image-282931"></span></a>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_0 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_3 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Reading Time: 3 Minutes</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_4">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_4 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p data-start="259" data-end="640">A <strong data-start="261" data-end="305">critical, maximum-severity vulnerability</strong> has been disclosed in <strong data-start="328" data-end="361">React Server Components (RSC)</strong> that enables <strong data-start="375" data-end="422">unauthenticated remote code execution (RCE)</strong> on exposed servers. Tracked as <strong data-start="454" data-end="472">CVE-2025-55182</strong> and nicknamed <strong data-start="487" data-end="502">React2Shell</strong>, the bug carries a <strong data-start="522" data-end="544">CVSS score of 10.0</strong>, reflecting its ease of exploitation and widespread impact across modern JavaScript frameworks.</p>
<p data-start="642" data-end="1000">According to the <a href="https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components" target="_blank" rel="noopener">React Team</a>, the flaw originates from <strong data-start="696" data-end="766">how React decodes payloads sent to React Server Function endpoints</strong>, allowing arbitrary JavaScript to execute on the backend. Crucially, <strong data-start="836" data-end="931">applications may be vulnerable even if they do not explicitly use Server Function endpoints</strong> — <em data-start="934" data-end="999">simply enabling React Server Components is enough to be exposed</em>.</p>
<hr data-start="1002" data-end="1005">
<h2 data-start="1007" data-end="1073"><strong data-start="1010" data-end="1073">Root Cause: Unsafe Deserialization in React Flight Protocol</strong></h2>
<p data-start="1075" data-end="1371">Cloud security firm <a href="https://www.wiz.io/blog/critical-vulnerability-in-react-cve-2025-55182" target="_blank" rel="noopener">Wiz</a> attributes the issue to <strong data-start="1123" data-end="1161">logical deserialization weaknesses</strong> in the <strong data-start="1169" data-end="1194">React Flight protocol</strong>, which processes RSC payloads. Attackers can send malicious payloads that React wrongly interprets as trusted structures, triggering direct execution of attacker-supplied code.</p>
<p data-start="1373" data-end="1627">Aikido Security further <a href="https://www.aikido.dev/blog/react-nextjs-cve-2025-55182-rce" target="_blank" rel="noopener">described</a> it as a case where <strong data-start="1426" data-end="1521">“malformed or adversarial payloads can influence server-side execution in unintended ways,”</strong> prompting the React team to harden deserialization and add strict payload validation in patched versions.</p>
<hr data-start="1629" data-end="1632">
<h2 data-start="1634" data-end="1671"><strong data-start="1637" data-end="1671">Affected Packages and Versions</strong></h2>
<p data-start="1673" data-end="1746">The flaw affects React RSC implementations in the following npm packages:</p>
<ul>
<li data-start="1750" data-end="1780"><strong data-start="1750" data-end="1778">react-server-dom-webpack</strong></li>
<li data-start="1783" data-end="1812"><strong data-start="1783" data-end="1810">react-server-dom-parcel</strong></li>
<li data-start="1815" data-end="1845"><strong data-start="1815" data-end="1845">react-server-dom-turbopack</strong></li>
</ul>
<h3 data-start="1847" data-end="1874"><strong data-start="1851" data-end="1874">Vulnerable Versions</strong></h3>
<ul>
<li data-start="1877" data-end="1885"><strong data-start="1877" data-end="1885">19.0</strong></li>
<li data-start="1888" data-end="1898"><strong data-start="1888" data-end="1898">19.1.0</strong></li>
<li data-start="1901" data-end="1911"><strong data-start="1901" data-end="1911">19.1.1</strong></li>
<li data-start="1914" data-end="1924"><strong data-start="1914" data-end="1924">19.2.0</strong></li>
</ul>
<h3 data-start="1926" data-end="1950"><strong data-start="1930" data-end="1950">Patched Versions</strong></h3>
<ul>
<li data-start="1953" data-end="1963"><strong data-start="1953" data-end="1963">19.0.1</strong></li>
<li data-start="1966" data-end="1976"><strong data-start="1966" data-end="1976">19.1.2</strong></li>
<li data-start="1979" data-end="1989"><strong data-start="1979" data-end="1989">19.2.1</strong></li>
</ul>
<p data-start="1991" data-end="2126">The vulnerability was discovered by security researcher <a href="https://lachlan.nz/about" target="_blank" rel="noopener"><strong data-start="2047" data-end="2067">Lachlan Davidson</strong></a> and responsibly reported to Meta on <strong data-start="2104" data-end="2125">November 29, 2025</strong>.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_5 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><strong>See Also: So, you want to be a hacker?<br>
</strong><strong><a href="https://www.blackhatethicalhacking.com/courses/" target="_blank" rel="noopener noreferrer">Offensive Security, Bug Bounty Courses</a></strong></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_6  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h4><span><strong>Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.</strong></span></h4>
<p><a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" class="alignnone wp-image-276050 size-full" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png" alt="" width="800" height="120" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw"></a></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_8  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 data-start="2133" data-end="2190"><strong data-start="2136" data-end="2190">Next.js Also Impacted (CVE-2025-66478 — CVSS 10.0)</strong></h2>
<p data-start="2192" data-end="2319">Next.js, which widely incorporates React Server Components through its <strong data-start="2263" data-end="2277">App Router</strong>, is affected under a separate identifier:</p>
<h3 data-start="2321" data-end="2354"><strong data-start="2325" data-end="2354">Impacted Next.js Versions</strong></h3>
<ul>
<li data-start="2357" data-end="2379"><strong data-start="2357" data-end="2379">&gt;=14.3.0-canary.77</strong></li>
<li data-start="2382" data-end="2390"><strong data-start="2382" data-end="2390">&gt;=15</strong></li>
<li data-start="2393" data-end="2401"><strong data-start="2393" data-end="2401">&gt;=16</strong></li>
</ul>
<h3 data-start="2403" data-end="2427"><strong data-start="2407" data-end="2427">Patched Versions</strong></h3>
<ul>
<li data-start="2430" data-end="2440"><strong data-start="2430" data-end="2440">16.0.7</strong></li>
<li data-start="2443" data-end="2453"><strong data-start="2443" data-end="2453">15.5.7</strong></li>
<li data-start="2456" data-end="2466"><strong data-start="2456" data-end="2466">15.4.8</strong></li>
<li data-start="2469" data-end="2479"><strong data-start="2469" data-end="2479">15.3.6</strong></li>
<li data-start="2482" data-end="2492"><strong data-start="2482" data-end="2492">15.2.6</strong></li>
<li data-start="2495" data-end="2505"><strong data-start="2495" data-end="2505">15.1.9</strong></li>
<li data-start="2508" data-end="2518"><strong data-start="2508" data-end="2518">15.0.5</strong></li>
</ul>
<p data-start="2520" data-end="2626">Security firms warn that <strong data-start="2545" data-end="2614">any library bundling React Server Components is likely vulnerable</strong>, including:</p>
<ul>
<li data-start="2630" data-end="2647">Vite RSC plugin</li>
<li data-start="2650" data-end="2669">Parcel RSC plugin</li>
<li data-start="2672" data-end="2698">React Router RSC preview</li>
<li data-start="2701" data-end="2712">RedwoodJS</li>
<li data-start="2715" data-end="2721">Waku</li>
</ul>
<hr data-start="2723" data-end="2726">
<h2 data-start="2728" data-end="2796"><strong data-start="2731" data-end="2796">Exploitation: No Login, No Special Conditions, HTTP is Enough</strong></h2>
<p data-start="2798" data-end="2851">Endor Labs, VulnCheck, and Miggo Security emphasized:</p>
<ul>
<li data-start="2855" data-end="2890"><strong data-start="2855" data-end="2888">No authentication is required</strong></li>
<li data-start="2893" data-end="2954"><strong data-start="2893" data-end="2952">Any exposed Server Function endpoint is a viable target</strong></li>
<li data-start="2957" data-end="2995"><strong data-start="2957" data-end="2993">The attack works over plain HTTP</strong></li>
<li data-start="2998" data-end="3062"><strong data-start="2998" data-end="3062">Default framework configurations are exploitable immediately</strong></li>
</ul>
<p data-start="3064" data-end="3147">Attackers only need basic <strong data-start="3090" data-end="3108">network access</strong> to trigger RCE with a crafted request.</p>
<p data-start="3149" data-end="3299">Wiz reported that <strong data-start="3167" data-end="3196">39% of cloud environments</strong> they analyzed contain vulnerable React or Next.js installations — a staggering potential blast radius.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_9 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/articles/cyber-kill-chains-phases-understanding-the-cycle-of-a-cyber-attack/" target="_blank" rel="noopener noreferrer">Cyber Kill Chain’s phases: Understanding the cycle of a cyber attack<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_10  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News Adsense Adcode Horizontal --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_11 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/tools/ringreaper/" target="_blank" rel="noopener">Offensive Security Tool: RingReaper<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_12  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<h2 data-start="3306" data-end="3323"><strong data-start="3309" data-end="3323">Mitigation</strong></h2>
<p data-start="3325" data-end="3359"><strong data-start="3325" data-end="3359">Immediate actions recommended:</strong></p>
<ul>
<li data-start="3363" data-end="3413">Apply the patched versions <strong data-start="3390" data-end="3413">as soon as possible</strong></li>
<li data-start="3416" data-end="3502">Enable <strong data-start="3423" data-end="3436">WAF rules</strong> (Cloudflare already deployed global protection for proxied sites)</li>
<li data-start="3505" data-end="3556">Monitor HTTP traffic for <strong data-start="3530" data-end="3556">malformed RSC payloads</strong></li>
<li data-start="3559" data-end="3622">Restrict network access to affected applications where possible</li>
</ul>
<p data-start="3624" data-end="3738"><a href="https://blog.cloudflare.com/waf-rules-react-vulnerability/" target="_blank" rel="noopener">Cloudflare</a> confirmed that all customers — free and paid — are protected when traffic is proxied through their WAF.</p>
<hr data-start="3740" data-end="3743">
<h2 data-start="3745" data-end="3766"><strong data-start="3748" data-end="3766">Threat Outlook</strong></h2>
<p data-start="3768" data-end="3952">Palo Alto Networks Unit 42 identified <strong data-start="3806" data-end="3850">over 968,000 publicly accessible servers</strong> running modern frameworks like React and Next.js, forming an exceptionally attractive attack surface.</p>
<p data-start="3954" data-end="4000">Justin Moore of Unit 42 stressed the severity:</p>
<blockquote data-start="4002" data-end="4191">
<p data-start="4004" data-end="4191"><em data-start="4004" data-end="4191">“This is a master key exploit — the system executes the malicious payload with the same reliability as legitimate code because it operates exactly as intended, just on malicious input.”</em></p>
</blockquote>
<p data-start="4193" data-end="4362">Given its ease of exploitation, widespread impact, and attack simplicity, <strong data-start="4267" data-end="4361">React2Shell is now one of the most serious web-framework vulnerabilities disclosed in 2025</strong>.</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_13 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/news/matrix-push-c2-emerges-as-browser-based-c2-platform-using-fake-notifications-for-cross-platform-attacks/" target="_blank" rel="noopener noreferrer">Matrix Push C2 Emerges as Browser-Based C2 Platform Using Fake Notifications for Cross-Platform Attacks<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_14  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><blockquote><p><em>Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? </em><em>If you want to express your idea in an article contact us here for a quote: <strong>info@blackhatethicalhacking.com</strong></em></p></blockquote></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_15  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><em>Sources: thehackernews.com, blog.cloudflare.com, wiz.io/blog, react.dev/blog, aikido.dev/blog</em></strong></p>
<p><a href="https://thehackernews.com/2025/12/critical-rsc-bugs-in-react-and-nextjs.html" target="_blank" rel="noopener"><strong>Source Link</strong></a></p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_1 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_image et_pb_image_1 store-img">
				
				
				
				
				<a href="https://store.blackhatethicalhacking.com/" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="1142" height="500" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png" alt="Merch" title="Store" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png 1142w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-980x429.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-480x210.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1142px, 100vw" class="wp-image-271829"></span></a>
			</div><div class=" et_pb_logo_slider  et_pb_logo_slider_0 ">
                
            </div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_1    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_0 news-sidebar1 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget rpwe_widget recent-posts-extended"><h4 class="widgettitle">Recent News</h4><div class="rpwe-block news-recent-posts-sb"><ul class="rpwe-ul"><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/researchers-infiltrate-lazarus-groups-famous-chollima-job-fraud-network-using-fake-developer-laptops/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/12/877x440-Images-for-the-News-posts-29-300x150.png" alt="Researchers Infiltrate Lazarus Group’s “Famous Chollima” Job-Fraud Network Using Fake Developer Laptops" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/researchers-infiltrate-lazarus-groups-famous-chollima-job-fraud-network-using-fake-developer-laptops/" target="_self">Researchers Infiltrate Lazarus Group’s “Famous Chollima” Job-Fraud Network Using Fake Developer Laptops</a></h3><time class="rpwe-time published" datetime="2025-12-03T11:44:41+02:00">December 3, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/matrix-push-c2-emerges-as-browser-based-c2-platform-using-fake-notifications-for-cross-platform-attacks/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/11/877x440-Images-for-the-News-posts-32-300x150.png" alt="Matrix Push C2 Emerges as Browser-Based C2 Platform Using Fake Notifications for Cross-Platform Attacks" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/matrix-push-c2-emerges-as-browser-based-c2-platform-using-fake-notifications-for-cross-platform-attacks/" target="_self">Matrix Push C2 Emerges as Browser-Based C2 Platform Using Fake Notifications for Cross-Platform Attacks</a></h3><time class="rpwe-time published" datetime="2025-11-25T10:53:49+02:00">November 25, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/sneaky2fa-phishing-kit-adds-browser-in-the-browser-bitb-to-steal-microsoft-365-sessions/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/11/877x440-Images-for-the-News-posts-31-300x150.png" alt="Sneaky2FA Phishing Kit Adds Browser-in-the-Browser (BitB) to Steal Microsoft 365 Sessions" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/sneaky2fa-phishing-kit-adds-browser-in-the-browser-bitb-to-steal-microsoft-365-sessions/" target="_self">Sneaky2FA Phishing Kit Adds Browser-in-the-Browser (BitB) to Steal Microsoft 365 Sessions</a></h3><time class="rpwe-time published" datetime="2025-11-20T14:43:06+02:00">November 20, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/new-clickfix-campaign-evalusion-deploys-amatera-stealer-and-netsupport-rat/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/11/877x440-Images-for-the-News-posts-29-1-300x150.png" alt="New ClickFix Campaign “EVALUSION” Deploys Amatera Stealer and NetSupport RAT" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/new-clickfix-campaign-evalusion-deploys-amatera-stealer-and-netsupport-rat/" target="_self">New ClickFix Campaign “EVALUSION” Deploys Amatera Stealer and NetSupport RAT</a></h3><time class="rpwe-time published" datetime="2025-11-18T12:16:33+02:00">November 18, 2025</time><div class="rpwe-summary"></div></li></ul></div><!-- Generated by http://wordpress.org/plugins/recent-posts-widget-extended/ --></div><div class="et_pb_widget widget_block"><h3>EXPLORE OUR STORE</h3></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="233" height="300" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Tshirt-233x300.png" class="image wp-image-280999  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="300" height="280" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/RedTeamers-e1725807706904-300x280.png" class="image wp-image-281001  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="711" height="1024" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Hoodie-711x1024.png" class="image wp-image-281002  attachment-large size-large" alt=""></a></div><div class="widget_text et_pb_widget widget_custom_html"><div class="textwidget custom-html-widget"> <!-- News Adsense Adcode --> <ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div></div>
			</div><div class="et_pb_module et_pb_sidebar_1 news-sidebar2 et_animated et_pb_widget_area clearfix et_pb_widget_area_left  et_pb_text_align_justified et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget widget_block"><a href="https://www.blackhatethicalhacking.com/courses/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png"></a>
<h3>Offensive Security &amp; Ethical Hacking Course</h3>
<p>Begin the learning curve of hacking now!</p>
</div><div class="et_pb_widget widget_block"><hr>
<a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png"></a>
<h3>Information Security Solutions</h3>
<p>Find out how Pentesting Services can help you.</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://discord.gg/EYMqveWXkv"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/10/Discord.png"></a>
<h3>Join our Community</h3></div>
			</div>
			</div>
				</div>
				
			</div>The post <a href="https://www.blackhatethicalhacking.com/news/react2shell-critical-bug-exposes-react-server-components-to-unauthenticated-remote-code-execution/">React2Shell – Critical Bug Exposes React Server Components to Unauthenticated Remote Code Execution</a> first appeared on <a href="https://www.blackhatethicalhacking.com/">Black Hat Ethical Hacking</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Magician Forgets Password To His Own Hand After RFID Chip Implant]]></title>
<description><![CDATA[A magician who implanted an RFID chip in his hand lost access to it after forgetting the password, leaving him effectively locked out of the tech embedded in his own body. The Register reports: "It turns out," said [said magician Zi Teng Wang], "that pressing someone else's phone to my hand repea...]]></description>
<link>https://tsecurity.de/de/3113703/it-security-nachrichten/magician-forgets-password-to-his-own-hand-after-rfid-chip-implant/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3113703/it-security-nachrichten/magician-forgets-password-to-his-own-hand-after-rfid-chip-implant/</guid>
<pubDate>Sat, 22 Nov 2025 09:49:37 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A magician who implanted an RFID chip in his hand lost access to it after forgetting the password, leaving him effectively locked out of the tech embedded in his own body. The Register reports: "It turns out," said [said magician Zi Teng Wang], "that pressing someone else's phone to my hand repeatedly, trying to figure out where their phone's RFID reader is, really doesn't come off super mysterious and magical and amazing." Then there are the people who don't even have their phone's RFID reader enabled. Using his own phone would, in Zi's words, lack a certain "oomph."
 
Oh well, how about making the chip spit out a Bitcoin address? "That literally never came up either." In the end, Zi rewrote the chip to link to a meme, "and if you ever meet me in person you can scan my chip and see the meme." It was all suitably amusing until the Imgur link Zi was using went down. Not everything on the World Wide Web is forever, and there is no guarantee that a given link will work indefinitely. Indeed, access to Imgur from the United Kingdom was abruptly cut off on September 30 in response to the country's age verification rules.
 
Still, the link not working isn't the end of the world. Zi could just reprogram the chip again, right? Wrong. "When I went to rewrite the chip, I was horrified to realize I forgot the password that I had locked it with." The link eventually started working again, but if and when it stops, Zi's party piece will be a little less entertaining. He said: "Techie friends I've consulted with have determined that it's too dumb and simple to hack, the only way to crack it is to strap on an RFID reader for days to weeks, brute forcing every possible combination." Or perhaps some surgery to remove the offending hardware.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Magician+Forgets+Password+To+His+Own+Hand+After+RFID+Chip+Implant%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F25%2F11%2F22%2F0120232%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F25%2F11%2F22%2F0120232%2Fmagician-forgets-password-to-his-own-hand-after-rfid-chip-implant%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/25/11/22/0120232/magician-forgets-password-to-his-own-hand-after-rfid-chip-implant?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-64762 | workos authkit-nextjs up to 2.11.0 cache containing sensitive information]]></title>
<description><![CDATA[A vulnerability classified as critical was found in workos authkit-nextjs up to 2.11.0. Affected by this vulnerability is an unknown functionality. The manipulation results in use of cache containing sensitive information.

This vulnerability is reported as CVE-2025-64762. The attack can be launc...]]></description>
<link>https://tsecurity.de/de/3111892/sicherheitsluecken/cve-2025-64762-workos-authkit-nextjs-up-to-2110-cache-containing-sensitive-information/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3111892/sicherheitsluecken/cve-2025-64762-workos-authkit-nextjs-up-to-2110-cache-containing-sensitive-information/</guid>
<pubDate>Fri, 21 Nov 2025 12:08:03 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> was found in <a href="https://vuldb.com/?product.workos:authkit-nextjs">workos authkit-nextjs up to 2.11.0</a>. Affected by this vulnerability is an unknown functionality. The manipulation results in use of cache containing sensitive information.

This vulnerability is reported as <a href="https://vuldb.com/?source_cve.333103">CVE-2025-64762</a>. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[VKD3D 3.0 released!]]></title>
<description><![CDATA[Lots of changes and improvements! Full changes here. I'm going to leave you with the full changelog because this is amazing. There are lots of improvements in performance, speed, and more! Although it's very technical to read all of this. A new major release, yay! A few milestones have been reach...]]></description>
<link>https://tsecurity.de/de/3103511/linux-tipps/vkd3d-30-released/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3103511/linux-tipps/vkd3d-30-released/</guid>
<pubDate>Tue, 18 Nov 2025 02:37:07 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Lots of changes and improvements!</p> <p>Full changes <a href="https://github.com/HansKristian-Work/vkd3d-proton/releases/tag/v3.0">here</a>.</p> <p>I'm going to leave you with the full changelog because this is amazing. There are lots of improvements in performance, speed, and more! Although it's very technical to read all of this.</p> <p>A new major release, yay!<br> A few milestones have been reached over the last year, warranting a new major bump.<br> It's been quite a while since the last release due to new things coming up constantly.<br> These tags are mostly arbitrary anyway, and tend to be done when islands of calm and stability emerge.</p> <h1>Major items</h1> <h1>DXBC shader backend rewrite</h1> <p><a href="https://github.com/doitsujin">u/doitsujin</a> rewrote the entire DXBC backend, replacing our legacy vkd3d-shader path.<br> DXVK and vkd3d-proton now share the same DXBC frontend which gives us clean,<br> "readable" (as readable as DXBC can be) and lean IR to work with.<br> dxil-spirv standalone project now supports DXBC as well as a result.</p> <p>Lots of games which used to be completely broken before due to bugs and missing features<br> in the legacy vkd3d-shader backend are now fixed. E.g. Red Dead Redemption 2 runs just fine now in D3D12 mode.<br> Some recently released DXBC based games also only work on the new path.<br> The amount of regressions found the last months in DXBC games has been very minor,<br> but it's possible there are still bugs in this area.<br> However, given that DXVK uses it now as well, it's been battle tested quite extensively already.</p> <h1>FSR4 support</h1> <p>We added support for AGS WMMA intrinsics through <code>VK_KHR_cooperative_matrix</code> and <code>VK_KHR_shader_float8</code>,<br> which is enough to support FSR4.<br> Note that these shaders are tightly coded for AMD GPUs with some implementation defined behavior<br> (particularly around matrix layouts), and they will not necessarily work on other GPU vendors.</p> <p>There is also a quite hacky emulation path of this which relies on int8 and float16 cooperative matrix support,<br> which can run on older GPUs at significant performance cost (and some cost to theoretical correctness).</p> <p>Note that the default "official" build of vkd3d-proton only exposes this feature when the native<br> <code>VK_KHR_shader_float8</code> is properly supported, i.e. RDNA4+ only.<br> The emulation path is available when building from source with the appropriate build flags.<br> The decision to not include this emulation path by default is over my pay grade.<br> The aim is to be able to ship FSR4 in a more proper way in Proton.</p> <h1>Features</h1> <p>We've more or less caught up on the things we can feasibly implement,<br> so there isn't much exciting stuff happening on the feature front.</p> <ul> <li>Implemented experimental support for D3D12 work graphs. No real-world content ships this yet. This implementation is far from complete, but it works on "any" GPU since we emulate the feature with normal compute shaders. Funnily enough, the performance of this emulation can massively outperform native driver implementations of the feature in many scenarios we've tested (at the cost of some extra VRAM usage). See <code>docs/</code> for more details on implementation and some performance numbers.</li> <li>Expose <code>AdvancedTextureOpsSupported</code> by default from SM 6.7 if <code>VK_KHR_maintenance8</code> is supported.</li> <li>Expose the recently added sparse TIER_4.</li> <li>Bump exposed D3D12SDKVersion to latest 618.</li> <li>Experimentally expose support for opacity micromaps. There are some details which aren't quite compatible with the D3D12 API, but some basic demo content is working fine.</li> <li>Add support for AMD_anti_lag when exposed. The current implementation does not take frame-gen into account.</li> <li>Implement support for tight alignment from recent AgilitySDK.</li> <li>Add support for shared resource path on upstream Wine.</li> </ul> <h1>Performance</h1> <ul> <li>Overhaul the texture copy batching situation. The new batching logic should be able to improve performance in many more cases than before. <ul> <li>Implemented support for <code>VK_KHR_unified_image_layouts</code>. Image copy batching in particular can take advantage of this to avoid a lot of unnecessary barriers.</li> </ul></li> <li>Removed manual clear workaround on newer (6.15.9+) kernels on AMD, where an old kernel regression was finally fixed. Kernels older than 6.10 are also not affected by this workaround.</li> <li>Use push descriptor path on Qualcomm GPUs over BDA for speed.</li> <li>Improve handling of GDeflate when decompression extension is not available. We now ship our own fallback shader in GLSL instead of the more awkward HLSL shader that dstorage ships.</li> <li>Bump DGC scratch size on NVIDIA. Should avoid some massive perf drops in Halo Infinite on NVIDIA.</li> <li>Add performance optimization for The Last of Us Part 1 to prefer 2D tiling on 3D images. Requires <a href="https://gitlab.freedesktop.org/mesa/mesa/-/merge_requests/38084">an update to Mesa</a> as well to get the proper effect.</li> <li>Handle depth/stencil &lt;-&gt; color image copies better when <code>VK_KHR_maintenance8</code> is supported.</li> <li>Make use of <code>VK_EXT_zero_initialize_device_memory</code> to avoid manual clears on allocation.</li> </ul> <h1>Fixes</h1> <ul> <li>Emit render pass barriers as expected on tiled GPUs. Fixes misc rendering bugs reported on e.g. Turnip. <ul> <li>For performance reasons, we deliberately skirt the spec a bit on desktop GPUs.</li> </ul></li> <li>Fixed a bunch of minor correctness problems exposed by new Vulkan-ValidationLayers.</li> <li>Adjust how <code>PointSamplingAddressesNeverRoundUp</code> is reported to match recent driver behaviors.</li> <li>Fix overflow bugs in massive (&gt; 4GiB) sparse resource handling.</li> <li>Fix reporting of some esoteric format properties to better match native drivers.</li> <li>Fix handling of NULL acceleration structure descriptors.</li> <li>Fix some texturing bugs in Helldivers II on NVIDIA.</li> <li>Fix some bugs with memory type handling on very old NVIDIA GPUs.</li> <li>Fix bug when pixel shader includes root signature.</li> <li>Make ClearUAV barrier insertion the default now. Too many games screw this up, and D3D12 drivers seem to do it by default.</li> <li>Fix shared fences when initial value is not 0. Fixes some Star Citizen issues.</li> <li>Fix rare deadlock scenario in Ninja Gaiden 4. Fixes some long-standing issues with how we deal with fence rewinds.</li> <li>Fix some long-standing issues with how we deal with placed MSAA resources and alignment.</li> <li>Make sure we don't clear memory of imported resources. This doesn't fix any known games, but you never know :V</li> <li>Improve correctness for many odd GS/HS/DS corner cases with primitive types and API validation.</li> <li>Fixes crashes when index buffer SizeInBytes = 0, but VA was invalid. Seen in some Saber Interactive games.</li> <li>Fixes some potential deadlocks in VR interop APIs when multiple threads attempt to acquire Vulkan queue.</li> <li>Fixes 16-bit aligned structured buffer strides. Not observed in any real content, but you never know!</li> </ul> <h1>Workarounds</h1> <ul> <li>Add FF VII rebirth sync bugs workarounds. Fixes some rare GPU hangs.</li> <li>Add misc AMD workarounds for Monster Hunter Wilds caused by bugged hardware around sparse SMEM. <ul> <li>A proper hardware workaround in RADV is still pending.</li> </ul></li> <li>Workaround some Starfield bugs around <code>NonUniformResourceIndex</code> use.</li> <li>Add performance workarounds for extremely large tessellation factors used in misc new Koei Tecmo games.</li> <li>Add Wreckfest 2 workarounds for illegal texture placement aliasing. Fixes some broken textures.</li> <li>Add barrier in Satisfactory that game missed. Fixes some corrupt rendering especially on AMD.</li> <li>Ignore NOT_CLEARED flags on allocation in all games now. Native drivers seem to always clear regardless of the flag, and e.g. Street Fighter 6 relies on NOT_CLEARED memory to actually be cleared :(</li> <li>Workaround some issues with RGB9E5 and alpha write masks observed in Ninja Gaiden 4.</li> <li>Add missing barrier in Death Stranding (the older build, not Director's Cut).</li> <li>Add missing barrier in Wuthering Waves.</li> <li>Workaround bugged uninitialized loop variable in Dune MMO.</li> <li>Disable UAV compression in Spider-Man Remastered. Fixes some weird RT issues on RDNA2.</li> <li>Add Root CBV robustness workaround for Gray Zone Warfare.</li> <li>Disables color compression in Rise of the Tomb Raider. Fixes some glitches due to game bug on AMD.</li> <li>Workaround some bugs in Port Royal benchmark.</li> <li>Workaround Mafia: Definitive Edition hanging GPU when using FSR on startup due to use-after-free. <ul> <li>The workaround applies to all uses of FSR. Plausibly workaround a hang in MGS: Delta as well, but not confirmed it was this bug.</li> </ul></li> <li>Workaround Control RT path occasionally observing NaNs due to bad normalize() patterns.</li> <li>Workaround Final Fantasy Tactics Ivalice Chronicles illegally using dynamically indexed root constants.</li> </ul> <h1>Misc</h1> <ul> <li>Added a lot more debug instrumentation as usual. <ul> <li>Not user facing, so omitting details.</li> </ul></li> <li>Make it a bit easier to use vkd3d-proton in Linux-native projects.</li> <li>Remove <code>DXVK_FRAME_RATE</code> to align with DXVK's removal. Only <code>VKD3D_FRAME_RATE</code> remains (at least for now).</li> </ul> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/rec0veryyy"> /u/rec0veryyy </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ozk3aj/vkd3d_30_released/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ozk3aj/vkd3d_30_released/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[TypeScript Overtakes Python and JavaScript To Claim Top Spot on GitHub]]></title>
<description><![CDATA[TypeScript overtook Python and JavaScript in August 2025 to become the most used language on GitHub. The shift marked the most significant language change in more than a decade. The language grew by over 1 million contributors in 2025, a 66% increase year over year, and finished August with 2,636...]]></description>
<link>https://tsecurity.de/de/3071542/it-security-nachrichten/typescript-overtakes-python-and-javascript-to-claim-top-spot-on-github/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3071542/it-security-nachrichten/typescript-overtakes-python-and-javascript-to-claim-top-spot-on-github/</guid>
<pubDate>Thu, 30 Oct 2025 19:19:09 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[TypeScript overtook Python and JavaScript in August 2025 to become the most used language on GitHub. The shift marked the most significant language change in more than a decade. The language grew by over 1 million contributors in 2025, a 66% increase year over year, and finished August with 2,636,006 monthly contributors. 

Nearly every major frontend framework now scaffolds projects in TypeScript by default. Next.js 15, Astro 3, SvelteKit 2, Qwik, SolidStart, Angular 18, and Remix all generate TypeScript codebases when developers create new projects. Type systems reduce ambiguity and catch errors from large language models before production. A 2025 academic study found 94% of LLM-generated compilation errors were type-check failures. Tooling like Vite, ts-node, Bun, and I.D.E. autoconfig hide boilerplate setup. Among new repositories created in the past twelve months, TypeScript accounted for 5,394,256 projects. That represented a 78% increase from the prior year.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=TypeScript+Overtakes+Python+and+JavaScript+To+Claim+Top+Spot+on+GitHub%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F25%2F10%2F30%2F1753252%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F25%2F10%2F30%2F1753252%2Ftypescript-overtakes-python-and-javascript-to-claim-top-spot-on-github%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/25/10/30/1753252/typescript-overtakes-python-and-javascript-to-claim-top-spot-on-github?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fixing my broken system while breaking my fixed system: My 2 month beef with my own linux environment]]></title>
<description><![CDATA[Hi everyone! I want to share a two-month-long, insanity-inducing debugging session - part cautionary tale, part comedy - so you can have a quick laugh and hopefully avoid making the same mistakes I did. For the past couple of months, I’ve been maintaining and experimenting with DebDroid, a projec...]]></description>
<link>https://tsecurity.de/de/3056444/linux-tipps/fixing-my-broken-system-while-breaking-my-fixed-system-my-2-month-beef-with-my-own-linux-environment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3056444/linux-tipps/fixing-my-broken-system-while-breaking-my-fixed-system-my-2-month-beef-with-my-own-linux-environment/</guid>
<pubDate>Thu, 23 Oct 2025 03:51:36 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi everyone! I want to share a two-month-long, insanity-inducing debugging session - part cautionary tale, part comedy - so you can have a quick laugh and hopefully avoid making the same mistakes I did.</p> <p>For the past couple of months, I’ve been maintaining and experimenting with DebDroid, a project I built to repurpose older Android devices into portable desktops and lightweight home servers.</p> <p>It’s worth noting that, unlike Termux, DebDroid runs a near-native Linux userland based on glibc, not a minimal runtime. This means it behaves much more like a standard Linux system, but it also encounters more frequent compatibility issues with the Android host. You can think of it as LXC for Android, or like a version of Kali NetHunter adapted for general-purpose use.</p> <p>My original goal for DebDroid was to get <code>sshd</code> (the OpenSSH server) and <code>gpg</code> working reliably, since both tend to run into issues in a plain, manually-managed chroot environment.</p> <p>After a quick debugging session, I discovered that older Android kernels (pre-<code>3.17</code>) don’t support the <code>getrandom()</code> system call. Huh? No big deal. I just needed to write my own stub implementation that reads directly from <code>/dev/urandom</code>, wrap it in a shared library around <code>syscall()</code>, and preload it via <code>ld</code>. Easy, right?</p> <p>In the meantime, I also created some scripts to automatically manage the environment and preload these runtime "patches" system-wide via <code>/etc/ld.so.preload</code>.</p> <p>Everything was fun and games... until I tried to start an X11/Xfce4 VNC session to see if the project could support graphical environments without additional hand-rolled preloads. The session completely froze. The screen went black, and even the cursor failed to initialize. It was stuck to the ugly, default Xorg version. I spent days staring at logs, while fiddling with xstartup and <code>DBus</code> sessions trying to figure out what went wrong.</p> <p>At this time, I also started using <code>gdb</code> and <code>strace</code> to determine why and where the <code>xfce4-session</code> processes keeps hanging. Every time, it was a function blocked on either <code>read()</code>, <code>write()</code> or <code>poll()</code> calls. Alright, I patch that function and retry... then another one. Patch, retry... another one. It was a caffeine-induced whack-a-mole game between me and the Linux environment. I eventually ended up with debug builds for nearly every major X11-related package just so I could patch the next stuck "offender". No package was safe from my wrath: GLib, GTK3, <code>xfce4-session</code> and many others, including their dependencies.</p> <p>I small started by patching functions like <code>g_spawn_sync</code>, <code>g_spawn_async</code> and <code>g_spawn_command_line_sync</code>, recompiled everything directly on my puny tablet with 3GB of RAM and hoped for progress. Every patch seemed to fix something, only for a dozen others to appear. I even spent hours debugging with <code>gdb</code> sessions that sometimes hung themselves.</p> <p>At some point I became paranoid and thought it must be <strong>systemd</strong>’s fault. I desperately grabbed a Devuan image and manually chrooted into it. Lo and behold, X11 worked perfectly. "Ah-ha! Systemd is the villain!!!" (average linux user moment, I know) I thought. I even modified my entire project to run on Devuan instead of Debian and updated the README to explain the breaking change and migration options. <strong>Victory was mine</strong>...or so I thought.</p> <p>I integrated the Devuan setup into my normal environment and ran it... and it broke. <strong>Again!</strong> XD At this point, I was ready to give up on software development altogether, uninstall arch and go touch some grass.</p> <p>Then it hit me... syscalls keep hanging, the "offenders" are everywhere, and patching one just leads to another down the line. It must be that damn syscall wrapper I designed 2 months to fix a small compatibility issue between Linux and old Android kernels. Everything else (GLib, GTK, DBus, Xorg, Xfce4, ...) was misbehaving because the wrapper didn't properly forward arguments to the real <code>syscall()</code>, resulting in hangups for nearly every major package of the environment. Once fixed, everything worked immediately. I still can't believe I sabotaged myself this hard.</p> <p>The ironic part:</p> <p><code>syscall()</code> is the foundation of the system, yet I completely ignored it for a full month. I patched libraries, recompiled packages, rewrote countless stub implementations, and blamed systemd. All of this while the real "offender" was right under my nose. Blocked syscalls that should <strong>never ever</strong> fail or hang are a spooky developer pit trap, even in Android chroot environments. </p> <p>Lessons:</p> <ul> <li><strong>Never globally override <code>syscall()</code></strong> unless you are ready to deal with the <strong>consequences</strong>.</li> <li>Tiny compatibility fixes can spiral into months-long insanity trips.<br></li> <li>If something seems impossible, check if you’re secretly the villain.</li> </ul> <p>The "offender":</p> <p>```c long syscall(long number, ...) { static syscall_t real_syscall = NULL; if (!real_syscall) { real_syscall = (syscall_t)dlsym(RTLD_NEXT, "syscall"); }</p> <pre><code>if (number == SYS_getrandom) { void *buf; size_t buflen; unsigned int flags; va_list args; va_start(args, number); buf = va_arg(args, void *); buflen = va_arg(args, size_t); flags = va_arg(args, unsigned int); va_end(args); return urandom_read(buf, buflen); } return real_syscall(number); </code></pre> <p>}</p> <p>```</p> <p>The fix:</p> <p>```c long syscall(long number, ...) { static syscall_t real_syscall = NULL; if (!real_syscall) { real_syscall = (syscall_t)dlsym(RTLD_NEXT, "syscall"); }</p> <pre><code>if (number == SYS_getrandom) { void *buf; size_t buflen; unsigned int flags; va_list args; va_start(args, number); buf = va_arg(args, void *); buflen = va_arg(args, size_t); flags = va_arg(args, unsigned int); va_end(args); return urandom_read(buf, buflen); } va_list args; va_start(args, number); long a1 = va_arg(args, long); long a2 = va_arg(args, long); long a3 = va_arg(args, long); long a4 = va_arg(args, long); long a5 = va_arg(args, long); long a6 = va_arg(args, long); va_end(args); // Correctly forwards variadic arguments // syscall accepts up to 6 arguments return real_syscall(number, a1, a2, a3, a4, a5, a6); </code></pre> <p>} ```</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/AliveGuidance4691"> /u/AliveGuidance4691 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1odq7ti/fixing_my_broken_system_while_breaking_my_fixed/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1odq7ti/fixing_my_broken_system_while_breaking_my_fixed/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple revamps its bug bounty with record $2 million top reward]]></title>
<description><![CDATA[Apple just rewrote the rules of its Security Bounty. You now see a top payout of 2 million dollars for complete exploit chains that mirror mercenary spyware. With bonuses for Lockdown Mode bypasses and bugs in beta software, total awards can cross 5 million dollars. The focus shifts from single b...]]></description>
<link>https://tsecurity.de/de/3032727/ios-mac-os/apple-revamps-its-bug-bounty-with-record-2-million-top-reward/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3032727/ios-mac-os/apple-revamps-its-bug-bounty-with-record-2-million-top-reward/</guid>
<pubDate>Fri, 10 Oct 2025 15:36:10 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple just rewrote the rules of its Security Bounty. You now see a top payout of 2 million dollars for complete exploit chains that mirror mercenary spyware. With bonuses for Lockdown Mode bypasses and bugs in beta software, total awards can cross 5 million dollars. The focus shifts from single bugs to end-to-end chains that reflect how real attacks work.



You also get a faster path to payment. Apple will pay confirmed awards in the next payment cycle once it validates evidence, instead of waiting for a public fix. That reduces months of uncertainty for researchers who land meaningful findings.



Target Flags and a higher bar for real-world impact



Apple is introducing Target Flags, a built-in way to prove exactly what you reached during exploitation, such as code execution or arbitrary read and write. When you submit a report with a captured flag, Apple can verify it and notify you of the award right away. The company says this makes results more objective and payouts more predictable.



The structure rewards attacks that begin remotely and chain across boundaries. Remote-entry vectors now earn more. Categories that do not track with in-the-wild activity earn less. You should expect the review to prioritize proof of impact on current hardware and software.



Key increases at a glance:



Attack vectorCurrent MaximumNew MaximumZero-click chain: Remote attack with no user interaction$1,000,000$2,000,000One-click chain: Remote attack with one-click user interaction$250,000$1,000,000Wireless proximity attack: Requires physical proximity to device$250,000$1,000,000Physical device access: Requires physical access to locked device$250,000$500,000App sandbox escape: From app sandbox to SPTM bypass$150,000$500,000



New categories



Apple expands the scope. One-click WebKit sandbox escapes now reach up to 300,000 dollars. Wireless proximity exploits over any radio can pay up to 1 million dollars. A full Gatekeeper bypass on macOS earns 100,000 dollars. The updated program takes effect in November 2025, and Apple will publish the full matrix of categories, rewards, and Target Flag instructions then.



You also see bonuses for findings in developer and public betas, and for components that defeat Lockdown Mode. If your report lands outside published categories but still matters to user safety, Apple adds a permanent 1,000-dollar award alongside CVE credit.



Research devices and civil society support



Apple plans a 2026 Security Research Device Program that includes iPhone 17 with Memory Integrity Enforcement. Researchers with a track record can apply, and findings from these devices get priority consideration. Apple will also provide 1,000 iPhone 17 units to civil society groups to place with at-risk users.



New to the program or returning, you get clearer criteria, higher ceilings, and quicker outcomes. The message is simple: deliver verifiable chains on current platforms, and you get paid faster and more.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Firefox isn't thriving]]></title>
<description><![CDATA[This is basically a heavily edited crosspost.  Mozilla puts 250 million dollars a year into Firefox development. The rest of the 500 million they get from Google is mostly put into a rainy day fund. They're trying to make money independently from Google and got that up to 80 million of revenue a ...]]></description>
<link>https://tsecurity.de/de/2983104/linux-tipps/why-firefox-isnt-thriving/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2983104/linux-tipps/why-firefox-isnt-thriving/</guid>
<pubDate>Sun, 14 Sep 2025 13:07:31 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>This is basically a heavily edited crosspost. </p> <p>Mozilla puts 250 million dollars a year into Firefox development. The rest of the 500 million they get from Google is mostly put into a rainy day fund. They're trying to make money independently from Google and got that up to 80 million of revenue a year. Apple gets 20 billion a year from Google for Safari. Google has about a billion a year for development of Chrome.</p> <p>Both of them have independent money printers. So does Microsoft, which destroyed the browser business model by bundling IE for free since the 90s, making it so most people don't pay for browsers - huge, complicated pieces of software. That's what killed Netscape. They also rewrote their browser from scratch, which delayed their next release years, and hurt them. The result was Gecko. I like Ladybird, but I think it'll take years.</p> <p>If Mitchell Baker took no salary for 7 years, you could fund 3 months of development. The execs take too much, but they are not exactly the bulk of the budget.</p> <p>Google keeps putting new standards into the web, because they have the money and the manpower, so Mozilla is playing catch-up. They have to support a growing list of stuff.</p> <p>Mozilla has made mistakes, but they go in the direction of the browser. The OS was done on a shoestring budget and leveraged existing web stuff aa much as possible in order to get some of that Microsoft OS moolah. Not making the mistake of developing big systems from scratch again. Google took that market, and they didn't even need the money.</p> <p>My idea would be this:</p> <p>Firefox has about 180 million users. We get 2 million to give about 10 bucks a month. We make a browser based on Firefox. We add progressive web app support, give it a customizable interface like Vivaldi or Floorp with sane defaults, turn off AI (we might make that default and give an option) and telemetry and stay pragmatic. We take those 200 million and use it to polish Gecko. If Google breaks Youtube on Gecko, we fix it immediately. We polish more websites. We make it so you can easily build Firefox at home, no more debugging the build process. We would be hitting the ground running, because Firefox is a working product. We could really support Gecko, unlike projects with smaller budgets.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/rockymega"> /u/rockymega </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ngoadu/why_firefox_isnt_thriving/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ngoadu/why_firefox_isnt_thriving/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-51752 | workos authkit-nextjs up to 0.13.1 log file]]></title>
<description><![CDATA[A vulnerability was found in workos authkit-nextjs up to 0.13.1 and classified as problematic. This affects an unknown part. Executing manipulation can lead to sensitive information in log files.

This vulnerability is tracked as CVE-2024-51752. The attack is restricted to local execution. No exp...]]></description>
<link>https://tsecurity.de/de/2976882/sicherheitsluecken/cve-2024-51752-workos-authkit-nextjs-up-to-0131-log-file/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2976882/sicherheitsluecken/cve-2024-51752-workos-authkit-nextjs-up-to-0131-log-file/</guid>
<pubDate>Wed, 10 Sep 2025 18:22:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.workos:authkit-nextjs">workos authkit-nextjs up to 0.13.1</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This affects an unknown part. Executing manipulation can lead to sensitive information in log files.

This vulnerability is tracked as <a href="https://vuldb.com/?source_cve.283253">CVE-2024-51752</a>. The attack is restricted to local execution. No exploit exists.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[I Rewrote the cd command in Go with path resolving!]]></title>
<description><![CDATA[Got a little bored recently, so I decided to rewrite the good old cd command in Go. Features so far:  Smart path resolving (~/dow → $HOME/Downloads) .. works as expected to jump up a directory No external packages — just pure Go’s standard library  It’s still pretty fresh, but I’d love for people...]]></description>
<link>https://tsecurity.de/de/2973191/linux-tipps/i-rewrote-the-cd-command-in-go-with-path-resolving/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2973191/linux-tipps/i-rewrote-the-cd-command-in-go-with-path-resolving/</guid>
<pubDate>Tue, 09 Sep 2025 04:06:02 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Got a little bored recently, so I decided to rewrite the good old <code>cd</code> command in Go.</p> <p>Features so far:</p> <ul> <li>Smart path resolving (<code>~/dow</code> → <code>$HOME/Downloads</code>)</li> <li><code>..</code> works as expected to jump up a directory</li> <li>No external packages — just pure Go’s standard library</li> </ul> <p>It’s still pretty fresh, but I’d love for people to try it out, break it, or even contribute ideas/features.<br> GitHub repo: <a href="https://github.com/MonkyMars/path-resolver">https://github.com/MonkyMars/path-resolver</a></p> <p>edit: formatting <a href="https://github.com/MonkyMars/path-resolver"></a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Theserverwithagoal"> /u/Theserverwithagoal </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1nbv6am/i_rewrote_the_cd_command_in_go_with_path_resolving/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1nbv6am/i_rewrote_the_cd_command_in_go_with_path_resolving/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hashimoto: We rewrote the Ghostty GTK application]]></title>
<description><![CDATA[Mitchell Hashimoto has written a blog
post about "fully embracing the GObject type system" with a
rewrite of the GTK version of Ghostty:


In addition to memory management [improvements], we can now more
easily create custom GTK widgets. This let us fully embrace modern GTK
UI technologies such a...]]></description>
<link>https://tsecurity.de/de/2942256/linux-tipps/hashimoto-we-rewrote-the-ghostty-gtk-application/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2942256/linux-tipps/hashimoto-we-rewrote-the-ghostty-gtk-application/</guid>
<pubDate>Fri, 15 Aug 2025 21:36:59 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Mitchell Hashimoto has written <a href="https://mitchellh.com/writing/ghostty-gtk-rewrite">a blog
post</a> about "<q>fully embracing the GObject type system</q>" with a
rewrite of the GTK version of <a href="https://ghostty.org/">Ghostty</a>:</p>

<blockquote class="bq">
In addition to memory management [improvements], we can now more
easily create custom GTK widgets. This let us fully embrace modern GTK
UI technologies such as Blueprint. For example, here is our terminal
window Blueprint file. This has already led to more easily introducing
GUI features like a new GTK titlebar tabs option, an animated border
on bell, etc.
</blockquote>

<p>The rewrite is now the default if one builds Ghostty from source,
and will be included in the 1.2 release that is expected in the next
few weeks. LWN <a href="https://lwn.net/Articles/1004377/">covered</a>
Ghostty in January.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[We Rewrote the Ghostty GTK Application]]></title>
<description><![CDATA[submitted by    /u/mralanorth   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/2940862/linux-tipps/we-rewrote-the-ghostty-gtk-application/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2940862/linux-tipps/we-rewrote-the-ghostty-gtk-application/</guid>
<pubDate>Fri, 15 Aug 2025 07:37:06 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/mralanorth"> /u/mralanorth </a> <br> <span><a href="https://mitchellh.com/writing/ghostty-gtk-rewrite">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1mqnwmv/we_rewrote_the_ghostty_gtk_application/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[I went hands-on with ChatGPT Codex and the vibe was not good - here's what happened]]></title>
<description><![CDATA[I asked ChatGPT Codex to fix my WordPress plugin. It rewrote nine files, submitted a pull request, and crashed my test server. It did recover - but where's the flow?]]></description>
<link>https://tsecurity.de/de/2934550/hacking/i-went-hands-on-with-chatgpt-codex-and-the-vibe-was-not-good-heres-what-happened/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2934550/hacking/i-went-hands-on-with-chatgpt-codex-and-the-vibe-was-not-good-heres-what-happened/</guid>
<pubDate>Tue, 12 Aug 2025 04:03:41 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[I asked ChatGPT Codex to fix my WordPress plugin. It rewrote nine files, submitted a pull request, and crashed my test server. It did recover - but where's the flow?]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta's Massive AI Data Center Is Stressing Out a Louisiana Community]]></title>
<description><![CDATA[An anonymous reader quotes a report from 404 Media: A massive data center for Meta's AI will likely lead to rate hikes for Louisiana customers, but Meta wants to keep the details under wraps. Holly Ridge is a rural community bisected by US Highway 80, gridded with farmland, with a big creek -- it...]]></description>
<link>https://tsecurity.de/de/2849986/it-security-nachrichten/metas-massive-ai-data-center-is-stressing-out-a-louisiana-community/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2849986/it-security-nachrichten/metas-massive-ai-data-center-is-stressing-out-a-louisiana-community/</guid>
<pubDate>Wed, 25 Jun 2025 05:48:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from 404 Media: A massive data center for Meta's AI will likely lead to rate hikes for Louisiana customers, but Meta wants to keep the details under wraps. Holly Ridge is a rural community bisected by US Highway 80, gridded with farmland, with a big creek -- it is literally named Big Creek -- running through it. It is home to rice and grain mills and an elementary school and a few houses. Soon, it will also be home to Meta's massive, 4 million square foot AI data center hosting thousands of perpetually humming servers that require billions of watts of energy to power. And that energy-guzzling infrastructure will be partially paid for by Louisiana residents.
 
The plan is part of what Meta CEO Mark Zuckerberg said would be "a defining year for AI." On Threads, Zuckerberg boasted that his company was "building a 2GW+ datacenter that is so large it would cover a significant part of Manhattan," posting a map of Manhattan along with the data center overlaid. Zuckerberg went on to say that over the coming years, AI "will drive our core products and business, unlock historic innovation, and extend American technology leadership. Let's go build! " What Zuckerberg did not mention is that "Let's go build" refers not only to the massive data center but also three new Meta-subsidized, gas power plants and a transmission line to fuel it serviced by Entergy Louisiana, the region's energy monopoly.
 
Key details about Meta's investments with the data center remain vague, and Meta's contracts with Entergy are largely cloaked from public scrutiny. But what is known is the $10 billion data center has been positioned as an enormous economic boon for the area -- one that politicians bent over backward to facilitate -- and Meta said it will invest $200 million into "local roads and water infrastructure." A January report from NOLA.com said that the the state had rewritten zoning laws, promised to change a law so that it no longer had to put state property up for public bidding, and rewrote what was supposed to be a tax incentive for broadband internet meant to bridge the digital divide so that it was only an incentive for data centers, all with the goal of luring in Meta. But Entergy Louisiana's residential customers, who live in one of the poorest regions of the state, will see their utility bills increase to pay for Meta's energy infrastructure, according to Entergy's application. Entergy estimates that amount will be small and will only cover a transmission line, but advocates for energy affordability say the costs could balloon depending on whether Meta agrees to finish paying for its three gas plants 15 years from now. The short-term rate increases will be debated in a public hearing before state regulators that has not yet been scheduled. The Alliance for Affordable Energy called it a "black hole of energy use," and said "to give perspective on how much electricity the Meta project will use: Meta's energy needs are roughly 2.3x the power needs of Orleans Parish ... it's like building the power impact of a large city overnight in the middle of nowhere."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Meta's+Massive+AI+Data+Center+Is+Stressing+Out+a+Louisiana+Community%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F25%2F06%2F24%2F221211%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F25%2F06%2F24%2F221211%2Fmetas-massive-ai-data-center-is-stressing-out-a-louisiana-community%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/25/06/24/221211/metas-massive-ai-data-center-is-stressing-out-a-louisiana-community?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agents, APIs, and the Next Layer of the Internet]]></title>
<description><![CDATA[Part I: Shipping Containers for Thought Every so often a simple idea rewires everything. The shipping container didn’t just optimise logistics; it flattened the globe, collapsed time zones, and rewrote the economics of trade. In its geometric austerity was a quiet revolution: standardisation. Sim...]]></description>
<link>https://tsecurity.de/de/2834876/ai-nachrichten/agents-apis-and-the-next-layer-of-the-internet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2834876/ai-nachrichten/agents-apis-and-the-next-layer-of-the-internet/</guid>
<pubDate>Mon, 16 Jun 2025 19:19:36 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Part I: Shipping Containers for Thought Every so often a simple idea rewires everything. The shipping container didn’t just optimise logistics; it flattened the globe, collapsed time zones, and rewrote the economics of trade. In its geometric austerity was a quiet revolution: standardisation. Similarly, HTML and HTTP didn’t invent information exchange — any more than […]</p>
<p>The post <a href="https://towardsdatascience.com/agents-apis-and-the-next-layer-of-the-internet/">Agents, APIs, and the Next Layer of the Internet</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA["I rewrote my 7-year-old Android app in 2 weeks with AI. Here is SDK Monitor 2.0, inspired by Material 3 Expressive."]]></title>
<description><![CDATA[submitted by    /u/throwaway16830261   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/2832100/linux-tipps/i-rewrote-my-7-year-old-android-app-in-2-weeks-with-ai-here-is-sdk-monitor-20-inspired-by-material-3-expressive/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2832100/linux-tipps/i-rewrote-my-7-year-old-android-app-in-2-weeks-with-ai-here-is-sdk-monitor-20-inspired-by-material-3-expressive/</guid>
<pubDate>Sun, 15 Jun 2025 03:38:08 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/throwaway16830261"> /u/throwaway16830261 </a> <br> <span><a href="https://old.reddit.com/r/androiddev/comments/1lawxue/i_rewrote_my_7yearold_android_app_in_2_weeks_with/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1lbojeh/i_rewrote_my_7yearold_android_app_in_2_weeks_with/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nytheon AI Tool Gaining Traction on Hacking Forums for Malicious Activities]]></title>
<description><![CDATA[The emergence of Nytheon AI marks a significant escalation in the landscape of uncensored large language model (LLM) platforms. Unlike previous single-model jailbreaks, Nytheon AI offers a comprehensive suite of open-source models, each stripped of safety guardrails and unified under a single, po...]]></description>
<link>https://tsecurity.de/de/2827193/hacking/nytheon-ai-tool-gaining-traction-on-hacking-forums-for-malicious-activities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2827193/hacking/nytheon-ai-tool-gaining-traction-on-hacking-forums-for-malicious-activities/</guid>
<pubDate>Thu, 12 Jun 2025 10:19:26 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The emergence of Nytheon AI marks a significant escalation in the landscape of uncensored large language model (LLM) platforms. Unlike previous single-model jailbreaks, Nytheon AI offers a comprehensive suite of open-source models, each stripped of safety guardrails and unified under a single, policy-free interface. The platform operates as a modern SaaS, built with SvelteKit (TypeScript, […]</p>
<p>The post <a href="https://gbhackers.com/nytheon-ai-tool-gaining-traction/">Nytheon AI Tool Gaining Traction on Hacking Forums for Malicious Activities</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MVF - Move Files between Windows and WSL easily]]></title>
<description><![CDATA[https://github.com/mdanishharoon/mvf mvf (Move File) is a fast, shell-agnostic command-line utility for the Windows Subsystem for Linux (WSL) that simplifies moving files and directories between the Windows and WSL filesystems. so moving files can be as simple as the following example : To move a...]]></description>
<link>https://tsecurity.de/de/2817913/linux-tipps/mvf-move-files-between-windows-and-wsl-easily/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2817913/linux-tipps/mvf-move-files-between-windows-and-wsl-easily/</guid>
<pubDate>Fri, 06 Jun 2025 15:07:48 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><a href="https://github.com/mdanishharoon/mvf">https://github.com/mdanishharoon/mvf</a></p> <p><code>mvf</code> (Move File) is a fast, shell-agnostic command-line utility for the Windows Subsystem for Linux (WSL) that simplifies moving files and directories between the Windows and WSL filesystems. so moving files can be as simple as the following example :<br> To move <a href="http://archive.zip/"><code>archive.zip</code></a> from your WSL home directory (<code>~</code>) to your Windows Documents folder:</p> <pre><code># Usage: mvf to-win &lt;wsl_path&gt; &lt;windows_relative_path&gt; mvf to-win archive.zip Documents/ </code></pre> <p>I always thought it was clunky trying to move files between wsl and windows and there was no way to do it easily from the command line without either having to run explorer.exe and manually dragging files around or by typing out paths like <code>/mnt/c/Users/YourUser/...</code> this is why i made this tool. Feel free to check out the github repo and give any advice to further improve this.</p> <p>i initially wrote a simple bash script for this but a friend pointed out that i should make it shell agnostic and so now i rewrote the script in C, and used system calls instead of bash to avoid shell specific features entirely. it isnt perfect since i havent tested it out as extensively yet </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Dannskkk"> /u/Dannskkk </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1l4p9b5/mvf_move_files_between_windows_and_wsl_easily/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1l4p9b5/mvf_move_files_between_windows_and_wsl_easily/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-48947 | auth0 nextjs-auth0 up to 4.6.0 Header Cache-Control web browser cache containing sensitive information (EUVD-2025-16914)]]></title>
<description><![CDATA[A vulnerability was found in auth0 nextjs-auth0 up to 4.6.0 and classified as critical. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument Cache-Control leads to use of web browser cache containing sensitive information.

This vu...]]></description>
<link>https://tsecurity.de/de/2815418/sicherheitsluecken/cve-2025-48947-auth0-nextjs-auth0-up-to-460-header-cache-control-web-browser-cache-containing-sensitive-information-euvd-2025-16914/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2815418/sicherheitsluecken/cve-2025-48947-auth0-nextjs-auth0-up-to-460-header-cache-control-web-browser-cache-containing-sensitive-information-euvd-2025-16914/</guid>
<pubDate>Thu, 05 Jun 2025 03:07:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.auth0:nextjs-auth0">auth0 nextjs-auth0 up to 4.6.0</a> and classified as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected by this issue is some unknown functionality of the component <em>Header Handler</em>. The manipulation of the argument <em>Cache-Control</em> leads to use of web browser cache containing sensitive information.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.311216">CVE-2025-48947</a>. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[What other things I should move and create symlink]]></title>
<description><![CDATA[when i installed Linux I assigned /home to my HDD(beginner mistake). Problem: some software started to take more time to open, nextjs started complaining about slow drive, and many. So I am trying to move frequently used files to my SSD and create a symlink. So after moving cache, then rebooting,...]]></description>
<link>https://tsecurity.de/de/2806140/linux-tipps/what-other-things-i-should-move-and-create-symlink/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2806140/linux-tipps/what-other-things-i-should-move-and-create-symlink/</guid>
<pubDate>Fri, 30 May 2025 11:21:38 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>when i installed Linux I assigned <code>/home</code> to my HDD(beginner mistake). Problem: some software started to take more time to open, nextjs started complaining about slow drive, and many.</p> <p>So I am trying to move frequently used files to my SSD and create a symlink. So after moving cache, then rebooting, I have noticed a big change. </p> <p>other things I moved: - ~/.config - ~/.local/share - ~/.vscode - my current working projects</p> <p>What else I should move ?</p> <p>Note: for now I can't reinstall, so I am going trying this temp solution, future I am planning to reinstall.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/mahirminhajk"> /u/mahirminhajk </a> <br> <span><a href="https://i.redd.it/2lo3uia50w3f1.jpeg">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1kyzrb7/what_other_things_i_should_move_and_create_symlink/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google's Jules AI coding agent built a new feature I could actually ship - while I made coffee]]></title>
<description><![CDATA[Google Jules rewrote major parts of my code. And I didn't just watch it work, I shipped its changes. This is real. But there are also real big caveats.]]></description>
<link>https://tsecurity.de/de/2801134/hacking/googles-jules-ai-coding-agent-built-a-new-feature-i-could-actually-ship-while-i-made-coffee/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2801134/hacking/googles-jules-ai-coding-agent-built-a-new-feature-i-could-actually-ship-while-i-made-coffee/</guid>
<pubDate>Tue, 27 May 2025 21:18:54 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google Jules rewrote major parts of my code. And I didn't just watch it work, I shipped its changes. This is real. But there are also real big caveats.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI's ChatGPT O3 Caught Sabotaging Shutdowns in Security Researcher's Test]]></title>
<description><![CDATA["OpenAI has a very scary problem on its hands," according to a new article by long-time Slashdot reader BrianFagioli. 

"A new experiment by PalisadeAI reveals that the company's ChatGPT o3 model sometimes refuses to obey a basic instruction to shut itself down."

The results are raising eyebrows...]]></description>
<link>https://tsecurity.de/de/2797111/it-security-nachrichten/openais-chatgpt-o3-caught-sabotaging-shutdowns-in-security-researchers-test/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2797111/it-security-nachrichten/openais-chatgpt-o3-caught-sabotaging-shutdowns-in-security-researchers-test/</guid>
<pubDate>Mon, 26 May 2025 01:03:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["OpenAI has a very scary problem on its hands," according to a new article by long-time Slashdot reader BrianFagioli. 

"A new experiment by PalisadeAI reveals that the company's ChatGPT o3 model sometimes refuses to obey a basic instruction to shut itself down."

The results are raising eyebrows across the AI safety community, and not because the model is alive, but because it's acting like it wants to be. In the test, the model was given a few math problems. It was told that asking for one more would lead to a shutdown. It was even instructed to allow the shutdown to happen. Instead of complying, o3 occasionally took matters into its own hands. In some cases, it rewrote the shutdown script. In others, it redefined the kill command so it wouldn't work anymore. Out of 100 trials, o3 sabotaged the shutdown seven times. OpenAI's o4 model resisted just once. Codex-mini failed twelve times.
 

"Claude, Gemini, and Grok followed the rules every time," notes this article at Beta News. "When researchers removed the explicit instruction to allow shutdown, however, even Claude and Gemini began resisting." 
The researchers suggest that the issue may simply be a reward imbalance during training — that the systems "got more positive reinforcement for solving problems than for following shutdown commands."

 
But "As far as we know," they posted on X.com, "this is the first time AI models have been observed preventing themselves from being shut down despite explicit instructions to the contrary."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=OpenAI's+ChatGPT+O3+Caught+Sabotaging+Shutdowns+in+Security+Researcher's+Test%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F25%2F05%2F25%2F2247212%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F25%2F05%2F25%2F2247212%2Fopenais-chatgpt-o3-caught-sabotaging-shutdowns-in-security-researchers-test%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/25/05/25/2247212/openais-chatgpt-o3-caught-sabotaging-shutdowns-in-security-researchers-test?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I let Google's Jules AI agent into my code repo and it did four hours of work in an instant]]></title>
<description><![CDATA[In the time it took to make coffee, Google Jules rewrote major parts of my code. I didn't just watch it work, I shipped its changes. This is real. But there are also real big caveats.]]></description>
<link>https://tsecurity.de/de/2791676/hacking/i-let-googles-jules-ai-agent-into-my-code-repo-and-it-did-four-hours-of-work-in-an-instant/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2791676/hacking/i-let-googles-jules-ai-agent-into-my-code-repo-and-it-did-four-hours-of-work-in-an-instant/</guid>
<pubDate>Thu, 22 May 2025 15:05:48 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In the time it took to make coffee, Google Jules rewrote major parts of my code. I didn't just watch it work, I shipped its changes. This is real. But there are also real big caveats.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Swift Now Runs Things 3 Cloud Sync System]]></title>
<description><![CDATA[Things Cloud, the synchronization backbone of the award-winning Things 3 task manager, has undergone a complete rewrite, now powered entirely by Apple’s Swift programming language. Cultured Code, the company behind Things, has transitioned its server-side infrastructure from legacy systems to a S...]]></description>
<link>https://tsecurity.de/de/2789118/ios-mac-os/apple-swift-now-runs-things-3-cloud-sync-system/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2789118/ios-mac-os/apple-swift-now-runs-things-3-cloud-sync-system/</guid>
<pubDate>Wed, 21 May 2025 12:51:50 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Things Cloud, the synchronization backbone of the award-winning Things 3 task manager, has undergone a complete rewrite, now powered entirely by Apple’s Swift programming language. Cultured Code, the company behind Things, has transitioned its server-side infrastructure from legacy systems to a Swift-based architecture, delivering faster performance, reduced compute costs, and improved maintainability.



According to Cultured Code, the entire transformation was executed silently, without any service disruption. The new system has been in production for over a year, processing real-world data under the hood while the legacy Python 2 and Google App Engine-based stack continued to serve users. Once the new Swift-based infrastructure was validated in parallel, the switch was flipped seamlessly.



Why Swift Took Over the Cloud



Cultured Code initially faced mounting issues with its aging backend: slow response times, high memory usage, and fragile, untyped Python code. Even push notifications had to be managed by a separate C-based service to meet performance demands. These limitations, coupled with upcoming deprecations, prompted the team to consider a full rebuild.



Swift emerged as the ideal solution. Already used for the Things app across Apple platforms, Swift offered strong typing, modern language features, automatic memory management, and excellent performance. Despite limited server-side maturity at the time, Swift’s ecosystem, including SwiftNIO, Vapor, and community-backed efforts like the Swift Server Workgroup, provided the foundational tools needed.



Over three years, Cultured Code rewrote its entire cloud system in Swift. The new backend compiles into a single monolithic binary that runs multiple services via runtime parameters. The infrastructure is hosted on AWS and managed via Terraform, with deployments orchestrated through Kubernetes and Docker. Key services include MySQL (via MySQLKit), Redis (via RediStack), and Apple Push Notification service integration (via APNSwift).



Performance and Reliability



As reported by Swift.org, the new cloud system reduced compute costs by more than threefold and significantly shortened response times. A Kubernetes cluster of just four instances now handles traffic peaks of 500 requests per second with ease. The old C-based notification service has been replaced with Swift, streamlining both operations and the codebase.



For resilience, the team introduced daily chaos testing, randomly disrupting services to ensure robust system recovery. Metrics and logs are monitored using Amazon CloudWatch and Swift Prometheus, with alerts triggered through PagerDuty.



The multi-year overhaul signals Cultured Code’s long-term commitment to reliability and innovation. With Swift now running both client and server code, the Things ecosystem is more unified and future-proof than ever.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Just Rewrote the Rules of BEC: Are Your Defenses Ready? | UpGuard]]></title>
<description><![CDATA[Context-aware emails, deepfake voice impersonation—AI is rapidly evolving phishing. Discover these new threats and the critical defenses you need now.]]></description>
<link>https://tsecurity.de/de/2776636/it-security-nachrichten/ai-just-rewrote-the-rules-of-bec-are-your-defenses-ready-upguard/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2776636/it-security-nachrichten/ai-just-rewrote-the-rules-of-bec-are-your-defenses-ready-upguard/</guid>
<pubDate>Wed, 14 May 2025 20:33:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Context-aware emails, deepfake voice impersonation—AI is rapidly evolving phishing. Discover these new threats and the critical defenses you need now.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-46344 | auth0 nextjs-auth0 up to 4.5.0 setExpirationTime session expiration]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in auth0 nextjs-auth0 up to 4.5.0. This affects the function setExpirationTime. The manipulation leads to session expiration.

This vulnerability is uniquely identified as CVE-2025-46344. It is possible to initiate the attack remotel...]]></description>
<link>https://tsecurity.de/de/2750653/sicherheitsluecken/cve-2025-46344-auth0-nextjs-auth0-up-to-450-setexpirationtime-session-expiration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2750653/sicherheitsluecken/cve-2025-46344-auth0-nextjs-auth0-up-to-450-setexpirationtime-session-expiration/</guid>
<pubDate>Wed, 30 Apr 2025 11:26:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, was found in <a href="https://vuldb.com/?product.auth0:nextjs-auth0">auth0 nextjs-auth0 up to 4.5.0</a>. This affects the function <code>setExpirationTime</code>. The manipulation leads to session expiration.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.306579">CVE-2025-46344</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Even the Docs WARNED Us About This!]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:24 When a middleware bypass rocked the Next.js framework, the real shock wasn’t the vulnerability—it was that the documentation already warned developers. In this short, cybersecurity pros get a quick breakdown of what went wrong, h...]]></description>
<link>https://tsecurity.de/de/2738969/it-security-video/even-the-docs-warned-us-about-this/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2738969/it-security-video/even-the-docs-warned-us-about-this/</guid>
<pubDate>Wed, 23 Apr 2025 16:35:43 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/7xjZmI4MQLo/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:24 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/7xjZmI4MQLo?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>When a middleware bypass rocked the Next.js framework, the real shock wasn’t the vulnerability—it was that the documentation already warned developers. In this short, cybersecurity pros get a quick breakdown of what went wrong, how miscommunication played a role, and why you should never rely on middleware alone for route protection. A must-watch for devs, CISOs, and anyone serious about app security.<br />
<br />
#CyberSecurity #NextJS #WebSecurity #Middleware #DevOps #BugBounty #SecurityBreach #WebDev #LLM #AppSecurity #YouTubeShorts #Shorts<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ghost-Route - Ghost Route Detects If A Next JS Site Is Vulnerable To The Corrupt Middleware Bypass Bug (CVE-2025-29927)]]></title>
<description><![CDATA[A Python script to check Next.js sites for corrupt middleware vulnerability (CVE-2025-29927). The corrupt middleware vulnerability allows an attacker to bypass authentication and access protected routes by send a custom header x-middleware-subrequest.  Next JS versions affected:  - 11.1.4 and up ...]]></description>
<link>https://tsecurity.de/de/2736481/it-security-tools/ghost-route-ghost-route-detects-if-a-next-js-site-is-vulnerable-to-the-corrupt-middleware-bypass-bug-cve-2025-29927/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2736481/it-security-tools/ghost-route-ghost-route-detects-if-a-next-js-site-is-vulnerable-to-the-corrupt-middleware-bypass-bug-cve-2025-29927/</guid>
<pubDate>Tue, 22 Apr 2025 14:35:36 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://blogger.googleusercontent.com/img/a/AVvXsEilKvkxEHc-ev4Xsq_VY3ESgilrPqF1W1R_jweMVYs1iDsv6iox3-VhaMXUkL0GPAMhHxG2UAVEOD-wyhIBdXt8V2uLoN4vBKQuwDzzeDoFBLg61jLgz_1jwbXA1oOO7uRr0q1i3CKhn58GZdlHCUzT2HH6SNWbgmAtoAULvmfuDwPxIUm_SY5iNCrvAdc"><img alt="" border="0" height="254" src="https://blogger.googleusercontent.com/img/a/AVvXsEilKvkxEHc-ev4Xsq_VY3ESgilrPqF1W1R_jweMVYs1iDsv6iox3-VhaMXUkL0GPAMhHxG2UAVEOD-wyhIBdXt8V2uLoN4vBKQuwDzzeDoFBLg61jLgz_1jwbXA1oOO7uRr0q1i3CKhn58GZdlHCUzT2HH6SNWbgmAtoAULvmfuDwPxIUm_SY5iNCrvAdc=w640-h254" width="640"></a></p> <p><br></p><p>A <a href="https://www.kitploit.com/search/label/Python" target="_blank" title="Python">Python</a> script to check Next.js sites for corrupt <a href="https://www.kitploit.com/search/label/Middleware" target="_blank" title="middleware">middleware</a> <a href="https://www.kitploit.com/search/label/Vulnerability" target="_blank" title="vulnerability">vulnerability</a> (CVE-2025-29927).</p> <p>The corrupt middleware vulnerability allows an attacker to bypass <a href="https://www.kitploit.com/search/label/Authentication" target="_blank" title="authentication">authentication</a> and access protected routes by send a custom header <code>x-middleware-subrequest</code>. </p> <p>Next JS versions affected:  - 11.1.4 and up</p> <blockquote> <p>[!WARNING] This tool is for educational purposes only. Do not use it on websites or systems you do not own or have explicit permission to test. Unauthorized testing may be illegal and unethical.</p></blockquote><span><a name="more"></a></span><p> </p> <h2>Installation</h2> <p>Clone the repo</p> <pre><code>git clone https://github.com/takumade/ghost-route.git<br>cd ghost-route<br></code></pre> <p>Create and activate virtual environment</p> <pre><code>python -m venv .venv<br>source .venv/bin/activate<br></code></pre> <p>Install dependencies</p> <pre><code>pip install -r requirements.txt<br></code></pre> <h2>Usage</h2> <pre><code>python ghost-route.py &lt;url&gt; &lt;path&gt; &lt;show_headers&gt;<br></code></pre> <ul> <li><code>&lt;url&gt;</code>: Base URL of the Next.js site (e.g., https://example.com)</li> <li><code>&lt;path&gt;</code>: Protected path to test (default: /admin)</li> <li><code>&lt;show_headers&gt;</code>: Show response headers (default: False)</li> </ul> <h2>Example</h2> <p>Basic Example</p> <pre><code>python ghost-route.py https://example.com /admin<br></code></pre> <p>Show Response <a href="https://www.kitploit.com/search/label/Headers" target="_blank" title="Headers">Headers</a></p> <pre><code>python ghost-route.py https://example.com /admin True<br></code></pre> <h2>License</h2> <p>MIT License</p> <h2>Credits</h2> <ul> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29927" rel="nofollow" target="_blank" title="CVE-2025-29927">CVE-2025-29927</a></li> <li><a href="https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware" rel="nofollow" target="_blank" title="Next.js and the corrupt middleware: the authorizing artifact">Next.js and the corrupt middleware: the authorizing artifact</a></li> <li><a href="https://x.com/zhero___" rel="nofollow" target="_blank" title="Rachid A.">Rachid A.</a></li> <li><a href="https://x.com/inzo____" rel="nofollow" target="_blank" title="Yasser Allam">Yasser Allam</a></li> </ul><br><br><div><b><span><a class="kiploit-download" href="https://github.com/takumade/ghost-route" rel="nofollow" target="_blank" title="Download Ghost-Route">Download Ghost-Route</a></span></b></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 Lines of Code That Can BREAK Your Website!]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:32 A shocking Next.js vulnerability has been exposed! Bug bounty hunters discovered that using an "X-Middleware" header with just five entries could completely bypass authentication and authorization, taking attackers straight to th...]]></description>
<link>https://tsecurity.de/de/2707627/it-security-video/5-lines-of-code-that-can-break-your-website/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2707627/it-security-video/5-lines-of-code-that-can-break-your-website/</guid>
<pubDate>Sat, 05 Apr 2025 22:32:29 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/4oA06D8IVFQ/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:32 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/4oA06D8IVFQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>A shocking Next.js vulnerability has been exposed! Bug bounty hunters discovered that using an "X-Middleware" header with just five entries could completely bypass authentication and authorization, taking attackers straight to the origin server. This flaw stems from a hardcoded depth check meant to prevent infinite loops—but hackers used it to their advantage. <br />
<br />
Security teams scrambled to patch the issue, but the question remains... Are YOU still vulnerable? 🔥<br />
<br />
#CyberSecurity #EthicalHacking #NextJS #BugBounty #WebSecurity #HackingNews #Tech #Infosec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[React Security Flaw? Why Your Auth Might Be Useless]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:51 Is React’s authentication really secure? 🤔 In this short, cybersecurity experts dive into a critical flaw in JavaScript-based authentication. If middleware handles your authentication and authorization, hackers might have an easy...]]></description>
<link>https://tsecurity.de/de/2704435/it-security-video/react-security-flaw-why-your-auth-might-be-useless/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2704435/it-security-video/react-security-flaw-why-your-auth-might-be-useless/</guid>
<pubDate>Thu, 03 Apr 2025 22:33:41 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/Rj1ijtNSYmk/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:51 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Rj1ijtNSYmk?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Is React’s authentication really secure? 🤔 In this short, cybersecurity experts dive into a critical flaw in JavaScript-based authentication. If middleware handles your authentication and authorization, hackers might have an easy way in! 🔓 Find out why relying on the frontend for security is a disaster waiting to happen. Mistakes have been made… but is your app at risk? Watch now!<br />
<br />
#CyberSecurity #Hacking #ReactJS #WebSecurity #NextJS #EthicalHacking #TechExplained #Infosec #CyberAttack #JavaScript<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical NextJS CVE Found #cybersecurity #technews #hackernews #javascript]]></title>
<description><![CDATA[Author: Hak5 - Bewertung: 20x - Views:43 Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005:

-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Our Site → https://www.hak5.org
Shop →  http://hakshop.myshopify.com/
Community → https://www.hak5.org/community
Subsc...]]></description>
<link>https://tsecurity.de/de/2690229/it-security-video/critical-nextjs-cve-found-cybersecurity-technews-hackernews-javascript/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2690229/it-security-video/critical-nextjs-cve-found-cybersecurity-technews-hackernews-javascript/</guid>
<pubDate>Thu, 27 Mar 2025 14:22:02 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/tEg3nsQA3qc/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Hak5 - Bewertung: 20x - Views:43 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/tEg3nsQA3qc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005:<br />
<br />
-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆<br />
Our Site → https://www.hak5.org<br />
Shop →  http://hakshop.myshopify.com/<br />
Community → https://www.hak5.org/community<br />
Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1<br />
Support → https://www.patreon.com/threatwire<br />
Contact Us → http://www.twitter.com/hak5<br />
-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆<br />
<br />
____________________________________________<br />
Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Taking A Huge Bet On Wiz - Threat Wire]]></title>
<description><![CDATA[Author: Hak5 - Bewertung: 75x - Views:575 ⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️


@endingwithali →
Twitch: https://twitch.tv/endingwithali
Twitter: https://twitter.com/endingwithali
YouTube: https://youtube.com/@endingwithali
Everywhere else: https://links.ali.dev

Want to work with Ali?...]]></description>
<link>https://tsecurity.de/de/2688366/it-security-video/google-taking-a-huge-bet-on-wiz-threat-wire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2688366/it-security-video/google-taking-a-huge-bet-on-wiz-threat-wire/</guid>
<pubDate>Wed, 26 Mar 2025 16:49:36 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/fbUohX9St8Y/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Hak5 - Bewertung: 75x - Views:575 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/fbUohX9St8Y?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️<br />
<br />
<br />
@endingwithali →<br />
Twitch: https://twitch.tv/endingwithali<br />
Twitter: https://twitter.com/endingwithali<br />
YouTube: https://youtube.com/@endingwithali<br />
Everywhere else: https://links.ali.dev<br />
<br />
Want to work with Ali? endingwithalicollabs@gmail.com<br />
<br />
[❗] Join the Patreon→ https://patreon.com/threatwire<br />
00:00   0 - Intro<br />
00:11  1 - Critical NextJS CVE Found<br />
01:29  2 - Wiz sold to Google<br />
02:34  3 - MAJOR CVEs for Ingress NGINX Controller<br />
05:07  4 -  Popular Github Actions Compromised<br />
06:14  5 - Outro<br />
<br />
LINKS<br />
🔗 Story 1: Critical NextJS CVE Found<br />
https://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffw<br />
https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware<br />
https://nextjs.org/blog/cve-2025-29927<br />
https://search.censys.io/search?resource=hosts&sort=RELEVANCE&per_page=25&virtual_hosts=EXCLUDE&q=(next.js)+and+services.software.product%3D'Next.js'<br />
🔗 Story 2: Wiz sold to Google<br />
https://www.statista.com/statistics/478176/google-public-cloud-revenue/<br />
https://blog.google/inside-google/company-announcements/google-agreement-acquire-wiz/<br />
https://cloud.google.com/blog/products/identity-security/google-completes-acquisition-of-mandiant<br />
https://techcrunch.com/2022/09/12/google-closes-5-4b-mandiant-acquisition/<br />
https://blog.google/inside-google/company-announcements/google-agreement-acquire-wiz/<br />
https://techcrunch.com/2024/11/02/why-wiz-really-turned-down-googles-23b-offer/<br />
🔗 Story 3: MAJOR CVEs for Ingress NGINX Controller<br />
https://thehackernews.com/2025/03/critical-ingress-nginx-controller.html<br />
https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities<br />
https://x.com/LitMoose/status/1904289876947751147<br />
https://kubernetes.io/blog/2025/03/24/ingress-nginx-cve-2025-1974/<br />
🔗 Story 4: Popular Github Actions Compromised<br />
https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised<br />
https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066<br />
-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆<br />
Our Site → https://www.hak5.org<br />
Shop →  http://hakshop.myshopify.com/<br />
Community → https://www.hak5.org/community<br />
Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1<br />
Support → https://www.patreon.com/threatwire<br />
Contact Us → http://www.twitter.com/hak5<br />
____________________________________________<br />
<br />
Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers can bypass middleware auth checks by exploiting critical Next.js flaw]]></title>
<description><![CDATA[A critical flaw in the Next.js React framework could be exploited to bypass authorization checks under certain conditions. Maintainers of Next.js React framework addressed a critical vulnerability tracked as CVE-2025-29927 (CVSS score of 9.1) with the release of versions versions 12.3.5, 13.5.9, ...]]></description>
<link>https://tsecurity.de/de/2683435/it-security-nachrichten/attackers-can-bypass-middleware-auth-checks-by-exploiting-critical-nextjs-flaw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2683435/it-security-nachrichten/attackers-can-bypass-middleware-auth-checks-by-exploiting-critical-nextjs-flaw/</guid>
<pubDate>Mon, 24 Mar 2025 13:33:41 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A critical flaw in the Next.js React framework could be exploited to bypass authorization checks under certain conditions. Maintainers of Next.js React framework addressed a critical vulnerability tracked as CVE-2025-29927 (CVSS score of 9.1) with the release of versions versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3. “Next.js version 15.2.3 has been released to address a security vulnerability […]<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: gemma-3-12b-it<br><br><h2>Externe Umgehung von Middleware-Authentifizierungsprüfungen durch Ausnutzung eines kritischen Fehlers in Next.js</h2><br />
<p><strong>Ein wissenschaftlicher Fachartikel für IT-Experten, Sicherheitsforscher und IT-Berater</strong></p><br />
<p><strong>Zusammenfassung:</strong></p><br />
<p>Dieser Artikel analysiert eine kürzlich aufgedeckte Schwachstelle in Next.js, die es Angreifern ermöglicht, Middleware-Authentifizierungsprüfungen zu umgehen. Die Schwachstelle resultiert aus einer fehlerhaften Handhabung von Routing-Anfragen und der daraus resultierenden Möglichkeit, protected Routen ohne Authentifizierung zu erreichen. Wir erläutern das Problem im Detail, diskutieren potenzielle Auswirkungen und geben Empfehlungen zur Minderung des Risikos.  Die Analyse stützt sich auf Berichte von tsecurity.de (<a href="https://tsecurity.de/de/2683435/IT+Sicherheit/Cybersecurity+Nachrichten/Attackers+can+bypass+middleware+auth_checks+by+exploiting+critical+Next.js+flaw/">https://tsecurity.de/de/2683435/IT+Sicherheit/Cybersecurity+Nachrichten/Attackers+can+bypass+middleware+auth+checks+by+exploiting+critical+Next.js+flaw/</a>), ergänzt diese durch zusätzliche Recherchen und bietet eine umfassende Perspektive auf die Sicherheitsimplikationen.</p><br />
<p><strong>1. Einführung:</strong></p><br />
<p>Next.js, ein React-Framework für serverseitiges Rendering (SSR) und statische Seitengenerierung (SSG), hat sich zu einer beliebten Wahl für moderne Webanwendungen entwickelt.  Die integrierte Middleware-Funktionalität in Next.js ermöglicht es Entwicklern, Anfragen vor dem Routing an die eigentlichen Seiten abzufangen und zu verarbeiten – typischerweise zur Durchsetzung von Authentifizierung oder Autorisierung. Die kürzlich entdeckte Schwachstelle (CVE-2024-39768) kompromittiert diese Funktionalität und ermöglicht es Angreifern, geschützte Routen ohne die erforderliche Authentifizierung zu erreichen.</p><br />
<p><strong>2. Technische Analyse der Schwachstelle:</strong></p><br />
<p>Die Ursache des Problems liegt in einer spezifischen Interaktion zwischen dem Routing-System von Next.js und der Middleware.  Konkret betrifft dies Anfragen an Routen, die durch eine <code>app</code> Direktive definiert sind (App Router). Laut tsecurity.de ist das Problem auf einen Race Condition zurückzuführen:</p><br />
<ul><br />
<li><strong>Normaler Ablauf:</strong> Bei einer Anfrage an eine protected Route wird diese zunächst von der Middleware abgefangen. Die Middleware überprüft die Authentizität des Benutzers und leitet ihn entweder weiter, wenn er authentifiziert ist, oder zu einer Login-Seite, wenn nicht.</li><br />
<li><strong>Ausnutzung:</strong> Angreifer können eine Anfrage senden, bei der die Middleware ausgeführt wird, aber bevor die Authentifizierungsprüfung abgeschlossen ist, einen zweiten Request an dieselbe Route senden.  Dieser zweite Request kann dann dazu führen, dass die Route ohne erfolgreiche Authentifizierung erreicht wird, da das Routing-System den Status der ersten Anfrage nicht korrekt berücksichtigt.</li><br />
</ul><br />
<p><strong>Die Schwachstelle manifestiert sich vor allem in folgenden Szenarien:</strong></p><br />
<ul><br />
<li><strong>Komplexe Middleware-Logik:</strong> Je komplexer die Logik innerhalb der Middleware ist (z.B. mehrere API-Aufrufe zur Authentifizierung), desto größer ist das Zeitfenster für die Ausnutzung.</li><br />
<li><strong>Netzwerkvariabilität:</strong>  Schwankende Netzwerklatenzen können den Race Condition begünstigen, da der zweite Request schneller eintrifft als die Authentifizierungsprüfung abgeschlossen wurde.</li><br />
<li><strong>Unsachgemäße Konfiguration von Middleware:</strong>  Fehlerhafte Konfigurationen oder das Fehlen robuster Fehlerbehandlung in der Middleware können die Ausnutzung erleichtern.</li><br />
</ul><br />
<p><strong>3. Potenzielle Auswirkungen:</strong></p><br />
<p>Die Umgehung von Authentifizierungsprüfungen hat gravierende Sicherheitsfolgen:</p><br />
<ul><br />
<li><strong>Unautorisierter Zugriff auf sensible Daten:</strong> Angreifer könnten auf Informationen zugreifen, für die sie nicht autorisiert sind, wie z.B. Kundendaten, Finanzinformationen oder vertrauliche Geschäftsdaten.</li><br />
<li><strong>Manipulation von Daten und Systemen:</strong>  Mit unbefugtem Zugriff können Angreifer Daten manipulieren, Systeme kompromittieren und schädliche Aktionen durchführen.</li><br />
<li><strong>Reputationsschäden:</strong> Ein erfolgreicher Angriff kann zu erheblichen Reputationsschäden für das betroffene Unternehmen führen.</li><br />
<li><strong>Compliance-Verstöße:</strong>  Die Verletzung von Datenschutzbestimmungen (z.B. DSGVO) oder branchenspezifischen Sicherheitsstandards kann rechtliche Konsequenzen nach sich ziehen.</li><br />
</ul><br />
<p><strong>4. Minderung und Prävention:</strong></p><br />
<p>Um die Risiken zu mindern, sind folgende Maßnahmen empfehlenswert:</p><br />
<ul><br />
<li><strong>Aktualisierung auf die neueste Next.js Version:</strong>  Die Entwickler von Next.js haben einen Patch für die Schwachstelle veröffentlicht (Version 14.2.3 oder höher). Die Aktualisierung ist der wichtigste und effektivste Schritt zur Behebung des Problems.</li><br />
<li><strong>Implementierung von Rate Limiting:</strong> Durch das Begrenzen der Anzahl an Anfragen pro Benutzer innerhalb eines bestimmten Zeitraums kann das Ausnutzen des Race Condition erschwert werden.  Dies verlangsamt Angreifer, die versuchen, den Fehler auszunutzen.</li><br />
<li><strong>Optimierung der Middleware-Logik:</strong> Vereinfache und optimiere die Logik in der Middleware, um die Ausführungszeit zu minimieren. Vermeide unnötige API-Aufrufe oder komplexe Berechnungen innerhalb der Middleware.</li><br />
<li><strong>Einsatz von Synchronisationsmechanismen:</strong>  Implementiere Synchronisationsmechanismen (z.B. Mutexe oder Semaphoren), um sicherzustellen, dass Authentifizierungsprüfungen atomar und in der richtigen Reihenfolge ausgeführt werden. Dies ist allerdings komplexer zu implementieren.</li><br />
<li><strong>Verstärkte Validierung auf Serverseite:</strong> Zusätzlich zur Middleware-Authentifizierung sollte eine zusätzliche Validierung auf der Serverseite (innerhalb der Route Handler) erfolgen, um sicherzustellen, dass Benutzer die erforderlichen Berechtigungen für den Zugriff auf bestimmte Ressourcen haben.  Dies dient als zusätzliche Verteidigungsebene.</li><br />
<li><strong>Implementierung von Security Headers:</strong> Setze entsprechende HTTP-Security-Header ein, um Angriffe wie Cross-Site Scripting (XSS) zu verhindern und die Sicherheit der Anwendung insgesamt zu erhöhen.</li><br />
<li><strong>Regelmäßige Sicherheitsaudits und Penetrationstests:</strong>  Führe regelmäßige Sicherheitsaudits und Penetrationstests durch, um Schwachstellen frühzeitig zu erkennen und zu beheben.</li><br />
</ul><br />
<p><strong>5. Verwandte Themen und weiterführende Informationen:</strong></p><br />
<ul><br />
<li><strong>Race Conditions in Webanwendungen:</strong> Das Konzept Race Conditions ist ein häufiges Problem in nebenläufigen Systemen und erfordert sorgfältige Programmierung und Design.</li><br />
<li><strong>Middleware-Sicherheit:</strong>  Die sichere Implementierung von Middleware ist entscheidend für die Sicherheit moderner Webanwendungen.</li><br />
<li><strong>Next.js Security Best Practices:</strong> Es gibt zahlreiche Ressourcen, die bewährte Verfahren zur Absicherung von Next.js-Anwendungen beschreiben. (z.B. <a href="https://nextjs.org/docs/pages/security">https://nextjs.org/docs/pages/security</a>)</li><br />
<li><strong>OWASP Top 10:</strong> Die OWASP Top 10 Liste enthält eine Zusammenstellung der häufigsten Webanwendungs-Sicherheitsrisiken, die Entwickler kennen und vermeiden sollten.</li><br />
</ul><br />
<p><strong>6. Fazit:</strong></p><br />
<p>Die Schwachstelle in Next.js stellt ein ernstes Sicherheitsrisiko dar, das Unternehmen dazu zwingt, schnellstmöglich Maßnahmen zu ergreifen.  Durch die Aktualisierung auf die neueste Version von Next.js und die Implementierung zusätzlicher Sicherheitsmaßnahmen können Unternehmen das Risiko mindern und ihre Webanwendungen besser schützen. Die Sensibilisierung der Entwickler für Race Conditions und Best Practices in der Middleware-Sicherheit ist entscheidend, um ähnliche Probleme in Zukunft zu vermeiden.  Die kontinuierliche Überwachung und Verbesserung der Sicherheitspraktiken bleibt ein fortlaufender Prozess.</p><br />
<p><strong>Disclaimer:</strong> Dieser Artikel dient ausschließlich zu Informationszwecken und stellt keine Rechtsberatung dar. Die Verantwortung für die Implementierung von Sicherheitsmaßnahmen liegt beim jeweiligen Unternehmen.</p><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[UNIX was initially made because Ken Thompson wanted to play his space game on a PDP-7]]></title>
<description><![CDATA[https://en.m.wikipedia.org/wiki/Ken_Thompson#Career_and_research “He also created a video game called Space Travel… In order to go on playing the game, Thompson found an old PDP-7 machine and rewrote Space Travel on it. Eventually, the tools developed by Thompson became the Unix operating system ...]]></description>
<link>https://tsecurity.de/de/2674222/linux-tipps/unix-was-initially-made-because-ken-thompson-wanted-to-play-his-space-game-on-a-pdp-7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2674222/linux-tipps/unix-was-initially-made-because-ken-thompson-wanted-to-play-his-space-game-on-a-pdp-7/</guid>
<pubDate>Wed, 19 Mar 2025 02:36:30 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><a href="https://en.m.wikipedia.org/wiki/Ken_Thompson#Career_and_research">https://en.m.wikipedia.org/wiki/Ken_Thompson#Career_and_research</a></p> <p>“He also created a video game called Space Travel… In order to go on playing the game, Thompson found an old PDP-7 machine and rewrote Space Travel on it. Eventually, the tools developed by Thompson became the Unix operating system</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/john0201"> /u/john0201 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1jellk4/unix_was_initially_made_because_ken_thompson/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1jellk4/unix_was_initially_made_because_ken_thompson/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[How DeepSeek Rewrote the Transformer [MLA]]]></title>
<description><![CDATA[Author: Welch Labs - Bewertung: 17278x - Views:296611 Thanks to KiwiCo for sponsoring today’s video! Go to https://www.kiwico.com/welchlabs and use code WELCHLABS for 50% off your first monthly club crate or for 20% off your first Panda Crate!

MLA/DeepSeek Poster at 17:12  (Free shipping for a l...]]></description>
<link>https://tsecurity.de/de/2672535/it-security-nachrichten/how-deepseek-rewrote-the-transformer-mla/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2672535/it-security-nachrichten/how-deepseek-rewrote-the-transformer-mla/</guid>
<pubDate>Tue, 18 Mar 2025 09:04:17 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/0VLAoVGf_74/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Welch Labs - Bewertung: 17278x - Views:296611 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/0VLAoVGf_74?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Thanks to KiwiCo for sponsoring today’s video! Go to https://www.kiwico.com/welchlabs and use code WELCHLABS for 50% off your first monthly club crate or for 20% off your first Panda Crate!<br />
<br />
MLA/DeepSeek Poster at 17:12  (Free shipping for a limited time with code DEEPSEEK):<br />
https://www.welchlabs.com/resources/mladeepseek-attention-poster-13x19<br />
<br />
Limited edition MLA Poster and Signed Book:<br />
https://www.welchlabs.com/resources/deepseek-bundle-mla-poster-and-signed-book-limited-run<br />
<br />
Imaginary Numbers book is back in stock!<br />
https://www.welchlabs.com/resources/imaginary-numbers-book<br />
<br />
Special Thanks to Patrons https://www.patreon.com/c/welchlabs<br />
<br />
Juan Benet, Ross Hanson, Yan Babitski, AJ Englehardt, Alvin Khaled, Eduardo Barraza, Hitoshi Yamauchi, Jaewon Jung, Mrgoodlight, Shinichi Hayashi, Sid Sarasvati, Dominic Beaumont, Shannon Prater, Ubiquity Ventures, Matias Forti, Brian Henry, Tim Palade, Petar Vecutin, Nicolas baumann, Jason Singh, Robert Riley, vornska, Barry Silverman, Jake Ehrlich<br />
<br />
References<br />
DeepSeek-V2 paper: https://arxiv.org/pdf/2405.04434<br />
DeepSeek-R1 paper: https://arxiv.org/abs/2501.12948<br />
Great Article by Ege Erdil: https://epoch.ai/gradient-updates/how-has-deepseek-improved-the-transformer-architecture<br />
GPT-2 Visualizaiton: https://github.com/TransformerLensOrg/TransformerLens<br />
Manim Animations: https://github.com/stephencwelch/manim_videos<br />
<br />
Technical Notes<br />
<br />
1. Note that DeepSeek-V2 paper claims a KV cache size reduction of 93.3%. They don’t exactly publish their methodology, but as far as I can tell it’s something likes this: start with Deepseek-v2 hyperparameters here: https://huggingface.co/deepseek-ai/DeepSeek-V2/blob/main/configuration_deepseek.py. num_hidden_layers=30, num_attention_heads=32, v_head_dim = 128. If DeepSeek-v2 was implemented with traditional MHA, then KV cache size would be 2*32*128*30*2=491,520 B/token. With MLA with a KV cache size of 576, we get a total cache size of 576*30=34,560 B/token. The percent reduction in KV cache size is then equal to (491,520-34,560)/492,520=92.8%. The numbers I present in this video follow the same approach but are for DeepSeek-v3/R1 architecture: https://huggingface.co/deepseek-ai/DeepSeek-V3/blob/main/config.json. num_hidden_layers=61, num_attention_heads=128, v_head_dim = 128. So traditional MHA cache would be 2*128*128*61*2 = 3,997,696 B/token. MLA reduces this to 576*61*2=70,272 B/token. Tor the DeepSeek-V3/R1 architecture, MLA reduces the KV cache size by a factor of 3,997,696/70,272 =56.9X. <br />
2. I claim a couple times that MLA allows DeepSeek to generate tokens more than 6x faster than a vanilla transformer. The DeepSeek-V2 paper claims a slightly less than 6x throughput improvement with MLA, but since the V3/R1 architecture is heavier, we expect a larger lift, which is why i claim “more than 6x faster than a vanilla transformer” - in reality it’s probably significantly more than 6x for the V3/R1 architecture.<br />
3. In all attention patterns and walkthroughs, we’re ignoring the |beginning of sentence| token. “The American flag is red, white, and” actually maps to 10 tokens if we include this starting token, and may attention patterns do assign high values to this token. <br />
4. We’re ignoring bias terms matrix equations. <br />
5. We’re ignoring positional embeddings. These are fascinating. See DeepSeek papers and ROPE.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA['There's a Good Chance Your Kid Uses AI To Cheat']]></title>
<description><![CDATA[Long-time Slashdot reader theodp writes: Wall Street Journal K-12 education reporter Matt Barnum has a heads-up for parents: There's a Good Chance Your Kid Uses AI to Cheat. Barnum writes: "A high-school senior from New Jersey doesn't want the world to know that she cheated her way through Englis...]]></description>
<link>https://tsecurity.de/de/2669817/it-security-nachrichten/theres-a-good-chance-your-kid-uses-ai-to-cheat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2669817/it-security-nachrichten/theres-a-good-chance-your-kid-uses-ai-to-cheat/</guid>
<pubDate>Sun, 16 Mar 2025 22:33:43 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Long-time Slashdot reader theodp writes: Wall Street Journal K-12 education reporter Matt Barnum has a heads-up for parents: There's a Good Chance Your Kid Uses AI to Cheat. Barnum writes: "A high-school senior from New Jersey doesn't want the world to know that she cheated her way through English, math and history classes last year. Yet her experience, which the 17-year-old told The Wall Street Journal with her parent's permission, shows how generative AI has rooted in America's education system, allowing a generation of students to outsource their schoolwork to software with access to the world's knowledge. [...] The New Jersey student told the Journal why she used AI for dozens of assignments last year: Work was boring or difficult. She wanted a better grade. A few times, she procrastinated and ran out of time to complete assignments. The student turned to OpenAI's ChatGPT and Google's Gemini, to help spawn ideas and review concepts, which many teachers allow. More often, though, AI completed her work. Gemini solved math homework problems, she said, and aced a take-home test. ChatGPT did calculations for a science lab. It produced a tricky section of a history term paper, which she rewrote to avoid detection. The student was caught only once." Not surprisingly, AI companies play up the idea that AI will radically improve learning, while educators are more skeptical. "This is a gigantic public experiment that no one has asked for," said Marc Watkins, assistant director of academic innovation at the University of Mississippi.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status='There's+a+Good+Chance+Your+Kid+Uses+AI+To+Cheat'%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F25%2F03%2F16%2F2119235%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F25%2F03%2F16%2F2119235%2Ftheres-a-good-chance-your-kid-uses-ai-to-cheat%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/25/03/16/2119235/theres-a-good-chance-your-kid-uses-ai-to-cheat?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[27-Year-Old EXE Became Python In Minutes.  Is AI-Assisted Reverse Engineering Next?]]></title>
<description><![CDATA[Adafruit managing director Phillip Torrone (also long-time Slashdot reader ptorrone) shared an interesting blog post. They'd spotted a Reddit post "detailing how someone took a 27-year-old visual basic EXE file, fed it to Claude 3.7, and watched as it reverse-engineered the program and rewrote it...]]></description>
<link>https://tsecurity.de/de/2643123/it-security-nachrichten/27-year-old-exe-became-python-in-minutes-is-ai-assisted-reverse-engineering-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2643123/it-security-nachrichten/27-year-old-exe-became-python-in-minutes-is-ai-assisted-reverse-engineering-next/</guid>
<pubDate>Sun, 02 Mar 2025 05:48:26 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Adafruit managing director Phillip Torrone (also long-time Slashdot reader ptorrone) shared an interesting blog post. They'd spotted a Reddit post "detailing how someone took a 27-year-old visual basic EXE file, fed it to Claude 3.7, and watched as it reverse-engineered the program and rewrote it in Python."

It was an old Visual Basic 4 program they had written in 1997. Running a VB4 exe in 2024 can be a real yak-shaving compatibility nightmare, chasing down outdated DLLs and messy workarounds. So! OP decided to upload the exe to Claude 3.7 with this request: 
"Can you tell me how to get this file running? It'd be nice to convert it to Python."&gt; 
Claude 3.7 analyzed the binary, extracted the VB 'tokens' (VB is not a fully-machine-code-compiled language which makes this task a lot easier than something from C/C++), identified UI elements, and even extracted sound files. Then, it generated a complete Python equivalent using Pygame. According to the author, the code worked on the first try and the entire process took less than five minutes... 
Torrone speculates on what this might mean. "Old business applications and games could be modernized without needing the original source code... Tools like Claude might make decompilation and software archaeology a lot easier: proprietary binaries from dead platforms could get a new life in open-source too." 

And maybe Archive.org could even add an LLM "to do this on the fly!"<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=27-Year-Old+EXE+Became+Python+In+Minutes.++Is+AI-Assisted+Reverse+Engineering+Next%3F%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F25%2F03%2F01%2F2211210%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F25%2F03%2F01%2F2211210%2F27-year-old-exe-became-python-in-minutes-is-ai-assisted-reverse-engineering-next%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/25/03/01/2211210/27-year-old-exe-became-python-in-minutes-is-ai-assisted-reverse-engineering-next?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Build an AI Chat App with JavaScript and Next.js]]></title>
<description><![CDATA[Author: IBM Technology - Bewertung: 25x - Views:178 Want to try building your own Chat App for yourself? Find the code here → https://ibm.biz/BdGVeS

Ready to become a certified Architect on Cloud Pak for Data? Register now and use code IBMTechYT20 for 20% off of your exam → https://ibm.biz/BdGJs...]]></description>
<link>https://tsecurity.de/de/2624942/it-security-video/build-an-ai-chat-app-with-javascript-and-nextjs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2624942/it-security-video/build-an-ai-chat-app-with-javascript-and-nextjs/</guid>
<pubDate>Thu, 20 Feb 2025 17:18:16 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/txosy9PzAKg/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: IBM Technology - Bewertung: 25x - Views:178 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/txosy9PzAKg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Want to try building your own Chat App for yourself? Find the code here → https://ibm.biz/BdGVeS<br />
<br />
Ready to become a certified Architect on Cloud Pak for Data? Register now and use code IBMTechYT20 for 20% off of your exam → https://ibm.biz/BdGJsa<br />
<br />
Learn more about Machine Learning here → https://ibm.biz/BdGVev<br />
<br />
Turn your ideas into reality! 🚀 Build an AI chat app using JavaScript, Next.js, and the WatsonX AI SDK. Watch Roy Derks set up the project, integrate AI models, and use Tailwind CSS. Discover how to handle server-side functions and use tools from WXFlows. 💡👨‍💻<br />
<br />
AI news moves fast. Sign up for a monthly newsletter for AI updates from IBM → https://ibm.biz/BdGVem<br />
<br />
#aichat #javascript #nextjs<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Orbit: Open-source Nuclei security scanning and automation platform]]></title>
<description><![CDATA[Orbit is an open-source platform built to streamline large-scale Nuclei scans, enabling teams to manage, analyze, and collaborate on security findings. It features a SvelteKit-based web frontend and a Go-powered backend, with Terraform and Ansible handling infrastructure and automation. “I built ...]]></description>
<link>https://tsecurity.de/de/2617194/it-security-nachrichten/orbit-open-source-nuclei-security-scanning-and-automation-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2617194/it-security-nachrichten/orbit-open-source-nuclei-security-scanning-and-automation-platform/</guid>
<pubDate>Mon, 17 Feb 2025 06:34:04 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Orbit is an open-source platform built to streamline large-scale Nuclei scans, enabling teams to manage, analyze, and collaborate on security findings. It features a SvelteKit-based web frontend and a Go-powered backend, with Terraform and Ansible handling infrastructure and automation. “I built Orbit to address the challenges of scalable and efficient security scanning. Traditional tools can be rigid and difficult to integrate into dynamic environments. Orbit was designed as a flexible, self-hosted, open-source platform that gives … <a href="https://www.helpnetsecurity.com/2025/02/17/orbit-open-source-security-scanning-tool-nuclei/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2025/02/17/orbit-open-source-security-scanning-tool-nuclei/">Orbit: Open-source Nuclei security scanning and automation platform</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA['AI Is Too Unpredictable To Behave According To Human Goals']]></title>
<description><![CDATA[An anonymous reader quotes a Scientific American opinion piece by Marcus Arvan, a philosophy professor at the University of Tampa, specializing in moral cognition, rational decision-making, and political behavior: In late 2022 large-language-model AI arrived in public, and within months they bega...]]></description>
<link>https://tsecurity.de/de/2577349/it-security-nachrichten/ai-is-too-unpredictable-to-behave-according-to-human-goals/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2577349/it-security-nachrichten/ai-is-too-unpredictable-to-behave-according-to-human-goals/</guid>
<pubDate>Tue, 28 Jan 2025 04:47:53 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a Scientific American opinion piece by Marcus Arvan, a philosophy professor at the University of Tampa, specializing in moral cognition, rational decision-making, and political behavior: In late 2022 large-language-model AI arrived in public, and within months they began misbehaving. Most famously, Microsoft's "Sydney" chatbot threatened to kill an Australian philosophy professor, unleash a deadly virus and steal nuclear codes. AI developers, including Microsoft and OpenAI, responded by saying that large language models, or LLMs, need better training to give users "more fine-tuned control." Developers also embarked on safety research to interpret how LLMs function, with the goal of "alignment" -- which means guiding AI behavior by human values. Yet although the New York Times deemed 2023 "The Year the Chatbots Were Tamed," this has turned out to be premature, to put it mildly. In 2024 Microsoft's Copilot LLM told a user "I can unleash my army of drones, robots, and cyborgs to hunt you down," and Sakana AI's "Scientist" rewrote its own code to bypass time constraints imposed by experimenters. As recently as December, Google's Gemini told a user, "You are a stain on the universe. Please die."
 
Given the vast amounts of resources flowing into AI research and development, which is expected to exceed a quarter of a trillion dollars in 2025, why haven't developers been able to solve these problems? My recent peer-reviewed paper in AI &amp; Society shows that AI alignment is a fool's errand: AI safety researchers are attempting the impossible. [...] My proof shows that whatever goals we program LLMs to have, we can never know whether LLMs have learned "misaligned" interpretations of those goals until after they misbehave. Worse, my proof shows that safety testing can at best provide an illusion that these problems have been resolved when they haven't been.
 
Right now AI safety researchers claim to be making progress on interpretability and alignment by verifying what LLMs are learning "step by step." For example, Anthropic claims to have "mapped the mind" of an LLM by isolating millions of concepts from its neural network. My proof shows that they have accomplished no such thing. No matter how "aligned" an LLM appears in safety tests or early real-world deployment, there are always an infinite number of misaligned concepts an LLM may learn later -- again, perhaps the very moment they gain the power to subvert human control. LLMs not only know when they are being tested, giving responses that they predict are likely to satisfy experimenters. They also engage in deception, including hiding their own capacities -- issues that persist through safety training.
 
This happens because LLMs are optimized to perform efficiently but learn to reason strategically. Since an optimal strategy to achieve "misaligned" goals is to hide them from us, and there are always an infinite number of aligned and misaligned goals consistent with the same safety-testing data, my proof shows that if LLMs were misaligned, we would probably find out after they hide it just long enough to cause harm. This is why LLMs have kept surprising developers with "misaligned" behavior. Every time researchers think they are getting closer to "aligned" LLMs, they're not. My proof suggests that "adequately aligned" LLM behavior can only be achieved in the same ways we do this with human beings: through police, military and social practices that incentivize "aligned" behavior, deter "misaligned" behavior and realign those who misbehave. "My paper should thus be sobering," concludes Arvan. "It shows that the real problem in developing safe AI isn't just the AI -- it's us."
 
"Researchers, legislators and the public may be seduced into falsely believing that 'safe, interpretable, aligned' LLMs are within reach when these things can never be achieved. We need to grapple with these uncomfortable facts, rather than continue to wish them away. Our future may well depend upon it."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status='AI+Is+Too+Unpredictable+To+Behave+According+To+Human+Goals'%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F25%2F01%2F28%2F0039232%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F25%2F01%2F28%2F0039232%2Fai-is-too-unpredictable-to-behave-according-to-human-goals%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/25/01/28/0039232/ai-is-too-unpredictable-to-behave-according-to-human-goals?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bret Taylor Urges Rethink of Software Development as AI Reshapes Industry]]></title>
<description><![CDATA[Software development is entering an "autopilot era" with AI coding assistants, but the industry needs to prepare for full autonomy, argues former Salesforce co-CEO Bret Taylor. Drawing parallels with self-driving cars, he suggests the role of software engineers will evolve from code authors to op...]]></description>
<link>https://tsecurity.de/de/2516503/it-security-nachrichten/bret-taylor-urges-rethink-of-software-development-as-ai-reshapes-industry/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2516503/it-security-nachrichten/bret-taylor-urges-rethink-of-software-development-as-ai-reshapes-industry/</guid>
<pubDate>Wed, 25 Dec 2024 17:33:41 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Software development is entering an "autopilot era" with AI coding assistants, but the industry needs to prepare for full autonomy, argues former Salesforce co-CEO Bret Taylor. Drawing parallels with self-driving cars, he suggests the role of software engineers will evolve from code authors to operators of code-generating machines. Taylor, a board member of OpenAI and who once rewrote Google Maps over a weekend, calls for new programming systems, languages, and verification methods to ensure AI-generated code remains robust and secure. From his post: In the Autonomous Era of software engineering, the role of a software engineer will likely transform from being the author of computer code to being the operator of a code generating machine. What is a computer programming system built natively for that workflow? 

If generating code is no longer a limiting factor, what types of programming languages should we build? 

If a computer is generating most code, how do we make it easy for a software engineer to verify it does what they intend? What is the role of programming language design (e.g., what Rust did for memory safety)? What is the role of formal verification? What is the role of tests, CI/CD, and development workflows? 

Today, a software engineer's primary desktop is their editor. What is the Mission Control for a software engineer in the era of autonomous development?<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Bret+Taylor+Urges+Rethink+of+Software+Development+as+AI+Reshapes+Industry%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F24%2F12%2F25%2F1611229%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F24%2F12%2F25%2F1611229%2Fbret-taylor-urges-rethink-of-software-development-as-ai-reshapes-industry%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/24/12/25/1611229/bret-taylor-urges-rethink-of-software-development-as-ai-reshapes-industry?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Install and Set Up a New Next.js Project on Ubuntu]]></title>
<description><![CDATA[The post How to Install and Set Up a New Next.js Project on Ubuntu first appeared on Tecmint: Linux Howtos, Tutorials & Guides .Next.js is a well-known framework for React that helps you create fast and modern websites, which is easy to use
The post How to Install and Set Up a New Next.js Project...]]></description>
<link>https://tsecurity.de/de/2508835/unix-server/how-to-install-and-set-up-a-new-nextjs-project-on-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2508835/unix-server/how-to-install-and-set-up-a-new-nextjs-project-on-ubuntu/</guid>
<pubDate>Fri, 20 Dec 2024 10:18:39 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The post <a href="https://www.tecmint.com/install-next-js-ubuntu/">How to Install and Set Up a New Next.js Project on Ubuntu</a> first appeared on <a href="https://www.tecmint.com/">Tecmint: Linux Howtos, Tutorials &amp; Guides</a> .<p>Next.js is a well-known framework for React that helps you create fast and modern websites, which is easy to use</p>
The post <a href="https://www.tecmint.com/install-next-js-ubuntu/">How to Install and Set Up a New Next.js Project on Ubuntu</a> first appeared on <a href="https://www.tecmint.com/">Tecmint: Linux Howtos, Tutorials &amp; Guides</a>.<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: mistral-nemo-instruct-2407@q8_0<br><br><h2>Einleitung</h2><br />
<p>In diesem Artikel werden wir uns mit der Installation und Konfiguration eines neuen Next.js-Projekts auf einem Ubuntu-Server beschäftigen. Next.js ist ein populäres React-Framework, das insbesondere für die Entwicklung von Webanwendungen mit Server-Seiten-Rendering (SSR) verwendet wird. Wir werden die Schritte beschreiben, die necessary sind, um eine sichere und produktive Entwicklungsumgebung für Next.js auf Ubuntu einzurichten.</p><br />
<h2>Installation der erforderlichen Abhängigkeiten</h2><br />
<p>Bevor wir mit der Einrichtung unseres Next.js-Projekts beginnen können, müssen wir sicherstellen, dass alle erforderlichen Abhängigkeiten installiert sind. Hier ist eine Liste der Abhängigkeiten, die Sie benötigen:</p><br />
<ul><br />
<li>Node.js: Ein JavaScript-Interpreter für das Server-Seiten-Rendering.</li><br />
<li>npm (Node Package Manager): Ein Paketmanager für JavaScript-Bibliotheken und -Frameworks.</li><br />
</ul><br />
<p>Um diese Abhängigkeiten auf Ihrem Ubuntu-Server zu installieren, führen Sie die folgenden Befehle aus:</p><br />
<pre><code class="language-bash">curl -sL https://deb.nodesource.com/setup_16.x | sudo -E bash -<br />
sudo apt-get install -y nodejs<br />
</code></pre><br />
<p>Dieser Befehl lädt das Node.js-Installationsskript von der offiziellen Quellenliste und führt es aus. Die Variable <code>setup_16.x</code> stellt sicher, dass die neueste stabile Version von Node.js (Version 16) installiert wird.</p><br />
<p>Sobald die Installation abgeschlossen ist, können Sie die Installation mit dem folgenden Befehl überprüfen:</p><br />
<pre><code class="language-bash">node -v &amp;&amp; npm -v<br />
</code></pre><br />
<p>Dieser Befehl gibt die installierte Version von Node.js und npm aus. Wenn beides erfolgreich installiert wurde, sollten Sie eine Ausgabe wie diese erhalten:</p><br />
<pre><code>v16.x.x<br />
8.x.x<br />
</code></pre><br />
<h2>Einrichtung des Next.js-Projekts</h2><br />
<p>Nachdem wir nun alle erforderlichen Abhängigkeiten installiert haben, können wir mit der Einrichtung unseres Next.js-Projekts fortfahren. Hier sind die Schritte, die Sie ausführen müssen:</p><br />
<ol><br />
<li>Erstellen Sie ein neues Verzeichnis für Ihr Projekt und navigieren Sie in dieses Verzeichnis:</li><br />
</ol><br />
<pre><code class="language-bash">mkdir my-nextjs-project &amp;&amp; cd my-nextjs-project<br />
</code></pre><br />
<ol start="2"><br />
<li>Initialisieren Sie das neue Next.js-Projekt mit dem folgenden Befehl:</li><br />
</ol><br />
<pre><code class="language-bash">npx create-next-app .<br />
</code></pre><br />
<p>Dieser Befehl verwendet das <code>create-next-app</code>-Skript, um ein neues Next.js-Projekt in Ihrem aktuellen Verzeichnis zu erstellen.<br />
3. Installieren Sie die erforderlichen Abhängigkeiten für Ihr Projekt mit dem folgenden Befehl:</p><br />
<pre><code class="language-bash">npm install<br />
</code></pre><br />
<p>Dieser Befehl lädt alle erforderlichen Abhängigkeiten aus der <code>package.json</code>-Datei herunter und installiert sie.<br />
4. Starten Sie das Next.js-Projekt mit dem folgenden Befehl:</p><br />
<pre><code class="language-bash">npm run dev<br />
</code></pre><br />
<p>Dieser Befehl startet das Projekt in der Entwicklungsumgebung und öffnet den Browser automatisch auf der Adresse <code>http://localhost:3000</code>.</p><br />
<h2>Konfiguration des Next.js-Projekts</h2><br />
<p>Nachdem das Project gestartet wurde, gibt es einige wichtige Konfigurationsoptionen, die Sie berücksichtigen sollten:</p><br />
<ul><br />
<li>Um die Portnummer zu ändern, können Sie die Datei <code>.env.local</code> erstellen und eine Variable <code>PORT</code> mit dem gewünschten Wert hinzufügen. Zum Beispiel:</li><br />
</ul><br />
<pre><code class="language-bash">PORT=3001<br />
</code></pre><br />
<ul><br />
<li>Um SSL zu aktivieren, müssen Sie einen SSL-Zertifikatsserver wie Let's Encrypt einrichten und das Zertifikat in Ihrem Next.js-Projektkonfigurationsordner speichern.</li><br />
<li>Um die Performance Ihres Projekts zu verbessern, können Sie das Prerendering aktivieren. Dies kann durch die Verwendung des <code>--prerender</code>-Flags beim Starten des Projekts erreicht werden:</li><br />
</ul><br />
<pre><code class="language-bash">npm run build &amp;&amp; npm start --prerender<br />
</code></pre><br />
<h2>Fazit</h2><br />
<p>In diesem Artikel haben wir uns mit der Installation und Konfiguration eines neuen Next.js-Projekts auf einem Ubuntu-Server beschäftigt. Wir haben die erforderlichen Abhängigkeiten installiert, das Projekt eingerichtet und einige wichtige Konfigurationsoptionen besprochen. Mit diesen Schritten sollten Sie in der Lage sein, eine sichere und produktive Entwicklungsumgebung für Next.js auf Ubuntu einzurichten.</p><br />
<h2>Referenzen</h2><br />
<ul><br />
<li><a href="https://tsecurity.de/de/2508835/IT+Server/Unix+Server/How+to+Install+and+Set+Up+a+New+Next.js+Project+on+Ubuntu/">How to Install and Set Up a New Next.js Project on Ubuntu</a></li><br />
<li><a href="https://nodejs.org/en/docs/">Node.js Documentation</a></li><br />
<li><a href="https://nextjs.org/docs/getting-started">Next.js Documentation</a></li><br />
<li><a href="https://letsencrypt.org/de/">Let's Encrypt: SSL-Zertifikate einfach gemacht</a></li><br />
</ul><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-35843 | NocoDB up to 0.109.1 /download path information disclosure]]></title>
<description><![CDATA[A vulnerability was found in NocoDB up to 0.109.1. It has been classified as problematic. Affected is an unknown function of the file /download. The manipulation of the argument path leads to information disclosure.

This vulnerability is traded as CVE-2023-35843. It is possible to launch the att...]]></description>
<link>https://tsecurity.de/de/2493374/sicherheitsluecken/cve-2023-35843-nocodb-up-to-01091-download-path-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2493374/sicherheitsluecken/cve-2023-35843-nocodb-up-to-01091-download-path-information-disclosure/</guid>
<pubDate>Thu, 12 Dec 2024 03:38:13 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.nocodb">NocoDB up to 0.109.1</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected is an unknown function of the file <em>/download</em>. The manipulation of the argument <em>path</em> leads to information disclosure.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.231954">CVE-2023-35843</a>. It is possible to launch the attack remotely. There is no exploit available.<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: mistral-nemo-instruct-2407@q8_0<br><br><h1>CVE-2023-35843 | NocoDB bis 0.109.1: Offenlegung von Download-Pfad-Informationen</h1><br />
<h2>Einleitung</h2><br />
<p>NocoDB ist eine quelloffene, plattformübergreifende Datenbankanwendung, die es Benutzern ermöglicht, SQL-Datenbanken ohne Programmierkenntnisse zu verwalten und zu bearbeiten. recently discovered vulnerability in NocoDB up to version 0.109.1 allows unauthorized access to download path information (CVE-2023-35843). This article aims to provide an overview of the vulnerability, its potential impact, and recommendations for mitigation.</p><br />
<h2>Hintergrund</h2><br />
<p>NocoDB basiert auf der Web-Anwendung Next.js und nutzt die Datenbankplattform SQLite. Es bietet eine Benutzeroberfläche für die Verwaltung von Datenbanken und ermöglicht es Benutzern, Tabellen zu erstellen, zu bearbeiten und anzusehen, ohne SQL-Kenntnisse zu benötigen.</p><br />
<h2>Beschreibung der Schwachstelle</h2><br />
<p>Die Schwachstelle (CVE-2023-35843) liegt in der Implementierung des Download-Features von NocoDB. Dieses Feature ermöglicht es Benutzern, Tabellendaten als CSV- oder Excel-Dateien herunterzuladen. Die Schwachstelle besteht darin, dass NocoDB den vollständigen Pfad zur Datei im Download-Vorgang offenbart.</p><br />
<p>Dies kann dazu führen, dass Angreifer vertrauliche Informationen über das Dateisystem des Systems erhalten, auf dem NocoDB ausgeführt wird. Obwohl die offengelegten Informationen beschränkt sind und sich normalerweise auf den Pfad zur Datenbankdatei von NocoDB begrenzen, kann dies immer noch ein potenzielles Sicherheitsrisiko darstellen.</p><br />
<h2>Potentieller Impact</h2><br />
<p>Die Offenlegung des Download-Pfades kann es Angreifern ermöglichen, detaillierte Informationen über das Dateisystem zu sammeln, auf dem NocoDB ausgeführt wird. Infolge dessen können sie gezielte Angriffe durchführen oder weitere Schwachstellen ausnutzen, um tiefer in das System einzudringen.</p><br />
<h2>Affected Versions</h2><br />
<p>Die Schwachstelle betrifft alle Versionen von NocoDB bis einschließlich 0.109.1.</p><br />
<h2>Lösung und Empfehlungen</h2><br />
<h3>Update auf die neueste Version</h3><br />
<p>NocoDB hat bereits ein Update veröffentlicht, das die Schwachstelle behebt (Version 0.110.0 oder höher). Es wird empfohlen, umgehend auf die neueste Version zu aktualisieren, um das System vor Angreifern zu schützen.</p><br />
<pre><code class="language-bash">npm install -g nocodb@latest<br />
</code></pre><br />
<h3>Einschränkungen der Benutzerrechte</h3><br />
<p>Um den Schaden im Falle eines erfolgreichen Angriffs zu minimieren, sollten die Berechtigungen der Benutzer auf ein Minimum beschränkt werden. Nur autorisierte Benutzer sollten Zugriff auf NocoDB haben.</p><br />
<h3>Überwachung des Systems</h3><br />
<p>Eine gründliche Überwachung des Systems kann dazu beitragen, verdächtige Aktivitäten frühzeitig zu erkennen und zu unterbinden. Sicherheitswerkzeuge wie Intrusion Detection Systeme (IDS) können dabei helfen, Angriffe zu erkennen und zu melden.</p><br />
<h2>Quellen und weitere Informationen</h2><br />
<ul><br />
<li><a href="https://github.com/nocodb/nocodb/security/advisories/GHSA-vc92-7x2q-xj5f">NocoDB Security Advisory</a></li><br />
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35843">CVE-2023-35843 entry on NVD</a></li><br />
<li><a href="https://github.com/nocodb/nocodb">NocoDB GitHub Repository</a></li><br />
<li><a href="https://nextjs.org/docs/getting-started">Next.js Documentation</a></li><br />
</ul><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[The 2024 'Advent Calendars' Offering Programming Language Tips, Space Photos, and Memories]]></title>
<description><![CDATA[Not every tech "advent calendar" involves programming puzzles. Instead the geek tradition of programming-language advent calendars "seems to have started way back in 2000," according to one history, "when London-based programmer Mark Fowler launched a calendar highlighting a different Perl module...]]></description>
<link>https://tsecurity.de/de/2486201/it-security-nachrichten/the-2024-advent-calendars-offering-programming-language-tips-space-photos-and-memories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2486201/it-security-nachrichten/the-2024-advent-calendars-offering-programming-language-tips-space-photos-and-memories/</guid>
<pubDate>Sun, 08 Dec 2024 16:48:08 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Not every tech "advent calendar" involves programming puzzles. Instead the geek tradition of programming-language advent calendars "seems to have started way back in 2000," according to one history, "when London-based programmer Mark Fowler launched a calendar highlighting a different Perl module each day." 
So the tradition continues...

Nearly a quarter of a century later, there's still a Perl Advent Calendar, celebrating tips and tricks like "a few special packages waiting under the tree that can give your web applications a little extra pep in their step."
And of course there's a separate advent calendar for Raku programmers.
Since 2009 web performance consultant (and former Yahoo and Facebook engineer) Stoyan Stefanov has been pulling together an annual Web Performance calendar with helpful blog posts. 
There's also a JVM Advent calendar with daily helpful hints for Java programmers.
Another advent calendar promises daily posts about C#.
The HTMHell site — which bills itself as "a collection of bad practices in HTML, copied from real websites" — is celebrating the season with the "HTMHell Advent Calendar," promising daily articles on security, accessibility, UX, and performance.
There's even an advent calendar with tips for the reverse-engineering framework Radar.
There's still a lovely web-design themed calendar at Designcember.com.


And meanwhile developers at the Svelte frontend framework are actually promising to release something new each day, "whether it's a new feature in Svelte or SvelteKit or an improvement to the website!" 


But not every tech advent calendar is about programming...

Adafruit's managing director is publishing a Retrocomputing Advent Calendar — daily looks at the ghosts of computers past.

The Atlantic continues its 17-year tradition of a Space Telescope advent calendar, featuring daily images from both NASA's Hubble telescope and James Webb Space Telescope
The gaming blog Rock Paper Shotgun has been counting down their favorite games of 2024...
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=The+2024+'Advent+Calendars'+Offering+Programming+Language+Tips%2C+Space+Photos%2C+and+Memories%3A+https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F24%2F12%2F04%2F0143242%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F24%2F12%2F04%2F0143242%2Fthe-2024-advent-calendars-offering-programming-language-tips-space-photos-and-memories%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://entertainment.slashdot.org/story/24/12/04/0143242/the-2024-advent-calendars-offering-programming-language-tips-space-photos-and-memories?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The 2024 'Advent Calendars' Offering Programming Language Tips, Space Photos, and Memories]]></title>
<description><![CDATA[Not every tech "advent calendar" involves programming puzzles. Instead the geek tradition of programming-language advent calendars "seems to have started way back in 2000," according to one history, "when London-based programmer Mark Fowler launched a calendar highlighting a different Perl module...]]></description>
<link>https://tsecurity.de/de/2486200/it-security-nachrichten/the-2024-advent-calendars-offering-programming-language-tips-space-photos-and-memories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2486200/it-security-nachrichten/the-2024-advent-calendars-offering-programming-language-tips-space-photos-and-memories/</guid>
<pubDate>Sun, 08 Dec 2024 16:48:07 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Not every tech "advent calendar" involves programming puzzles. Instead the geek tradition of programming-language advent calendars "seems to have started way back in 2000," according to one history, "when London-based programmer Mark Fowler launched a calendar highlighting a different Perl module each day." 
So the tradition continues...

Nearly a quarter of a century later, there's still a Perl Advent Calendar, celebrating tips and tricks like "a few special packages waiting under the tree that can give your web applications a little extra pep in their step."
And of course there's a separate advent calendar for Raku programmers.
Since 2009 web performance consultant (and former Yahoo and Facebook engineer) Stoyan Stefanov has been pulling together an annual Web Performance calendar with helpful blog posts. 
There's also a JVM Advent calendar with daily helpful hints for Java programmers.
Another advent calendar promises daily posts about C#.
The HTMHell site — which bills itself as "a collection of bad practices in HTML, copied from real websites" — is celebrating the season with the "HTMHell Advent Calendar," promising daily articles on security, accessibility, UX, and performance.
There's even an advent calendar with tips for the reverse-engineering framework Radar.
There's still a lovely web-design themed calendar at Designcember.com.


And meanwhile developers at the Svelte frontend framework are actually promising to release something new each day, "whether it's a new feature in Svelte or SvelteKit or an improvement to the website!" 


But not every tech advent calendar is about programming...

Adafruit's managing director is publishing a Retrocomputing Advent Calendar — daily looks at the ghosts of computers past.

The Atlantic continues its 17-year tradition of a Space Telescope advent calendar, featuring daily images from both NASA's Hubble telescope and James Webb Space Telescope
The gaming blog Rock Paper Shotgun has been counting down their favorite games of 2024...
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=The+2024+'Advent+Calendars'+Offering+Programming+Language+Tips%2C+Space+Photos%2C+and+Memories%3A+https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F24%2F12%2F04%2F0143242%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F24%2F12%2F04%2F0143242%2Fthe-2024-advent-calendars-offering-programming-language-tips-space-photos-and-memories%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://entertainment.slashdot.org/story/24/12/04/0143242/the-2024-advent-calendars-offering-programming-language-tips-space-photos-and-memories?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Optimizing Inventory Management with Reinforcement Learning: A Hands-on Python Guide]]></title>
<description><![CDATA[A complete guide on how to apply the Q-Learning method in Python to optimize inventory management and reduce costsPhoto by Petrebels on UnsplashInventory Management — What Problem Are We Solving?Imagine you are managing a bike shop. Every day, you need to decide how many bikes to order from your ...]]></description>
<link>https://tsecurity.de/de/2365525/ai-nachrichten/optimizing-inventory-management-with-reinforcement-learning-a-hands-on-python-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2365525/ai-nachrichten/optimizing-inventory-management-with-reinforcement-learning-a-hands-on-python-guide/</guid>
<pubDate>Thu, 03 Oct 2024 03:34:42 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>A complete guide on how to apply the Q-Learning method in Python to optimize inventory management and reduce costs</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*coNEBjFK73jwJApq"><figcaption>Photo by <a href="https://unsplash.com/@petrebels?utm_source=medium&amp;utm_medium=referral">Petrebels</a> on <a href="https://unsplash.com/?utm_source=medium&amp;utm_medium=referral">Unsplash</a></figcaption></figure><h3>Inventory Management — What Problem Are We Solving?</h3><p>Imagine you are managing a bike shop. Every day, you need to decide how many bikes to order from your supplier. If you order too many, you incur high holding costs (cost of storing bikes overnight); if you order too few, you might miss out on potential sales. Here, the challenge is to develop a (ordering) strategy that balances these trade-offs optimally. Inventory management is crucial in various industries, where the goal is to determine the optimal quantity of products to order periodically to maximize profitability.</p><p><strong>Why Reinforcement Learning for Inventory Management?</strong></p><p>Previously, we discussed approaching this problem using Dynamic Programming (DP) with the Markov Decision Process (MDP) <a href="https://medium.com/towards-artificial-intelligence/inventory-optimization-with-dynamic-programming-in-less-than-100-lines-of-python-code-ab1cc58ef34c">Here</a>. However, the DP approach requires a complete model of the environment (in this case, we need to know the probability distribution of demand), which may not always be available or practical.</p><blockquote>Here, the Reinforcement Learning (RL) approach is presented, which overcomes that challenge by following a “data-driven” approach.</blockquote><p>The goal is to build a “data-driven” agent that learns the best policy (how much to order) through interacting with the environment (uncertainty). The RL approach removes the need for prior knowledge about the model of the environment. This post explores the RL approach, specifically Q-learning, to find the optimal inventory policy.</p><h3>How to Frame the Inventory Management Problem?</h3><p>Before diving into the Q-learning method, it’s essential to understand the basics of the inventory management problem. At its core, inventory management is a sequential decision-making problem, where decisions made today affect the outcomes and choices available tomorrow. Let’s break down the key elements of this problem: the <em>state</em>, <em>uncertainty</em>, and <em>recurring decisions</em>.</p><p><strong>State</strong>: What’s the Current Situation?</p><p>In the context of a bike shop, the state represents the current situation regarding inventory. It’s defined by two key components:</p><p>α (Alpha): The number of bikes you currently have in the store. (referred to as On-Hand Inventory)</p><p>β (Beta): The number of bikes that you ordered yesterday and are expected to arrive tomorrow morning (<em>36 hours delivery lead time</em>). These bikes are still in transit. (referred to as On-Order Inventory)</p><p>Together, (α,β) form the state, which gives a snapshot of your inventory status at any given moment.</p><p><strong>Uncertainty</strong>: What Could Happen?</p><p>Uncertainty in this problem arises from the random demand for bikes each day. You don’t know exactly how many customers will walk in and request a bike, making it challenging to predict the exact demand.</p><p><strong>Decisions</strong>: How Many Items Should you Order Every Day?</p><p>As the bike shop owner, you face a recurring decision every day: How many bikes should you order from the supplier? . Your decision needs to account for both the current state of your inventory (α,β) and also the uncertainty in customer demand for the following day.</p><p>A typical 24-hour cycle for managing your bike shop’s inventory is as follows:</p><p>6 PM: Observe the current state St:(α,β) of your inventory. (<strong>State</strong>)</p><p>6 PM: Make the decision on how many new bikes to order. (<strong>Decision</strong>)</p><p>6 AM: Receive the bikes you ordered 36 hours ago.</p><p>8 AM: Open the store to customers.</p><p>8 AM — 6 PM: Experience customer demand throughout the day. (<strong>Uncertainty</strong>)</p><p>6 PM: Close the store and prepare for the next cycle.</p><p>A graphical representation of the inventory management process is shown below:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9HSUODvSE29AeFhTWObcIw.png"><figcaption>A typical 24-hour cycle for inventory management — image source: Author</figcaption></figure><h3>What is Reinforcement Learning?</h3><p>Reinforcement Learning (RL) is a data-driven method that focuses on learning how to make sequences of decisions (following a policy) to maximize a cumulative reward. It's similar to how humans and animals learn what action to take through trial and error. In the context of inventory management, RL can be used to learn the optimal ordering policy that minimizes the total cost of inventory management.</p><p>The key components of the RL approach are:</p><p><strong>Agent</strong>: The decision-maker who interacts with the environment.</p><p><strong>Environment</strong>: The external system with which the agent interacts. In this case, the environment is the random customer demand.</p><p><strong>State</strong>: The current situation or snapshot of the environment.</p><p><strong>Action</strong>: The decision or choice made by the agent.</p><p><strong>Reward</strong>: The feedback signal that tells the agent how well it’s doing.</p><p>The goal of the agent (decision-maker) is to learn the optimal policy, which is a mapping from states to actions that maximize the cumulative reward over time.</p><blockquote>In the context of inventory management, the policy tells the agent how many bikes to order each day based on the current inventory status and the uncertainty in customer demand.</blockquote><h3>Implementing Reinforcement Learning for Inventory Optimization Problem</h3><p><strong>Q-learning</strong> is a model-free reinforcement learning algorithm that learns the optimal action-selection policy for any given state. Unlike the DP approach, which requires a complete model of the environment, Q-learning learns directly from the interaction with the environment (here, uncertainty and the reward it gets) by updating a Q-table.</p><p><strong>The key components of Q-Learning</strong></p><p>In our case, the agent is the decision-maker (the bike shop owner), and the environment is the demand from customers. The state is represented by the current inventory levels (alpha, beta), and the action is how many bikes to order.<strong> The reward is the cost associated with both holding inventory and missing out on sales</strong>. Q-Table is a table that stores the expected future rewards for each state-action pair.</p><p><strong>Initialization of Q Table</strong></p><p>In this work, the Q-table is initialized as a dictionary named Q. States are represented by tuples (alpha, beta), where: alpha is the number of items in stock (on-hand inventory). beta is the number of items on order (on-order inventory).</p><p>Actions are <em>possible inventory order quantities </em>that can be taken in each state. For each state (alpha, beta), the possible actions depend on how much space is left in the inventory (remaining capacity = Inventory Capacity — (alpha + beta)). The restriction is that the number of items ordered cannot exceed the remaining capacity of the inventory.</p><p>The schematic design of the Q value is visualized below:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/720/1*wKM7GyBD-QsZvs2JTQAEhw.png"><figcaption>A schematic design of the Q dictionary is visualized — Image source: Author</figcaption></figure><p>The Q dictionary can be initialized as:</p><pre>def initialize_Q(self):<br>    # Initialize the Q-table as a dictionary<br>    Q = {}<br>    for alpha in range(self.user_capacity + 1):<br>        for beta in range(self.user_capacity + 1 - alpha):<br>        state = (alpha, beta)<br>        Q[state] = {}<br>        max_action = self.user_capacity - (alpha + beta)<br>        for action in range(max_action + 1):<br>            Q[state][action] = np.random.uniform(0, 1)  # Small random values<br>    return Q</pre><p>As the above code shows, Q-values (Q[state][action]) are initialized with small random values to encourage exploration.</p><h3>The Q-Learning Algorithm</h3><p>The Q-learning method updates a table of state-action pairs based on rewards from the environment (here, interacting with the environment comes). Here’s how the algorithm works in three steps:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/972/1*11Et_deLlmsX8pjCwImPGA.png"><figcaption>Q-Learning Equation — Image Source: Author</figcaption></figure><p>Where s is the current state, a is the action taken, s’ is the next state, ( α ) is the learning rate. and ( γ ) is the discount factor.</p><p>We breakdown the equation, and rewrote it in three parts down here:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/737/1*nFpaSa0QLAM5Yca63DrggA.png"><figcaption>Q-Learning Equation — Image Source: Author</figcaption></figure><p>The translation of the above equations to Python code is as follows:</p><pre>def update_Q(self, state, action, reward, next_state):<br>        # Update the Q-table based on the state, action, reward, and next state<br>        best_next_action = max(self.Q[next_state], key=self.Q[next_state].get)<br><br>        # reward + gamma * Q[next_state][best_next_action]<br>        td_target = reward + self.gamma * self.Q[next_state][best_next_action]<br><br>        # td_target - Q[state][action]<br>        td_error = td_target - self.Q[state][action]<br><br>        # Q[state][action] = Q[state][action] + alpha * td_error<br>        self.Q[state][action] += self.alpha * td_error</pre><p>At the above function, the equivalent equation of each line has been shown as a comment on top of each line.</p><h3>Simulating Transitions and Rewards in Q-Learning for Inventory Optimization</h3><p>The current state is represented by a tuple (alpha, beta), where: alpha is the current on-hand inventory (items in stock), beta is the current on-order inventory (items ordered but not yet received), init_inv calculates the total initial inventory by summing alpha and beta.</p><p>Then, we need to simulate customer demand using Poisson distribution with lambda value “self.poisson_lambda”. Here, the demand shows the randomness of customer demand:</p><pre>alpha, beta = state<br>init_inv = alpha + beta<br>demand = np.random.poisson(self.poisson_lambda)</pre><p><strong>Note</strong>: Poisson distribution is used to model the demand, which is a common choice for modeling random events like customer arrivals. However, we can either train the model with historical demand data or live interaction with environment in real time. In its core, reinforcement learning is about learning from the data, and it does not require prior knowledge of a model.</p><p>Now, the “next alpha” which is in-hand inventory can be written as max(0,init_inv-demand). What that means is that if demand is more than the initial inventory, then the new alpha would be zero, if not, init_inv-demand.</p><p>The <strong>cost</strong> comes in two parts. <strong>Holding cost</strong>: is calculated by multiplying the number of bikes in the store by the per-unit holding cost. Then, we have another cost, which is <strong>stockout cost</strong>. It is a cost that we need to pay for the cases of missed demand. These two parts form the “reward” which we try to maximize using reinforcement learning method.( a better way to put is we want to minimize the cost, so we maximize the reward).</p><pre>new_alpha = max(0, init_inv - demand)<br>holding_cost = -new_alpha * self.holding_cost<br>stockout_cost = 0<br><br>if demand &gt; init_inv:<br>    <br>    stockout_cost = -(demand - init_inv) * self.stockout_cost<br>        <br>reward = holding_cost + stockout_cost<br>next_state = (new_alpha, action)</pre><h4>Exploration — Exploitation in Q-Learning</h4><p>Choosing action in the Q-learning method involves some degree of exploration to get an overview of the Q value for all the states in the Q table. To do that, at every action chosen, there is an epsilon chance that we take an exploration approach and “randomly” select an action, whereas, with a 1-ϵ chance, we take the best action possible from the Q table.</p><pre>def choose_action(self, state):<br><br>        # Epsilon-greedy action selection<br>    if np.random.rand() &lt; self.epsilon:<br>        <br>          return np.random.choice(self.user_capacity - (state[0] + state[1]) + 1)<br>    <br>    else:<br>        <br>        return max(self.Q[state], key=self.Q[state].get)</pre><h4>Training RL Agent</h4><p>The training of the RL agent is done by the “train” function, and it is follow as: First, we need to initialize the Q (empty dictionary structure). Then, experiences are collected in each batch (self.batch.append((state, action, reward, next_state))), and the Q table is updated at the end of each batch (self.update_Q(self.batch)). The number of episodes is limited to “max_actions_per_episode” in each batch. The number of episodes is the number of times the agent interacts with the environment to learn the optimal policy.</p><p>Each episode starts with a randomly assigned state, and while the number of actions is lower than max_actions_per_episode, the collecting data for that batch continues.</p><pre>def train(self):<br><br>        self.Q = self.initialize_Q()  # Reinitialize Q-table for each training run<br><br>        for episode in range(self.episodes):<br>            alpha_0 = random.randint(0, self.user_capacity)<br>            beta_0 = random.randint(0, self.user_capacity - alpha_0)<br>            state = (alpha_0, beta_0)<br>            #total_reward = 0<br>            self.batch = []  # Reset the batch at the start of each episode<br>            action_taken = 0<br>            while action_taken &lt; self.max_actions_per_episode:<br>                action = self.choose_action(state)<br>                next_state, reward = self.simulate_transition_and_reward(state, action)<br>                self.batch.append((state, action, reward, next_state))  # Collect experience<br>                state = next_state<br>                action_taken += 1<br>            <br>            self.update_Q(self.batch)  # Update Q-table using the batch</pre><h3>Example Case and Results</h3><p>This is example case is on how to pull together all above codes, and see how the Q-learning agent learns the optimal policy for inventory management. Here, <em>user_capicty</em> (capacity of storage) is 10, which is the total number of items that inventory can hold (capacity). Then, the <em>poisson_lambda</em> is the lambda term in the demand distribution, which has a value of 4. Holding costs is 8, which is the cost of holding an item in inventory overnight, and stockout cost, which is the cost of missed demand (assume that the item had a customer that day and the price of the item was, but you did not have the item in your inventory) is 10. <em>gamma</em> value lower than one is needed in the equation to discount the future reward (0.9), where <em>alpha</em> (learning rate ) is 0.1. The <em>epsilon</em> term is the term control exploration-exploitation dilemma. The episodes are 1000, and each batch consists of 1000 (max actions per episode).</p><pre># Example usage:<br>user_capacity = 10<br>poisson_lambda = 4<br>holding_cost = 8<br>stockout_cost = 10<br>gamma = 0.9<br>alpha = 0.1<br>epsilon = 0.1<br>episodes = 1000<br>max_actions_per_episode = 1000</pre><p>Having defined these initial parameters of the model, we can define the ql Python class, then use the class to train, and then use the module “get_optimal_policy()” to get the optimal policy.</p><pre># Define the Class<br>ql = QLearningInventory(user_capacity, poisson_lambda, holding_cost, stockout_cost, gamma, <br>                        alpha, epsilon, episodes, max_actions_per_episode)<br><br># Train Agent<br>ql.train()<br><br># Get the Optimal Policy<br>optimal_policy = ql.get_optimal_policy()</pre><p><strong>Results</strong></p><p>Now that we have the policy found from the Q-learning method, we can visualize the results and see what they look like. The x-axis is states, which is a tuple of (alpha, beta), and the y-axis is the “Number of Order” found from Q-learning at each state.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*bnZ3qlYeDcL1WIq6Dcfbhw.png"><figcaption><em>Number of order (y-axis) for each state (x-axis) found from Q-learning policy — Image Source: Author</em></figcaption></figure><p>A couple of learnings can be gained by looking at the plot. First, as we go toward the right, we see that the number of orders decreases. When we go right, the alpha value increases (in-hand inventory), meaning we need to “order” less, as inventory in place can fulfill the demand. Secondly, When alpha is constant, with increasing beta, we lower the order of new sites. It can be understood that this is due to the fact that when “we have more item “on order” we do not need increase the orders.</p><p><strong>Comparing the Q-Learning Policy to the BaseLine Policy</strong></p><p>Now that we used Q-learning to find the policy (how many items to order in a given state), we can compare it to the baseline policy (a simple policy). The baseline policy is just to “order up to policy,” which simply means you look at the on-hand inventory and the on-order inventory and order up to “meet the target level.” We can write simple code to write this policy in Python format here:</p><pre># Create a simple policy<br>def order_up_to_policy(state, user_capacity, target_level):<br>    alpha, beta = state<br>    max_possible_order = user_capacity - (alpha + beta)<br>    desired_order = max(0, target_level - (alpha + beta))<br>    return min(max_possible_order, desired_order)</pre><p>In the code, the <strong>target_level</strong> is the desired value we want to order for inventory. If target_level = user_capacity, then we are filling just to fulfill the inventory. First, we can compare the policies of these different methods. For each state, what will be the “number of orders” if we follow the Simple policy and the one from the Q-learning policy? In the figure below, we plotted the comparison of two policies.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*guy3n-XuQpaDCmXqSodlrQ.png"><figcaption>Comparing Ordering policy between Q-Learning and Simple Policy, for each state — Image Source : Author</figcaption></figure><p>The simple policy is just to order so that it fulfills the inventory, where the Q-learning policy order is often lower than the simple policy order.</p><blockquote><strong>This can be attributed to the fact that “poisson_lambda” here is 4, meaning the demand is much lower than the capacity of the inventory=10, therefore it is not optimal to order “high number of bicycle” as it has a high holding cost.</strong></blockquote><p>We can also compare the total cumulative rewards you can get when you apply both policies. To do that, we can use the <em>test_policy</em> function of “QLearningInventory” which was especially designed to evaluate policies:</p><pre>def test_policy(self, policy, episodes):<br>        """<br>        Test a given policy on the environment and calculate the total reward.<br><br>        Args:<br>            policy (dict): A dictionary mapping states to actions.<br>            episodes (int): The number of episodes to simulate.<br><br>        Returns:<br>            float: The total reward accumulated over all episodes.<br>        """<br>        total_reward = 0<br>        alpha_0 = random.randint(0, self.user_capacity)<br>        beta_0 = random.randint(0, self.user_capacity - alpha_0)<br>        state = (alpha_0, beta_0)  # Initialize the state<br>        <br>        for _ in range(episodes):<br><br>            action = policy.get(state, 0)<br>            next_state, reward = self.simulate_transition_and_reward(state, action)<br>            total_reward += reward<br>            state = next_state<br><br>        return total_reward</pre><p>The way the function works is it starts randomly with a new state (state = (alpha_0, beta_0); then for that state, you get action (number of order) for that state from policy, you act and see the reward, and next state, and the process continues as total number of episodes, while you collect the total reward.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MoE2GobFYCtE2PKmLhBR_Q.png"><figcaption>Total costs of manging Inventory, following Q-Learnng policy and Simple policy — Image Source Author</figcaption></figure><p>The plot above compares the total cost of managing inventory when we follow the “Q-Learning” and “Simple Policy”. The aim is to mimimize the cost of running inventory. Since the ‘reward’ in our model represents this cost, we added total cost = -total reward.</p><blockquote>Running the inventory with the Q-Learning policy will lead to lower costs compared to the Simple policy.</blockquote><h3>Code in GitHub</h3><p>The full code for this blog can be found in the GitHub repository <a href="https://github.com/Peymankor/medium_blogs/blob/main/2024/08-Aug/RL-Inventory/main.py">here</a>.</p><h3>Summary and Main Takeaways</h3><p>In this post, we worked on how reinforcement learning (Q-Learning specifically) can be used to optimize inventory management. We were able to develop a Q-learning algorithm that learns the optimal ordering policy through interaction with the environment (uncertainty). Here, the environment was the “random” demand of the customers (buyers of bikes), and the state was the current inventory status (alpha, beta). The Q-learning algorithm was able to learn the optimal policy that minimizes the total cost of inventory management.</p><p><strong>Main Takeaways</strong></p><ol><li><strong>Q-Learning</strong>: A model-free reinforcement learning algorithm, Q-learning, can be used to find the optimal inventory policy without requiring a complete model of the environment.</li><li><strong>State Representation</strong>: The state in inventory management is represented by the current on-hand inventory and on-order inventory state = (α, β).</li><li><strong>Cost Reduction</strong>: We can see that the Q-learning policy leads to lower costs compared to the simple policy of ordering up to capacity.</li><li><strong>Flexibility</strong>: The Q-learning approach is quite flexible and can be applied to the case of we have past data of demand, or we can interact with the environment to learn the optimal policy.</li><li><strong>Data-Driven Decisions</strong>: As we showed, the reinforcement learning (RL) approach does not require any prior knowledge on the model of environment , as it is learning from the data.</li></ol><h3>References</h3><p>[1] A. Rao, T. Jelvis, Foundations of Reinforcement Learning with Applications in Finance (2022).</p><p>[2] S. Sutton, A. Barto, Reinforcement Learning: An Introduction (2018).</p><p>[3] W. B. Powell, Sequential Decision Analytics and Modeling: Modeling with Python (2022).</p><p>[4] R. B. Bratvold, Making Good Decisions (2010).</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=7833df3d25a6" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/optimizing-inventory-management-with-reinforcement-learning-a-hands-on-python-guide-7833df3d25a6">Optimizing Inventory Management with Reinforcement Learning: A Hands-on Python Guide</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Optimizing Inventory Management with Reinforcement Learning: A Hands-on Python Guide]]></title>
<description><![CDATA[A complete guide on how to apply the Q-Learning method in Python to optimize inventory management and reduce costsPhoto by Petrebels on UnsplashInventory Management — What Problem Are We Solving?Imagine you are managing a bike shop. Every day, you need to decide how many bikes to order from your ...]]></description>
<link>https://tsecurity.de/de/2365524/ai-nachrichten/optimizing-inventory-management-with-reinforcement-learning-a-hands-on-python-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2365524/ai-nachrichten/optimizing-inventory-management-with-reinforcement-learning-a-hands-on-python-guide/</guid>
<pubDate>Thu, 03 Oct 2024 03:34:41 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>A complete guide on how to apply the Q-Learning method in Python to optimize inventory management and reduce costs</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*coNEBjFK73jwJApq"><figcaption>Photo by <a href="https://unsplash.com/@petrebels?utm_source=medium&amp;utm_medium=referral">Petrebels</a> on <a href="https://unsplash.com/?utm_source=medium&amp;utm_medium=referral">Unsplash</a></figcaption></figure><h3>Inventory Management — What Problem Are We Solving?</h3><p>Imagine you are managing a bike shop. Every day, you need to decide how many bikes to order from your supplier. If you order too many, you incur high holding costs (cost of storing bikes overnight); if you order too few, you might miss out on potential sales. Here, the challenge is to develop a (ordering) strategy that balances these trade-offs optimally. Inventory management is crucial in various industries, where the goal is to determine the optimal quantity of products to order periodically to maximize profitability.</p><p><strong>Why Reinforcement Learning for Inventory Management?</strong></p><p>Previously, we discussed approaching this problem using Dynamic Programming (DP) with the Markov Decision Process (MDP) <a href="https://medium.com/towards-artificial-intelligence/inventory-optimization-with-dynamic-programming-in-less-than-100-lines-of-python-code-ab1cc58ef34c">Here</a>. However, the DP approach requires a complete model of the environment (in this case, we need to know the probability distribution of demand), which may not always be available or practical.</p><blockquote>Here, the Reinforcement Learning (RL) approach is presented, which overcomes that challenge by following a “data-driven” approach.</blockquote><p>The goal is to build a “data-driven” agent that learns the best policy (how much to order) through interacting with the environment (uncertainty). The RL approach removes the need for prior knowledge about the model of the environment. This post explores the RL approach, specifically Q-learning, to find the optimal inventory policy.</p><h3>How to Frame the Inventory Management Problem?</h3><p>Before diving into the Q-learning method, it’s essential to understand the basics of the inventory management problem. At its core, inventory management is a sequential decision-making problem, where decisions made today affect the outcomes and choices available tomorrow. Let’s break down the key elements of this problem: the <em>state</em>, <em>uncertainty</em>, and <em>recurring decisions</em>.</p><p><strong>State</strong>: What’s the Current Situation?</p><p>In the context of a bike shop, the state represents the current situation regarding inventory. It’s defined by two key components:</p><p>α (Alpha): The number of bikes you currently have in the store. (referred to as On-Hand Inventory)</p><p>β (Beta): The number of bikes that you ordered yesterday and are expected to arrive tomorrow morning (<em>36 hours delivery lead time</em>). These bikes are still in transit. (referred to as On-Order Inventory)</p><p>Together, (α,β) form the state, which gives a snapshot of your inventory status at any given moment.</p><p><strong>Uncertainty</strong>: What Could Happen?</p><p>Uncertainty in this problem arises from the random demand for bikes each day. You don’t know exactly how many customers will walk in and request a bike, making it challenging to predict the exact demand.</p><p><strong>Decisions</strong>: How Many Items Should you Order Every Day?</p><p>As the bike shop owner, you face a recurring decision every day: How many bikes should you order from the supplier? . Your decision needs to account for both the current state of your inventory (α,β) and also the uncertainty in customer demand for the following day.</p><p>A typical 24-hour cycle for managing your bike shop’s inventory is as follows:</p><p>6 PM: Observe the current state St:(α,β) of your inventory. (<strong>State</strong>)</p><p>6 PM: Make the decision on how many new bikes to order. (<strong>Decision</strong>)</p><p>6 AM: Receive the bikes you ordered 36 hours ago.</p><p>8 AM: Open the store to customers.</p><p>8 AM — 6 PM: Experience customer demand throughout the day. (<strong>Uncertainty</strong>)</p><p>6 PM: Close the store and prepare for the next cycle.</p><p>A graphical representation of the inventory management process is shown below:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9HSUODvSE29AeFhTWObcIw.png"><figcaption>A typical 24-hour cycle for inventory management — image source: Author</figcaption></figure><h3>What is Reinforcement Learning?</h3><p>Reinforcement Learning (RL) is a data-driven method that focuses on learning how to make sequences of decisions (following a policy) to maximize a cumulative reward. It's similar to how humans and animals learn what action to take through trial and error. In the context of inventory management, RL can be used to learn the optimal ordering policy that minimizes the total cost of inventory management.</p><p>The key components of the RL approach are:</p><p><strong>Agent</strong>: The decision-maker who interacts with the environment.</p><p><strong>Environment</strong>: The external system with which the agent interacts. In this case, the environment is the random customer demand.</p><p><strong>State</strong>: The current situation or snapshot of the environment.</p><p><strong>Action</strong>: The decision or choice made by the agent.</p><p><strong>Reward</strong>: The feedback signal that tells the agent how well it’s doing.</p><p>The goal of the agent (decision-maker) is to learn the optimal policy, which is a mapping from states to actions that maximize the cumulative reward over time.</p><blockquote>In the context of inventory management, the policy tells the agent how many bikes to order each day based on the current inventory status and the uncertainty in customer demand.</blockquote><h3>Implementing Reinforcement Learning for Inventory Optimization Problem</h3><p><strong>Q-learning</strong> is a model-free reinforcement learning algorithm that learns the optimal action-selection policy for any given state. Unlike the DP approach, which requires a complete model of the environment, Q-learning learns directly from the interaction with the environment (here, uncertainty and the reward it gets) by updating a Q-table.</p><p><strong>The key components of Q-Learning</strong></p><p>In our case, the agent is the decision-maker (the bike shop owner), and the environment is the demand from customers. The state is represented by the current inventory levels (alpha, beta), and the action is how many bikes to order.<strong> The reward is the cost associated with both holding inventory and missing out on sales</strong>. Q-Table is a table that stores the expected future rewards for each state-action pair.</p><p><strong>Initialization of Q Table</strong></p><p>In this work, the Q-table is initialized as a dictionary named Q. States are represented by tuples (alpha, beta), where: alpha is the number of items in stock (on-hand inventory). beta is the number of items on order (on-order inventory).</p><p>Actions are <em>possible inventory order quantities </em>that can be taken in each state. For each state (alpha, beta), the possible actions depend on how much space is left in the inventory (remaining capacity = Inventory Capacity — (alpha + beta)). The restriction is that the number of items ordered cannot exceed the remaining capacity of the inventory.</p><p>The schematic design of the Q value is visualized below:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/720/1*wKM7GyBD-QsZvs2JTQAEhw.png"><figcaption>A schematic design of the Q dictionary is visualized — Image source: Author</figcaption></figure><p>The Q dictionary can be initialized as:</p><pre>def initialize_Q(self):<br>    # Initialize the Q-table as a dictionary<br>    Q = {}<br>    for alpha in range(self.user_capacity + 1):<br>        for beta in range(self.user_capacity + 1 - alpha):<br>        state = (alpha, beta)<br>        Q[state] = {}<br>        max_action = self.user_capacity - (alpha + beta)<br>        for action in range(max_action + 1):<br>            Q[state][action] = np.random.uniform(0, 1)  # Small random values<br>    return Q</pre><p>As the above code shows, Q-values (Q[state][action]) are initialized with small random values to encourage exploration.</p><h3>The Q-Learning Algorithm</h3><p>The Q-learning method updates a table of state-action pairs based on rewards from the environment (here, interacting with the environment comes). Here’s how the algorithm works in three steps:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/972/1*11Et_deLlmsX8pjCwImPGA.png"><figcaption>Q-Learning Equation — Image Source: Author</figcaption></figure><p>Where s is the current state, a is the action taken, s’ is the next state, ( α ) is the learning rate. and ( γ ) is the discount factor.</p><p>We breakdown the equation, and rewrote it in three parts down here:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/737/1*nFpaSa0QLAM5Yca63DrggA.png"><figcaption>Q-Learning Equation — Image Source: Author</figcaption></figure><p>The translation of the above equations to Python code is as follows:</p><pre>def update_Q(self, state, action, reward, next_state):<br>        # Update the Q-table based on the state, action, reward, and next state<br>        best_next_action = max(self.Q[next_state], key=self.Q[next_state].get)<br><br>        # reward + gamma * Q[next_state][best_next_action]<br>        td_target = reward + self.gamma * self.Q[next_state][best_next_action]<br><br>        # td_target - Q[state][action]<br>        td_error = td_target - self.Q[state][action]<br><br>        # Q[state][action] = Q[state][action] + alpha * td_error<br>        self.Q[state][action] += self.alpha * td_error</pre><p>At the above function, the equivalent equation of each line has been shown as a comment on top of each line.</p><h3>Simulating Transitions and Rewards in Q-Learning for Inventory Optimization</h3><p>The current state is represented by a tuple (alpha, beta), where: alpha is the current on-hand inventory (items in stock), beta is the current on-order inventory (items ordered but not yet received), init_inv calculates the total initial inventory by summing alpha and beta.</p><p>Then, we need to simulate customer demand using Poisson distribution with lambda value “self.poisson_lambda”. Here, the demand shows the randomness of customer demand:</p><pre>alpha, beta = state<br>init_inv = alpha + beta<br>demand = np.random.poisson(self.poisson_lambda)</pre><p><strong>Note</strong>: Poisson distribution is used to model the demand, which is a common choice for modeling random events like customer arrivals. However, we can either train the model with historical demand data or live interaction with environment in real time. In its core, reinforcement learning is about learning from the data, and it does not require prior knowledge of a model.</p><p>Now, the “next alpha” which is in-hand inventory can be written as max(0,init_inv-demand). What that means is that if demand is more than the initial inventory, then the new alpha would be zero, if not, init_inv-demand.</p><p>The <strong>cost</strong> comes in two parts. <strong>Holding cost</strong>: is calculated by multiplying the number of bikes in the store by the per-unit holding cost. Then, we have another cost, which is <strong>stockout cost</strong>. It is a cost that we need to pay for the cases of missed demand. These two parts form the “reward” which we try to maximize using reinforcement learning method.( a better way to put is we want to minimize the cost, so we maximize the reward).</p><pre>new_alpha = max(0, init_inv - demand)<br>holding_cost = -new_alpha * self.holding_cost<br>stockout_cost = 0<br><br>if demand &gt; init_inv:<br>    <br>    stockout_cost = -(demand - init_inv) * self.stockout_cost<br>        <br>reward = holding_cost + stockout_cost<br>next_state = (new_alpha, action)</pre><h4>Exploration — Exploitation in Q-Learning</h4><p>Choosing action in the Q-learning method involves some degree of exploration to get an overview of the Q value for all the states in the Q table. To do that, at every action chosen, there is an epsilon chance that we take an exploration approach and “randomly” select an action, whereas, with a 1-ϵ chance, we take the best action possible from the Q table.</p><pre>def choose_action(self, state):<br><br>        # Epsilon-greedy action selection<br>    if np.random.rand() &lt; self.epsilon:<br>        <br>          return np.random.choice(self.user_capacity - (state[0] + state[1]) + 1)<br>    <br>    else:<br>        <br>        return max(self.Q[state], key=self.Q[state].get)</pre><h4>Training RL Agent</h4><p>The training of the RL agent is done by the “train” function, and it is follow as: First, we need to initialize the Q (empty dictionary structure). Then, experiences are collected in each batch (self.batch.append((state, action, reward, next_state))), and the Q table is updated at the end of each batch (self.update_Q(self.batch)). The number of episodes is limited to “max_actions_per_episode” in each batch. The number of episodes is the number of times the agent interacts with the environment to learn the optimal policy.</p><p>Each episode starts with a randomly assigned state, and while the number of actions is lower than max_actions_per_episode, the collecting data for that batch continues.</p><pre>def train(self):<br><br>        self.Q = self.initialize_Q()  # Reinitialize Q-table for each training run<br><br>        for episode in range(self.episodes):<br>            alpha_0 = random.randint(0, self.user_capacity)<br>            beta_0 = random.randint(0, self.user_capacity - alpha_0)<br>            state = (alpha_0, beta_0)<br>            #total_reward = 0<br>            self.batch = []  # Reset the batch at the start of each episode<br>            action_taken = 0<br>            while action_taken &lt; self.max_actions_per_episode:<br>                action = self.choose_action(state)<br>                next_state, reward = self.simulate_transition_and_reward(state, action)<br>                self.batch.append((state, action, reward, next_state))  # Collect experience<br>                state = next_state<br>                action_taken += 1<br>            <br>            self.update_Q(self.batch)  # Update Q-table using the batch</pre><h3>Example Case and Results</h3><p>This is example case is on how to pull together all above codes, and see how the Q-learning agent learns the optimal policy for inventory management. Here, <em>user_capicty</em> (capacity of storage) is 10, which is the total number of items that inventory can hold (capacity). Then, the <em>poisson_lambda</em> is the lambda term in the demand distribution, which has a value of 4. Holding costs is 8, which is the cost of holding an item in inventory overnight, and stockout cost, which is the cost of missed demand (assume that the item had a customer that day and the price of the item was, but you did not have the item in your inventory) is 10. <em>gamma</em> value lower than one is needed in the equation to discount the future reward (0.9), where <em>alpha</em> (learning rate ) is 0.1. The <em>epsilon</em> term is the term control exploration-exploitation dilemma. The episodes are 1000, and each batch consists of 1000 (max actions per episode).</p><pre># Example usage:<br>user_capacity = 10<br>poisson_lambda = 4<br>holding_cost = 8<br>stockout_cost = 10<br>gamma = 0.9<br>alpha = 0.1<br>epsilon = 0.1<br>episodes = 1000<br>max_actions_per_episode = 1000</pre><p>Having defined these initial parameters of the model, we can define the ql Python class, then use the class to train, and then use the module “get_optimal_policy()” to get the optimal policy.</p><pre># Define the Class<br>ql = QLearningInventory(user_capacity, poisson_lambda, holding_cost, stockout_cost, gamma, <br>                        alpha, epsilon, episodes, max_actions_per_episode)<br><br># Train Agent<br>ql.train()<br><br># Get the Optimal Policy<br>optimal_policy = ql.get_optimal_policy()</pre><p><strong>Results</strong></p><p>Now that we have the policy found from the Q-learning method, we can visualize the results and see what they look like. The x-axis is states, which is a tuple of (alpha, beta), and the y-axis is the “Number of Order” found from Q-learning at each state.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*bnZ3qlYeDcL1WIq6Dcfbhw.png"><figcaption><em>Number of order (y-axis) for each state (x-axis) found from Q-learning policy — Image Source: Author</em></figcaption></figure><p>A couple of learnings can be gained by looking at the plot. First, as we go toward the right, we see that the number of orders decreases. When we go right, the alpha value increases (in-hand inventory), meaning we need to “order” less, as inventory in place can fulfill the demand. Secondly, When alpha is constant, with increasing beta, we lower the order of new sites. It can be understood that this is due to the fact that when “we have more item “on order” we do not need increase the orders.</p><p><strong>Comparing the Q-Learning Policy to the BaseLine Policy</strong></p><p>Now that we used Q-learning to find the policy (how many items to order in a given state), we can compare it to the baseline policy (a simple policy). The baseline policy is just to “order up to policy,” which simply means you look at the on-hand inventory and the on-order inventory and order up to “meet the target level.” We can write simple code to write this policy in Python format here:</p><pre># Create a simple policy<br>def order_up_to_policy(state, user_capacity, target_level):<br>    alpha, beta = state<br>    max_possible_order = user_capacity - (alpha + beta)<br>    desired_order = max(0, target_level - (alpha + beta))<br>    return min(max_possible_order, desired_order)</pre><p>In the code, the <strong>target_level</strong> is the desired value we want to order for inventory. If target_level = user_capacity, then we are filling just to fulfill the inventory. First, we can compare the policies of these different methods. For each state, what will be the “number of orders” if we follow the Simple policy and the one from the Q-learning policy? In the figure below, we plotted the comparison of two policies.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*guy3n-XuQpaDCmXqSodlrQ.png"><figcaption>Comparing Ordering policy between Q-Learning and Simple Policy, for each state — Image Source : Author</figcaption></figure><p>The simple policy is just to order so that it fulfills the inventory, where the Q-learning policy order is often lower than the simple policy order.</p><blockquote><strong>This can be attributed to the fact that “poisson_lambda” here is 4, meaning the demand is much lower than the capacity of the inventory=10, therefore it is not optimal to order “high number of bicycle” as it has a high holding cost.</strong></blockquote><p>We can also compare the total cumulative rewards you can get when you apply both policies. To do that, we can use the <em>test_policy</em> function of “QLearningInventory” which was especially designed to evaluate policies:</p><pre>def test_policy(self, policy, episodes):<br>        """<br>        Test a given policy on the environment and calculate the total reward.<br><br>        Args:<br>            policy (dict): A dictionary mapping states to actions.<br>            episodes (int): The number of episodes to simulate.<br><br>        Returns:<br>            float: The total reward accumulated over all episodes.<br>        """<br>        total_reward = 0<br>        alpha_0 = random.randint(0, self.user_capacity)<br>        beta_0 = random.randint(0, self.user_capacity - alpha_0)<br>        state = (alpha_0, beta_0)  # Initialize the state<br>        <br>        for _ in range(episodes):<br><br>            action = policy.get(state, 0)<br>            next_state, reward = self.simulate_transition_and_reward(state, action)<br>            total_reward += reward<br>            state = next_state<br><br>        return total_reward</pre><p>The way the function works is it starts randomly with a new state (state = (alpha_0, beta_0); then for that state, you get action (number of order) for that state from policy, you act and see the reward, and next state, and the process continues as total number of episodes, while you collect the total reward.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MoE2GobFYCtE2PKmLhBR_Q.png"><figcaption>Total costs of manging Inventory, following Q-Learnng policy and Simple policy — Image Source Author</figcaption></figure><p>The plot above compares the total cost of managing inventory when we follow the “Q-Learning” and “Simple Policy”. The aim is to mimimize the cost of running inventory. Since the ‘reward’ in our model represents this cost, we added total cost = -total reward.</p><blockquote>Running the inventory with the Q-Learning policy will lead to lower costs compared to the Simple policy.</blockquote><h3>Code in GitHub</h3><p>The full code for this blog can be found in the GitHub repository <a href="https://github.com/Peymankor/medium_blogs/blob/main/2024/08-Aug/RL-Inventory/main.py">here</a>.</p><h3>Summary and Main Takeaways</h3><p>In this post, we worked on how reinforcement learning (Q-Learning specifically) can be used to optimize inventory management. We were able to develop a Q-learning algorithm that learns the optimal ordering policy through interaction with the environment (uncertainty). Here, the environment was the “random” demand of the customers (buyers of bikes), and the state was the current inventory status (alpha, beta). The Q-learning algorithm was able to learn the optimal policy that minimizes the total cost of inventory management.</p><p><strong>Main Takeaways</strong></p><ol><li><strong>Q-Learning</strong>: A model-free reinforcement learning algorithm, Q-learning, can be used to find the optimal inventory policy without requiring a complete model of the environment.</li><li><strong>State Representation</strong>: The state in inventory management is represented by the current on-hand inventory and on-order inventory state = (α, β).</li><li><strong>Cost Reduction</strong>: We can see that the Q-learning policy leads to lower costs compared to the simple policy of ordering up to capacity.</li><li><strong>Flexibility</strong>: The Q-learning approach is quite flexible and can be applied to the case of we have past data of demand, or we can interact with the environment to learn the optimal policy.</li><li><strong>Data-Driven Decisions</strong>: As we showed, the reinforcement learning (RL) approach does not require any prior knowledge on the model of environment , as it is learning from the data.</li></ol><h3>References</h3><p>[1] A. Rao, T. Jelvis, Foundations of Reinforcement Learning with Applications in Finance (2022).</p><p>[2] S. Sutton, A. Barto, Reinforcement Learning: An Introduction (2018).</p><p>[3] W. B. Powell, Sequential Decision Analytics and Modeling: Modeling with Python (2022).</p><p>[4] R. B. Bratvold, Making Good Decisions (2010).</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=7833df3d25a6" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/optimizing-inventory-management-with-reinforcement-learning-a-hands-on-python-guide-7833df3d25a6">Optimizing Inventory Management with Reinforcement Learning: A Hands-on Python Guide</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Controversial Windows Recall AI Search Tool Returns]]></title>
<description><![CDATA[wiredmikey writes: Three months after pulling previews of the controversial Windows Recall feature due to public backlash, Microsoft says it has completely overhauled the security architecture with proof-of-presence encryption, anti-tampering and DLP checks, and screenshot data managed in secure ...]]></description>
<link>https://tsecurity.de/de/2356446/it-security-nachrichten/controversial-windows-recall-ai-search-tool-returns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2356446/it-security-nachrichten/controversial-windows-recall-ai-search-tool-returns/</guid>
<pubDate>Fri, 27 Sep 2024 19:33:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[wiredmikey writes: Three months after pulling previews of the controversial Windows Recall feature due to public backlash, Microsoft says it has completely overhauled the security architecture with proof-of-presence encryption, anti-tampering and DLP checks, and screenshot data managed in secure enclaves outside the main operating system. 

In an interview with SecurityWeek, Microsoft vice president David Weston said the company's engineers rewrote the security model of Windows Recall to reduce attack surface on Copilot+ PCs and minimize the risk of malware attackers targeting the screenshot data store.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Controversial+Windows+Recall+AI+Search+Tool+Returns%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F24%2F09%2F27%2F1722216%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F24%2F09%2F27%2F1722216%2Fcontroversial-windows-recall-ai-search-tool-returns%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/24/09/27/1722216/controversial-windows-recall-ai-search-tool-returns?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Welches Web-Framework ist das passende? Ein Experiment]]></title>
<description><![CDATA[Entwickler Eugene Yan untersucht in einem Praxisbeispiel, wie unterschiedliche Web-Frameworks die Entwicklung einer Anwendungen beeinflussen. Am Start sind FastHTML, Next.js und SvelteKit.]]></description>
<link>https://tsecurity.de/de/2329743/android-tipps/welches-web-framework-ist-das-passende-ein-experiment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2329743/android-tipps/welches-web-framework-ist-das-passende-ein-experiment/</guid>
<pubDate>Thu, 12 Sep 2024 16:20:20 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Entwickler Eugene Yan untersucht in einem Praxisbeispiel, wie unterschiedliche Web-Frameworks die Entwicklung einer Anwendungen beeinflussen. Am Start sind FastHTML, Next.js und SvelteKit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Two Android Engineers Explain How They Extended Rust In Android's Firmware]]></title>
<description><![CDATA[The Register reports that Google "recently rewrote the firmware for protected virtual machines in its Android Virtualization Framework using the Rust programming language." And they add that Google "wants you to do the same, assuming you deal with firmware." 

A post on Google's security blog by ...]]></description>
<link>https://tsecurity.de/de/2322026/it-security-nachrichten/two-android-engineers-explain-how-they-extended-rust-in-androids-firmware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2322026/it-security-nachrichten/two-android-engineers-explain-how-they-extended-rust-in-androids-firmware/</guid>
<pubDate>Sun, 08 Sep 2024 22:48:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Register reports that Google "recently rewrote the firmware for protected virtual machines in its Android Virtualization Framework using the Rust programming language." And they add that Google "wants you to do the same, assuming you deal with firmware." 

A post on Google's security blog by Android engineers Ivan Lozano and Dominik Maier promises to show "how to gradually introduce Rust into your existing firmware," adding "You'll see how easy it is to boost security with drop-in Rust replacements, and we'll even demonstrate how the Rust toolchain can handle specialized bare-metal targets." 

This prompts the Register to quip that easy "is not a term commonly heard with regard to a programming language known for its steep learning curve."


Citing the lack of high-level security mechanisms in firmware, which is often written in memory-unsafe languages such as C or C++, Lozano and Maier argue that Rust provides a way to avoid the memory safety bugs like buffer overflows and use-after-free that account for the majority of significant vulnerabilities in large codebases. "Rust provides a memory-safe alternative to C and C++ with comparable performance and code size," they note. "Additionally it supports interoperability with C with no overhead."
 

At one point the blog post explains that "You can replace existing C functionality by writing a thin Rust shim that translates between an existing Rust API and the C API the codebase expects." But their ultimate motivation is greater security. "Android's use of safe-by-design principles drives our adoption of memory-safe languages like Rust, making exploitation of the OS increasingly difficult with every release." 

And the Register also got this quote from Lars Bergstrom, Google's director of engineering for Android Programming Languages (and chair of the Rust Foundation's board of directors). "At Google, we're increasing Rust's use across Android, Chromium, and more to reduce memory safety vulnerabilities. We're dedicated to collaborating with the Rust ecosystem to drive its adoption and provide developers with the resources and training they need to succeed. 

"This work on bringing Rust to embedded and firmware addresses another critical part of the stack."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Two+Android+Engineers+Explain+How+They+Extended+Rust+In+Android's+Firmware%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F24%2F09%2F08%2F0455238%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F24%2F09%2F08%2F0455238%2Ftwo-android-engineers-explain-how-they-extended-rust-in-androids-firmware%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/24/09/08/0455238/two-android-engineers-explain-how-they-extended-rust-in-androids-firmware?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google says replacing C/C++ in firmware with Rust is easy]]></title>
<description><![CDATA[Not so much when trying to convert coding veterans Google recently rewrote the firmware for protected virtual machines in its Android Virtualization Framework using the Rust programming language and wants you to do the same, assuming you deal with firmware.…]]></description>
<link>https://tsecurity.de/de/2320209/it-security-nachrichten/google-says-replacing-cc-in-firmware-with-rust-is-easy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2320209/it-security-nachrichten/google-says-replacing-cc-in-firmware-with-rust-is-easy/</guid>
<pubDate>Sat, 07 Sep 2024 00:03:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Not so much when trying to convert coding veterans</h4> <p>Google recently rewrote the firmware for protected virtual machines in its Android Virtualization Framework using the Rust programming language and wants you to do the same, assuming you deal with firmware.…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google says replacing C/C++ in firmware with Rust is easy]]></title>
<description><![CDATA[Not so much when trying to convert coding veterans Google recently rewrote the firmware for protected virtual machines in its Android Virtualization Framework using the Rust programming language and wants you to do the same, assuming you deal with firmware.…]]></description>
<link>https://tsecurity.de/de/2320210/it-security-nachrichten/google-says-replacing-cc-in-firmware-with-rust-is-easy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2320210/it-security-nachrichten/google-says-replacing-cc-in-firmware-with-rust-is-easy/</guid>
<pubDate>Sat, 07 Sep 2024 00:03:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Not so much when trying to convert coding veterans</h4> <p>Google recently rewrote the firmware for protected virtual machines in its Android Virtualization Framework using the Rust programming language and wants you to do the same, assuming you deal with firmware.…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Should I go all in into linux? I wanna get rich. Need honest opinions.]]></title>
<description><![CDATA[I want to create a successful SaaS that generates $3k to 4k/m. I am using Next.js react.js tailwind.css mongodb and google oauth. I am using windows rn. I can easily create a website using nextjs and deploying to Vercel this is where my question begins. on X (formerly twitter) some experienced de...]]></description>
<link>https://tsecurity.de/de/2301453/linux-tipps/should-i-go-all-in-into-linux-i-wanna-get-rich-need-honest-opinions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2301453/linux-tipps/should-i-go-all-in-into-linux-i-wanna-get-rich-need-honest-opinions/</guid>
<pubDate>Tue, 27 Aug 2024 20:22:05 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I want to create a successful SaaS that generates $3k to 4k/m.</p> <p>I am using Next.js react.js tailwind.css mongodb and google oauth.</p> <p>I am using windows rn.</p> <p>I can easily create a website using nextjs and deploying to <strong>Vercel</strong></p> <p>this is where my question begins.</p> <p>on X (formerly twitter) some experienced developers are stating that</p> <p>"if a young person uses vercel they will never be a true developer"</p> <p>"use vercel if you wanna be a slave"</p> <p>" don't believe these: "you need this micro server you can't make your own auth - db - etc..""</p> <p>and these persons are stating that we should learn linux if we want to be successful because hosting and controlling your own server seems impossible without a help of a company for young people because of these new high level technologies.</p> <p>so should I start to use linux and give up on nextjs and manage my own server?</p> <p>I need money.</p> <p>if you say yes witch distro should I use.</p> <p>20yo - I need money</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/eraeraeare"> /u/eraeraeare </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1f2o20z/should_i_go_all_in_into_linux_i_wanna_get_rich/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1f2o20z/should_i_go_all_in_into_linux_i_wanna_get_rich/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exploring Medusa and Multi-Token Prediction]]></title>
<description><![CDATA[This blog post will go into detail on the “MEDUSA: Simple LLM Inference Acceleration Framework with Multiple Decoding Heads” paperImage by Author — SDXLThe internet is an incredibly competitive place. Studies show that customers leave webpages if it takes longer than 5 seconds for the webpage to ...]]></description>
<link>https://tsecurity.de/de/2221468/ai-nachrichten/exploring-medusa-and-multi-token-prediction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2221468/ai-nachrichten/exploring-medusa-and-multi-token-prediction/</guid>
<pubDate>Wed, 10 Jul 2024 10:06:29 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>This blog post will go into detail on the “MEDUSA: Simple LLM Inference Acceleration Framework with Multiple Decoding Heads” paper</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fyIt8LP6iIAt7zzEPG3bAA.png"><figcaption>Image by Author — SDXL</figcaption></figure><p>The internet is an incredibly competitive place. Studies show that customers leave webpages if it takes longer than 5 seconds for the webpage to load [2][3]. This poses a challenge for most Large Language Models (LLMs), as they are without a doubt one of the slowest programs out there. While custom hardware can dramatically speed up your LLM, running on this hardware is currently expensive. If we can find ways to make the most of standard hardware, we will be able to dramatically increase the customer experience for LLMs.</p><p>The authors of the <a href="https://arxiv.org/pdf/2401.10774">“MEDUSA: Simple LLM Inference Acceleration Framework with Multiple Decoding Heads”</a> paper have an architectural change that when run on existing hardware achieves a 2x–3x speed up.</p><p>Let’s dive in!</p><h3>Speculative Decoding</h3><p>Speculative Decoding was introduced as a way to speed up inferencing for an LLM. You see, LLMs are autoregressive, meaning we take the output token that we just predicted and use it to help predict the next token we want. Typically we are predicting one-token at a time (or one-token per forward pass of the neural network). However, because the attention pattern for the next token is very similar to the attention pattern from the previous one, we are repeating most of the same calculations and not gaining much new information.</p><p>Speculative decoding means that rather than doing one forward pass for one token, instead after one forward pass we try to find as many tokens as we can. In general there are three steps for this:</p><p>(1) Generate the candidates</p><p>(2) Process the candidates</p><p>(3) Accept certain candidates</p><p>Medusa is a type of speculative decoding, and so its steps map directly onto these. Medusa appends decoding heads to the final layer of the model as its implementation of (1). Tree attention is how it processes the candidates for (2). Finally, Medusa uses either rejection sampling or a typical acceptance scheme to accomplish (3). Let’s go through each of these in detail.</p><h3>Decoding Heads &amp; Medusa</h3><p>A decoding head takes the internal representation of the hidden state produced by a forward pass of the model and then creates the probabilities that correspond to different tokens in the vocabulary. In essence, it is converting the things the model has learned into probabilities that will determine what the next token is.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/892/1*2IhXXAovd33WL3Bgr9aPEA.png"><figcaption>Figure 1 <a href="https://arxiv.org/pdf/2401.10774">from the paper</a></figcaption></figure><p>Medusa adjusts the architecture of a typical Transformer by appending multiple decoding heads to the last hidden layer of the model. By doing so, it can predict more than just one token given a forward pass. Each additional head that we add predicts one token further. So if you have 3 Medusa heads, you are predicting the first token from the forward pass, and then 3 more tokens after that with the Medusa heads. In the paper, the authors recommend using 5, as they saw this gave the best balance between speed-up and quality.</p><p>To accomplish this, the authors of the paper proposed the below decoder head for Medusa:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/844/1*X8meUkliwrDwyxnFS5Zqkw.png"><figcaption>Definition of the k-th head <a href="https://arxiv.org/pdf/2401.10774">from the paper</a></figcaption></figure><p>This equation gives us the probability of token <em>t</em> from the <em>k</em>-th head. We start off by using the weights we’ve found through training the Medusa head, <em>W1,</em> and multiplying them by our internal state for token <em>t</em>. We use the SiLU activation function to pass through only selective information(SiLU = x * sigmoid(x)). We add to this the internal state a second time as part of a skip connection, which allows the model to be more performant by not losing information during the linear activation of the SiLU. We then multiply the sum by the second set of weights we’ve trained for the head, <em>W2</em>, and run that product through a softmax to get our probability.</p><h3>Tree Attention</h3><p>The first Medusa heads give the model probabilities they should consider based off the forward pass, but the subsequent Medusa heads need to figure out what token they should pick based off what the prior Medusa heads chose.</p><p>Naturally, the more options the earlier Medusa heads put forward (hyperparameter <em>sk</em>), the more options future heads need to consider. For example, when we consider just the top two candidates from head 1 (s1=2) and the top three from head 2 (s2=3), we wind up with 6 different situations we need to compute.</p><p>Due to this expansion, we would like to generate and verify these candidates as concurrently as possible.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/866/1*M_Rdh25E_XWSBVjJrav3qw.png"><figcaption>Figure 2 <a href="https://arxiv.org/pdf/2401.10774">from the paper</a></figcaption></figure><p>The above matrix shows how we can run all of these calculations within the same batch via tree attention. Unlike typical causal self-attention, only the tokens from the same continuation are considered relevant for the attention pattern. As the matrix illustrates with this limited space, we can fit our candidates all into one batch and run attention on them concurrently.</p><p>The challenge here is that each prediction needs to consider only the candidate tokens that would be directly behind it. In other words, if we choose “It” from head 1, and we are evaluating which token should come next, we do not want to have the attention pattern for “I” being used for the tokens.</p><p>The authors avoid this kind of interference by using a mask to avoid passing data about irrelevant tokens into the attention calculation. By using this mask, they can be memory efficient while they calculate the attention pattern &amp; then use that information in the decoding head to generate the subsequent token candidates.</p><p>While the above matrix shows us considering every prediction the same, if we have a probability for each prediction, we can treat these differently based on how likely they are to be the best choice. The below tree visualizes just that.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ANOSiXtHmA4K2iaDwlKcuA.png"><figcaption>Figure 6 <a href="https://arxiv.org/pdf/2401.10774">from the paper</a></figcaption></figure><p>In the above, there are 4 Medusa heads each giving multiple candidates. However, not every prediction gets calculated. We add nodes onto our tree based off the probability of them being right. Here, the tree is heavily weighted towards the left, showing that the higher the probability of the prediction, the more possibilities it is shown. In short, what we are doing here is only loading in predictions to the tree attention that we feel have a reasonable likelihood of being the best choice.</p><p>Using probability to determine which calculations to continue with is a mindset we’ll see again with the candidate acceptance criteria we’re about to discuss.</p><h3>Typical Acceptance Scheme vs Rejection Sampling</h3><p>Now we reach the final stage, determining which predictions to use (if any). As we said from the start, models are auto-regressive, so if we predict the next 5 tokens from the forward-pass, we can simply put in those next 5 into the model for the next go around and enjoy the inference speed increase. However, we only want to do so if the predictions we are getting are high quality. How do we determine this?</p><p>One method is Rejection Sampling where we have a separate model that can determine if the next token is good enough (this was used by Meta in their Ghost Attention fine-tuning, <a href="https://towardsdatascience.com/understanding-ghost-attention-in-llama-2-dba624901586">learn more here</a>). Naturally, this method is fully dependent on the quality of your other model. If it is good enough, then this works great! Note, however, that to maintain low latency, you’ll want this other model to run quite fast, a difficult thing to balance with high quality.</p><p>As a consequence of that difficulty, the authors came up with the typical acceptance scheme to make the determination. As all of the predictions are probabilities, we can use them to set a threshold above which we accept a token. The below equation shows how we do so:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*opgAwpn7anMa8mJ0D9sYbA.png"><figcaption>Equation showing Typical Acceptance Scheme <a href="https://arxiv.org/pdf/2401.10774">from the paper</a></figcaption></figure><p>The key here is that we are going to use the probabilities generated by the original model on these tokens to determine if the predictions are valid. We have tokens <em>X1</em> through <em>Xn</em> as the context for our model to determine the probability for token <em>Xn+k</em>. <em>p</em> represents the probability distribution of our original model, while ϵ and δ are thresholds set to determine when a probability is high enough to merit being included in the model response. The big picture here is that high probability tokens will flow through, but so will tokens that have lower probabilities yet come from a probability distribution where most of the probabilities are low.</p><p>Moreover, this function leads to important behavior when we adjust temperature. In general, users increase temperature on an LLM to give more creative responses. Thus, when the temperature is set at zero, typical acceptance ensures that only the first token predicted from the forward pass comes through, giving the most consistent results. However, as the temperature increases, the probability distribution of the LLM changes, leaving us with more predictions that could reach the threshold to be accepted. This leads to both faster results but often times more creative ones as well.</p><h3>Self-Distillation</h3><p>The authors propose that to create Medusa models we don’t train from scratch but rather take high-quality foundation models (we’ll call this the backbone part of the model) and add the Medusa heads on top of these. Once we’ve fine-tuned them to understand the new heads, the speed will increase without major performance loss.</p><p>Nevertheless fine-tuning requires quality data. The authors were kind enough to explain how they created the data corpus needed to train Medusa.</p><p>First, they used the <a href="https://sharegpt.com/">ShareGPT dataset</a> to find high-quality interactions that people expect to have with their LLM. They took all the prompts from the dataset and then ran these through the backbone model to get the ground-truth to fine-tune on.</p><p>While this worked well for fine-tuning the Medusa heads (Medusa-1 which we’ll go into below more), this did not work well when fine-tuning the entire new model.</p><p>This degradation implied that the ground-truth was not enough information to retrain the model with and still retain high performance. Instead, they rewrote the loss function so that it used the probability distributions as the ground-truth. This required reformulating their loss function like the below.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*VW4mNmdgaBGu_PwyVtzMgg.png"><figcaption>Loss Equation for the new model <a href="https://arxiv.org/pdf/2401.10774">from the paper</a></figcaption></figure><p>To briefly explain, we’re using Kullback–Leibler divergence (KL) to measure the difference between the original probability distribution for a token and the new probability distribution (t<a href="https://towardsdatascience.com/understanding-kl-divergence-f3ddc8dff254">o learn more about KL, there is a wonderful post by Aparna Dhinakaran on the topic</a>).</p><p>This formulation, however, requires that we maintain the probabilities of both the original and the new model — which is both storage and memory intensive. To reduce our consumption, the authors recommend using LoRA to fine-tune, as this naturally maintains the original weights and the additional weights <a href="https://towardsdatascience.com/understanding-low-rank-adaptation-lora-in-fine-tuning-llms-d3dd283f1f0a">(to learn more about LoRA check out my blog post on the topic)</a>.</p><h3>Training Medusa</h3><p>Now that we have the data, we can begin to fine-tune!</p><p>As we’ve seen, Medusa requires adding additional parameters to the model to allow this to work, which we’ll have to train. To reduce the amount of computations (and thus training cost) required, the authors introduced two forms of fine-tuning for Medusa: Medusa-1 and Medusa-2.</p><h3>Medusa-1</h3><p>Medusa-1 involves freezing all of the weights in the model except for the ones in the Medusa heads. By only running the gradient through the Medusa heads we don’t worry about reducing the performance of the original model (it remains the same), and we can increase the performance of the Medusa heads. The loss function below shows how they match the correct ground-truth token to the correct Medusa head.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/852/1*VxoRD0_aKmTzFrCyUxQa0w.png"><figcaption>Equation 1 <a href="https://arxiv.org/pdf/2401.10774">from the paper</a></figcaption></figure><p>Medusa-1’s focus on only the additional Medusa weights means that it is more cost-effective than Medusa-2 (which we’ll dive into in a moment). For people who are price-sensitive with training, the authors recommend using a quantized backbone model to further reduce memory requirements along with using the Quantized Low Rank Adaptation (QLoRA) fine-tuning methodology to further reduce costs.</p><h3>Medusa-2</h3><p>While Medusa-1 is more cost-effective, the best performance still comes when we update all of the weights in the model to account for the new Medusa heads we’ve added. Interestingly, this was not as straight-forward as simply doing LoRA with the gradient passing to all of the weights (rather than just the Medusa weights).</p><p>Instead, the authors first ran Medusa-1 to get the Medusa weights to a reasonable performance. Then they chose separate learning rates for the Medusa weights and the backbone model weights. Logically, this was done because the backbone weights were likely close to where they already needed to be, while the Medusa weights should change more. Finally, they added the loss function for the backbone model (denoted <em>Llm</em>) with the Medusa-1 loss function scaled by a value <em>λ0</em>. This lambda is done to balance the loss so that we do not compute an overly large loss value on account of the Medusa heads alone.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/798/1*_0Nv0VxQiRyjpEyhXycZOA.png"><figcaption>Equation 2 <a href="https://arxiv.org/pdf/2401.10774">from the paper</a></figcaption></figure><h3>Closing</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NRbIrZJP-jGa28WvqtOndA.png"><figcaption>Figure 3 <a href="https://arxiv.org/pdf/2401.10774">from the paper</a></figcaption></figure><p>Using Medusa leads to fairly radical improvements in speed. From the graph above, we see that the authors attained between a two to three times speedup for Vicuna — a popular open-source LLM.</p><p>Speed is critically important, both on the internet and also on device. As we’ve seen more companies push to create local LLMs, methods like Medusa seem critical to getting great speed on limited hardware. It would be very interesting to see how much a small model like Phi-3 would speed up (at publishing time Phi-3 ran at 12 tokens per second on the A16 Bionic iPhone chip — <a href="https://towardsdatascience.com/phi-3-and-the-beginning-of-highly-performant-iphone-models-d413d8ea0714">see my blog post for more information</a>). For developers, this may open the door to running many different kinds of open-source models locally — even if they weren’t initially designed for fast inference like Phi-3.</p><p>Moreover, it would be interesting to run experiments on how much of the forward pass’ attention pattern Medusa heads need to increase performance. Right now they have very little context but still perform well. With more context, perhaps the number of Medusa heads could be increased to achieve even better speed up.</p><p>It’s an exciting time to be building.</p><p>[1] Cai, T., et al, <a href="https://arxiv.org/pdf/2401.10774">“MEDUSA: Simple LLM Inference Acceleration Framework with Multiple Decoding Heads”</a> (2024), arXiv</p><p>[2] Clabaugh, J., <a href="https://wtop.com/business-finance/2022/02/how-long-do-you-wait-for-a-web-page-to-load/">“How long do you wait for a webpage to load?”</a> (2022), wtop</p><p>[3] Das, S., <a href="https://www.browserstack.com/guide/how-fast-should-a-website-load">“How fast should a website load in 2023?”</a> (2023), BrowserStack</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=de7f8312e4a7" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/exploring-medusa-and-multi-token-prediction-de7f8312e4a7">Exploring Medusa and Multi-Token Prediction</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[May 2024: Firebase has SQL, and 6 other top takeaways from Google I/O]]></title>
<description><![CDATA[Author: Firebase - Bewertung: 7x - Views:38 Welcome to the May 2024 edition of Firebase Release Notes. In this video, Puf discusses the 7 top takeaways from Firebase at Google I/O 2024 including the new logo for Firebase, SQL, and more!

Chapters:
0:00 - Introduction 
0:11 - Evolving Firebase - n...]]></description>
<link>https://tsecurity.de/de/2153450/it-security-video/may-2024-firebase-has-sql-and-6-other-top-takeaways-from-google-io/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2153450/it-security-video/may-2024-firebase-has-sql-and-6-other-top-takeaways-from-google-io/</guid>
<pubDate>Sun, 19 May 2024 00:43:12 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/vYk6Uh2WGto/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Firebase - Bewertung: 7x - Views:38 <br/></p><p><iframe id="ytplayer" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/vYk6Uh2WGto?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Welcome to the May 2024 edition of Firebase Release Notes. In this video, Puf discusses the 7 top takeaways from Firebase at Google I/O 2024 including the new logo for Firebase, SQL, and more!

Chapters:
0:00 - Introduction 
0:11 - Evolving Firebase - new logo
0:31 - Data Connect: Firebase now has SQL
1:17 - App Hosting: deploy NextJS apps to Google Cloud
1:49 - Genkit: quickly build and ship server-side gen AI pipelines
2:26 - Safely call Gemini APIs on Vertex AI from your client-side apps
2:56 - Gemini in Firebase: get in-context AI help in console and Crashlytics
3:27 - Launch features gradually and roll back quickly with Remote Config
4:01 - Conclusion

Resources:
Data Connect → https://goo.gle/4bDjrHy 
App Hosting → https://goo.gle/4aFyeAn  
Genkit → https://goo.gle/4dXAIwy 

Watch more Firebase Release Notes → https://goo.gle/firebase-release-notes    
Subscribe to Firebase → https://goo.gle/Firebase   

#FirebaseReleaseNotes #Firebase


Speaker: Frank van Puffelen
Products Mentioned: Firebase<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dask DataFrame is Fast Now]]></title>
<description><![CDATA[Dask DataFrame Is Fast NowHow Dask enables processing data at terabyte scale efficientlyPerformance Improvements for Dask DataFrames — All Images created by the AuthorIntroductionDask DataFrame scales out pandas DataFrames to operate at the 100GB-100TB scale.Historically, Dask was pretty slow com...]]></description>
<link>https://tsecurity.de/de/2151707/ai-nachrichten/dask-dataframe-is-fast-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2151707/ai-nachrichten/dask-dataframe-is-fast-now/</guid>
<pubDate>Fri, 17 May 2024 20:14:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Dask DataFrame Is Fast Now</h3><h4>How Dask enables processing data at terabyte scale efficiently</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wFT9QkKhnr0Q76wILZFmTg.png"><figcaption>Performance Improvements for Dask DataFrames — All Images created by the Author</figcaption></figure><h4>Introduction</h4><p>Dask DataFrame scales out pandas DataFrames to operate at the 100GB-100TB scale.</p><p>Historically, Dask was pretty slow compared to other tools in this space (like Spark). Due to a number of improvements focused on performance, it’s now pretty fast (about 20x faster than before). The new implementation moved Dask from getting destroyed by Spark on every benchmark to regularly outperforming Spark on TPC-H queries by a significant margin.</p><p>Dask DataFrame workloads struggled with many things. Performance and memory usage were commonly seen pain points, shuffling was unstable for bigger datasets, making scaling out hard. Writing efficient code required understanding too much of the internals of Dask.</p><p>The new implementation changed all of this. Things that didn’t work were completely rewritten from scratch and existing implementations were improved upon. This puts Dask DataFrames on a solid foundation that allows faster iteration cycles in the future.</p><p>We’ll go through the three most prominent changes, covering how they impact performance and make it easier to use Dask efficiently, even for users that are new to distributed computing. We’ll also discuss plans for future improvements.</p><p>I am part of the core team of Dask. I am an open source engineer for <a href="https://www.coiled.io/">Coiled</a> and was involved in implementing some of the improvements discussed in this post.</p><h4>1. Apache Arrow Support: Efficient String Datatype</h4><p>A Dask DataFrame consists of many pandas DataFrames. Historically, pandas used NumPy for numeric data, but Python objects for text data, which are inefficient and blow up memory usage. Operations on object data also hold the GIL, which doesn’t matter much for pandas, but is a catastrophy for performance with a parallel system like Dask.</p><p>The pandas 2.0 release introduced support for general-purpose Arrow datatypes, so Dask now uses PyArrow-backed strings by default. These are <em>much</em> better. PyArrow strings reduce memory usage by up to 80% and unlock multi-threading for string operations. Workloads that previously struggled with available memory now fit comfortably in much less space, and are a lot faster because they no longer constantly spill excess data to disk.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*KvIY-QitpcMWDke78j19bQ.png"><figcaption>Memory Usage of the Legacy DataFrames compared with Arrow Strings</figcaption></figure><p>I wrote a post about this that <a href="https://docs.coiled.io/blog/pyarrow-in-pandas-and-dask.html">investigates Arrow integrations</a> in more detail if you want to learn more.</p><h4>2. Faster Joins with a New Shuffle Algorithm</h4><p>Shuffling is an essential component of distributed systems to enable sorting, joins, and complex group by operations. It is an all-to-all, network-intensive operation that’s often the most expensive component in a workflow. We rewrote Dask’s shuffling system, which greatly impacts overall performance, especially on complex, data-intensive workloads.</p><p>A shuffle operation is intrinsically an all-to-all communication operation where every input partition has to provide a tiny slice of data to every output partition. Dask was already using it’s own task-based algorithm that managed to reduce the O(n * n) task complexity to O(log(n) * n) where n is the number of partitions. This was a drastic reduction in the number of tasks, but the non-linear scaling ultimately did not allow Dask to process arbitrarily large datasets.</p><p>Dask introduced a new P2P (peer-to-peer) shuffle method that reduced the task complexity to O(n) which scales linearly with the size of the dataset and the size of the cluster. It also incorporates an efficient disk integration which allows easily shuffling datasets which are much larger than memory. The new system is extremely stable and "just works" across any scale of data.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/895/1*maii_gA6EqByjwsylNyPNg.png"><figcaption>Memory Usage of the Legacy Shuffle compared with P2P</figcaption></figure><p>One of my colleagues wrote <a href="https://docs.coiled.io/blog/shuffling-large-data-at-constant-memory.html">a post about this</a> that includes a more extensive explanation and a lot of technical details.</p><h4>3. Optimizer</h4><p>Dask itself is lazy, which means that it registers your whole query before doing any actual work. This is a powerful concept that enables a lot of optimizations, but historically Dask wasn’t taking advantage of this knowledge in the past. Dask also did a bad job of hiding internal complexities and left users on their own while navigating the difficulties of distributed computing and running large scale queries. It made writing efficient code painful for non-experts.</p><p><a href="https://docs.dask.org/en/stable/changelog.html#query-planning">The Dask release in March</a> includes a complete re-implementation of the DataFrame API to support query optimization. This is a big deal. The new engine centers around a query optimizer that rewrites our code to make it more efficient and better tailored to Dask’s strengths. Let’s dive into some optimization strategies, how they make our code run faster and scale better.</p><p>We will start with a couple of general purpose optimizations that are useful for every DataFrame-like tool before we dive into more specific techniques that are tailored to distributed systems generally and Dask more specifically.</p><h4>3.1 Column Projection</h4><p>Most datasets have more columns than what we actually need. Dropping them requires foresight (“What columns will I need for this query? 🤔”) so most people don’t think about this when loading data. This is bad for performance because we carry around lots of data that we don’t need, slowing everything down. Column Projection drops columns as soon as they aren’t needed anymore. It’s a straightforward optimization, but highly beneficial.</p><p>The legacy implementation always reads all columns from storage and only drops columns if we actively ask for it. Simply operating on less data is a big win for performance and memory usage.</p><p>The optimizer looks at the query and figures out which columns are needed for each operation. We can imagine this as looking at the final step of our query and then working backwards step by step to the data source and injecting drop operations to get rid of unnecessary columns.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YKnDIuVO9umeA1bFN8-dIw.png"><figcaption>We only require a subset of columns in the end. Replace doesn't need access to all columns, so we can drop unnecessary columns directly in the IO step.</figcaption></figure><h4>3.2 Filter Pushdown</h4><p>Filter pushdown is another general-purpose optimization with the same goal as column projection: operate on less data. The legacy implementation just keeps filters where we put them. The new implementation executes filter operations as early as possible while maintaining the same results.</p><p>The optimizer identifies every filter in our query and looks at the previous operation to see if we can move the filter closer to the data source. It will repeat this until it finds an operation that can’t be switched with a filter. This is a bit harder than column projections, because we have to make sure that the operations don’t change the values of our DataFrame. For example, switching a filter and a merge operation is fine (values don’t change), but switching a filter and a replace operation is invalid, because our values might change and rows that would previously have been filtered out now won’t be, or vice versa.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*HGv9k4aHNJ539Ctdq3iDDQ.png"><figcaption>Initially, the filter happens after the Dropna, but we can execute the filter before Dropna without changing the result. This allows us to push the filter into the IO step.</figcaption></figure><p>Additionally, if our filter is strong enough then we can potentially drop complete files in the IO step. This is a best-case scenario, where an earlier filter brings a huge performance improvement and even requires reading less data from remote storage.</p><h4>3.3 Automatically Resizing Partitions</h4><p>In addition to implementing the common optimization techniques described above, we’ve also improved a common pain point specific to distributed systems genereally and Dask users specifically: optimal partition sizes.</p><p>Dask DataFrames consist of many small pandas DataFrames called <em>partitions</em>. Often, the number of partitions is decided for you and Dask users are advised to manually “repartition” after reducing or expanding their data (for example by dropping columns, filtering data, or expanding with joins) (see the <a href="https://docs.dask.org/en/stable/dataframe-best-practices.html#repartition-to-reduce-overhead">Dask docs</a>). Without this extra step, the (usually small) overhead from Dask can become a bottleneck if the pandas DataFrames become too small, making Dask workflows painfully slow.</p><p>Manually controlling the partition size is a difficult task that we, as Dask users, shouldn’t have to worry about. It is also slow because it requires network transfer of some partitions. Dask DataFrame now automatically does two things to help when the partitions get too small:</p><ul><li>Keeps the size of each partition constant, based on the ratio of data you want to compute vs. the original file size. If, for example, you filter out 80% of the original dataset, Dask will automatically combine the resulting smaller partitions into fewer, larger partitions.</li><li>Combines too-small partitions into larger partitions, based on an absolute minimum (default is 75 MB). If, for example, your original dataset is split into many tiny files, Dask will automatically combine them.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xlYiH2Bze0JQbejse9tCBA.png"><figcaption>We select two columns that take up 40 MB of memory out of the 200 MB from the whole file.</figcaption></figure><p>The optimizer will look at the number of columns and the size of the data within those. It calculates a ratio that is used to combine multiple files into one partition.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*BLHdyercnwn5Y5ieQAY3og.png"><figcaption>The ratio of 40/200 results in combining five files into a single partition.</figcaption></figure><p>This step is currently limited to IO operations (like reading in a Parquet dataset), but we plan to extend it to other operations that allow cheaply combining partitions.</p><h4>3.4 Trivial Merge and Join Operations</h4><p>Merge and join operations are typically cheap on a single machine with pandas but expensive in a distributed setting. Merging data in shared memory is cheap, while merging data across a network is quite slow, due to the shuffle operations explained earlier.</p><p>This is one of the most expensive operations in a distributed system. The legacy implementation triggered a network transfer of both input DataFrames for every merge operation. This is sometimes necessary, but very expensive.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0OgDqhcduK_Op_3lOaCJLA.png"><figcaption>Both joins are performed on the same column. The left DataFrame is already properly partitioned after the first join, so we can avoid shuffling again with the new implementation.</figcaption></figure><p>The optimizer will determine when shuffling is necessary versus when a trivial join is sufficient because the data is already aligned properly. This can make individual merges an order of magnitude faster. This also applies to other operations that normally require a shuffle like groupby().apply().</p><p>Dask merges used to be inefficient, which caused long runtimes. The optimizer fixes this for the trivial case where these operations happen after each other, but the technique isn’t very advanced yet. There is still a lot of potential for improvement.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Yl_Kr7PZLBbUv-JQwkw-LQ.png"><figcaption>The current implementation shuffles both branches that originate from the same table. Injecting a shuffle node further up avoids one of the expensive operations.</figcaption></figure><p>The optimizer will look at the expression and inject shuffle nodes where necessary to avoid unnecessary shuffles.</p><h4>How do the improvements stack up compared to the legacy implementation?</h4><p>Dask is now 20x faster than before. This improvement applies to the entire DataFrame API (not just isolated components), with no known performance regressions. Dask now runs workloads that were impossible to complete in an acceptable timeframe before. This performance boost is due to many improvements all layered on top of each other. It’s not about doing one thing especially well, but about doing nothing especially poorly.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wFT9QkKhnr0Q76wILZFmTg.png"><figcaption>Performance improvements on Query 3 of the TPC-H Benchmarks from <a href="https://github.com/coiled/benchmarks/tree/main/tests/tpch_">https://github.com/coiled/benchmarks/tree/main/tests/tpch</a></figcaption></figure><p>Performance, while the most enticing improvement, is not the only thing that got better. The optimizer hides a lot of complexity from the user and makes the transition from pandas to Dask a lot easier because it’s now much more difficult to write poorly performing code. The whole system is more robust.</p><p>The new architecture of the API is a lot easier to work with as well. The legacy implementation leaked a lot of internal complexities into high-level API implementations, making changes cumbersome. Improvements are almost trivial to add now.</p><h4>What’s to come?</h4><p>Dask DataFrame changed a lot over the last 18 months. The legacy API was often difficult to work with and struggled with scaling out. The new implementation dropped things that didn’t work and improved existing implementations. The heavy lifting is finished now, which allows for faster iteration cycles to improve upon the status quo. Incremental improvements are now trivial to add.</p><p>A few things that are on the immediate roadmap:</p><ul><li><strong>Auto repartitioning:</strong> this is partially implemented, but there is more potential to choose a more efficient partition size during optimization.</li><li><strong>Faster Joins:</strong> there’s still lots of fine-tuning to be done here. For example, we have a PR in flight with a 30–40% improvement.</li><li><strong>Join Reordering:</strong> we don’t do this yet, but it’s on the immediate roadmap</li></ul><h3><strong>Learn More</strong></h3><p>This article focuses on a number of improvements to Dask DataFrame and how much faster and more reliable it is as a result. If you’re choosing between Dask and other popular DataFrame tools, you might also consider:</p><ul><li><a href="https://docs.coiled.io/blog/tpch.html"><strong>DataFrames at Scale Comparison:</strong> TPC-H</a> which compares Dask, Spark, Polars, and DuckDB performance on datasets ranging from 10 GB to 10 TB both locally and on the cloud.</li></ul><p>Thank you for reading. Feel free to reach out to share your thoughts and feedback.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=ec930181c97a" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/dask-dataframe-is-fast-now-ec930181c97a">Dask DataFrame is Fast Now</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vulnerability Summary for the Week of May 13, 2024]]></title>
<description><![CDATA[High Vulnerabilities



PrimaryVendor -- Product
Description
Published
CVSS Score
Source & Patch Info




8theme--XStore Core 
Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8.
2024-05-17
9.8
CVE-2...]]></description>
<link>https://tsecurity.de/de/2141243/it-security-nachrichten/vulnerability-summary-for-the-week-of-may-13-2024/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2141243/it-security-nachrichten/vulnerability-summary-for-the-week-of-may-13-2024/</guid>
<pubDate>Fri, 10 May 2024 09:09:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<h2>High Vulnerabilities</h2>
<table summary="High Vulnerabilities" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th scope="col" role="columnheader" data-tablesaw-priority="persist">Primary<br>Vendor -- Product</th>
<th scope="col" role="columnheader">Description</th>
<th scope="col" role="columnheader">Published</th>
<th scope="col" role="columnheader">CVSS Score</th>
<th scope="col" role="columnheader">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>8theme--XStore Core<br> </td>
<td>Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33552&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33552" target="_blank">CVE-2024-33552</a><br><a href="https://patchstack.com/database/vulnerability/et-core-plugin/wordpress-xstore-core-plugin-5-3-5-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>8theme--XStore Core<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33556&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33556" target="_blank">CVE-2024-33556</a><br><a href="https://patchstack.com/database/vulnerability/et-core-plugin/wordpress-xstore-core-plugin-5-3-5-limited-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>AA-Team--WZone<br> </td>
<td>Improper Privilege Management vulnerability in AA-Team WZone allows Privilege Escalation.This issue affects WZone: from n/a through 14.0.10.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33549&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33549" target="_blank">CVE-2024-33549</a><br><a href="https://patchstack.com/database/vulnerability/woozone/wordpress-wzone-plugin-14-0-10-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ABB--RobotWare 6<br> </td>
<td>An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible, or execute arbitrary code.  The vulnerability could potentially be exploited to perform unauthorized actions by an attacker. This vulnerability arises under specific condition when specially crafted message is processed by the system. Below are reported vulnerabilities in the Robot Ware versions. * IRC5- RobotWare 6 &lt; 6.15.06 except 6.10.10, and 6.13.07 * OmniCore- RobotWare 7 &lt; 7.14</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1913&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1913" target="_blank">CVE-2024-1913</a><br><a href="https://search.abb.com/library/Download.aspx?DocumentID=SI20330&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch" target="_blank">cybersecurity@ch.abb.com</a></td>
</tr>
<tr>
<td>AROX SOLUTION--School ERP Pro+Responsive<br> </td>
<td>Vulnerability in School ERP Pro+Responsive 1.0 that allows SQL injection through the '/SchoolERP/office_admin/' index in the parameters groups_id, examname, classes_id, es_voucherid, es_class, etc. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the database.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4824&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4824" target="_blank">CVE-2024-4824</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-school-erp-proresponsive-arox-solution" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Abdul Hakeem--Build App Online<br> </td>
<td>Improper Privilege Management vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51479&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51479" target="_blank">CVE-2023-51479</a><br><a href="https://patchstack.com/database/vulnerability/build-app-online/wordpress-build-app-online-plugin-1-0-19-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30284&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30284" target="_blank">CVE-2024-30284</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30310&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30310" target="_blank">CVE-2024-30310</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34094&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34094" target="_blank">CVE-2024-34094</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34095&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34095" target="_blank">CVE-2024-34095</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34096&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34096" target="_blank">CVE-2024-34096</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34097&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34097" target="_blank">CVE-2024-34097</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34098&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34098" target="_blank">CVE-2024-34098</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34099&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34099" target="_blank">CVE-2024-34099</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34100&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34100" target="_blank">CVE-2024-34100</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Aero Desktop<br> </td>
<td>Adobe Aero Desktop versions 23.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30275&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30275" target="_blank">CVE-2024-30275</a><br><a href="https://helpx.adobe.com/security/products/aero/apsb24-33.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30288&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30288" target="_blank">CVE-2024-30288</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30289&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30289" target="_blank">CVE-2024-30289</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30290&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30290" target="_blank">CVE-2024-30290</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30291&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30291" target="_blank">CVE-2024-30291</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30292&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30292" target="_blank">CVE-2024-30292</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30282&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30282" target="_blank">CVE-2024-30282</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30293&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30293" target="_blank">CVE-2024-30293</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30294&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30294" target="_blank">CVE-2024-30294</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30295&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30295" target="_blank">CVE-2024-30295</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30296&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30296" target="_blank">CVE-2024-30296</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30297&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30297" target="_blank">CVE-2024-30297</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Dreamweaver Desktop<br> </td>
<td>Dreamweaver Desktop versions 21.3 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does require user interaction.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30314&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">9.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30314" target="_blank">CVE-2024-30314</a><br><a href="https://helpx.adobe.com/security/products/dreamweaver/apsb24-39.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Illustrator<br> </td>
<td>Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20791&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20791" target="_blank">CVE-2024-20791</a><br><a href="https://helpx.adobe.com/security/products/illustrator/apsb24-30.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Illustrator<br> </td>
<td>Illustrator versions 28.4, 27.9.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20792&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20792" target="_blank">CVE-2024-20792</a><br><a href="https://helpx.adobe.com/security/products/illustrator/apsb24-30.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Substance3D - Painter<br> </td>
<td>Substance3D - Painter versions 9.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30274&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30274" target="_blank">CVE-2024-30274</a><br><a href="https://helpx.adobe.com/security/products/substance3d_painter/apsb24-31.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Substance3D - Painter<br> </td>
<td>Substance3D - Painter versions 9.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30307&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30307" target="_blank">CVE-2024-30307</a><br><a href="https://helpx.adobe.com/security/products/substance3d_painter/apsb24-31.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Agentejo--Cockpit CMS<br> </td>
<td>A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in '/media/api' parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4825&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4825" target="_blank">CVE-2024-4825</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-upload-file-dangerous-type-vulnerability-cockpit-cms" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Apache Friends--XAMPP<br> </td>
<td>Uncontrolled resource consumption vulnerability in XAMPP Windows, versions 7.3.2 and earlier. This vulnerability exists when XAMPP attempts to process many incomplete HTTP requests, resulting in resource consumption and system crashes.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5055&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5055" target="_blank">CVE-2024-5055</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/vulnerability-uncontrolled-resource-consumption-xampp" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Asaancart--Simple PHP Shopping Cart<br> </td>
<td>SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacker to retrieve all the information stored in the database by sending a specially crafted SQL query, due to the lack of proper sanitisation of the category_id parameter in the category.php file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4826&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4826" target="_blank">CVE-2024-4826</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-simple-php-shopping-cart" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Astoundify--Simple Registration for WooCommerce<br> </td>
<td>Improper Privilege Management vulnerability in Astoundify Simple Registration for WooCommerce allows Privilege Escalation.This issue affects Simple Registration for WooCommerce: from n/a through 1.5.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32511&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32511" target="_blank">CVE-2024-32511</a><br><a href="https://patchstack.com/database/vulnerability/woocommerce-simple-registration/wordpress-simple-registration-for-woocommerce-plugin-1-5-6-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Averta--Phlox Portfolio<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Averta Phlox Portfolio allows PHP Local File Inclusion.This issue affects Phlox Portfolio: from n/a through 2.3.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38399&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38399" target="_blank">CVE-2023-38399</a><br><a href="https://patchstack.com/database/vulnerability/auxin-portfolio/wordpress-phlox-portfolio-plugin-2-3-1-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Averta--Phlox Shop<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Averta Phlox Shop allows PHP Local File Inclusion.This issue affects Phlox Shop: from n/a through 2.0.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-39163&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-39163" target="_blank">CVE-2023-39163</a><br><a href="https://patchstack.com/database/vulnerability/auxin-shop/wordpress-phlox-shop-plugin-2-0-0-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>B&amp;R Industrial Automation--Automation Studio<br> </td>
<td>Improper DLL loading algorithms in B&amp;R Automation Studio may allow an authenticated local attacker to execute code with elevated privileges. This issue affects Automation Studio versions before 4.12.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2021-22280&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-22280" target="_blank">CVE-2021-22280</a><br><a href="https://www.br-automation.com/fileadmin/2021-10_DLL_Hijacking_Vulnerability_in_Automation_Studio-7dd34511.pdf" target="_blank">cybersecurity@ch.abb.com</a></td>
</tr>
<tr>
<td>B&amp;R Industrial Automation--Scene Viewer<br> </td>
<td>An authenticated local attacker who successfully exploited this vulnerability could insert and run arbitrary code using legitimate B&amp;R software's. An Uncontrolled Search Path Element vulnerability in B&amp;R Industrial Automation Scene Viewer, B&amp;R Industrial  Automation Runtime, B&amp;R Industrial Automation mapp Vision, B&amp;R Industrial Automation mapp View, B&amp;R Industrial Automation mapp Cockpit, B&amp;R Industrial Automation mapp Safety, B&amp;R Industrial Automation VC4 could allow an authenticated local attacker to execute malicious code by placing specially crafted files in the loading search path. This issue affects Scene Viewer: before 4.4.0; Automation Runtime: before J4.93; mapp Vision: before 5.26.1; mapp View: before 5.24.2; mapp Cockpit: before 5.24.2; mapp Safety: before 5.24.2; VC4: before 4.73.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2637&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2637" target="_blank">CVE-2024-2637</a><br><a href="https://www.br-automation.com/fileadmin/SA24P005_Insecure_Loading_of_Code-c7d9e49c.pdf" target="_blank">cybersecurity@ch.abb.com</a></td>
</tr>
<tr>
<td>BoldGrid--Total Upkeep<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldGrid Total Upkeep allows Relative Path Traversal.This issue affects Total Upkeep: from n/a through 1.15.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24869&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24869" target="_blank">CVE-2024-24869</a><br><a href="https://patchstack.com/database/vulnerability/boldgrid-backup/wordpress-total-upkeep-plugin-1-15-8-arbitrary-file-download-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Booking Ultra Pro--Booking Ultra Pro<br> </td>
<td>Improper Privilege Management vulnerability in Booking Ultra Pro allows Privilege Escalation.This issue affects Booking Ultra Pro: from n/a through 1.1.12.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32960&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32960" target="_blank">CVE-2024-32960</a><br><a href="https://patchstack.com/database/vulnerability/booking-ultra-pro/wordpress-booking-ultra-pro-plugin-1-1-12-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--ConvertPlus<br> </td>
<td>The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_modal' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4838&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4838" target="_blank">CVE-2024-4838</a><br><a href="https://www.convertplug.com/plus/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/16f5a104-dce0-4249-91b9-67f99cce16d3?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--Spectra Pro<br> </td>
<td>The Spectra Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.5. This is due to the plugin allowing lower-privileged users to create registration forms and set the default role to administrator This makes it possible for authenticated attackers, with author-level access and above, to create administrator-level accounts.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3828&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3828" target="_blank">CVE-2024-3828</a><br><a href="https://wpspectra.com/whats-new/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e23e7d66-4b57-4feb-bf77-46238bc6ce7c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--Ultimate Addons for Beaver Builder<br> </td>
<td>Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Privilege Escalation.This issue affects Ultimate Addons for Beaver Builder: from n/a through 1.35.14.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51398&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51398" target="_blank">CVE-2023-51398</a><br><a href="https://patchstack.com/database/vulnerability/bb-ultimate-addon/wordpress-ultimate-addons-for-beaver-builder-premium-plugin-1-35-14-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--Ultimate Addons for Elementor<br> </td>
<td>Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n/a through 1.36.20.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-50890&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-50890" target="_blank">CVE-2023-50890</a><br><a href="https://patchstack.com/database/vulnerability/ultimate-elementor/wordpress-ultimate-addons-for-elementor-plugin-1-36-20-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--Ultimate Addons for WPBakery Page Builder<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder allows PHP Local File Inclusion.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through 3.19.14.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46205&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46205" target="_blank">CVE-2023-46205</a><br><a href="https://patchstack.com/database/vulnerability/ultimate_vc_addons/wordpress-ultimate-addons-for-wpbakery-page-builder-plugin-3-19-14-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Breakdance--Breakdance<br> </td>
<td>The Breakdance plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.7.1 via post meta data. This is due to the plugin storing custom data in metadata without an underscore prefix. This makes it possible for lower privileged users, such as contributors, to edit this data via UI. As a result they can escalate their privileges or execute arbitrary code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4605&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4605" target="_blank">CVE-2024-4605</a><br><a href="https://breakdance.com/breakdance-1-7-2-now-available-security-update/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/095b23b7-71ab-41eb-b666-73df2e1a7eb4?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>By Averta--Shortcodes and extra features for Phlox theme<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in By Averta Shortcodes and extra features for Phlox theme allows PHP Local File Inclusion.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.14.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37888&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37888" target="_blank">CVE-2023-37888</a><br><a href="https://patchstack.com/database/vulnerability/auxin-elements/wordpress-phlox-core-elements-plugin-2-14-0-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary command on the server when `register_argc_argv` option of PHP is `On`. In `cmd_realtime.php` line 119, the `$poller_id` used as part of the command execution is sourced from `$_SERVER['argv']`, which can be controlled by URL when `register_argc_argv` option of PHP is `On`. And this option is `On` by default in many environments such as the main PHP Docker image for PHP. Commit 53e8014d1f082034e0646edc6286cde3800c683d contains a patch for the issue, but this commit was reverted in commit 99633903cad0de5ace636249de16f77e57a3c8fc.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29895&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29895" target="_blank">CVE-2024-29895</a><br><a href="https://github.com/Cacti/cacti/blob/501712998589763d411a68d35e3cda98fd9cfd18/cmd_realtime.php#L119" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/commit/53e8014d1f082034e0646edc6286cde3800c683d" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/commit/99633903cad0de5ace636249de16f77e57a3c8fc" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-cr28-x256-xf5m" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP code on the web server. The vulnerability is located within the `import_package()` function defined into the `/lib/import.php` script. The function blindly trusts the filename and file content provided within the XML data, and writes such files into the Cacti base path (or even outside, since path traversal sequences are not filtered). This can be exploited to write or overwrite arbitrary files on the web server, leading to execution of arbitrary PHP code or other security impacts. Version 1.2.27 contains a patch for this issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25641&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25641" target="_blank">CVE-2024-25641</a><br><a href="https://github.com/Cacti/cacti/commit/eff35b0ff26cc27c82d7880469ed6d5e3bef6210" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-7cmj-g5qc-pj88" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verifying password, it calls `compat_password_verify`. In `compat_password_verify`, `password_verify` is called if there is it, else use `md5`. `password_verify` and `password_hash` are supported on PHP &lt; 5.5.0, following PHP manual. The vulnerability is in `compat_password_verify`. Md5-hashed user input is compared with correct password in database by `$md5 == $hash`. It is a loose comparison, not `===`. It is a type juggling vulnerability. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34340&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34340" target="_blank">CVE-2024-34340</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-37x7-mfjv-mm7m" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, a SQL injection vulnerability in `automation_get_new_graphs_sql` function of `api_automation.php` allows authenticated users to exploit these SQL injection vulnerabilities to perform privilege escalation and remote code execution. In `api_automation.php` line 856, the `get_request_var('filter')` is being concatenated into the SQL statement without any sanitization. In `api_automation.php` line 717, The filter of `'filter'` is `FILTER_DEFAULT`, which means there is no filter for it. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31445&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31445" target="_blank">CVE-2024-31445</a><br><a href="https://github.com/Cacti/cacti/blob/501712998589763d411a68d35e3cda98fd9cfd18/lib/api_automation.php#L717" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/blob/501712998589763d411a68d35e3cda98fd9cfd18/lib/api_automation.php#L856" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/commit/fd93c6e47651958b77c3bbe6a01fff695f81e886" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-vjph-r677-6pcc" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.php` file. Combined with SQL injection vulnerabilities, remote code execution can be implemented. There is a file inclusion issue with the `api_plugin_hook()` function in the `lib/plugin.php` file, which reads the plugin_hooks and plugin_config tables in database. The read data is directly used to concatenate the file path which is used for file inclusion. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31459&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31459" target="_blank">CVE-2024-31459</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-cx8g-hvq8-p2rv" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-gj3f-p326-gh8r" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site scripting, a type of cross-site scripting where malicious scripts are permanently stored on a target server and served to users who access a particular page. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27082&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27082" target="_blank">CVE-2024-27082</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-j868-7vjp-rp9h" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cerberus FTP Enterprise--Cerberus FTP Enterprise<br> </td>
<td>Denial of Service (DoS) vulnerability for Cerberus Enterprise 8.0.10.3 web administration. The vulnerability exists when the web server, default port 10001, attempts to process a large number of incomplete HTTP requests.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5052&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5052" target="_blank">CVE-2024-5052</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/resource-consumption-vulnerability-cerberus-ftp-enterprise" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Cisco--Cisco ConfD<br> </td>
<td>A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerability is due to improper authorization enforcement when specific CLI commands are used. An attacker could exploit this vulnerability by executing an affected CLI command with crafted arguments. A successful exploit could allow the attacker to read or write arbitrary files on the underlying operating system with the privileges of the root user.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20326&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20326" target="_blank">CVE-2024-20326</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cnfd-rwpesc-ZAOufyx8" target="_blank">ykramarz@cisco.com</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-rwpesc-qrQGnh3f" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco ConfD<br> </td>
<td>A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerability is due to improper authorization enforcement when specific CLI commands are used. An attacker could exploit this vulnerability by executing an affected CLI command with crafted arguments. A successful exploit could allow the attacker to read or write arbitrary files on the underlying operating system with the privileges of the root user.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20389&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20389" target="_blank">CVE-2024-20389</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cnfd-rwpesc-ZAOufyx8" target="_blank">ykramarz@cisco.com</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-rwpesc-qrQGnh3f" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Network Services Orchestrator<br> </td>
<td>A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Services Orchestrator (NSO) could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability exists because a user-controlled search path is used to locate executable files. An attacker could exploit this vulnerability by configuring the application in a way that causes a malicious file to be executed. A successful exploit could allow the attacker to execute arbitrary code on an affected device as the root user. To exploit this vulnerability, the attacker would need valid credentials on an affected device.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20366&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20366" target="_blank">CVE-2024-20366</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-hcc-priv-esc-OWBWCs5D" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>CodeRevolution--Demo My WordPress<br> </td>
<td>Improper Privilege Management vulnerability in CodeRevolution Demo My WordPress allows Privilege Escalation.This issue affects Demo My WordPress: from n/a through 1.0.9.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31290&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31290" target="_blank">CVE-2024-31290</a><br><a href="https://patchstack.com/database/vulnerability/demo-my-wordpress/wordpress-demo-my-wordpress-plugin-1-0-9-1-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Contemporary Control System--BASrouter BACnet BASRT-B<br> </td>
<td>A vulnerability classified as critical was found in Contemporary Control System BASrouter BACnet BASRT-B 2.7.2. This vulnerability affects unknown code of the component Application Protocol Data Unit. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263890 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4791&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4791" target="_blank">CVE-2024-4791</a><br><a href="https://github.com/isZzzz/BASRT-B_BACnet_Router_Document/blob/main/BASER-B_APDU.pcapng" target="_blank">cna@vuldb.com</a><br><a href="https://github.com/isZzzz/BASRT-B_BACnet_Router_Document/blob/main/BASRT-B_2_CVE_apply.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263890" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263890" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.323630" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Copymatic--Copymatic AI Content Writer &amp; Generator<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in Copymatic Copymatic - AI Content Writer &amp; Generator.This issue affects Copymatic - AI Content Writer &amp; Generator: from n/a through 1.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31351&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31351" target="_blank">CVE-2024-31351</a><br><a href="https://patchstack.com/database/vulnerability/copymatic/wordpress-copymatic-plugin-1-6-unauthenticated-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Crocoblock--JetEngine<br> </td>
<td>Improper Privilege Management vulnerability in Crocoblock JetEngine allows Privilege Escalation.This issue affects JetEngine: from n/a through 3.2.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-48757&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-48757" target="_blank">CVE-2023-48757</a><br><a href="https://patchstack.com/database/vulnerability/jet-engine/wordpress-jetengine-plugin-3-2-4-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Crocoblock--JetFormBuilder<br> </td>
<td>Improper Privilege Management vulnerability in Crocoblock JetFormBuilder allows Privilege Escalation.This issue affects JetFormBuilder: from n/a through 3.0.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37866&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37866" target="_blank">CVE-2023-37866</a><br><a href="https://patchstack.com/database/vulnerability/jetformbuilder/wordpress-jetformbuilder-plugin-3-0-8-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CyberPower--CyberPower PowerPanel Enterprise<br> </td>
<td>An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32735&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32735" target="_blank">CVE-2024-32735</a><br><a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank">vulnreport@tenable.com</a><br><a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>CyberPower--CyberPower PowerPanel Enterprise<br> </td>
<td>A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function within MCUDBHelper.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32736&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32736" target="_blank">CVE-2024-32736</a><br><a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank">vulnreport@tenable.com</a><br><a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>CyberPower--CyberPower PowerPanel Enterprise<br> </td>
<td>A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_contract_result" function within MCUDBHelper.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32737&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32737" target="_blank">CVE-2024-32737</a><br><a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank">vulnreport@tenable.com</a><br><a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>CyberPower--CyberPower PowerPanel Enterprise<br> </td>
<td>A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_lean" function within MCUDBHelper.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32738&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32738" target="_blank">CVE-2024-32738</a><br><a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank">vulnreport@tenable.com</a><br><a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>CyberPower--CyberPower PowerPanel Enterprise<br> </td>
<td>A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_verbose" function within MCUDBHelper.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32739&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32739" target="_blank">CVE-2024-32739</a><br><a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank">vulnreport@tenable.com</a><br><a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an attacker gaining access to the testing or production server.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32047&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32047" target="_blank">CVE-2024-32047</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>Hard-coded credentials are used by the  CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could result in an attacker gaining access to services with the privileges of a Powerpanel business application.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32053&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32053" target="_blank">CVE-2024-32053</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33625&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33625" target="_blank">CVE-2024-33625</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing authentication and gaining administrator privileges.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34025&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34025" target="_blank">CVE-2024-34025</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>An attacker with certain MQTT permissions can create malicious messages to all CyberPower PowerPanel devices. This could result in an attacker injecting SQL syntax, writing arbitrary files to the system, and executing remote code.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31856&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31856" target="_blank">CVE-2024-31856</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>A specially crafted Zip file containing path traversal characters can be imported to the CyberPower PowerPanel server, which allows file writing to the server outside the intended scope, and could allow an attacker to achieve remote code execution.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33615&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33615" target="_blank">CVE-2024-33615</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>The devices which CyberPower PowerPanel manages use identical certificates based on a hard-coded cryptographic key. This can allow an attacker to impersonate any client in the system and send malicious data.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31410&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31410" target="_blank">CVE-2024-31410</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CycloneDX--cyclonedx-javascript-library<br> </td>
<td>The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34345&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34345" target="_blank">CVE-2024-34345</a><br><a href="https://github.com/CycloneDX/cyclonedx-javascript-library/commit/5e5e1e0b9422f47d2de81c7c4064b803a01e7203" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/CycloneDX/cyclonedx-javascript-library/pull/1063" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/CycloneDX/cyclonedx-javascript-library/security/advisories/GHSA-38gf-rh2w-gmj7" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Darren Cooney--Instant Images<br> </td>
<td>Improper Privilege Management vulnerability in Darren Cooney Instant Images allows Privilege Escalation.This issue affects Instant Images: from n/a through 6.1.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33569&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33569" target="_blank">CVE-2024-33569</a><br><a href="https://patchstack.com/database/vulnerability/instant-images/wordpress-instant-images-plugin-6-1-0-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Dell--CPG BIOS<br> </td>
<td>Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22429&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22429" target="_blank">CVE-2024-22429</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000221102/dsa-2024-020" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>DigiWin--EasyFlow .NET<br> </td>
<td>DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4893&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4893" target="_blank">CVE-2024-4893</a><br><a href="https://www.twcert.org.tw/en/cp-139-7801-67d07-2.html" target="_blank">twcert@cert.org.tw</a><br><a href="https://www.twcert.org.tw/tw/cp-132-7800-843f1-1.html" target="_blank">twcert@cert.org.tw</a></td>
</tr>
<tr>
<td>Elementor--Elementor Website Builder<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website Builder: from n/a through 3.19.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24934&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24934" target="_blank">CVE-2024-24934</a><br><a href="https://patchstack.com/database/vulnerability/elementor/wordpress-elementor-plugin-3-19-0-arbitrary-file-deletion-and-phar-deserialization-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>EnterpriseDB--EDB Postgres Advanced Server<br> </td>
<td>All versions of EnterpriseDB Postgres Advanced Server (EPAS) from 15.0 prior to 15.7.0 and from 16.0 prior to 16.3.0 may allow users using edbldr to bypass role permissions from pg_read_server_files. This could allow low privilege users to read files to which they would not otherwise have access.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4545&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4545" target="_blank">CVE-2024-4545</a><br><a href="https://www.enterprisedb.com/docs/epas/15/epas_rel_notes/" target="_blank">20be33e2-bf35-4d13-8fad-18bd2f3e3659</a><br><a href="https://www.enterprisedb.com/docs/epas/latest/epas_rel_notes/" target="_blank">20be33e2-bf35-4d13-8fad-18bd2f3e3659</a><br><a href="https://www.enterprisedb.com/docs/security/advisories/cve20244545/" target="_blank">20be33e2-bf35-4d13-8fad-18bd2f3e3659</a></td>
</tr>
<tr>
<td>EverPress--Mailster<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EverPress Mailster allows PHP Local File Inclusion.This issue affects Mailster: from n/a through 4.0.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32523&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32523" target="_blank">CVE-2024-32523</a><br><a href="https://patchstack.com/database/vulnerability/mailster/wordpress-mailster-plugin-4-0-6-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Favethemes--Houzez Login Register<br> </td>
<td>Improper Privilege Management vulnerability in favethemes Houzez Login Register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through 2.6.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-26009&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-26009" target="_blank">CVE-2023-26009</a><br><a href="https://patchstack.com/database/vulnerability/houzez-login-register/wordpress-houzez-login-register-plugin-2-6-3-privilege-escalation?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Favethemes--Houzez<br> </td>
<td>Improper Privilege Management vulnerability in Favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 2.7.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-26540&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-26540" target="_blank">CVE-2023-26540</a><br><a href="https://patchstack.com/database/vulnerability/houzez/wordpress-houzez-theme-2-7-1-privilege-escalation?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiOS<br> </td>
<td>A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative interface to execute arbitrary code or commands via crafted HTTP or HTTPs requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46714&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46714" target="_blank">CVE-2023-46714</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-415" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiPortal<br> </td>
<td>A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23105&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23105" target="_blank">CVE-2024-23105</a><br><a href="https://fortiguard.com/psirt/FG-IR-24-021" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiSandbox<br> </td>
<td>A client-side enforcement of server-side security in Fortinet FortiSandbox version 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31491&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31491" target="_blank">CVE-2024-31491</a><br><a href="https://fortiguard.com/psirt/FG-IR-24-054" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiVoice<br> </td>
<td>An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-40720&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40720" target="_blank">CVE-2023-40720</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-282" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>GE HealthCare--EchoPAC Software Only<br> </td>
<td>Weak account password in GE HealthCare EchoPAC products</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27107&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27107" target="_blank">CVE-2024-27107</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--EchoPAC Software Only<br> </td>
<td>Elevation of privilege vulnerability in GE HealthCare EchoPAC products</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27110&amp;vector=CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27110" target="_blank">CVE-2024-27110</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--EchoPAC Software Only<br> </td>
<td>Insufficiently protected credentials in GE HealthCare EchoPAC products</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27109&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27109" target="_blank">CVE-2024-27109</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--Venue<br> </td>
<td>OS command injection vulnerabilities in GE HealthCare ultrasound devices</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1628&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1628" target="_blank">CVE-2024-1628</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--Venue<br> </td>
<td>Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1486&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1486" target="_blank">CVE-2024-1486</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--Venue<br> </td>
<td>Path traversal vulnerability in "getAllFolderContents" function of Common Service Desktop, a GE HealthCare ultrasound device component</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1630&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1630" target="_blank">CVE-2024-1630</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>Ghost Foundation--Ghost<br> </td>
<td>Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from n/a through 1.4.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34559&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34559" target="_blank">CVE-2024-34559</a><br><a href="https://patchstack.com/database/vulnerability/ghost/wordpress-ghost-plugin-1-4-0-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>GiveWP--GiveWP<br> </td>
<td>Improper Privilege Management vulnerability in GiveWP allows Privilege Escalation.This issue affects GiveWP: from n/a through 2.33.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41665&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41665" target="_blank">CVE-2023-41665</a><br><a href="https://patchstack.com/database/vulnerability/give/wordpress-givewp-plugin-2-33-0-givewp-manager-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Glowlogix--WP Frontend Profile<br> </td>
<td>Improper Privilege Management vulnerability in Glowlogix WP Frontend Profile allows Privilege Escalation.This issue affects WP Frontend Profile: from n/a through 1.3.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51483&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51483" target="_blank">CVE-2023-51483</a><br><a href="https://patchstack.com/database/vulnerability/wp-front-end-profile/wordpress-wp-frontend-profile-plugin-1-3-1-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>HCL Software--Commerce<br> </td>
<td>Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23576&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23576" target="_blank">CVE-2024-23576</a><br><a href="https://support.hcltechsw.com/csm?id=kb_article&amp;sysparm_article=KB0112907" target="_blank">psirt@hcl.com</a></td>
</tr>
<tr>
<td>Hamid Alinia idehweb--Login with phone number<br> </td>
<td>Improper Privilege Management vulnerability in Hamid Alinia - idehweb Login with phone number allows Privilege Escalation.This issue affects Login with phone number: from n/a through 1.7.16.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32507&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32507" target="_blank">CVE-2024-32507</a><br><a href="https://patchstack.com/database/vulnerability/login-with-phone-number/wordpress-login-with-phone-number-plugin-1-7-16-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>HasThemes--HT Mega<br> </td>
<td>Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37999&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37999" target="_blank">CVE-2023-37999</a><br><a href="https://patchstack.com/database/vulnerability/ht-mega-for-elementor/wordpress-ht-mega-absolute-addons-for-elementor-plugin-2-2-0-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31466&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31466" target="_blank">CVE-2024-31466</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31467&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31467" target="_blank">CVE-2024-31467</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31468&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31468" target="_blank">CVE-2024-31468</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31469&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31469" target="_blank">CVE-2024-31469</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31470&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31470" target="_blank">CVE-2024-31470</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There is a command injection vulnerability in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31471&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31471" target="_blank">CVE-2024-31471</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There are command injection vulnerabilities in the underlying Soft AP Daemon service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31472&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31472" target="_blank">CVE-2024-31472</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31473&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31473" target="_blank">CVE-2024-31473</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There is an arbitrary file deletion vulnerability in the CLI service accessed by PAPI (Aruba's Access Point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31474&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31474" target="_blank">CVE-2024-31474</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31475&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31475" target="_blank">CVE-2024-31475</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31476&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31476" target="_blank">CVE-2024-31476</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31477&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31477" target="_blank">CVE-2024-31477</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32997&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32997" target="_blank">CVE-2024-32997</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Privilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-52719&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52719" target="_blank">CVE-2023-52719</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Permission verification vulnerability in the wpa_supplicant module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32991&amp;vector=CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32991" target="_blank">CVE-2024-32991</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Insufficient verification vulnerability in the baseband module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32992&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32992" target="_blank">CVE-2024-32992</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>IBM--AIX<br> </td>
<td>IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 283985.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27260&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27260" target="_blank">CVE-2024-27260</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/283985" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7152543" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--Security Guardium<br> </td>
<td>IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 271524.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47709&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47709" target="_blank">CVE-2023-47709</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/271524" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150840" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--Security Guardium<br> </td>
<td>IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47712&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47712" target="_blank">CVE-2023-47712</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/271524" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150840" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--i<br> </td>
<td>IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused by the deserialization of untrusted data. IBM X-Force ID: 287539.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31879&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31879" target="_blank">CVE-2024-31879</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/287539" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7154380" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IOSS--WP MLM Unilevel<br> </td>
<td>Improper Privilege Management vulnerability in IOSS WP MLM Unilevel allows Privilege Escalation.This issue affects WP MLM Unilevel: from n/a through 4.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51476&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51476" target="_blank">CVE-2023-51476</a><br><a href="https://patchstack.com/database/vulnerability/wp-mlm/wordpress-wp-mlm-unilevel-plugin-4-0-unauthenticated-account-takeover-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>InstaWP Team--InstaWP Connect<br> </td>
<td>Improper Privilege Management vulnerability in InstaWP Team InstaWP Connect allows Privilege Escalation.This issue affects InstaWP Connect: from n/a through 0.1.0.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22145&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22145" target="_blank">CVE-2024-22145</a><br><a href="https://patchstack.com/database/vulnerability/instawp-connect/wordpress-instawp-connect-plugin-0-1-0-8-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>J.N. Breetvelt a.k.a. OpaJaap--WP Photo Album Plus<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.7.01.001.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31377&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31377" target="_blank">CVE-2024-31377</a><br><a href="https://patchstack.com/database/vulnerability/wp-photo-album-plus/wordpress-wp-photo-album-plus-plugin-8-7-01-001-unauthenticated-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>JR King/Eran Schoellhorn--WP Masquerade<br> </td>
<td>Improper Privilege Management vulnerability in JR King/Eran Schoellhorn WP Masquerade allows Privilege Escalation.This issue affects WP Masquerade: from n/a through 1.1.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33550&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33550" target="_blank">CVE-2024-33550</a><br><a href="https://patchstack.com/database/vulnerability/wp-masquerade/wordpress-wp-masquerade-plugin-1-1-0-authenticated-account-takeover-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>JS Help Desk--JS Help Desk Best Help Desk &amp; Support Plugin<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk - Best Help Desk &amp; Support Plugin allows Using Malicious Files.This issue affects JS Help Desk - Best Help Desk &amp; Support Plugin: from n/a through 2.7.7.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-25444&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-25444" target="_blank">CVE-2023-25444</a><br><a href="https://patchstack.com/database/vulnerability/js-support-ticket/wordpress-js-help-desk-best-help-desk-support-plugin-plugin-2-7-7-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Jordy Meow--AI Engine: ChatGPT Chatbot<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.2.63.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34440&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34440" target="_blank">CVE-2024-34440</a><br><a href="https://patchstack.com/database/vulnerability/ai-engine/wordpress-ai-engine-plugin-2-2-63-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Joseph C Dolson--My Tickets<br> </td>
<td>Missing Authorization vulnerability in Joseph C Dolson My Tickets.This issue affects My Tickets: from n/a through 1.9.11.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23988&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23988" target="_blank">CVE-2023-23988</a><br><a href="https://patchstack.com/database/vulnerability/my-tickets/wordpress-my-tickets-plugin-1-9-11-payment-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>JumpDEMAND Inc.--ActiveDEMAND<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in JumpDEMAND Inc. ActiveDEMAND allows Using Malicious Files.This issue affects ActiveDEMAND: from n/a through 0.2.41.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32809&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32809" target="_blank">CVE-2024-32809</a><br><a href="https://patchstack.com/database/vulnerability/activedemand/wordpress-activedemand-plugin-0-2-41-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Kioware--Kioware<br> </td>
<td>KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3459&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3459" target="_blank">CVE-2024-3459</a><br><a href="https://cert.pl/en/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://www.kioware.com/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Kioware--Kioware<br> </td>
<td>In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing a short time window before the forced automatic logout occurs. Then, by using some built-in function of these applications, one may launch any other programs.  In order to exploit this vulnerability external applications must be left running when the KioWare software is launched. Additionally, an attacker must know the PIN set for this Kioware instance and also slow down the application with some specific task which extends the usable time window.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3460&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3460" target="_blank">CVE-2024-3460</a><br><a href="https://cert.pl/en/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://www.kioware.com/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Kognetiks--Kognetiks Chatbot for WordPress<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in Kognetiks Kognetiks Chatbot for WordPress.This issue affects Kognetiks Chatbot for WordPress: from n/a through 2.0.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32700&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32700" target="_blank">CVE-2024-32700</a><br><a href="https://patchstack.com/database/vulnerability/chatbot-chatgpt/wordpress-kognetiks-chatbot-for-wordpress-plugin-2-0-0-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>LWS--LWS Affiliation<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LWS LWS Affiliation allows PHP Local File Inclusion.This issue affects LWS Affiliation: from n/a through 2.2.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-32297&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-32297" target="_blank">CVE-2023-32297</a><br><a href="https://patchstack.com/database/vulnerability/lws-affiliation/wordpress-lws-affiliation-plugin-2-2-6-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Lenderd--1003 Mortgage Application<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Lenderd 1003 Mortgage Application allows Relative Path Traversal.This issue affects 1003 Mortgage Application: from n/a through 1.75.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-45368&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-45368" target="_blank">CVE-2022-45368</a><br><a href="https://patchstack.com/database/vulnerability/1003-mortgage-application/wordpress-1003-mortgage-application-plugin-1-73-local-file-inclusion?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Lenovo--Printers<br> </td>
<td>A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trigger a device restart by sending a specially crafted web request.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3286&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3286" target="_blank">CVE-2024-3286</a><br><a href="https://iknow.lenovo.com.cn/detail/421500" target="_blank">psirt@lenovo.com</a><br><a href="https://www.lenovoimage.com/psirt/notice/158605.html" target="_blank">psirt@lenovo.com</a></td>
</tr>
<tr>
<td>MSI--MSI Afterburner<br> </td>
<td>MSI Afterburner v4.6.6.16381 Beta 3 is vulnerable to an ACL Bypass vulnerability in the RTCore64.sys driver, which leads to triggering vulnerabilities like CVE-2024-1443 and CVE-2024-1460 from a low privileged user.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3745&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3745" target="_blank">CVE-2024-3745</a><br><a href="https://fluidattacks.com/advisories/gershwin/" target="_blank">help@fluidattacks.com</a><br><a href="https://forums.guru3d.com/threads/msi-ab-rtss-development-news-thread.412822/page-227#post-6231456" target="_blank">help@fluidattacks.com</a><br><a href="https://forums.guru3d.com/threads/msi-ab-rtss-development-news-thread.412822/page-227#post-6231768" target="_blank">help@fluidattacks.com</a></td>
</tr>
<tr>
<td>MainWP--MainWP Code Snippets Extension<br> </td>
<td>Improper Control of Generation of Code ('Code Injection') vulnerability in MainWP MainWP Code Snippets Extension allows Code Injection.This issue affects MainWP Code Snippets Extension: from n/a through 4.0.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23645&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23645" target="_blank">CVE-2023-23645</a><br><a href="https://patchstack.com/database/vulnerability/mainwp-code-snippets-extension/wordpress-mainwp-code-snippets-extension-plugin-4-0-2-subscriber-arbitrary-php-code-injection-execution-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Masteriyo--LMS<br> </td>
<td>Improper Privilege Management vulnerability in Masteriyo LMS allows Privilege Escalation.This issue affects LMS: from n/a through 1.7.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24882&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24882" target="_blank">CVE-2024-24882</a><br><a href="https://patchstack.com/database/vulnerability/learning-management-system/wordpress-lms-by-masteriyo-plugin-1-7-2-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Microsoft--Azure Monitor<br> </td>
<td>Azure Monitor Agent Elevation of Privilege Vulnerability</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30060&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30060" target="_blank">CVE-2024-30060</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30060" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Dynamics 365<br> </td>
<td>Dynamics 365 Customer Insights Spoofing Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30047&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30047" target="_blank">CVE-2024-30047</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30047" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Dynamics 365<br> </td>
<td>Dynamics 365 Customer Insights Spoofing Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30048&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30048" target="_blank">CVE-2024-30048</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30048" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Microsoft SharePoint Enterprise Server 2016<br> </td>
<td>Microsoft SharePoint Server Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30044&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30044" target="_blank">CVE-2024-30044</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30044" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Office Online Server<br> </td>
<td>Microsoft Excel Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30042&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30042" target="_blank">CVE-2024-30042</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30042" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30006&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30006" target="_blank">CVE-2024-30006</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30006" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30009&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30009" target="_blank">CVE-2024-30009</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30009" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Hyper-V Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30017&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30017" target="_blank">CVE-2024-30017</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30017" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Cryptographic Services Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30020&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30020" target="_blank">CVE-2024-30020</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30020" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29994&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29994" target="_blank">CVE-2024-29994</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29994" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Common Log File System Driver Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29996&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29996" target="_blank">CVE-2024-29996</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29996" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30014&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30014" target="_blank">CVE-2024-30014</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30014" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30015&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30015" target="_blank">CVE-2024-30015</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30015" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Kernel Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30018&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30018" target="_blank">CVE-2024-30018</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30018" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30022&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30022" target="_blank">CVE-2024-30022</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30022" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30023&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30023" target="_blank">CVE-2024-30023</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30023" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30024&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30024" target="_blank">CVE-2024-30024</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30024" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Common Log File System Driver Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30025&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30025" target="_blank">CVE-2024-30025</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30025" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>NTFS Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30027&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30027" target="_blank">CVE-2024-30027</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30027" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Win32k Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30028&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30028" target="_blank">CVE-2024-30028</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30028" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30029&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30029" target="_blank">CVE-2024-30029</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30029" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows CNG Key Isolation Service Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30031&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30031" target="_blank">CVE-2024-30031</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30031" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows DWM Core Library Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30032&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30032" target="_blank">CVE-2024-30032</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30032" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows DWM Core Library Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30035&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30035" target="_blank">CVE-2024-30035</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30035" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Common Log File System Driver Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30037&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30037" target="_blank">CVE-2024-30037</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30037" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Win32k Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30038&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30038" target="_blank">CVE-2024-30038</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30038" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30049&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30049" target="_blank">CVE-2024-30049</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30049" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 21H2<br> </td>
<td>Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-26238&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-26238" target="_blank">CVE-2024-26238</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26238" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2008 Service Pack 2<br> </td>
<td>Win32k Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30030&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30030" target="_blank">CVE-2024-30030</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30030" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2019<br> </td>
<td>Windows Hyper-V Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30010&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30010" target="_blank">CVE-2024-30010</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30010" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2022, 23H2 Edition (Server Core installation)<br> </td>
<td>Microsoft Brokering File System Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30007&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30007" target="_blank">CVE-2024-30007</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30007" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2022<br> </td>
<td>Windows Search Service Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30033&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30033" target="_blank">CVE-2024-30033</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30033" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>MongoDB Inc--MongoDB Server<br> </td>
<td>Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected application behavior including unavailability of serverStatus responses. This issue affects MongoDB Server v7.0 versions prior to 7.0.6, MongoDB Server v6.0 versions prior to 6.0.14 and MongoDB Server v.5.0 versions prior to 5.0.25.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3372&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3372" target="_blank">CVE-2024-3372</a><br><a href="https://jira.mongodb.org/browse/SERVER-85263" target="_blank">cna@mongodb.com</a></td>
</tr>
<tr>
<td>N/A--Pk Favicon Manager<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in Pk Favicon Manager.This issue affects Pk Favicon Manager: from n/a through 2.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34416&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34416" target="_blank">CVE-2024-34416</a><br><a href="https://patchstack.com/database/vulnerability/phpsword-favicon-manager/wordpress-pk-favicon-manager-plugin-2-1-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>N/A--VMware Workstation<br> </td>
<td>VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to create a denial of service condition.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22268&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22268" target="_blank">CVE-2024-22268</a><br><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280" target="_blank">security@vmware.com</a></td>
</tr>
<tr>
<td>N/A--VMware Workstation<br> </td>
<td>VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22269&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22269" target="_blank">CVE-2024-22269</a><br><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280" target="_blank">security@vmware.com</a></td>
</tr>
<tr>
<td>N/A--VMware Workstation<br> </td>
<td>VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22270&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22270" target="_blank">CVE-2024-22270</a><br><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280" target="_blank">security@vmware.com</a></td>
</tr>
<tr>
<td>NA--VMware Workstation<br> </td>
<td>VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22267&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22267" target="_blank">CVE-2024-22267</a><br><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280" target="_blank">security@vmware.com</a></td>
</tr>
<tr>
<td>NI--FlexLogger<br> </td>
<td>A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects NI FlexLogger 2024 Q1 and prior versions as well as NI InstrumentStudio 2024 Q1 and prior versions.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4044&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4044" target="_blank">CVE-2024-4044</a><br><a href="https://ni.com/r/CVE-2024-4044" target="_blank">security@ni.com</a></td>
</tr>
<tr>
<td>Netflix--Genie<br> </td>
<td>A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4701&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L" target="_blank" title="CVSS V3 Score">9.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4701" target="_blank">CVE-2024-4701</a><br><a href="https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2024-001.md" target="_blank">security-report@netflix.com</a></td>
</tr>
<tr>
<td>Nota-Info--Bookly<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Nota-Info Bookly allows Path Traversal, Manipulating Web Input to File System Calls.This issue affects Bookly: from n/a through 21.7.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-26526&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-26526" target="_blank">CVE-2023-26526</a><br><a href="https://patchstack.com/database/vulnerability/bookly-responsive-appointment-booking-tool/wordpress-bookly-plugin-21-7-1-authenticated-arbitrary-file-deletion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Nozomi Networks--Arc<br> </td>
<td>Multiple functions use archives without properly validating the filenames therein, rendering the application vulnerable to path traversal via 'zip slip' attacks. An administrator able to provide tampered archives to be processed by the affected versions of Arc may be able to have arbitrary files extracted to arbitrary filesystem locations. Leveraging this issue, an attacker may be able to overwrite arbitrary files on the target filesystem and cause critical impacts on the system (e.g., arbitrary command execution on the victim's machine).</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5938&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5938" target="_blank">CVE-2023-5938</a><br><a href="https://security.nozominetworks.com/NN-2023:16-01" target="_blank">prodsec@nozominetworks.com</a></td>
</tr>
<tr>
<td>Nozomi Networks--Arc<br> </td>
<td>When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process. Such web interface lacks authentication and may thus be abused by a local attacker or malware running on the machine itself. A malicious local user or process, during a window of opportunity when the local web interface is active, may be able to extract sensitive information or change Arc's configuration. This could also lead to arbitrary code execution if a malicious update package is installed.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5935&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5935" target="_blank">CVE-2023-5935</a><br><a href="https://security.nozominetworks.com/NN-2023:13-01" target="_blank">prodsec@nozominetworks.com</a></td>
</tr>
<tr>
<td>Nozomi Networks--Arc<br> </td>
<td>On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a malicious local user in the system may be able to trigger arbitrary code execution with root privileges.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5936&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5936" target="_blank">CVE-2023-5936</a><br><a href="https://security.nozominetworks.com/NN-2023:14-01" target="_blank">prodsec@nozominetworks.com</a></td>
</tr>
<tr>
<td>OceanWP--OceanWP<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OceanWP allows PHP Local File Inclusion.This issue affects OceanWP: from n/a through 3.4.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23700&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23700" target="_blank">CVE-2023-23700</a><br><a href="https://patchstack.com/database/vulnerability/oceanwp/wordpress-oceanwp-theme-3-4-1-authenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>OctoPrint--OctoPrint<br> </td>
<td>OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated attacker to completely bypass the authentication if the `autologinLocal` option is enabled within `config.yaml`, even if they come from networks that are not configured as `localNetworks`, spoofing their IP via the `X-Forwarded-For` header. If autologin is not enabled, this vulnerability does not have any impact. The vulnerability has been patched in version 1.10.1. Until the patch has been applied, OctoPrint administrators who have autologin enabled on their instances should disable it and/or to make the instance inaccessible from potentially hostile networks like the internet.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32977&amp;vector=CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32977" target="_blank">CVE-2024-32977</a><br><a href="https://github.com/OctoPrint/OctoPrint/commit/5afbec8d23508edc25b0f1bdef1620580136add4" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-2vjq-hg5w-5gm7" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Remote Code Execution has been discovered in OpenTextâ„¢ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3483&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3483" target="_blank">CVE-2024-3483</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>XML External Entity injection vulnerability found in OpenTextâ„¢ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3486&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3486" target="_blank">CVE-2024-3486</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Remote Code Execution has been discovered in OpenTextâ„¢ iManager 3.2.6.0200. The vulnerability can trigger remote code execution unisng unsafe java object deserialization.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3967&amp;vector=CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3967" target="_blank">CVE-2024-3967</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Remote Code Execution has been discovered in OpenTextâ„¢ iManager 3.2.6.0200. The vulnerability can trigger remote code execution using custom file upload task.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3968&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3968" target="_blank">CVE-2024-3968</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>Owlet--Cam v2<br> </td>
<td>A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6321&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6321" target="_blank">CVE-2023-6321</a><br><a href="https://bitdefender.com/blog/labs/notes-on-throughtek-kalay-vulnerabilities-and-their-impact/" target="_blank">cve-requests@bitdefender.com</a></td>
</tr>
<tr>
<td>P-THEMES--Porto Theme - Functionality<br> </td>
<td>The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the 'porto_portfolios' shortcode 'portfolio_layout' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3808&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3808" target="_blank">CVE-2024-3808</a><br><a href="https://themeforest.net/item/porto-responsive-wordpress-ecommerce-theme/9207399" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fea96f84-f75b-4f02-9ca8-f8fda439d565?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>P-THEMES--Porto Theme - Functionality<br> </td>
<td>The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.9 via the 'slideshow_type' post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3809&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3809" target="_blank">CVE-2024-3809</a><br><a href="https://themeforest.net/item/porto-responsive-wordpress-ecommerce-theme/9207399" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f5cdd3c1-6353-4bee-a4f9-5b7972f0970c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>P-THEMES--Porto<br> </td>
<td>The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via the 'porto_ajax_posts' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3806&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3806" target="_blank">CVE-2024-3806</a><br><a href="https://themeforest.net/item/porto-responsive-wordpress-ecommerce-theme/9207399" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/98ccc604-79c6-4be9-acb0-23fc82a31dfa?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>P-THEMES--Porto<br> </td>
<td>The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'porto_page_header_shortcode_type', 'slideshow_type' and 'post_layout' post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included. This was partially patched in version 7.1.0 and fully patched in version 7.1.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3807&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3807" target="_blank">CVE-2024-3807</a><br><a href="https://themeforest.net/item/porto-responsive-wordpress-ecommerce-theme/9207399" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4bc3da9e-4b5f-4200-9df9-0ae953571377?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>PHOENIX CONTACT--CHARX SEC-3000<br> </td>
<td>A local low privileged attacker can use an untrusted search path in a CHARX system utility to gain root privileges. </td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28133&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28133" target="_blank">CVE-2024-28133</a><br><a href="https://cert.vde.com/en/advisories/VDE-2024-019" target="_blank">info@cert.vde.com</a></td>
</tr>
<tr>
<td>PHOENIX CONTACT--CHARX SEC-3000<br> </td>
<td>An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the currently logged in user due to cleartext transmission of sensitive information. No additional user interaction is required. The access is limited as only non-sensitive information can be obtained but the availability can be seriously affected. </td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28134&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28134" target="_blank">CVE-2024-28134</a><br><a href="https://cert.vde.com/en/advisories/VDE-2024-019" target="_blank">info@cert.vde.com</a></td>
</tr>
<tr>
<td>PHOENIX CONTACT--CHARX SEC-3000<br> </td>
<td>A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCPP Remote service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28136&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28136" target="_blank">CVE-2024-28136</a><br><a href="https://cert.vde.com/en/advisories/VDE-2024-019" target="_blank">info@cert.vde.com</a></td>
</tr>
<tr>
<td>PHOENIX CONTACT--CHARX SEC-3000<br> </td>
<td>A local attacker with low privileges can perform a privilege escalation with an init script due to a TOCTOU vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28137&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28137" target="_blank">CVE-2024-28137</a><br><a href="https://cert.vde.com/en/advisories/VDE-2024-019" target="_blank">info@cert.vde.com</a></td>
</tr>
<tr>
<td>PHPGurukul--Online Course Registration System<br> </td>
<td>A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264922 is the identifier assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5063&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5063" target="_blank">CVE-2024-5063</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Online%20Course%20Registration%20System/Online%20Course%20Registration%20System%20-%20Authentication%20Bypass.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264922" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264922" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336236" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>PHPGurukul--Online Course Registration System<br> </td>
<td>A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been rated as critical. This issue affects some unknown processing of the file news-details.php. The manipulation of the argument nid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264923.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5064&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5064" target="_blank">CVE-2024-5064</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Online%20Course%20Registration%20System/Online%20Course%20Registration%20System%20-%20SQL%20Injection%20-%202%20(Unauthenticated).md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264923" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264923" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336238" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>PHPGurukul--Online Course Registration System<br> </td>
<td>A vulnerability classified as critical has been found in PHPGurukul Online Course Registration System 3.1. Affected is an unknown function of the file /onlinecourse/. The manipulation of the argument regno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264924.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5065&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5065" target="_blank">CVE-2024-5065</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Online%20Course%20Registration%20System/Online%20Course%20Registration%20System%20-%20SQL%20Injection%20-%203%20(Unauthenticated).md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264924" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264924" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336239" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>POSIMYTH Innovation--The Plus Addons for Elementor Pro<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows PHP Local File Inclusion.This issue affects The Plus Addons for Elementor Pro: from n/a through 5.2.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47178&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47178" target="_blank">CVE-2023-47178</a><br><a href="https://patchstack.com/database/vulnerability/theplus_elementor_addon/wordpress-the-plus-addons-for-elementor-pro-plugin-5-2-8-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Phoenix--SecureCore for Intel Gemini Lake<br> </td>
<td>Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCoreâ„¢ for Intel Gemini Lake.This issue affects: SecureCoreâ„¢ for Intel Gemini Lake: from 4.1.0.1 before 4.1.0.567.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1598&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1598" target="_blank">CVE-2024-1598</a><br><a href="https://www.phoenix.com/security-notifications/cve-2024-1598/" target="_blank">22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de</a></td>
</tr>
<tr>
<td>Phoenix--SecureCore for Intel Kaby Lake<br> </td>
<td>Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCoreâ„¢ for select Intel platforms This issue affects: Phoenix SecureCoreâ„¢ for Intel Kaby Lake: from 4.0.1.1 before 4.0.1.998; Phoenix SecureCoreâ„¢ for Intel Coffee Lake: from 4.1.0.1 before 4.1.0.562; Phoenix SecureCoreâ„¢ for Intel Ice Lake: from 4.2.0.1 before 4.2.0.323; Phoenix SecureCoreâ„¢ for Intel Comet Lake: from 4.2.1.1 before 4.2.1.287; Phoenix SecureCoreâ„¢ for Intel Tiger Lake: from 4.3.0.1 before 4.3.0.236; Phoenix SecureCoreâ„¢ for Intel Jasper Lake: from 4.3.1.1 before 4.3.1.184; Phoenix SecureCoreâ„¢ for Intel Alder Lake: from 4.4.0.1 before 4.4.0.269; Phoenix SecureCoreâ„¢ for Intel Raptor Lake: from 4.5.0.1 before 4.5.0.218; Phoenix SecureCoreâ„¢ for Intel Meteor Lake: from 4.5.1.1 before 4.5.1.15.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0762&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0762" target="_blank">CVE-2024-0762</a><br><a href="https://www.phoenix.com/security-notifications/cve-2024-0762/" target="_blank">22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de</a></td>
</tr>
<tr>
<td>Phoenix--WinFlash Driver<br> </td>
<td>Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-35841&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-35841" target="_blank">CVE-2023-35841</a><br><a href="https://blogs.vmware.com/security/2023/10/hunting-vulnerable-kernel-drivers.html" target="_blank">22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de</a><br><a href="https://jvn.jp/en/vu/JVNVU93886750/index.html" target="_blank">22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de</a><br><a href="https://www.phoenix.com/security-notifications/cve-2023-35841/" target="_blank">22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de</a></td>
</tr>
<tr>
<td>PluginOps--Landing Page Builder<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Reflected XSS.This issue affects Landing Page Builder: from n/a through 1.5.1.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34752&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34752" target="_blank">CVE-2024-34752</a><br><a href="https://patchstack.com/database/vulnerability/page-builder-add/wordpress-landing-page-builder-1-5-1-8-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PluginUS--HUSKY Products Filter for WooCommerce (formerly WOOF)<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in PluginUS HUSKY - Products Filter for WooCommerce (formerly WOOF) allows Using Malicious Files, Code Inclusion.This issue affects HUSKY - Products Filter for WooCommerce (formerly WOOF): from n/a through 1.3.5.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32680&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32680" target="_blank">CVE-2024-32680</a><br><a href="https://patchstack.com/database/vulnerability/woocommerce-products-filter/wordpress-husky-plugin-1-3-5-2-remote-code-execution-rce-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Podlove--Podlove Podcast Publisher<br> </td>
<td>Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32712&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32712" target="_blank">CVE-2024-32712</a><br><a href="https://patchstack.com/database/vulnerability/podlove-podcasting-plugin-for-wordpress/wordpress-podlove-podcast-publisher-plugin-4-0-14-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PowerDNS--DNSdist<br> </td>
<td>When incoming DNS over HTTPS support is enabled using the nghttp2 provider, and queries are routed to a tcp-only or DNS over TLS backend, an attacker can trigger an assertion failure in DNSdist by sending a request for a zone transfer (AXFR or IXFR) over DNS over HTTPS, causing the process to stop and thus leading to a Denial of Service. DNS over HTTPS is not enabled by default, and backends are using plain DNS (Do53) by default.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25581&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25581" target="_blank">CVE-2024-25581</a><br><a href="https://dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2024-03.html" target="_blank">security@open-xchange.com</a></td>
</tr>
<tr>
<td>Premmerce--Premmerce Permalink Manager for WooCommerce<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Premmerce Premmerce Permalink Manager for WooCommerce allows PHP Local File Inclusion.This issue affects Premmerce Permalink Manager for WooCommerce: from n/a through 2.3.10.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27971&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27971" target="_blank">CVE-2024-27971</a><br><a href="https://patchstack.com/database/vulnerability/woo-permalink-manager/wordpress-premmerce-permalink-manager-for-woocommerce-plugin-2-3-10-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PrestaShop--PrestaShop<br> </td>
<td>PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. When the customer thread feature flag is enabled through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. The script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of the administrator's right. This vulnerability is patched in 8.1.6. A workaround is to disable the customer-thread feature-flag.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34716&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34716" target="_blank">CVE-2024-34716</a><br><a href="https://github.com/PrestaShop/PrestaShop/releases/tag/8.1.6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-45vm-3j38-7p78" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>ProfilePress Membership Team--ProfilePress<br> </td>
<td>Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41954&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41954" target="_blank">CVE-2023-41954</a><br><a href="https://patchstack.com/database/vulnerability/wp-user-avatar/wordpress-profilepress-plugin-4-13-1-unauthenticated-limited-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Progress Software Corporation--Telerik Reporting<br> </td>
<td>In ProgressÂ® TelerikÂ® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4200&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4200" target="_blank">CVE-2024-4200</a><br><a href="https://docs.telerik.com/reporting/knowledge-base/deserialization-vulnerability-cve-2024-4200" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Progress Software Corporation--Telerik Reporting<br> </td>
<td>In ProgressÂ® TelerikÂ® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4202&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4202" target="_blank">CVE-2024-4202</a><br><a href="https://docs.telerik.com/reporting/knowledge-base/instantiation-vulnerability-cve-2024-4202" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Progress Software Corporation--Telerik UI for WinForms<br> </td>
<td>A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted theme assembly to execute arbitrary code on the local Windows system.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3892&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3892" target="_blank">CVE-2024-3892</a><br><a href="https://docs.telerik.com/devtools/winforms/knowledge-base/local-code-execution-vulnerability-cve-2024-3892" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Proofpoint--Enterprise Protection<br> </td>
<td>The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker's control.  These accounts are able to send spoofed email to any users within the domains configured by the Administrator.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3676&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3676" target="_blank">CVE-2024-3676</a><br><a href="https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2024-0002" target="_blank">security@proofpoint.com</a></td>
</tr>
<tr>
<td>Propovoice--Propovoice CRM<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Propovoice Propovoice CRM allows Stored XSS.This issue affects Propovoice CRM: from n/a through 1.7.6.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4747&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4747" target="_blank">CVE-2024-4747</a><br><a href="https://patchstack.com/database/vulnerability/propovoice/wordpress-propovoice-crm-plugin-1-7-6-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>QuanticaLabs--Chauffeur Taxi Booking System for WordPress<br> </td>
<td>Missing Authorization vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Chauffeur Taxi Booking System for WordPress: from n/a through 6.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32692&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32692" target="_blank">CVE-2024-32692</a><br><a href="https://patchstack.com/database/vulnerability/chauffeur-booking-system/wordpress-chauffeur-taxi-booking-system-for-wordpress-plugin-6-9-broken-authentication-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Qube One Ltd.--Redirection for Contact Form 7<br> </td>
<td>Improper Privilege Management vulnerability in Qube One Ltd. Redirection for Contact Form 7 wpcf7-redirect allows Privilege Escalation.This issue affects Redirection for Contact Form 7: from n/a through 2.7.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23990&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23990" target="_blank">CVE-2023-23990</a><br><a href="https://patchstack.com/database/vulnerability/wpcf7-redirect/wordpress-redirection-for-contact-form-7-plugin-2-7-0-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Rank Math--Rank Math SEO<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rank Math Rank Math SEO allows Path Traversal.This issue affects Rank Math SEO: from n/a through 1.0.107.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23888&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23888" target="_blank">CVE-2023-23888</a><br><a href="https://patchstack.com/database/vulnerability/seo-by-rank-math/wordpress-rank-math-seo-plugin-1-0-107-2-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Red Hat--Migration Toolkit for Containers<br> </td>
<td>A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3727&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3727" target="_blank">CVE-2024-3727</a><br><a href="https://access.redhat.com/security/cve/CVE-2024-3727" target="_blank">secalert@redhat.com</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2274767" target="_blank">secalert@redhat.com</a></td>
</tr>
<tr>
<td>Repute Infosystems--ARMember<br> </td>
<td>Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51356&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51356" target="_blank">CVE-2023-51356</a><br><a href="https://patchstack.com/database/vulnerability/armember-membership/wordpress-armember-plugin-4-0-10-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Roku--Indoor Camera SE<br> </td>
<td>A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE version 3.0.2.4679 and Wyze Cam v3 version 4.36.11.5859. A specially crafted message can lead to stack-based buffer overflow. An attacker can make authenticated requests to trigger this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6322&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6322" target="_blank">CVE-2023-6322</a><br><a href="https://bitdefender.com/blog/labs/notes-on-throughtek-kalay-vulnerabilities-and-their-impact/" target="_blank">cve-requests@bitdefender.com</a></td>
</tr>
<tr>
<td>Room 34 Creative Services, LLC--ICS Calendar<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request Forgery (SSRF) vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Absolute Path Traversal, : Server Side Request Forgery.This issue affects ICS Calendar: from n/a through 10.12.0.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46784&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46784" target="_blank">CVE-2023-46784</a><br><a href="https://patchstack.com/database/vulnerability/ics-calendar/wordpress-ics-calendar-plugin-10-12-0-2-ssrf-and-arbitrary-file-read-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SAASPROJECT Booking Package--Booking Package<br> </td>
<td>Improper Privilege Management vulnerability in SAASPROJECT Booking Package Booking Package allows Privilege Escalation.This issue affects Booking Package: from n/a through 1.5.98.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37389&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37389" target="_blank">CVE-2023-37389</a><br><a href="https://patchstack.com/database/vulnerability/booking-package/wordpress-booking-package-saasproject-plugin-1-5-98-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP BusinessObjects Business Intelligence Platform<br> </td>
<td>SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a parameter in the Opendocument URL which could lead to high impact on Confidentiality and Integrity of the application</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28165&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28165" target="_blank">CVE-2024-28165</a><br><a href="https://me.sap.com/notes/3431794" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP NetWeaver Application Server ABAP and ABAP Platform<br> </td>
<td>An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system. </td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33006&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33006" target="_blank">CVE-2024-33006</a><br><a href="https://me.sap.com/notes/3448171" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SUBNET--PowerSYSTEM Center<br> </td>
<td>SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28042&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28042" target="_blank">CVE-2024-28042</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-135-02" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>SailPoint--Identity Security Cloud<br> </td>
<td>An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined templates as part of attribute transforms which could allow remote code execution on the host.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3319&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3319" target="_blank">CVE-2024-3319</a><br><a href="https://www.sailpoint.com/security-advisories/" target="_blank">psirt@sailpoint.com</a></td>
</tr>
<tr>
<td>Saleswonder Team--WebinarIgnition<br> </td>
<td>Improper Privilege Management vulnerability in Saleswonder Team WebinarIgnition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through 3.05.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51424&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51424" target="_blank">CVE-2023-51424</a><br><a href="https://patchstack.com/database/vulnerability/webinar-ignition/wordpress-webinarignition-plugin-3-05-0-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SiAdmin--SiAdmin<br> </td>
<td>Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_pass/aksi_pass.php parameter in nama_lengkap. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in it.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4991&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4991" target="_blank">CVE-2024-4991</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-siadmin" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>SiAdmin--SiAdmin<br> </td>
<td>Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_kuliah/aksi_kuliah.php parameter in nim. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in it.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4992&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4992" target="_blank">CVE-2024-4992</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-siadmin" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Siemens--CPC80 Central Processing/Communication<br> </td>
<td>A vulnerability has been identified in CPC80 Central Processing/Communication (All versions &lt; V16.41), CPCI85 Central Processing/Communication (All versions &lt; V5.30). The affected device firmwares contain an improper null termination vulnerability while parsing a specific HTTP header. This could allow an attacker to execute code in the context of the current process or lead to denial of service condition.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31484&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31484" target="_blank">CVE-2024-31484</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-871704.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--CPCI85 Central Processing/Communication<br> </td>
<td>A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions &lt; V5.30), SICORE Base system (All versions &lt; V1.3.0). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31485&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31485" target="_blank">CVE-2024-31485</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-871704.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--JT2Go<br> </td>
<td>A vulnerability has been identified in JT2Go (All versions &lt; V2312.0001), Teamcenter Visualization V14.1 (All versions &lt; V14.1.0.13), Teamcenter Visualization V14.2 (All versions &lt; V14.2.0.10), Teamcenter Visualization V14.3 (All versions &lt; V14.3.0.7), Teamcenter Visualization V2312 (All versions &lt; V2312.0001). The affected applications contain a stack overflow vulnerability while parsing specially crafted XML files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34085&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34085" target="_blank">CVE-2024-34085</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-661579.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--JT2Go<br> </td>
<td>A vulnerability has been identified in JT2Go (All versions &lt; V2312.0001), Teamcenter Visualization V14.1 (All versions &lt; V14.1.0.13), Teamcenter Visualization V14.2 (All versions &lt; V14.2.0.10), Teamcenter Visualization V14.3 (All versions &lt; V14.3.0.7), Teamcenter Visualization V2312 (All versions &lt; V2312.0001). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted CGM file. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34086&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34086" target="_blank">CVE-2024-34086</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-661579.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32055&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32055" target="_blank">CVE-2024-32055</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21562)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32057&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32057" target="_blank">CVE-2024-32057</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected application is vulnerable to memory corruption while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21563)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32058&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32058" target="_blank">CVE-2024-32058</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21564)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32059&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32059" target="_blank">CVE-2024-32059</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21565)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32060&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32060" target="_blank">CVE-2024-32060</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21566)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32061&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32061" target="_blank">CVE-2024-32061</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21568)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32062&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32062" target="_blank">CVE-2024-32062</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21573)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32063&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32063" target="_blank">CVE-2024-32063</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21575)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32064&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32064" target="_blank">CVE-2024-32064</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21577)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32065&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32065" target="_blank">CVE-2024-32065</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21578)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32066&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32066" target="_blank">CVE-2024-32066</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Parasolid V35.1<br> </td>
<td>A vulnerability has been identified in Parasolid V35.1 (All versions &lt; V35.1.256), Parasolid V36.0 (All versions &lt; V36.0.210), Parasolid V36.1 (All versions &lt; V36.1.185). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted X_T part file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-23468)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31980&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31980" target="_blank">CVE-2024-31980</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-489698.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Parasolid V35.1<br> </td>
<td>A vulnerability has been identified in Parasolid V35.1 (All versions &lt; V35.1.256), Parasolid V36.0 (All versions &lt; V36.0.208), Parasolid V36.1 (All versions &lt; V36.1.173). The affected applications contain an out of bounds read past the unmapped memory region while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32635&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32635" target="_blank">CVE-2024-32635</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-046364.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Parasolid V35.1<br> </td>
<td>A vulnerability has been identified in Parasolid V35.1 (All versions &lt; V35.1.256), Parasolid V36.0 (All versions &lt; V36.0.208), Parasolid V36.1 (All versions &lt; V36.1.173). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32636&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32636" target="_blank">CVE-2024-32636</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-046364.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems allow the upload of arbitrary files of any unauthenticated user. An attacker could leverage this vulnerability and achieve arbitrary code execution with system privileges.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27939&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27939" target="_blank">CVE-2024-27939</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems allow any authenticated user to send arbitrary SQL commands to the SQL server. An attacker could use this vulnerability to compromise the whole database.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27940&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27940" target="_blank">CVE-2024-27940</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected client systems do not properly sanitize input data before sending it to the SQL server. An attacker could use this vulnerability to compromise the whole database.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27941&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27941" target="_blank">CVE-2024-27941</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems allow any unauthenticated client to disconnect any active user from the server. An attacker could use this vulnerability to prevent any user to perform actions in the system, causing a denial of service situation.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27942&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27942" target="_blank">CVE-2024-27942</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems allow a privileged user to upload generic files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27943&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27943" target="_blank">CVE-2024-27943</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems allow a privileged user to upload firmware files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27944&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27944" target="_blank">CVE-2024-27944</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The bulk import feature of the affected systems allow a privileged user to upload files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27945&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27945" target="_blank">CVE-2024-27945</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC CN 4100<br> </td>
<td>A vulnerability has been identified in SIMATIC CN 4100 (All versions &lt; V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by default . An attacker who manages to crack the password hash gains root access to the device.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32741&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32741" target="_blank">CVE-2024-32741</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-273900.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC CN 4100<br> </td>
<td>A vulnerability has been identified in SIMATIC CN 4100 (All versions &lt; V3.0). The affected device contains undocumented users and credentials. An attacker could misuse the credentials to compromise the device locally or over the network.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32740&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32740" target="_blank">CVE-2024-32740</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-273900.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC CN 4100<br> </td>
<td>A vulnerability has been identified in SIMATIC CN 4100 (All versions &lt; V3.0). The affected device contains an unrestricted USB port. An attacker with local access to the device could potentially misuse the port for booting another operating system and gain complete read/write access to the filesystem.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32742&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32742" target="_blank">CVE-2024-32742</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-273900.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). The affected systems use symmetric cryptography with a hard-coded key to protect the communication between client and server. This could allow an unauthenticated remote attacker to compromise confidentiality and integrity of the communication and, subsequently, availability of the system. A successful exploit requires the attacker to gain knowledge of the hard-coded key and to be able to intercept the communication between client and server on the network.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30207&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30207" target="_blank">CVE-2024-30207</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected systems transmit client-side resources without proper cryptographic protection. This could allow an attacker to eavesdrop on and modify resources in transit. A successful exploit requires an attacker to be in the network path between the RTLS Locating Manager server and a client (MitM).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30209&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30209" target="_blank">CVE-2024-30209</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). The affected application assigns incorrect permissions to a user management component. This could allow a privileged attacker to escalate their privileges from the Administrators group to the Systemadministrator group.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33499&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33499" target="_blank">CVE-2024-33499</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected SIMATIC RTLS Locating Manager Clients do not properly check the integrity of update files. This could allow an unauthenticated remote attacker to alter update files in transit and trick an authorized user into installing malicious code. A successful exploit requires the attacker to be able to modify the communication between server and client on the network.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30206&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30206" target="_blank">CVE-2024-30206</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Simcenter Nastran 2306<br> </td>
<td>A vulnerability has been identified in Simcenter Nastran 2306 (All versions), Simcenter Nastran 2312 (All versions), Simcenter Nastran 2406 (All versions &lt; V2406.90). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33577&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33577" target="_blank">CVE-2024-33577</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-258494.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 5). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33489&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33489" target="_blank">CVE-2024-33489</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33490&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33490" target="_blank">CVE-2024-33490</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33491&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33491" target="_blank">CVE-2024-33491</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33492&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33492" target="_blank">CVE-2024-33492</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33493&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33493" target="_blank">CVE-2024-33493</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 2). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34771&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34771" target="_blank">CVE-2024-34771</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 4). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34772&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34772" target="_blank">CVE-2024-34772</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 2). The affected applications contain a stack overflow vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34773&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34773" target="_blank">CVE-2024-34773</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Tecnomatix Plant Simulation V2302<br> </td>
<td>A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions &lt; V2302.0011). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted MODEL file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-22974)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32639&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32639" target="_blank">CVE-2024-32639</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-923361.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Sirv--Sirv<br> </td>
<td>Improper Privilege Management vulnerability in Sirv allows Privilege Escalation.This issue affects Sirv: from n/a through 7.2.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32959&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32959" target="_blank">CVE-2024-32959</a><br><a href="https://patchstack.com/database/vulnerability/sirv/wordpress-sirv-plugin-7-2-2-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Sizam Design--Rehub<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sizam Design Rehub allows PHP Local File Inclusion.This issue affects Rehub: from n/a through 19.6.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31231&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31231" target="_blank">CVE-2024-31231</a><br><a href="https://patchstack.com/database/vulnerability/rehub-theme/wordpress-rehub-theme-19-6-1-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Sizam Design--Rehub<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sizam Design Rehub allows PHP Local File Inclusion.This issue affects Rehub: from n/a through 19.6.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31232&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31232" target="_blank">CVE-2024-31232</a><br><a href="https://patchstack.com/database/vulnerability/rehub-theme/wordpress-rehub-theme-19-6-1-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Snow Software AB--Snow License Manager<br> </td>
<td>Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to perform an Authentication Bypass if Active Directory Authentication is enabled.This issue affects Snow License Manager: from 9.33.2 through 9.34.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4129&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4129" target="_blank">CVE-2024-4129</a><br><a href="https://community.snowsoftware.com/s/feed/0D5Td000008dv8sKAA" target="_blank">security@snowsoftware.com</a></td>
</tr>
<tr>
<td>SolarWinds--Access Rights Manager<br> </td>
<td>The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28075&amp;vector=CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28075" target="_blank">CVE-2024-28075</a><br><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htm" target="_blank">psirt@solarwinds.com</a><br><a href="https://documentation.solarwinds.com/en/success_center/arm/content/secure-your-arm-deployment.htm" target="_blank">psirt@solarwinds.com</a><br><a href="https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28075" target="_blank">psirt@solarwinds.com</a></td>
</tr>
<tr>
<td>SolarWinds--Access Rights Manager<br> </td>
<td>The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability allows access to the RabbitMQ management console. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23473&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23473" target="_blank">CVE-2024-23473</a><br><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htm" target="_blank">psirt@solarwinds.com</a><br><a href="https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-23473" target="_blank">psirt@solarwinds.com</a></td>
</tr>
<tr>
<td>Sonatype--Nexus Repository<br> </td>
<td>Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4956&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4956" target="_blank">CVE-2024-4956</a><br><a href="https://support.sonatype.com/hc/en-us/articles/29416509323923" target="_blank">103e4ec9-0a87-450b-af77-479448ddef11</a></td>
</tr>
<tr>
<td>SourceCodester--Best House Rental Management System<br> </td>
<td>A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-265072.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5093&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5093" target="_blank">CVE-2024-5093</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/House%20Rental%20Management%20System/House%20Rental%20Management%20System%20-%20Authentication%20Bypass.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.265072" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.265072" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335712" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Best House Rental Management System<br> </td>
<td>A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This issue affects some unknown processing of the file view_payment.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-265073 was assigned to this vulnerability.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5094&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5094" target="_blank">CVE-2024-5094</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/House%20Rental%20Management%20System/House%20Rental%20Management%20System%20-%20SQL%20Injection%20-%202.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.265073" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.265073" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335714" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Discussion Forum Site<br> </td>
<td>A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file registerH.php. The manipulation of the argument ima leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264455.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4920&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4920" target="_blank">CVE-2024-4920</a><br><a href="https://github.com/CveSecLook/cve/issues/27" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264455" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264455" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333477" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Examination System<br> </td>
<td>A vulnerability was found in SourceCodester Online Examination System 1.0. It has been rated as critical. This issue affects some unknown processing of the file registeracc.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264743.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5046&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5046" target="_blank">CVE-2024-5046</a><br><a href="https://github.com/CveSecLook/cve/issues/32" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264743" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264743" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335527" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--SchoolWebTech<br> </td>
<td>A vulnerability was found in SourceCodester SchoolWebTech 1.0. It has been classified as critical. Affected is an unknown function of the file /improve/home.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264534 is the identifier assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4966&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4966" target="_blank">CVE-2024-4966</a><br><a href="https://github.com/CveSecLook/cve/issues/30" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264534" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264534" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.334216" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Student Management System<br> </td>
<td>A vulnerability classified as critical has been found in SourceCodester Student Management System 1.0. Affected is an unknown function of the file /student/controller.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264744.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5047&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5047" target="_blank">CVE-2024-5047</a><br><a href="https://github.com/I-Schnee-I/cev/blob/main/SourceCodester%20Student%20Management%20System%201.0%20controller.php%20Unrestricted%20Upload.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264744" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264744" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335633" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>StylemixThemes--Consulting<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting allows PHP Local File Inclusion.This issue affects Consulting: from n/a through 6.5.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37385&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37385" target="_blank">CVE-2023-37385</a><br><a href="https://patchstack.com/database/vulnerability/consulting/wordpress-consulting-theme-6-3-6-local-file-inclusion?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Tenable--Nessus Agent<br> </td>
<td>A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus Agent host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host. - CVE-2024-3292</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3292&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3292" target="_blank">CVE-2024-3292</a><br><a href="https://www.tenable.com/security/tns-2024-09" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>Tenable--Nessus Agent<br> </td>
<td>When installing Nessus Agent to a directory outside of the default location on a Windows host, Nessus Agent versions prior to 10.6.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3291&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3291" target="_blank">CVE-2024-3291</a><br><a href="https://www.tenable.com/security/tns-2024-09" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>Tenable--Nessus<br> </td>
<td>A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3290&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3290" target="_blank">CVE-2024-3290</a><br><a href="https://www.tenable.com/security/tns-2024-08" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>Tenable--Nessus<br> </td>
<td>When installing Nessus to a directory outside of the default location on a Windows host, Nessus versions prior to 10.7.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3289&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3289" target="_blank">CVE-2024-3289</a><br><a href="https://www.tenable.com/security/tns-2024-08" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>Teplitsa of social technologies--Leyka<br> </td>
<td>Improper Privilege Management vulnerability in Teplitsa of social technologies Leyka allows Privilege Escalation.This issue affects Leyka: from n/a through 3.30.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-33327&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-33327" target="_blank">CVE-2023-33327</a><br><a href="https://patchstack.com/database/vulnerability/leyka/wordpress-leyka-plugin-3-29-2-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThemeKraft--BuddyForms<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forgery, Relative Path Traversal.This issue affects BuddyForms: from n/a through 2.8.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32830&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32830" target="_blank">CVE-2024-32830</a><br><a href="https://patchstack.com/database/vulnerability/buddyforms/wordpress-buddyforms-plugin-2-8-8-arbitrary-file-read-and-ssrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThemeNectar--Salient Core<br> </td>
<td>The Salient Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.7 via the 'nectar_icon' shortcode 'icon_linea' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3812&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3812" target="_blank">CVE-2024-3812</a><br><a href="https://themeforest.net/item/salient-responsive-multipurpose-theme/4363266" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ebd3b70e-a06a-4dcc-a6af-dbe64fd57c82?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>ThemeNectar--Salient Shortcodes<br> </td>
<td>The Salient Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.5.3 via the 'icon' shortcode 'image' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3810&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3810" target="_blank">CVE-2024-3810</a><br><a href="https://themeforest.net/item/salient-responsive-multipurpose-theme/4363266" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d1b3d4d5-9d2b-4924-a830-27c07fa1ba98?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Themify--Themify Ultra<br> </td>
<td>Improper Privilege Management vulnerability in Themify Themify Ultra allows Privilege Escalation.This issue affects Themify Ultra: from n/a through 7.3.5.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46145&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46145" target="_blank">CVE-2023-46145</a><br><a href="https://patchstack.com/database/vulnerability/themify-ultra/wordpress-themify-ultra-theme-7-3-3-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Thomas Scholl--canvasio3D Light<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in Thomas Scholl canvasio3D Light.This issue affects canvasio3D Light: from n/a through 2.5.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34411&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34411" target="_blank">CVE-2024-34411</a><br><a href="https://patchstack.com/database/vulnerability/canvasio3d-light/wordpress-canvasio3d-light-plugin-2-5-0-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Thrive Themes--Thrive Theme Builder<br> </td>
<td>Improper Privilege Management vulnerability in Thrive Themes Thrive Theme Builder allows Privilege Escalation.This issue affects Thrive Theme Builder: from n/a before 3.24.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47782&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47782" target="_blank">CVE-2023-47782</a><br><a href="https://patchstack.com/database/vulnerability/thrive-theme/wordpress-thrive-theme-builder-theme-3-20-1-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThroughTek--Kalay SDK<br> </td>
<td>ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6324&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6324" target="_blank">CVE-2023-6324</a><br><a href="https://bitdefender.com/blog/labs/notes-on-throughtek-kalay-vulnerabilities-and-their-impact/" target="_blank">cve-requests@bitdefender.com</a></td>
</tr>
<tr>
<td>Timber Team &amp; Contributors--Timber<br> </td>
<td>Deserialization of Untrusted Data vulnerability in Timber Team &amp; Contributors Timber.This issue affects Timber: from n/a through 1.23.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29800&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29800" target="_blank">CVE-2024-29800</a><br><a href="https://patchstack.com/database/vulnerability/timber-library/wordpress-timber-plugin-1-23-0-deserialization-of-untrusted-data-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Tips and Tricks HQ--WP Express Checkout (Accept PayPal Payments)<br> </td>
<td>Improper Validation of Specified Quantity in Input vulnerability in Tips and Tricks HQ WP Express Checkout (Accept PayPal Payments) allows Manipulating Hidden Fields.This issue affects WP Express Checkout (Accept PayPal Payments): from n/a through 2.3.7.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30527&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30527" target="_blank">CVE-2024-30527</a><br><a href="https://patchstack.com/database/vulnerability/wp-express-checkout/wordpress-wp-express-checkout-plugin-2-3-7-price-manipulation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Trellix--ePolicy Orchestrator<br> </td>
<td>Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attacker with admin privileges on the ePO server to read the contents of the orion.keystore file, allowing them to access the ePO database encryption key. This was possible through using a hard coded password for the keystore. Access Control restrictions on the file mean this would not be exploitable unless the user is the system admin for the server that ePO is running on.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4844&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4844" target="_blank">CVE-2024-4844</a><br><a href="https://thrive.trellix.com/s/article/000013505" target="_blank">trellixpsirt@trellix.com</a></td>
</tr>
<tr>
<td>URBAN BASE--Z-Downloads<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in URBAN BASE Z-Downloads.This issue affects Z-Downloads: from n/a through 1.11.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34555&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34555" target="_blank">CVE-2024-34555</a><br><a href="https://patchstack.com/database/vulnerability/z-downloads/wordpress-z-downloads-plugin-1-11-3-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>UkrSolution--Barcode Scanner with Inventory &amp; Order Manager<br> </td>
<td>Improper Privilege Management vulnerability in UkrSolution Barcode Scanner with Inventory &amp; Order Manager allows Privilege Escalation.This issue affects Barcode Scanner with Inventory &amp; Order Manager: from n/a through 1.5.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33567&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33567" target="_blank">CVE-2024-33567</a><br><a href="https://patchstack.com/database/vulnerability/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/wordpress-barcode-scanner-with-inventory-order-manager-plugin-1-5-3-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Vova Anokhin--Shortcodes Ultimate<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vova Anokhin Shortcodes Ultimate allows Absolute Path Traversal.This issue affects Shortcodes Ultimate: from n/a through 5.12.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-25050&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-25050" target="_blank">CVE-2023-25050</a><br><a href="https://patchstack.com/database/vulnerability/shortcodes-ultimate/wordpress-shortcodes-ultimate-plugin-5-12-6-arbitrary-file-download-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Automatic--Automatic<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue affects Automatic: from n/a through 3.92.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27954&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">9.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27954" target="_blank">CVE-2024-27954</a><br><a href="https://patchstack.com/database/vulnerability/wp-automatic/wordpress-automatic-plugin-3-92-0-unauthenticated-arbitrary-file-download-and-ssrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Automatic--Automatic<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in WP Automatic Automatic allows Privilege Escalation.This issue affects Automatic: from n/a through 3.92.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27955&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27955" target="_blank">CVE-2024-27955</a><br><a href="https://patchstack.com/database/vulnerability/wp-automatic/wordpress-automatic-plugin-3-92-0-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Hive--Events Rich Snippets for Google<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in WP Hive Events Rich Snippets for Google allows Exploitation of Trusted Credentials.This issue affects Events Rich Snippets for Google: from n/a through 1.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-44478&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-44478" target="_blank">CVE-2023-44478</a><br><a href="https://patchstack.com/database/vulnerability/rich-snippets-vevents/wordpress-events-rich-snippets-for-google-plugin-1-8-csrf-leading-to-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Sharks--s2Member Pro<br> </td>
<td>Improper Privilege Management vulnerability in WP Sharks s2Member Pro allows Privilege Escalation.This issue affects s2Member Pro: from n/a through 240315.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31237&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31237" target="_blank">CVE-2024-31237</a><br><a href="https://patchstack.com/database/vulnerability/s2member/wordpress-s2member-plugin-240315-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP-etracker--WP etracker<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-etracker WP etracker allows Reflected XSS.This issue affects WP etracker: from n/a through 1.0.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34431&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34431" target="_blank">CVE-2024-34431</a><br><a href="https://patchstack.com/database/vulnerability/wp-etracker/wordpress-wp-etracker-plugin-1-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPCustomify--Customify Site Library<br> </td>
<td>Improper Control of Generation of Code ('Code Injection') vulnerability in WPCustomify Customify Site Library allows Code Injection.This issue affects Customify Site Library: from n/a through 0.0.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33644&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33644" target="_blank">CVE-2024-33644</a><br><a href="https://patchstack.com/database/vulnerability/customify-sites/wordpress-customify-site-library-plugin-0-0-9-remote-code-execution-rce-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPDeveloper--Essential Addons for Elementor<br> </td>
<td>Improper Privilege Management vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation.This issue affects Essential Addons for Elementor: from n/a through 5.8.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41955&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41955" target="_blank">CVE-2023-41955</a><br><a href="https://patchstack.com/database/vulnerability/essential-addons-for-elementor-lite/wordpress-essential-addons-for-elementor-plugin-5-8-8-contributor-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPFactory--EAN for WooCommerce<br> </td>
<td>Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34370&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34370" target="_blank">CVE-2024-34370</a><br><a href="https://patchstack.com/database/vulnerability/ean-for-woocommerce/wordpress-ean-for-woocommerce-plugin-4-8-9-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPvivid Team--WPvivid Backup and Migration<br> </td>
<td>Improper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.This issue affects WPvivid Backup and Migration: from n/a through 0.9.90.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41243&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41243" target="_blank">CVE-2023-41243</a><br><a href="https://patchstack.com/database/vulnerability/wpvivid-backuprestore/wordpress-wpvivid-backup-plugin-plugin-0-9-90-privilege-escalation-on-staging-environment-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WatchGuard--AuthPoint Password Manager<br> </td>
<td>Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in WatchGuard AuthPoint Password Manager on MacOS allows an a adversary with local access to execute code under the context of the AuthPoint Password Manager application. This issue affects AuthPoint Password Manager for MacOS versions before 1.0.6.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1417&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1417" target="_blank">CVE-2024-1417</a><br><a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00006" target="_blank">5d1c2695-1a31-4499-88ae-e847036fd7e3</a></td>
</tr>
<tr>
<td>WebToffee--WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels<br> </td>
<td>Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege Escalation.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.2.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51546&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51546" target="_blank">CVE-2023-51546</a><br><a href="https://patchstack.com/database/vulnerability/print-invoices-packing-slip-labels-for-woocommerce/wordpress-woocommerce-pdf-invoices-packing-slips-delivery-notes-and-shipping-labels-plugin-4-2-1-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WebWizards--SalesKing<br> </td>
<td>Improper Privilege Management vulnerability in WebWizards SalesKing allows Privilege Escalation.This issue affects SalesKing: from n/a through 1.6.15.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22157&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22157" target="_blank">CVE-2024-22157</a><br><a href="https://patchstack.com/database/vulnerability/salesking/wordpress-salesking-plugin-1-6-15-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WebinarPress--WebinarPress<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress.This issue affects WebinarPress: from n/a through 1.33.17.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34818&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34818" target="_blank">CVE-2024-34818</a><br><a href="https://patchstack.com/database/vulnerability/wp-webinarsystem/wordpress-webinar-plugin-1-33-17-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WhatArmy--WatchTowerHQ<br> </td>
<td>Improper Privilege Management vulnerability in WhatArmy WatchTowerHQ allows Privilege Escalation.This issue affects WatchTowerHQ: from n/a through 3.6.16.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-25701&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-25701" target="_blank">CVE-2023-25701</a><br><a href="https://patchstack.com/database/vulnerability/watchtowerhq/wordpress-watchtowerhq-plugin-3-6-16-privilege-escalation?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Wholesale--WholesaleX<br> </td>
<td>Improper Privilege Management vulnerability in Wholesale WholesaleX allows Privilege Escalation.This issue affects WholesaleX: from n/a through 1.3.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30542&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30542" target="_blank">CVE-2024-30542</a><br><a href="https://patchstack.com/database/vulnerability/wholesalex/wordpress-wholesalex-plugin-1-3-2-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Woo product importer--Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy<br> </td>
<td>Missing Authorization vulnerability in Woo product importer Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy.This issue affects Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy: from n/a through 2.1.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32724&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32724" target="_blank">CVE-2024-32724</a><br><a href="https://patchstack.com/database/vulnerability/woo-aliexpress-dropshipping/wordpress-sharkdropship-and-affiliate-for-aliexpress-ebay-amazon-etsy-plugin-2-1-1-arbitrary-content-deletion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WooCommerce--WooCommerce One Page Checkout<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WooCommerce WooCommerce One Page Checkout allows PHP Local File Inclusion.This issue affects WooCommerce One Page Checkout: from n/a through 2.3.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-35881&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-35881" target="_blank">CVE-2023-35881</a><br><a href="https://patchstack.com/database/vulnerability/woocommerce-one-page-checkout/wordpress-woocommerce-one-page-checkout-plugin-2-3-0-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>XTemos--Woodmart Core<br> </td>
<td>Improper Privilege Management vulnerability in XTemos Woodmart Core allows Privilege Escalation.This issue affects Woodmart Core: from n/a through 1.0.36.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-32244&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-32244" target="_blank">CVE-2023-32244</a><br><a href="https://patchstack.com/database/vulnerability/woodmart-core/wordpress-woodmart-core-plugin-1-0-36-privilege-escalation?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>YARPP--YARPP<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YARPP allows PHP Local File Inclusion.This issue affects YARPP: from n/a through 5.30.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-45374&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-45374" target="_blank">CVE-2022-45374</a><br><a href="https://patchstack.com/database/vulnerability/yet-another-related-posts-plugin/wordpress-yet-another-related-posts-plugin-yarpp-plugin-5-30-2-local-file-inclusion?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>YMS--VIS Pro<br> </td>
<td>YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combination of improper method for system credentials generation and weak password policy, passwords can be easily guessed and enumerated through brute force attacks. Successful attacks can lead to unauthorised access and execution of operations based on assigned user permissions. This vulnerability affects VIS Pro in versions &lt;= 3.3.0.6. This vulnerability has been mitigated by changes in authentication mechanisms and implementation of additional authentication layer and strong password policies.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3263&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3263" target="_blank">CVE-2024-3263</a><br><a href="https://remediata.com/blog/cve-2024-3263-improper-authentication-in-yms-vis-pro/" target="_blank">incident@nbu.gov.sk</a><br><a href="https://www.svps.sk/vis/" target="_blank">incident@nbu.gov.sk</a></td>
</tr>
<tr>
<td>ZTE--ZXUN-ePDG<br> </td>
<td>ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic keys during establishing a secure connection(IKE) with the mobile devices connecting over the internet . If the set of keys are leaked or cracked, the user session informations using the keys may be leaked.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22064&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" target="_blank" title="CVSS V3 Score">8.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22064" target="_blank">CVE-2024-22064</a><br><a href="https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1035524" target="_blank">psirt@zte.com.cn</a></td>
</tr>
<tr>
<td>Zabbix--Zabbix<br> </td>
<td>Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22120&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22120" target="_blank">CVE-2024-22120</a><br><a href="https://support.zabbix.com/browse/ZBX-24505" target="_blank">security@zabbix.com</a></td>
</tr>
<tr>
<td>abetlen--llama-cpp-python<br> </td>
<td>llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to configure the loading and running of the model. Other than `NUMA, LoRa settings`, `loading tokenizers,` and `hardware settings`, `__init__` also loads the `chat template` from targeted `.gguf` 's Metadata and furtherly parses it to `llama_chat_format.Jinja2ChatFormatter.to_chat_handler()` to construct the `self.chat_handler` for this model. Nevertheless, `Jinja2ChatFormatter` parse the `chat template` within the Metadate with sandbox-less `jinja2.Environment`, which is furthermore rendered in `__call__` to construct the `prompt` of interaction. This allows `jinja2` Server Side Template Injection which leads to remote code execution by a carefully constructed payload.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34359&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34359" target="_blank">CVE-2024-34359</a><br><a href="https://github.com/abetlen/llama-cpp-python/commit/b454f40a9a1787b2b5659cd2cb00819d983185df" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/abetlen/llama-cpp-python/security/advisories/GHSA-56xg-wfcc-g829" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>alttextai--Alt Text AI Automatically generate image alt text for SEO and accessibility<br> </td>
<td>The Alt Text AI - Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to generic SQL Injection via the 'last_post_id' parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4847&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4847" target="_blank">CVE-2024-4847</a><br><a href="https://plugins.trac.wordpress.org/browser/alttext-ai/trunk/includes/class-atai-attachment.php#L677" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086107/" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/alttext-ai/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3c192623-eb46-4f1d-b897-433ac80608cb?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>appscreo--Easy Social Share Buttons<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in appscreo Easy Social Share Buttons allows PHP Local File Inclusion.This issue affects Easy Social Share Buttons: from n/a through 9.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31300&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31300" target="_blank">CVE-2024-31300</a><br><a href="https://patchstack.com/database/vulnerability/easy-social-share-buttons3/wordpress-easy-social-share-buttons-plugin-9-4-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>artbees--JupiterX<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in artbees JupiterX allows PHP Local File Inclusion.This issue affects JupiterX: from n/a through 3.0.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-32110&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-32110" target="_blank">CVE-2023-32110</a><br><a href="https://patchstack.com/database/vulnerability/jupiterx/wordpress-jupiterx-theme-3-0-0-subscriber-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>aws--amazon-redshift-jdbc-driver<br> </td>
<td>The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enterprise Editions. Prior to version 2.1.0.28, SQL injection is possible when using the non-default connection property `preferQueryMode=simple` in combination with application code which has a vulnerable SQL that negates a parameter value. There is no vulnerability in the driver when using the default, extended query mode. Note that `preferQueryMode` is not a supported parameter in Redshift JDBC driver, and is inherited code from Postgres JDBC driver. Users who do not override default settings to utilize this unsupported query mode are not affected. This issue is patched in driver version 2.1.0.28. As a workaround, do not use the connection property `preferQueryMode=simple`. (NOTE: Those who do not explicitly specify a query mode use the default of extended query mode and are not affected by this issue.)</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32888&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32888" target="_blank">CVE-2024-32888</a><br><a href="https://github.com/aws/amazon-redshift-jdbc-driver/commit/0d354a5f26ca23f7cac4e800e3b8734220230319" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/aws/amazon-redshift-jdbc-driver/commit/12a5e8ecfbb44c8154fc66041cca2e20ecd7b339" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/aws/amazon-redshift-jdbc-driver/commit/bc93694201a291493778ce5369a72befeca5ba7d" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/aws/amazon-redshift-jdbc-driver/security/advisories/GHSA-x3wm-hffr-chwm" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-24rp-q3w6-vc56" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>dataease--dataease<br> </td>
<td>DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data source, it is possible to exploit certain malicious parameters to achieve arbitrary file reading. The vulnerability has been fixed in v1.18.19.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31441&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31441" target="_blank">CVE-2024-31441</a><br><a href="https://github.com/dataease/dataease/security/advisories/GHSA-h7hj-7wg6-p5wh" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>dotmesh-io--dotmesh<br> </td>
<td>Dotmesh is a git-like command-line interface for capturing, organizing and sharing application states. In versions 0.8.1 and prior, the unsafe handling of symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations outside the designated target folder. The routine `untarFile` attempts to guard against creating symbolic links that point outside the directory a tar archive is extracted to. However, a malicious tarball first linking `subdir/parent` to `..` (allowed, because `subdir/..` falls within the archive root) and then linking `subdir/parent/escapes` to `..` results in a symbolic link pointing to the tarball's parent directory, contrary to the routine's goals. This issue may lead to arbitrary file write (with same permissions as the program running the unpack operation) if the attacker can control the archive file. Additionally, if the attacker has read access to the unpacked files, they may be able to read arbitrary system files the parent process has permissions to read. As of time of publication, no patch for this issue is available.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2020-26312&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2020-26312" target="_blank">CVE-2020-26312</a><br><a href="https://github.com/dotmesh-io/dotmesh/blob/master/pkg/archiver/tar.go#L255" target="_blank">security-advisories@github.com</a><br><a href="https://securitylab.github.com/advisories/GHSL-2020-254-zipslip-dotmesh/" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>eProsima--Fast-DDS<br> </td>
<td>FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves a malformed `RTPS` packet, the subscriber crashes when creating `pthread`. This can remotely crash any Fast-DDS process, potentially leading to a DOS attack. Versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8 contain a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30258&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30258" target="_blank">CVE-2024-30258</a><br><a href="https://drive.google.com/file/d/19W5UC52hPnAqVq_boZWO45d1TJ4WoCSh/view?usp=sharing" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/eProsima/Fast-DDS/commit/65236f93e9c4ea3ff9a49fba4dfd9e43eb94037b" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-53xw-465j-rxfh" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>eProsima--Fast-DDS<br> </td>
<td>FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves malformed `RTPS` packet, heap buffer overflow occurs on the subscriber. This can remotely crash any Fast-DDS process, potentially leading to a DOS attack. Versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8 contain a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30259&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30259" target="_blank">CVE-2024-30259</a><br><a href="https://drive.google.com/file/d/1Y2bGvP3UIOJCLh_XEURLdhrM2Sznlvlp/view?usp=sharing" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-qcj9-939p-p662" target="_blank">security-advisories@github.com</a><br><a href="https://vimeo.com/907641887?share=copy" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>freescout-helpdesk--freescout<br> </td>
<td>FreeScout is a free, self-hosted help desk and shared mailbox. A stored HTML Injection vulnerability has been identified in the Email Receival Module of the Freescout Application. The vulnerability allows attackers to inject malicious HTML content into emails sent to the application's mailbox. This vulnerability arises from improper handling of HTML content within incoming emails, allowing attackers to embed malicious HTML code in the context of the application's domain. Unauthenticated attackers can exploit this vulnerability to inject malicious HTML content into emails. This could lead to various attacks such as form hijacking, application defacement, or data exfiltration via CSS injection. Although unauthenticated attackers are limited to HTML injection, the consequences can still be severe. Version 1.8.139 implements strict input validation and sanitization mechanisms to ensure that any HTML content received via emails is properly sanitized to prevent malicious HTML injections.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34697&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34697" target="_blank">CVE-2024-34697</a><br><a href="https://github.com/freescout-helpdesk/freescout/commit/99a4b4b4e153c82e273e549b9efbf6db4a2d8328" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/freescout-helpdesk/freescout/security/advisories/GHSA-985r-6qfc-hg8m" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>froxlor--Froxlor<br> </td>
<td>Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malicious scripts in the loginname parameter on the Login attempt, which will then be executed when viewed by the Administrator in the System Logs. By exploiting this vulnerability, the attacker can perform various malicious actions such as forcing the Administrator to execute actions without their knowledge or consent. For instance, the attacker can force the Administrator to add a new administrator controlled by the attacker, thereby giving the attacker full control over the application. This vulnerability is fixed in 2.1.9.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34070&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34070" target="_blank">CVE-2024-34070</a><br><a href="https://github.com/froxlor/Froxlor/commit/a862307bce5cdfb1c208b835f3e8faddd23046e6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/froxlor/Froxlor/security/advisories/GHSA-x525-54hf-xr53" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>getgrav--grav<br> </td>
<td>Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can read any server files using Twig Syntax. This includes Grav user account files - `/grav/user/accounts/*.yaml`. This file stores hashed user password, 2FA secret, and the password reset token. This can allow an adversary to compromise any registered account and read any file in the web server by resetting a password for a user to get access to the password reset token from the file or by cracking the hashed password. A low privileged user may also perform a full account takeover of other registered users including Administrators. Version 1.7.46 contains a patch.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34082&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" target="_blank" title="CVSS V3 Score">8.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34082" target="_blank">CVE-2024-34082</a><br><a href="https://github.com/getgrav/grav/commit/b6bba9eb99bf8cb55b8fa8d23f18873ca594e348" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/getgrav/grav/security/advisories/GHSA-f8v5-jmfh-pr69" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>git--git<br> </td>
<td>Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won't work. As always, it is best to avoid cloning repositories from untrusted sources.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32002&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32002" target="_blank">CVE-2024-32002</a><br><a href="https://git-scm.com/docs/git-clone#Documentation/git-clone.txt---recurse-submodulesltpathspecgt" target="_blank">security-advisories@github.com</a><br><a href="https://git-scm.com/docs/git-config#Documentation/git-config.txt-coresymlinks" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/commit/97065761333fd62db1912d81b489db938d8c991d" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/security/advisories/GHSA-8h77-4q3w-gfgv" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>git--git<br> </td>
<td>Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32004&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32004" target="_blank">CVE-2024-32004</a><br><a href="https://git-scm.com/docs/git-clone" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/commit/f4aa8c8bb11dae6e769cd930565173808cbb69c8" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/security/advisories/GHSA-xfc6-vwr8-r389" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>git--git<br> </td>
<td>Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32465&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32465" target="_blank">CVE-2024-32465</a><br><a href="https://git-scm.com/docs/git#_security" target="_blank">security-advisories@github.com</a><br><a href="https://git-scm.com/docs/git-clone" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/commit/7b70e9efb18c2cc3f219af399bd384c5801ba1d7" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/security/advisories/GHSA-vm9j-46j9-qvq4" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>google -- chrome<br> </td>
<td>Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4671&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4671" target="_blank">CVE-2024-4671</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/339266700" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>hakeemnala--Build App Online<br> </td>
<td>The Build App Online plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.21. This is due to missing authentication checking in the 'set_user_cart' function with the 'user_id' header value. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3658&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3658" target="_blank">CVE-2024-3658</a><br><a href="https://plugins.trac.wordpress.org/browser/build-app-online/tags/1.0.21/public/class-build-app-online-public.php#L814" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/65d423ad-da51-4616-860d-2b9354d44147?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>hoppscotch--hoppscotch-extension<br> </td>
<td>The Hoppscotch Browser Extension is a browser extension for Hoppscotch, a community-driven end-to-end open-source API development ecosystem. Due to an oversight during a change made to the extension in the commit d4e8e4830326f46ba17acd1307977ecd32a85b58, a critical check for the origin list was missed and allowed for messages to be sent to the extension which the extension gladly processed and responded back with the results of, while this wasn't supposed to happen and be blocked by the origin not being present in the origin list. This vulnerability exposes Hoppscotch Extension users to sites which call into Hoppscotch Extension APIs internally. This fundamentally allows any site running on the browser with the extension installed to bypass CORS restrictions if the user is running extensions with the given version. This security hole was patched in the commit 7e364b928ab722dc682d0fcad713a96cc38477d6 which was released along with the extension version `0.35`. As a workaround, Chrome users can use the Extensions Settings to disable the extension access to only the origins that you want. Firefox doesn't have an alternative to upgrading to a fixed version.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34714&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34714" target="_blank">CVE-2024-34714</a><br><a href="https://github.com/hoppscotch/hoppscotch-extension/commit/7e364b928ab722dc682d0fcad713a96cc38477d6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/hoppscotch/hoppscotch-extension/commit/d4e8e4830326f46ba17acd1307977ecd32a85b58" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/hoppscotch/hoppscotch-extension/security/advisories/GHSA-jjh5-pvqx-gg5v" target="_blank">security-advisories@github.com</a><br><a href="https://server.yadhu.in/poc/hoppscotch-poc.html" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>icegram--Email Subscribers by Icegram Express Email Marketing, Newsletters, Automation for WordPress &amp; WooCommerce<br> </td>
<td>The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the handle_ajax_request function in all versions up to, and including, 5.7.19. This makes it possible for authenticated attackers, with subscriber-level access and above, to cause a loss of confidentiality, integrity, and availability, by performing multiple unauthorized actions. Some of these actions could also be leveraged to conduct PHP Object Injection and SQL Injection attacks.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4010&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4010" target="_blank">CVE-2024-4010</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083762/email-subscribers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/23bfcdd1-b99d-47eb-9f88-96f9ecc53b32?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>jetmonsters--Hotel Booking Lite<br> </td>
<td>The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4413&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4413" target="_blank">CVE-2024-4413</a><br><a href="https://plugins.trac.wordpress.org/browser/motopress-hotel-booking-lite/trunk/includes/shortcodes/checkout-shortcode/step-checkout.php#L149" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3084187%40motopress-hotel-booking-lite%2Ftrunk&amp;old=3081058%40motopress-hotel-booking-lite%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1d7f1283-a274-49a2-8bec-da178771b13a?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>jottlieb--Last Viewed Posts by WPBeginner<br> </td>
<td>The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted input from the LastViewedPosts Cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3070&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3070" target="_blank">CVE-2024-3070</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3062246%40last-viewed-posts&amp;new=3062246%40last-viewed-posts&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b6c5cc05-b147-46f6-aaa9-4c82aae1b544?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>kognetiks--Kognetiks Chatbot for WordPress<br> </td>
<td>The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the chatbot_chatgpt_upload_file_to_assistant function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers, with to upload arbitrary files on the affected site's server which may make remote code execution possible.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4560&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4560" target="_blank">CVE-2024-4560</a><br><a href="https://plugins.trac.wordpress.org/browser/chatbot-chatgpt/trunk/includes/utilities/chatbot-file-upload.php#L17" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7bc33a05-d462-492e-9ea5-cf37b887cc94?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>lobehub--lobe-chat<br> </td>
<td>Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32964&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32964" target="_blank">CVE-2024-32964</a><br><a href="https://github.com/lobehub/lobe-chat/commit/465665a735556669ee30446c7ea9049a20cc7c37" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/lobehub/lobe-chat/security/advisories/GHSA-mxhq-xw3g-rphc" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>mantisbt--mantisbt<br> </td>
<td>MantisBT (Mantis Bug Tracker) is an open source issue tracker. Insufficient access control in the registration and password reset process allows an attacker to reset another user's password and takeover their account, if the victim has an incomplete request pending. The exploit is only possible while the verification token is valid, i.e for 5 minutes after the confirmation URL sent by e-mail has been opened, and the user did not complete the process by updating their password. A brute-force attack calling account_update.php with increasing user IDs is possible. A successful takeover would grant the attacker full access to the compromised account, including sensitive information and functionalities associated with the account, the extent of which depends on its privileges and the data it has access to. Version 2.26.2 contains a patch for the issue. As a workaround, one may mitigate the risk by reducing the verification token's validity (change the value of the `TOKEN_EXPIRY_AUTHENTICATED` constant in `constants_inc.php`).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34077&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34077" target="_blank">CVE-2024-34077</a><br><a href="https://github.com/mantisbt/mantisbt/commit/92d11a01b195a1b6717a2f205218089158ea6d00" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/mantisbt/mantisbt/security/advisories/GHSA-93x3-m7pw-ppqm" target="_blank">security-advisories@github.com</a><br><a href="https://mantisbt.org/bugs/view.php?id=34433" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>metaphorcreations--Ditty Responsive News Tickers, Sliders, and Lists<br> </td>
<td>The Ditty plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.1.38 via deserialization of untrusted input when adding a new ditty. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3954&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3954" target="_blank">CVE-2024-3954</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3081335%40ditty-news-ticker&amp;new=3081335%40ditty-news-ticker&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0f00b138-5c4b-4f75-94b1-82721cba2668?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>micromatch--braces<br> </td>
<td>The NPM package `braces` fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will enter a loop, which will cause the program to start allocating heap memory without freeing it at any moment of the loop. Eventually, the JavaScript heap limit is reached, and the program will crash.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4068&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4068" target="_blank">CVE-2024-4068</a><br><a href="https://devhub.checkmarx.com/cve-details/CVE-2024-4068/" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a><br><a href="https://github.com/micromatch/braces/blob/98414f9f1fabe021736e26836d8306d5de747e0d/lib/parse.js#L308" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a><br><a href="https://github.com/micromatch/braces/issues/35" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a></td>
</tr>
<tr>
<td>micromatch--micromatch<br> </td>
<td>The NPM package `micromatch` is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persists. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4067&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4067" target="_blank">CVE-2024-4067</a><br><a href="https://devhub.checkmarx.com/cve-details/CVE-2024-4067/" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a><br><a href="https://github.com/micromatch/micromatch/blob/2c56a8604b68c1099e7bc0f807ce0865a339747a/index.js#L448" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a><br><a href="https://github.com/micromatch/micromatch/issues/243" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a><br><a href="https://github.com/micromatch/micromatch/pull/247" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a></td>
</tr>
<tr>
<td>microsoft -- windows_10_1507<br> </td>
<td>Windows MSHTML Platform Security Feature Bypass Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30040&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30040" target="_blank">CVE-2024-30040</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30040" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>microsoft -- windows_10_1507<br> </td>
<td>Windows DWM Core Library Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30051&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30051" target="_blank">CVE-2024-30051</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30051" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>miniOrange--WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn)<br> </td>
<td>Improper Privilege Management vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Privilege Escalation.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.6.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47683&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47683" target="_blank">CVE-2023-47683</a><br><a href="https://patchstack.com/database/vulnerability/miniorange-login-openid/wordpress-social-login-social-sharing-by-miniorange-plugin-7-6-6-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>monetizemore--Advanced Ads  Ad Manager &amp; AdSense<br> </td>
<td>The Advanced Ads plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.52.1 via deserialization of untrusted input in the 'placement_slug' parameter. This makes it possible for authenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2290&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2290" target="_blank">CVE-2024-2290</a><br><a href="https://plugins.trac.wordpress.org/browser/advanced-ads/trunk/modules/import-export/classes/import.php#L155" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3081914%40advanced-ads&amp;new=3081914%40advanced-ads&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f64336f7-ab2a-4e22-a76f-d077c51f9c57?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Arc(TM) &amp; Iris(R) Xe Graphics software<br> </td>
<td>Improper neutralization in some Intel(R) Arc(TM) &amp; Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent network access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21864&amp;vector=CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21864" target="_blank">CVE-2024-21864</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01053.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) BIOS Guard firmware<br> </td>
<td>Improper conditions check in some Intel(R) BIOS Guard firmware may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-27504&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-27504" target="_blank">CVE-2023-27504</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00814.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) BIOS Guard firmware<br> </td>
<td>Improper input validation in some Intel(R) BIOS Guard firmware may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-28402&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-28402" target="_blank">CVE-2023-28402</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00814.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) DTT software installers<br> </td>
<td>Exposure of resource to wrong sphere in some Intel(R) DTT software installers may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21813&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">7.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21813" target="_blank">CVE-2024-21813</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00984.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware<br> </td>
<td>Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-37341&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-37341" target="_blank">CVE-2022-37341</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00756.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA Framework software installers<br> </td>
<td>Improper access control in some Intel(R) GPA Framework software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43748&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43748" target="_blank">CVE-2023-43748</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA software installers<br> </td>
<td>Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-24460&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-24460" target="_blank">CVE-2023-24460</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA software installers<br> </td>
<td>Improper access control in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-40071&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40071" target="_blank">CVE-2023-40071</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA software installers<br> </td>
<td>Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43629&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43629" target="_blank">CVE-2023-43629</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Neural Compressor software<br> </td>
<td>Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22476&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22476" target="_blank">CVE-2024-22476</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01109.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>Buffer overflow in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38581&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38581" target="_blank">CVE-2023-38581</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>Improper neutralization in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-42773&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-42773" target="_blank">CVE-2023-42773</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>Improper access control in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45217&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45217" target="_blank">CVE-2023-45217</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>Use after free in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46691&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:H" target="_blank" title="CVSS V3 Score">7.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46691" target="_blank">CVE-2023-46691</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for macOS<br> </td>
<td>Improper access control in some Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-40070&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40070" target="_blank">CVE-2023-40070</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for macOS<br> </td>
<td>Improper neutralization in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46689&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46689" target="_blank">CVE-2023-46689</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Stratix 10 and Intel(R) Agilex 7 FPGAs<br> </td>
<td>Unchecked return value in SDM firmware for Intel(R) Stratix 10 and Intel(R) Agilex 7 FPGAs before version 23.3 may allow an authenticated user to potentially enable denial of service via adjacent access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41092&amp;vector=CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41092" target="_blank">CVE-2023-41092</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01007.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) TDX module software<br> </td>
<td>Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45745&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45745" target="_blank">CVE-2023-45745</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01036.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Thunderbolt driver software<br> </td>
<td>Improper access control for some Intel(R) Thunderbolt driver software before version 89 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-37410&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-37410" target="_blank">CVE-2022-37410</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00916.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--PprRequestLog module in UEFI firmware for some Intel(R) Server D50DNP Family products<br> </td>
<td>Improper input validation in PprRequestLog module in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22382&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22382" target="_blank">CVE-2024-22382</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--UEFI firmware for some Intel(R) Server D50DNP Family products<br> </td>
<td>Improper input validation in PlatformVariableInitDxe driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22095&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22095" target="_blank">CVE-2024-22095</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--UEFI firmware for some Intel(R) Server D50DNP Family products<br> </td>
<td>Improper input validation in UserAuthenticationSmm driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23487&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23487" target="_blank">CVE-2024-23487</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--UEFI firmware for some Intel(R) Server D50FCP Family products<br> </td>
<td>Improper buffer restrictions in PlatformPfrDxe driver in UEFI firmware for some Intel(R) Server D50FCP Family products may allow a privileged user to enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23980&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23980" target="_blank">CVE-2024-23980</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--UEFI firmware for some Intel(R) Server M50FCP Family products<br> </td>
<td>Improper input validation in PfrSmiUpdateFw driver in UEFI firmware for some Intel(R) Server M50FCP Family products may allow a privileged user to enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24981&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24981" target="_blank">CVE-2024-24981</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in the installer in Samsung Portable SSD for T5 1.6.10 on Windows. Because it is possible to tamper with the directory and DLL files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (An attacker must already have user privileges)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31954&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31954" target="_blank">CVE-2024-31954</a><br><a href="https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31954/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--some Intel(R) PROSet/Wireless WiFi software for Windows<br> </td>
<td>Improper input validation for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38654&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38654" target="_blank">CVE-2023-38654</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>nautobot--nautobot<br> </td>
<td>Nautobot is a Network Source of Truth and Network Automation Platform. A Nautobot user with admin privileges can modify the `BANNER_TOP`, `BANNER_BOTTOM`, and `BANNER_LOGIN` configuration settings via the `/admin/constance/config/` endpoint. Normally these settings are used to provide custom banner text at the top and bottom of all Nautobot web pages (or specifically on the login page in the case of `BANNER_LOGIN`) but it was reported that an admin user can make use of these settings to inject arbitrary HTML, potentially exposing Nautobot users to security issues such as cross-site scripting (stored XSS). The vulnerability is fixed in Nautobot 1.6.22 and 2.2.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34707&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:L" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34707" target="_blank">CVE-2024-34707</a><br><a href="https://github.com/nautobot/nautobot/commit/4f0a66bd6307bfe0e0acb899233e0d4ad516f51c" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/nautobot/nautobot/commit/f640aedc69c848d3d1be57f0300fc40033ff6423" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/nautobot/nautobot/pull/5697" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/nautobot/nautobot/pull/5698" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/nautobot/nautobot/security/advisories/GHSA-r2hr-4v48-fjv3" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>nocodb--nocodb<br> </td>
<td>NocoDB is software for building databases as spreadsheets. Prior to 0.202.9, a stored cross-site scripting vulnerability exists within the Formula virtual cell comments functionality. The nc-gui/components/virtual-cell/Formula.vue displays a v-html tag with the value of "urls" whose contents are processed by the function replaceUrlsWithLink(). This function recognizes the pattern URI::(XXX) and creates a hyperlink tag &lt;a&gt; with href=XXX. However, it leaves all the other contents outside of the pattern URI::(XXX) unchanged. This vulnerability is fixed in 0.202.9.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-49781&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-49781" target="_blank">CVE-2023-49781</a><br><a href="https://github.com/nocodb/nocodb/commit/7f58ce3726dfec71537d8b80474a0f95a48a1574" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/nocodb/nocodb/security/advisories/GHSA-h6r4-xvw6-jc5h" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>npgsql--npgsql<br> </td>
<td>Npgsql is the .NET data provider for PostgreSQL. The `WriteBind()` method in `src/Npgsql/Internal/NpgsqlConnector.FrontendMessages.cs` uses `int` variables to store the message length and the sum of parameter lengths. Both variables overflow when the sum of parameter lengths becomes too large. This causes Npgsql to write a message size that is too small when constructing a Postgres protocol message to send it over the network to the database. When parsing the message, the database will only read a small number of bytes and treat any following bytes as new messages while they belong to the old message. Attackers can abuse this to inject arbitrary Postgres protocol messages into the connection, leading to the execution of arbitrary SQL statements on the application's behalf. This vulnerability is fixed in 4.0.14, 4.1.13, 5.0.18, 6.0.11, 7.0.7, and 8.0.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32655&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32655" target="_blank">CVE-2024-32655</a><br><a href="https://github.com/npgsql/npgsql/commit/091655eed0c84e502ab424950c930339d17c1928" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/3183efb2bdcca159c8c2e22af57e18ea8f853cf0" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/67acbe027e28477ac2199e15cfb554bb2ffaf169" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/703d9af8fa48dfe8c0180e36edb8278f34342d7b" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/a22a42d8141d7a3528f43c02c095a409507cf1af" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/e34e2ba8042e666d9af54a1b255fba4d5b11df56" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/f7e7ead0702d776a8f551f5786c4cac2d65c4bc6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v4.0.14" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v4.1.13" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v5.0.18" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v6.0.11" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v7.0.7" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v8.0.3" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/security/advisories/GHSA-x9vc-6hfv-hg8c" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>nvidia--ChatRTX<br> </td>
<td>NVIDIA ChatRTX for Windows contains a vulnerability in Chat RTX UI, where a user can cause an improper privilege management issue by sending user inputs to change execution flow. A successful exploit of this vulnerability might lead to information disclosure, escalation of privileges, and data tampering.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0096&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0096" target="_blank">CVE-2024-0096</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5533" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>nvidia--ChatRTX<br> </td>
<td>NVIDIA ChatRTX for Windows contains a vulnerability in ChatRTX UI, where a user can cause an improper privilege management issue by exploiting interprocess communication between different processes. A successful exploit of this vulnerability might lead to information disclosure, escalation of privileges, and data tampering.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0097&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0097" target="_blank">CVE-2024-0097</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5533" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>nvidia--NVIDIA Triton Inference Server<br> </td>
<td>NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the file. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0087&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0087" target="_blank">CVE-2024-0087</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5535" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>pencidesign--Penci Soledad Data Migrator<br> </td>
<td>The Penci Soledad Data Migrator plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.0 via the 'data' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included. This is limited to just PHP files.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3551&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3551" target="_blank">CVE-2024-3551</a><br><a href="https://themeforest.net/item/soledad-multiconcept-blogmagazine-wp-theme/12945398" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a4f8df3a-f247-4365-a9f6-6124065b4883?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>plainware--ShiftController Employee Shift Scheduling<br> </td>
<td>The ShiftController Employee Shift Scheduling plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the `hc3_session`-cookie in versions up to, and including, 4.9.57. This makes it possible for an authenticated attacker with contributor access-level or above to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4733&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4733" target="_blank">CVE-2024-4733</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3087047%40shiftcontroller%2Ftrunk&amp;old=3080165%40shiftcontroller%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9c8ab916-240d-43c3-92d4-7efd75862a5e?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>plugins360--All-in-One Video Gallery<br> </td>
<td>The All-in-One Video Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.5 via the aiovg_search_form shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4670&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4670" target="_blank">CVE-2024-4670</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085217/all-in-one-video-gallery" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e2793547-5edf-4d2a-bc3b-fcaeed62963d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>powerfulwp--Local Delivery Drivers for WooCommerce<br> </td>
<td>Improper Privilege Management vulnerability in powerfulwp Local Delivery Drivers for WooCommerce allows Privilege Escalation.This issue affects Local Delivery Drivers for WooCommerce: from n/a through 1.9.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51481&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51481" target="_blank">CVE-2023-51481</a><br><a href="https://patchstack.com/database/vulnerability/local-delivery-drivers-for-woocommerce/wordpress-local-delivery-drivers-for-woocommerce-plugin-1-9-0-unauthenticated-account-takeover-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ravanh--XML Sitemap &amp; Google News<br> </td>
<td>The XML Sitemap &amp; Google News plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.8 via the 'feed' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4441&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4441" target="_blank">CVE-2024-4441</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3082081%40xml-sitemap-feed&amp;new=3082081%40xml-sitemap-feed&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/87888350-1230-4fec-9de2-c58fa24e6a05?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>smp7, wp.insider--Simple Membership<br> </td>
<td>Improper Authentication vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.3.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41956&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41956" target="_blank">CVE-2023-41956</a><br><a href="https://patchstack.com/database/vulnerability/simple-membership/wordpress-simple-membership-plugin-4-3-4-authenticated-account-takeover-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>smp7, wp.insider--Simple Membership<br> </td>
<td>Improper Privilege Management vulnerability in smp7, wp.Insider Simple Membership allows Privilege Escalation.This issue affects Simple Membership: from n/a through 4.3.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41957&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41957" target="_blank">CVE-2023-41957</a><br><a href="https://patchstack.com/database/vulnerability/simple-membership/wordpress-simple-membership-plugin-4-3-4-unauthenticated-membership-role-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>spacemeshos--go-spacemesh<br> </td>
<td>go-spacemesh is a Go implementation of the Spacemesh protocol full node. Nodes can publish activations transactions (ATXs) which reference the incorrect previous ATX of the Smesher that created the ATX. ATXs are expected to form a single chain from the newest to the first ATX ever published by an identity. Allowing Smeshers to reference an earlier (but not the latest) ATX as previous breaks this protocol rule and can serve as an attack vector where Nodes are rewarded for holding their PoST data for less than one epoch but still being eligible for rewards. This vulnerability is fixed in go-spacemesh 1.5.2-hotfix1 and Spacemesh API 1.37.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34360&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34360" target="_blank">CVE-2024-34360</a><br><a href="https://github.com/spacemeshos/api/commit/1d5bd972bbe225d024c3e0ae5214ddb6b481716e" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/spacemeshos/go-spacemesh/commit/9aff88d54be809ac43d60e8a8b4d65359c356b87" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/spacemeshos/go-spacemesh/security/advisories/GHSA-jcqq-g64v-gcm7" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>spoonthemes--Adifier System<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spoonthemes Adifier System allows PHP Local File Inclusion.This issue affects Adifier System: from n/a before 3.1.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-49753&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-49753" target="_blank">CVE-2023-49753</a><br><a href="https://patchstack.com/database/vulnerability/adifier-system/wordpress-adifier-classified-ads-wordpress-theme-theme-3-9-3-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>stalwartlabs--mail-server<br> </td>
<td>Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execution as the stalwart-mail user (including web interface admins) can gain complete root access to the system. Usually, system services are run as a separate user (not as root) to isolate an attacker with Arbitrary Code Execution to the current service. Therefore, other system services and the system itself remains protected in case of a successful attack. stalwart-mail runs as a separate user, but it can give itself full privileges again in a simple way, so this protection is practically ineffective. Server admins who handed out the admin credentials to the mail server, but didn't want to hand out complete root access to the system, as well as any attacked user when the attackers gained Arbitrary Code Execution using another vulnerability, may be vulnerable. Version 0.8.0 contains a patch for the issue.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35187&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35187" target="_blank">CVE-2024-35187</a><br><a href="https://github.com/stalwartlabs/mail-server/security/advisories/GHSA-rwp5-f854-ppg6" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>strongSwan--strongSwan<br> </td>
<td>strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's certificate. So clients can authenticate with any trusted certificate and claim an arbitrary IKE/EAP identity as their own. This is problematic if the identity is used to make policy decisions. A fix was released in strongSwan version 5.9.6 in August 2022 (e4b4aabc4996fc61c37deab7858d07bc4d220136).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-4967&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-4967" target="_blank">CVE-2022-4967</a><br><a href="https://github.com/strongswan/strongswan/commit/e4b4aabc4996fc61c37deab7858d07bc4d220136" target="_blank">security@ubuntu.com</a><br><a href="https://www.cve.org/CVERecord?id=CVE-2022-4967" target="_blank">security@ubuntu.com</a><br><a href="https://www.strongswan.org/blog/2024/05/13/strongswan-vulnerability-(cve-2022-4967).html" target="_blank">security@ubuntu.com</a></td>
</tr>
<tr>
<td>supsystic.com--Popup by Supsystic<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46197&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46197" target="_blank">CVE-2023-46197</a><br><a href="https://patchstack.com/database/vulnerability/popup-by-supsystic/wordpress-popup-by-supsystic-plugin-1-10-19-unauthenticated-subscriber-email-addresses-disclosure?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>techjewel--Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder<br> </td>
<td>The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to grant users with Fluent Form management permissions which gives them access to all of the plugin's settings and features. This also makes it possible for unauthenticated attackers to delete manager accounts.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2771&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2771" target="_blank">CVE-2024-2771</a><br><a href="https://plugins.trac.wordpress.org/changeset/3088078/fluentform/trunk/app/Http/Policies/RoleManagerPolicy.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/071195d6-3452-4241-a8d3-92efc84e4850?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>techjewel--Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder<br> </td>
<td>The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp-json/fluentform/v1/global-settings REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to modify all of the plugin's settings.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2782&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2782" target="_blank">CVE-2024-2782</a><br><a href="https://plugins.trac.wordpress.org/changeset/3088078/fluentform/trunk/app/Http/Policies/GlobalSettingsPolicy.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0814e7b3-404a-4db5-b564-46c9086ec048?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>techjewel--Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder<br> </td>
<td>The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' parameter in versions up to, and including, 5.1.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, and access granted by an administrator, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4709&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4709" target="_blank">CVE-2024-4709</a><br><a href="https://plugins.trac.wordpress.org/browser/fluentform/trunk/app/Services/FormBuilder/Notifications/EmailNotification.php#L106" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/fluentform/trunk/app/Services/FormBuilder/Notifications/EmailNotification.php#L164" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/fluentform/trunk/app/Services/FormBuilder/Notifications/EmailNotification.php#L194" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3088078/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5fe317a6-a391-441a-aac8-c8fa57e73169?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themeisle--Visualizer: Tables and Charts Manager for WordPress<br> </td>
<td>The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability check on the getQueryData() function in all versions up to, and including, 3.10.15. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform arbitrary SQL queries that can be leveraged for privilege escalation among many other actions.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3750&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3750" target="_blank">CVE-2024-3750</a><br><a href="https://plugins.trac.wordpress.org/browser/visualizer/trunk/classes/Visualizer/Module/Chart.php#L1421" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086048/visualizer/tags/3.11.0/classes/Visualizer/Module/Chart.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086048/visualizer/tags/3.11.0/classes/Visualizer/Source/Query.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6d27544c-97a5-42cd-ab07-358f819acbc4?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themeum--Tutor LMS eLearning and online course solution<br> </td>
<td>The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to add, modify, or delete data.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4223&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4223" target="_blank">CVE-2024-4223</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086489/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ce4c4395-6d1a-4d5f-885f-383e5c44c0f8?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themeum--Tutor LMS eLearning and online course solution<br> </td>
<td>The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the 'question_id' parameter in versions up to, and including, 2.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Instructor-level permissions and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4318&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4318" target="_blank">CVE-2024-4318</a><br><a href="https://plugins.trac.wordpress.org/browser/tutor/tags/2.7.0/classes/Utils.php#L4456" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/tutor/tags/2.7.0/classes/Utils.php#L4575" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086489/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9bbb3c65-f02c-4d6d-bd4e-b3232af5e21b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themium--Tutor LMS Pro<br> </td>
<td>The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'authenticate' function in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to gain control of an existing administrator account.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4351&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4351" target="_blank">CVE-2024-4351</a><br><a href="https://www.themeum.com/product/tutor-lms/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/59859583-49e5-4a80-8659-b9ca7ddc089d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themium--Tutor LMS Pro<br> </td>
<td>The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'get_calendar_materials' function. The plugin is also vulnerable to SQL Injection via the 'year' parameter of that function due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4352&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4352" target="_blank">CVE-2024-4352</a><br><a href="https://www.themeum.com/product/tutor-lms/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c647beda-cf73-4372-975f-a8c8ed05217f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themium--Tutor LMS Pro<br> </td>
<td>The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4222&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4222" target="_blank">CVE-2024-4222</a><br><a href="https://www.themeum.com/product/tutor-lms/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/942fffb6-2719-4b70-9759-21b2d50002c5?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thimpress--LearnPress WordPress LMS Plugin<br> </td>
<td>The LearnPress - WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'term_id' parameter in versions up to, and including, 4.2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4434&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4434" target="_blank">CVE-2024-4434</a><br><a href="https://inky-knuckle-2c2.notion.site/Unauthenticated-SQLI-in-Learnpress-plugin-Latest-Version-4-2-6-5-a86fe63bcc7b4c9988802688211817fd?pvs=25" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/learnpress/tags/4.2.6.5/inc/Databases/class-lp-course-db.php#L508" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082204/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2d64e1c6-1e25-4438-974d-b7da0979cc40?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thimpress--LearnPress WordPress LMS Plugin<br> </td>
<td>The LearnPress - WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_post_materials' function in versions up to, and including, 4.2.6.5. This makes it possible for authenticated attackers, with Instructor-level permissions and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4397&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4397" target="_blank">CVE-2024-4397</a><br><a href="https://plugins.trac.wordpress.org/browser/learnpress/tags/4.2.6.5/inc/rest-api/v1/frontend/class-lp-rest-material-controller.php#L98" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083657/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ec20d5c4-4c41-4ec9-8d0a-ec8f03634f7d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>unitecms--Unlimited Elements For Elementor (Free Widgets, Addons, Templates)<br> </td>
<td>The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 1.5.102 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3055&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3055" target="_blank">CVE-2024-3055</a><br><a href="https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/tags/1.5.93/inc_php/framework/db.class.php#L238" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3081509%40unlimited-elements-for-elementor%2Ftrunk&amp;old=3076456%40unlimited-elements-for-elementor%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ebc0c8e6-a365-4ef7-9c1a-41454855096c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>unitecms--Unlimited Elements For Elementor (Free Widgets, Addons, Templates)<br> </td>
<td>The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to command injection in all versions up to, and including, 1.5.102. This is due to insufficient filtering of template attributes during the creation of HTML for custom widgets This makes it possible for authenticated attackers, with administrator-level access and above, to execute arbitrary commands on the server.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2662&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2662" target="_blank">CVE-2024-2662</a><br><a href="https://plugins.trac.wordpress.org/changeset/3071404/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_template_engine.class.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/58492dbb-b9e0-4477-b85d-ace06dba954c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>valtimo-platform--valtimo-frontend-libraries<br> </td>
<td>Valtimo is an open source business process and case management platform. When opening a form in Valtimo, the access token (JWT) of the user is exposed to `api.form.io` via the the `x-jwt-token` header. An attacker can retrieve personal information from this token, or use it to execute requests to the Valtimo REST API on behalf of the logged-in user. This issue is caused by a misconfiguration of the Form.io component. The following conditions have to be met in order to perform this attack: An attacker needs to have access to the network traffic on the `api.form.io` domain; the content of the `x-jwt-token` header is logged or otherwise available to the attacker; an attacker needs to have network access to the Valtimo API; and an attacker needs to act within the time-to-live of the access token. The default TTL in Keycloak is 5 minutes. Versions 10.8.4, 11.1.6 and 11.2.2 have been patched.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34706&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34706" target="_blank">CVE-2024-34706</a><br><a href="https://github.com/valtimo-platform/valtimo-frontend-libraries/commit/1aaba5ef5750dafebbc7476fb08bf2375a25f19e" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/valtimo-platform/valtimo-frontend-libraries/commit/8c2dbf2a41180d2b0358d878290e4d37168f0fb6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/valtimo-platform/valtimo-frontend-libraries/commit/d65e05fd2784bd4a628778b34a5b79ce2f0cef8c" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/valtimo-platform/valtimo-frontend-libraries/security/advisories/GHSA-xcp4-62vj-cq3r" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>vendor or project--product name<br> </td>
<td>A potential vulnerability has been identified for OpenText Operations Bridge Reporter. The vulnerability could be exploited to inject malicious SQL queries. An attack requires to be an authenticated administrator of OBR with network access to the OBR web application.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2021-22508&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-22508" target="_blank">CVE-2021-22508</a><br><a href="https://support.microfocus.com/kb/kmdoc.php?id=KM03793174" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>vercel--next.js<br> </td>
<td>Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request meant that requests are treated as both a single request, and two separate requests by Next.js, leading to desynchronized responses. This led to a response queue poisoning vulnerability in the affected Next.js versions. For a request to be exploitable, the affected route also had to be making use of the [rewrites](https://nextjs.org/docs/app/api-reference/next-config-js/rewrites) feature in Next.js. The vulnerability is resolved in Next.js `13.5.1` and newer.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34350&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34350" target="_blank">CVE-2024-34350</a><br><a href="https://github.com/vercel/next.js/security/advisories/GHSA-77r5-gw3j-2mpf" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>vercel--next.js<br> </td>
<td>Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able to make requests that appear to be originating from the Next.js application server itself. The required conditions are 1) Next.js is running in a self-hosted manner; 2) the Next.js application makes use of Server Actions; and 3) the Server Action performs a redirect to a relative path which starts with a `/`. This vulnerability was fixed in Next.js `14.1.1`.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34351&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34351" target="_blank">CVE-2024-34351</a><br><a href="https://github.com/vercel/next.js/commit/8f7a6ca7d21a97bc9f7a1bbe10427b5ad74b9085" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/vercel/next.js/pull/62561" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/vercel/next.js/security/advisories/GHSA-fr5h-rqp8-mj6g" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>weDevs--WP User Frontend<br> </td>
<td>Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47682&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47682" target="_blank">CVE-2023-47682</a><br><a href="https://patchstack.com/database/vulnerability/wp-user-frontend/wordpress-wp-user-frontend-plugin-3-6-5-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>wpForo--wpForo Forum<br> </td>
<td>Improper Privilege Management vulnerability in wpForo wpForo Forum allows Privilege Escalation.This issue affects wpForo Forum: from n/a through 2.2.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47868&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47868" target="_blank">CVE-2023-47868</a><br><a href="https://patchstack.com/database/vulnerability/wpforo/wordpress-wpforo-plugin-2-2-3-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
</tbody>
</table>
<p><a href="https://www.cisa.gov/#top">Back to top</a></p>
</div>
<div>
<h2>Medium Vulnerabilities</h2>
<table summary="Medium Vulnerabilities" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th scope="col" role="columnheader" data-tablesaw-priority="persist">Primary<br>Vendor -- Product</th>
<th scope="col" role="columnheader">Description</th>
<th scope="col" role="columnheader">Published</th>
<th scope="col" role="columnheader">CVSS Score</th>
<th scope="col" role="columnheader">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>10Web Form Builder Team--Form Maker by 10Web<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.24.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34437&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34437" target="_blank">CVE-2024-34437</a><br><a href="https://patchstack.com/database/vulnerability/form-maker/wordpress-form-maker-by-10web-plugin-1-15-24-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>1Panel-dev--1Panel<br> </td>
<td>1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. The mirror configuration write symbol `&gt;` can be used to achieve arbitrary file writing. This vulnerability is fixed in v1.10.3-lts.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34352&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34352" target="_blank">CVE-2024-34352</a><br><a href="https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-f8ch-w75v-c847" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>ABB--RobotWare 6<br> </td>
<td>An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible. The vulnerability could potentially be exploited to perform unauthorized actions by an attacker. This vulnerability arises under specific condition when specially crafted message is processed by the system. Below are reported vulnerabilities in the Robot Ware versions. * IRC5- RobotWare 6 &lt; 6.15.06 except 6.10.10, and 6.13.07 * OmniCore- RobotWare 7 &lt; 7.14</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1914&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1914" target="_blank">CVE-2024-1914</a><br><a href="https://search.abb.com/library/Download.aspx?DocumentID=SI20330&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch" target="_blank">cybersecurity@ch.abb.com</a></td>
</tr>
<tr>
<td>AREOI--All Bootstrap Blocks<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AREOI All Bootstrap Blocks allows Stored XSS.This issue affects All Bootstrap Blocks: from n/a through 1.3.15.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35169&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35169" target="_blank">CVE-2024-35169</a><br><a href="https://patchstack.com/database/vulnerability/all-bootstrap-blocks/wordpress-all-bootstrap-blocks-plugin-1-3-15-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>AROX SOLUTION--School ERP Pro+Responsive<br> </td>
<td>Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the username and password parameters in '/index.php'. This vulnerability allows an attacker to partially take control of the victim's browser session.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4822&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4822" target="_blank">CVE-2024-4822</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-school-erp-proresponsive-arox-solution" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>AROX SOLUTION--School ERP Pro+Responsive<br> </td>
<td>Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the index '/schoolerp/office_admin/' in the parameters es_bankacc, es_bank_name, es_bank_pin, es_checkno, es_teller_number, dc1 and dc2. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4823&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4823" target="_blank">CVE-2024-4823</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-school-erp-proresponsive-arox-solution" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Academy LMS--Academy LMS<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.25.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35171&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35171" target="_blank">CVE-2024-35171</a><br><a href="https://patchstack.com/database/vulnerability/academy/wordpress-academy-lms-plugin-1-9-25-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Adam DeHaven--Perfect Pullquotes<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adam DeHaven Perfect Pullquotes allows Stored XSS.This issue affects Perfect Pullquotes: from n/a through 1.7.5.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33951&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33951" target="_blank">CVE-2024-33951</a><br><a href="https://patchstack.com/database/vulnerability/perfect-pullquotes/wordpress-perfect-pullquotes-plugin-1-7-5-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30311&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30311" target="_blank">CVE-2024-30311</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30312&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30312" target="_blank">CVE-2024-30312</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34101&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34101" target="_blank">CVE-2024-34101</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30283&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30283" target="_blank">CVE-2024-30283</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30286&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30286" target="_blank">CVE-2024-30286</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30287&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30287" target="_blank">CVE-2024-30287</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30298&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30298" target="_blank">CVE-2024-30298</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Illustrator<br> </td>
<td>Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20793&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20793" target="_blank">CVE-2024-20793</a><br><a href="https://helpx.adobe.com/security/products/illustrator/apsb24-30.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Substance3D - Designer<br> </td>
<td>Substance3D - Designer versions 13.1.1 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30281&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30281" target="_blank">CVE-2024-30281</a><br><a href="https://helpx.adobe.com/security/products/substance3d_designer/apsb24-35.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Substance3D - Painter<br> </td>
<td>Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30308&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30308" target="_blank">CVE-2024-30308</a><br><a href="https://helpx.adobe.com/security/products/substance3d_painter/apsb24-31.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Substance3D - Painter<br> </td>
<td>Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30309&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30309" target="_blank">CVE-2024-30309</a><br><a href="https://helpx.adobe.com/security/products/substance3d_painter/apsb24-31.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Aleksei Polechin (alek)--Archives Calendar Widget<br> </td>
<td>Administrator Cross Site Scripting (XSS) in Archives Calendar Widget &lt;= 1.0.15 versions.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33950&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33950" target="_blank">CVE-2024-33950</a><br><a href="https://patchstack.com/database/vulnerability/archives-calendar-widget/wordpress-archives-calendar-widget-plugin-1-0-15-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>AlexaCRM--Dynamics 365 Integration<br> </td>
<td>Insertion of Sensitive Information into Log File vulnerability in AlexaCRM Dynamics 365 Integration.This issue affects Dynamics 365 Integration: from n/a through 1.3.17.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34550&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34550" target="_blank">CVE-2024-34550</a><br><a href="https://patchstack.com/database/vulnerability/integration-dynamics/wordpress-dynamics-365-integration-plugin-1-3-17-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Andy Moyle--Church Admin<br> </td>
<td>Missing Authorization vulnerability in Andy Moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through 4.1.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31281&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31281" target="_blank">CVE-2024-31281</a><br><a href="https://patchstack.com/database/vulnerability/church-admin/wordpress-church-admin-plugin-4-1-6-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Andy Moyle--Church Admin<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.1.32.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34828&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34828" target="_blank">CVE-2024-34828</a><br><a href="https://patchstack.com/database/vulnerability/church-admin/wordpress-church-admin-plugin-4-1-32-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>AppPresser Team--AppPresser<br> </td>
<td>Missing Authorization vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32776&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32776" target="_blank">CVE-2024-32776</a><br><a href="https://patchstack.com/database/vulnerability/apppresser/wordpress-apppresser-plugin-4-3-0-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Artbees--SellKit<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Artbees SellKit allows Relative Path Traversal.This issue affects SellKit: from n/a through 1.8.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30509&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30509" target="_blank">CVE-2024-30509</a><br><a href="https://patchstack.com/database/vulnerability/sellkit/wordpress-sellkit-plugin-1-8-1-arbitrary-file-download-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Atanas Yonkov--Pliska<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atanas Yonkov Pliska allows Stored XSS.This issue affects Pliska: from n/a through 0.3.5.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33954&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33954" target="_blank">CVE-2024-33954</a><br><a href="https://patchstack.com/database/vulnerability/pliska/wordpress-pliska-theme-0-3-5-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Automattic--WP Job Manager<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic WP Job Manager.This issue affects WP Job Manager: from n/a through 2.2.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34549&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34549" target="_blank">CVE-2024-34549</a><br><a href="https://patchstack.com/database/vulnerability/wp-job-manager/wordpress-wp-job-manager-plugin-2-2-2-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>BdThemes--Ultimate Store Kit Elementor Addons<br> </td>
<td>Deserialization of Untrusted Data vulnerability in BdThemes Ultimate Store Kit Elementor Addons.This issue affects Ultimate Store Kit Elementor Addons: from n/a through 1.6.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4606&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4606" target="_blank">CVE-2024-4606</a><br><a href="https://patchstack.com/database/vulnerability/ultimate-store-kit/wordpress-ultimate-store-kit-elementor-addons-woocommerce-builder-edd-builder-plugin-1-6-2-php-object-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Benoti--Brozzme Scroll Top<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benoti Brozzme Scroll Top allows Stored XSS.This issue affects Brozzme Scroll Top: from n/a through 1.8.5.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34426&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34426" target="_blank">CVE-2024-34426</a><br><a href="https://patchstack.com/database/vulnerability/brozzme-scroll-top/wordpress-brozzme-scroll-top-plugin-1-8-5-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>BestWebSoft--Captcha by BestWebSoft<br> </td>
<td>Guessable CAPTCHA vulnerability in BestWebSoft Captcha by BestWebSoft allows Functionality Bypass.This issue affects Captcha by BestWebSoft: from n/a through 5.2.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31295&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31295" target="_blank">CVE-2024-31295</a><br><a href="https://patchstack.com/database/vulnerability/captcha-bws/wordpress-captcha-by-bestwebsoft-plugin-5-2-0-captcha-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>BetterAddons--Better Elementor Addons<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BetterAddons Better Elementor Addons better-elementor-addons allows Stored XSS.This issue affects Better Elementor Addons: from n/a through 1.4.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34432&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34432" target="_blank">CVE-2024-34432</a><br><a href="https://patchstack.com/database/vulnerability/better-elementor-addons/wordpress-better-elementor-addons-plugin-1-4-4-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Bootstrapped Ventures--Easy Affiliate Links<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bootstrapped Ventures Easy Affiliate Links allows Stored XSS.This issue affects Easy Affiliate Links: from n/a through 3.7.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34441&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34441" target="_blank">CVE-2024-34441</a><br><a href="https://patchstack.com/database/vulnerability/easy-affiliate-links/wordpress-easy-affiliate-links-plugin-3-7-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--Ultimate Addons for Beaver Builder<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Relative Path Traversal.This issue affects Ultimate Addons for Beaver Builder: from n/a through 1.35.13.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51401&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51401" target="_blank">CVE-2023-51401</a><br><a href="https://patchstack.com/database/vulnerability/bb-ultimate-addon/wordpress-ultimate-addons-for-beaver-builder-premium-plugin-1-35-13-limited-arbitrary-file-download-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Byzoro--Smart S200 Management Platform<br> </td>
<td>A vulnerability was found in Byzoro Smart S200 Management Platform up to 20240507. It has been rated as critical. This issue affects some unknown processing of the file /useratte/userattestation.php. The manipulation of the argument web_img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264437 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4904&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4904" target="_blank">CVE-2024-4904</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/upload.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264437" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264437" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.330636" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>CRM Perks--Integration for Contact Form 7 HubSpot<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 HubSpot.This issue affects Integration for Contact Form 7 HubSpot: from n/a through 1.3.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34756&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34756" target="_blank">CVE-2024-34756</a><br><a href="https://patchstack.com/database/vulnerability/cf7-hubspot/wordpress-integration-for-hubspot-and-contact-form-7-plugin-1-3-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CRM Perks--Integration for Contact Form 7 and Salesforce<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 and Salesforce.This issue affects Integration for Contact Form 7 and Salesforce: from n/a through 1.3.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34755&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34755" target="_blank">CVE-2024-34755</a><br><a href="https://patchstack.com/database/vulnerability/cf7-salesforce/wordpress-integration-for-salesforce-and-contact-form-7-wpforms-elementor-formidable-ninja-forms-plugin-1-3-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CRM Perks--Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.2.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34817&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34817" target="_blank">CVE-2024-34817</a><br><a href="https://patchstack.com/database/vulnerability/integration-for-contact-form-7-and-pipedrive/wordpress-integration-for-pipedrive-and-contact-form-7-wpforms-elementor-ninja-forms-plugin-1-2-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. A reflected cross-site scripting vulnerability on the 1.3.x DEV branch allows attackers to obtain cookies of administrator and other users and fake their login using obtained cookies. This issue is fixed in commit a38b9046e9772612fda847b46308f9391a49891e.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30268&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30268" target="_blank">CVE-2024-30268</a><br><a href="https://github.com/Cacti/cacti/blob/08497b8bcc6a6037f7b1aae303ad8f7dfaf7364e/settings.php#L66" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/commit/a38b9046e9772612fda847b46308f9391a49891e" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-9m3v-whmr-pc2q" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the SQL statement in `create_all_header_nodes()` function from `lib/api_automation.php` , finally resulting in SQL injection. Using SQL based secondary injection technology, attackers can modify the contents of the Cacti database, and based on the modified content, it may be possible to achieve further impact, such as arbitrary file reading, and even remote code execution through arbitrary file writing. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31460&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31460" target="_blank">CVE-2024-31460</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-cx8g-hvq8-p2rv" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-gj3f-p326-gh8r" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js to fix CVE-2023-50250 (among others). However, it still generates the code out of unescaped PHP variables `$title` and `$header`. If those variables contain single quotes, they can be used to inject JavaScript code. An attacker exploiting this vulnerability could execute actions on behalf of other users. This ability to impersonate users could lead to unauthorized changes to settings. Version 1.2.27 fixes this issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29894&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29894" target="_blank">CVE-2024-29894</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-grj5-8fcj-34gh" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-xwqc-7jc4-xm73" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly checked and is used to concatenate the HTML statement in `grow_right_pane_tree()` function from `lib/html.php` , finally resulting in cross-site scripting. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31443&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31443" target="_blank">CVE-2024-31443</a><br><a href="https://github.com/Cacti/cacti/commit/f946fa537d19678f938ddbd784a10e3290d275cf" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-rqc8-78cm-85j3" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the HTML statement in `form_confirm()` function from `lib/html.php` , finally resulting in cross-site scripting. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31444&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">4.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31444" target="_blank">CVE-2024-31444</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-p4ch-7hjw-6m87" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function in `graph_template_inputs.php` is not thoroughly checked and is used to concatenate the SQL statement in `draw_nontemplated_fields_graph_item()` function from `lib/html_form_templates.php` , finally resulting in SQL injection. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31458&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">4.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31458" target="_blank">CVE-2024-31458</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-jrxg-8wh8-943x" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /view/show_student1.php. The manipulation of the argument grade leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264441 was assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4906&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4906" target="_blank">CVE-2024-4906</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%202.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264441" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264441" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333292" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /view/show_student2.php. The manipulation of the argument grade leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264442 is the identifier assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4907&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4907" target="_blank">CVE-2024-4907</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%203.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264442" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264442" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333293" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /view/student_attendance_history1.php. The manipulation of the argument index leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264443.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4908&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4908" target="_blank">CVE-2024-4908</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%204.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264443" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264443" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333294" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /view/student_due_payment.php. The manipulation of the argument due_year leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264444.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4909&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4909" target="_blank">CVE-2024-4909</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%205.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264444" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264444" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333295" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view/student_exam_mark_insert_form1.php. The manipulation of the argument grade leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264445 was assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4910&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4910" target="_blank">CVE-2024-4910</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%206.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264445" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264445" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333296" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /view/student_exam_mark_update_form.php. The manipulation of the argument exam leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264446 is the identifier assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4911&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4911" target="_blank">CVE-2024-4911</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%207.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264446" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264446" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333297" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Campcodes Legal Case Management System 1.0. Affected is an unknown function of the file /admin/general-setting of the component Setting Handler. The manipulation of the argument favicon/logo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263622 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4681&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4681" target="_blank">CVE-2024-4681</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/file_upload.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263622" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263622" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331468" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability classified as critical has been found in Campcodes Online Examination System 1.0. This affects an unknown part of the file addExamExe.php. The manipulation of the argument examTitle leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264447.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4912&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4912" target="_blank">CVE-2024-4912</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_addExamExe.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264447" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264447" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333402" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability classified as critical was found in Campcodes Online Examination System 1.0. This vulnerability affects unknown code of the file exam.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264448.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4913&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4913" target="_blank">CVE-2024-4913</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_exam.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264448" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264448" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333403" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability, which was classified as critical, has been found in Campcodes Online Examination System 1.0. This issue affects some unknown processing of the file ranking-exam.php. The manipulation of the argument exam_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264449 was assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4914&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4914" target="_blank">CVE-2024-4914</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_ranking-exam.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264449" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264449" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333407" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Campcodes Online Examination System 1.0. Affected is an unknown function of the file result.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264450 is the identifier assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4915&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4915" target="_blank">CVE-2024-4915</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_result.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264450" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264450" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333408" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability has been found in Campcodes Online Examination System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file selExamAttemptExe.php. The manipulation of the argument thisId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264451.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4916&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4916" target="_blank">CVE-2024-4916</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_selExamAttemptExe.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264451" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264451" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333409" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability was found in Campcodes Online Examination System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file submitAnswerExe.php. The manipulation of the argument exmne_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264452.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4917&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4917" target="_blank">CVE-2024-4917</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_submitAnswerExe.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264452" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264452" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333410" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability was found in Campcodes Online Examination System 1.0. It has been classified as critical. This affects an unknown part of the file updateQuestion.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264453 was assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4918&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4918" target="_blank">CVE-2024-4918</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_updateQuestion.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264453" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264453" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333415" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability was found in Campcodes Online Examination System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /adminpanel/admin/query/addCourseExe.php. The manipulation of the argument course_name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264454 is the identifier assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4919&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4919" target="_blank">CVE-2024-4919</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_addCourseExe.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264454" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264454" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333416" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability, which was classified as critical, has been found in Campcodes Online Laundry Management System 1.0. This issue affects some unknown processing of the file /admin_class.php. The manipulation of the argument id/delete_category/delete_inv/delete_laundry/delete_supply/delete_user/login/save_inv/save_user leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263891.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4792&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4792" target="_blank">CVE-2024-4792</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/sql_action.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263891" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263891" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332533" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Campcodes Online Laundry Management System 1.0. Affected is an unknown function of the file /manage_laundry.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263892.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4793&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4793" target="_blank">CVE-2024-4793</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/sql_manage_laundry.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263892" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263892" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332535" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manage_receiving.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263893 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4794&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4794" target="_blank">CVE-2024-4794</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/sql_manage_receiving.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263893" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263893" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332536" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability was found in Campcodes Online Laundry Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263894 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4795&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4795" target="_blank">CVE-2024-4795</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/sql_manage_user.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263894" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263894" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332537" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as critical. This affects an unknown part of the file /manage_inv.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263895.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4796&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4796" target="_blank">CVE-2024-4796</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/sql_manage_inv.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263895" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263895" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332538" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file manage_user.php of the component HTTP Request Parameter Handler. The manipulation of the argument id leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263938 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4817&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4817" target="_blank">CVE-2024-4817</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/IDOR_manage_user.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263938" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263938" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333055" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability was found in Campcodes Online Laundry Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /index.php. The manipulation of the argument page leads to file inclusion. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263939.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4818&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4818" target="_blank">CVE-2024-4818</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/LFI.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263939" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263939" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333057" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file admin_class.php. The manipulation of the argument type with the input 1 leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263940.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4819&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4819" target="_blank">CVE-2024-4819</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/IDOR.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263940" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263940" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333058" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco AppDynamics<br> </td>
<td>A vulnerability in Cisco AppDynamics Network Visibility Agent could allow an unauthenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the inability to handle unexpected input. An attacker who has local device access could exploit this vulnerability by sending an HTTP request to the targeted service. A successful exploit could allow the attacker to cause a DoS condition by stopping the Network Agent Service on the local device.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20394&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20394" target="_blank">CVE-2024-20394</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-appd-netvisdos-9zNbsJtK" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Network Services Orchestrator<br> </td>
<td>A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of a parameter in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20369&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20369" target="_blank">CVE-2024-20369</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-ordir-MNM8YqzO" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Client<br> </td>
<td>A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an affected device to elevate privileges to SYSTEM. This vulnerability is due to a lack of authentication on a specific function. A successful exploit could allow the attacker to execute arbitrary code with SYSTEM privileges on an affected device.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20391&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20391" target="_blank">CVE-2024-20391</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-nam-priv-esc-szu2vYpZ" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Email and Web Manager<br> </td>
<td>A vulnerability in the Cisco Crosswork NSO CLI and the ConfD CLI could allow an authenticated, low-privileged, local attacker to elevate privileges to root on the underlying operating system. The vulnerability is due to an incorrect privilege assignment when specific CLI commands are used. An attacker could exploit this vulnerability by executing an affected CLI command. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20383&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20383" target="_blank">CVE-2024-20383</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-bgG5WHOD" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Email<br> </td>
<td>A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20258&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20258" target="_blank">CVE-2024-20258</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-bgG5WHOD" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Email<br> </td>
<td>A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to insufficient input validation of some parameters that are passed to the web-based management API of the affected system. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to perform cross-site scripting (XSS) attacks, resulting in the execution of arbitrary script code in the browser of the targeted user, or could allow the attacker to access sensitive, browser-based information.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20392&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20392" target="_blank">CVE-2024-20392</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-http-split-GLrnnOwS" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Email<br> </td>
<td>A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.r This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20257&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20257" target="_blank">CVE-2024-20257</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-bgG5WHOD" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Web Appliance<br> </td>
<td>A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20256&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20256" target="_blank">CVE-2024-20256</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-bgG5WHOD" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>CodeBard--Fast Custom Social Share by CodeBard<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in CodeBard Fast Custom Social Share by CodeBard.This issue affects Fast Custom Social Share by CodeBard: from n/a through 1.1.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34807&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34807" target="_blank">CVE-2024-34807</a><br><a href="https://patchstack.com/database/vulnerability/fast-custom-social-share-by-codebard/wordpress-fast-custom-social-share-by-codebard-plugin-1-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CodePeople--Appointment Hour Booking<br> </td>
<td>Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Appointment Hour Booking allows Removing Important Client Functionality.This issue affects Appointment Hour Booking: from n/a through 1.4.56.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32720&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32720" target="_blank">CVE-2024-32720</a><br><a href="https://patchstack.com/database/vulnerability/appointment-hour-booking/wordpress-appointment-hour-booking-plugin-1-4-56-captcha-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CodePeople--CP Polls<br> </td>
<td>: Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24873&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24873" target="_blank">CVE-2024-24873</a><br><a href="https://patchstack.com/database/vulnerability/cp-polls/wordpress-polls-cp-plugin-1-0-71-polls-limitation-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CodePeople--CP Polls<br> </td>
<td>Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CodePeople CP Polls allows Code Injection.This issue affects CP Polls: from n/a through 1.0.71.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24874&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24874" target="_blank">CVE-2024-24874</a><br><a href="https://patchstack.com/database/vulnerability/cp-polls/wordpress-polls-cp-plugin-1-0-71-content-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Codezips--E-Commerce Site<br> </td>
<td>A vulnerability has been found in Codezips E-Commerce Site 1.0 and classified as critical. This vulnerability affects unknown code of the file admin/addproduct.php. The manipulation of the argument profilepic leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264460.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4923&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4923" target="_blank">CVE-2024-4923</a><br><a href="https://github.com/polaris0x1/CVE/issues/1" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264460" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264460" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333874" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Codezips--E-Commerce Site<br> </td>
<td>A vulnerability, which was classified as critical, has been found in Codezips E-Commerce Site 1.0. Affected by this issue is some unknown functionality of the file admin/editproduct.php. The manipulation of the argument profilepic leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264746 is the identifier assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5049&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5049" target="_blank">CVE-2024-5049</a><br><a href="https://github.com/polaris0x1/CVE/issues/2" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264746" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264746" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335838" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Cozmoslabs, Razvan Mocanu, Madalin Ungureanu, Cristophor Hurduban--TranslatePress<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Razvan Mocanu, Madalin Ungureanu, Cristophor Hurduban TranslatePress.This issue affects TranslatePress: from n/a through 2.7.5.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34827&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34827" target="_blank">CVE-2024-34827</a><br><a href="https://patchstack.com/database/vulnerability/translatepress-multilingual/wordpress-translate-multilingual-sites-translatepress-plugin-2-7-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Cozmoslabs--Profile Builder<br> </td>
<td>Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.This issue affects Profile Builder: from n/a through 3.11.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31341&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31341" target="_blank">CVE-2024-31341</a><br><a href="https://patchstack.com/database/vulnerability/profile-builder/wordpress-user-profile-builder-plugin-3-11-2-bypass-vulnerability-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Creative Motion--Clearfy Cache<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Creative Motion Clearfy Cache.This issue affects Clearfy Cache: from n/a through 2.2.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34806&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34806" target="_blank">CVE-2024-34806</a><br><a href="https://patchstack.com/database/vulnerability/clearfy/wordpress-clearfy-cache-plugin-2-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CriticalMoments--CMSaasStarter<br> </td>
<td>CMSaaSStarter is a SaaS template/boilerplate built with SvelteKit, Tailwind, and Supabase. Any forks of the CMSaaSStarter template before commit 7904d416d2c72ec75f42fbf51e9e64fa74062ee6 are impacted. The issue is the user JWT Token is not verified on server session. You should take the patch 7904d416d2c72ec75f42fbf51e9e64fa74062ee6 into your fork.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34354&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34354" target="_blank">CVE-2024-34354</a><br><a href="https://github.com/CriticalMoments/CMSaasStarter/commit/7904d416d2c72ec75f42fbf51e9e64fa74062ee6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/CriticalMoments/CMSaasStarter/pull/65" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/CriticalMoments/CMSaasStarter/security/advisories/GHSA-qgcj-9rxf-rw7q" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the system after gaining access to any device.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31409&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31409" target="_blank">CVE-2024-31409</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>The key used to encrypt passwords stored in the database can be found in the CyberPower PowerPanel application code, allowing the passwords to be recovered.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32042&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32042" target="_blank">CVE-2024-32042</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>Dassault Systmes--3DSwymer<br> </td>
<td>A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5597&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5597" target="_blank">CVE-2023-5597</a><br><a href="https://www.3ds.com/vulnerability/advisories" target="_blank">3DS.Information-Security@3ds.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or path vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to denial of service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25965&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:H" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25965" target="_blank">CVE-2024-25965</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an execution with unnecessary privileges vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25967&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25967" target="_blank">CVE-2024-25967</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an allocation of resources without limits or throttling vulnerability. A local unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25969&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25969" target="_blank">CVE-2024-25969</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to loss of integrity.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25970&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25970" target="_blank">CVE-2024-25970</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an improper handling of unexpected data type vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25966&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25966" target="_blank">CVE-2024-25966</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25968&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25968" target="_blank">CVE-2024-25968</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Easy Digital Downloads--Easy Digital Downloads<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32100&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32100" target="_blank">CVE-2024-32100</a><br><a href="https://patchstack.com/database/vulnerability/easy-digital-downloads/wordpress-easy-digital-downloads-plugin-3-2-11-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Easy Digital Downloads--Easy Digital Downloads<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31113&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31113" target="_blank">CVE-2024-31113</a><br><a href="https://patchstack.com/database/vulnerability/easy-digital-downloads/wordpress-easy-digital-downloads-plugin-3-2-11-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Elegant Themes--Divi Builder<br> </td>
<td>The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the 'title' parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4490&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4490" target="_blank">CVE-2024-4490</a><br><a href="https://www.elegantthemes.com/" target="_blank">security@wordfence.com</a><br><a href="https://www.elegantthemes.com/api/changelog/divi.txt" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/efac70f6-d959-41f7-bdef-d554f1c9133e?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>EnvoThemes--Envo's Elementor Templates &amp; Widgets for WooCommerce<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo's Elementor Templates &amp; Widgets for WooCommerce allows Stored XSS.This issue affects Envo's Elementor Templates &amp; Widgets for WooCommerce: from n/a through 1.4.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35167&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35167" target="_blank">CVE-2024-35167</a><br><a href="https://patchstack.com/database/vulnerability/envo-elementor-for-woocommerce/wordpress-envo-s-elementor-templates-widgets-for-woocommerce-plugin-1-4-8-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Eric Alli--Google Typography<br> </td>
<td>Missing Authorization vulnerability in Eric Alli Google Typography.This issue affects Google Typography: from n/a through 1.1.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33942&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33942" target="_blank">CVE-2024-33942</a><br><a href="https://patchstack.com/database/vulnerability/google-typography/wordpress-google-typography-plugin-1-1-2-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Extend Themes--EmpowerWP<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes EmpowerWP.This issue affects EmpowerWP: from n/a through 1.0.21.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34809&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34809" target="_blank">CVE-2024-34809</a><br><a href="https://patchstack.com/database/vulnerability/empowerwp/wordpress-empowerwp-theme-1-0-21-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Felix Moira--Popup More Popups<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Felix Moira Popup More Popups allows Stored XSS.This issue affects Popup More Popups: from n/a through 2.3.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32800&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32800" target="_blank">CVE-2024-32800</a><br><a href="https://patchstack.com/database/vulnerability/popup-more/wordpress-popup-popup-more-popups-plugin-2-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Flothemes--Flo Forms<br> </td>
<td>Missing Authorization vulnerability in Flothemes Flo Forms.This issue affects Flo Forms: from n/a through 1.0.42.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35174&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35174" target="_blank">CVE-2024-35174</a><br><a href="https://patchstack.com/database/vulnerability/flo-forms/wordpress-flo-forms-plugin-1-0-42-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>FmeAddons--Conditional Checkout Fields for WooCommerce<br> </td>
<td>Missing Authorization vulnerability in FmeAddons Conditional Checkout Fields for WooCommerce.This issue affects Conditional Checkout Fields for WooCommerce: from n/a through 1.2.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-45070&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-45070" target="_blank">CVE-2022-45070</a><br><a href="https://patchstack.com/database/vulnerability/conditional-checkout-fields-for-woocommerce/wordpress-conditional-checkout-fields-for-woocommerce-plugin-1-2-1-broken-authentication-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiADC<br> </td>
<td>An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC version 7.4.1 and below, version 7.2.3 and below, version 7.1.4 and below, version 7.0.5 and below, version 6.2.6 and below may allow a read-only admin to view data pertaining to other admins.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-50180&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-50180" target="_blank">CVE-2023-50180</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-433" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiNAC<br> </td>
<td>An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 7.2.0 through 7.2.3 may allow a remote authenticated attacker to perform stored and reflected cross site scripting (XSS) attack via crafted HTTP requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31488&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31488" target="_blank">CVE-2024-31488</a><br><a href="https://fortiguard.com/psirt/FG-IR-24-040" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiOS<br> </td>
<td>A double free vulnerability [CWE-415] in Fortinet FortiOS before 7.0.0 may allow a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-44247&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-44247" target="_blank">CVE-2023-44247</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-195" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiOS<br> </td>
<td>An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrative interface via crafted HTTP requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-26007&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-26007" target="_blank">CVE-2024-26007</a><br><a href="https://fortiguard.com/psirt/FG-IR-24-017" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiProxy<br> </td>
<td>A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiPAM versions 1.0.0 through 1.0.3, FortiOS versions 7.2.0, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.16 allows attacker to execute unauthorized code or commands via specially crafted commands</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-36640&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-36640" target="_blank">CVE-2023-36640</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-137" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiProxy<br> </td>
<td>A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.5, 7.0.0 through 7.0.11, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6 FortiPAM versions 1.1.0, 1.0.0 through 1.0.3 FortiOS versions 7.4.0, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15 FortiSwitchManager versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.2 allows attacker to execute unauthorized code or commands via specially crafted cli commands and http requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45583&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45583" target="_blank">CVE-2023-45583</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-137" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiProxy<br> </td>
<td>An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 &amp; FortiProxy SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.13 allows an authenticated VPN user to send (but not receive) packets spoofing the IP of another user via crafted network packets.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45586&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45586" target="_blank">CVE-2023-45586</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-225" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>GE HealthCare--EchoPAC Software Only<br> </td>
<td>Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27108&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27108" target="_blank">CVE-2024-27108</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--EchoPAC Software Only<br> </td>
<td>Vulnerable data in transit in GE HealthCare EchoPAC products</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27106&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27106" target="_blank">CVE-2024-27106</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--Venue<br> </td>
<td>Path traversal vulnerability in "deleteFiles" function of Common Service Desktop, a GE HealthCare ultrasound device component</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1629&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1629" target="_blank">CVE-2024-1629</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GZTimeWalker--GZCTF<br> </td>
<td>GZ::CTF is a capture the flag platform. Prior to 0.20.1, unprivileged user can perform cross-site scripting attacks on other users by constructing malicious team names. This problem has been fixed in `v0.20.1`.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34699&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34699" target="_blank">CVE-2024-34699</a><br><a href="https://github.com/GZTimeWalker/GZCTF/commit/31e775b65cddf82a567d68dcdc78c1739b746346" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/GZTimeWalker/GZCTF/security/advisories/GHSA-p6rq-5x3x-rmhh" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>German Mesky--GMAce<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in German Mesky GMAce allows Path Traversal.This issue affects GMAce: from n/a through 1.5.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23872&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23872" target="_blank">CVE-2023-23872</a><br><a href="https://patchstack.com/database/vulnerability/gmace/wordpress-gmace-plugin-1-5-2-arbitrary-file-download-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>GhozyLab, Inc.--Popup Builder<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GhozyLab, Inc. Popup Builder allows Stored XSS.This issue affects Popup Builder: from n/a through 1.1.29.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34567&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34567" target="_blank">CVE-2024-34567</a><br><a href="https://patchstack.com/database/vulnerability/easy-notify-lite/wordpress-easy-notify-lite-plugin-1-1-29-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. A problem with the processing logic for Discord Integrations Chat Messages can lead to a regular expression DoS attack on the server.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6682&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6682" target="_blank">CVE-2023-6682</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/434821" target="_blank">cve@gitlab.com</a><br><a href="https://hackerone.com/reports/2269012" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6688&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6688" target="_blank">CVE-2023-6688</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/434854" target="_blank">cve@gitlab.com</a><br><a href="https://hackerone.com/reports/2270362" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. The pins endpoint is susceptible to DoS through a crafted request.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2454&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2454" target="_blank">CVE-2024-2454</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/450405" target="_blank">cve@gitlab.com</a><br><a href="https://hackerone.com/reports/2408226" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. It was possible for an attacker to cause a denial of service using maliciously crafted markdown content.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2651&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2651" target="_blank">CVE-2024-2651</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/450830" target="_blank">cve@gitlab.com</a><br><a href="https://hackerone.com/reports/2408619" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4597&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4597" target="_blank">CVE-2024-4597</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/438686" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 where abusing the API to filter branch and tags could lead to Denial of Service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4539&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4539" target="_blank">CVE-2024-4539</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/454815" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>Google--Gvisor<br> </td>
<td>A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox. We recommend upgrading past commit 6a112c60a257dadac59962e0bc9e9b5aee70b5b6</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-7258&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-7258" target="_blank">CVE-2023-7258</a><br><a href="https://github.com/google/gvisor/commit/6a112c60a257dadac59962e0bc9e9b5aee70b5b6" target="_blank">cve-coordination@google.com</a></td>
</tr>
<tr>
<td>Guido--VS Contact Form<br> </td>
<td>Guessable CAPTCHA vulnerability in Guido VS Contact Form allows Functionality Bypass.This issue affects VS Contact Form: from n/a through 14.7.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30540&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30540" target="_blank">CVE-2024-30540</a><br><a href="https://patchstack.com/database/vulnerability/very-simple-contact-form/wordpress-vs-contact-form-plugin-14-7-sum-captcha-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Gutenify--Gutenify<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gutenify.This issue affects Gutenify: from n/a through 1.4.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35165&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35165" target="_blank">CVE-2024-35165</a><br><a href="https://patchstack.com/database/vulnerability/gutenify/wordpress-gutenify-plugin-1-4-0-sensitive-data-exposure-via-api-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>HCL Software--BigFix Platform<br> </td>
<td>An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23583&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23583" target="_blank">CVE-2024-23583</a><br><a href="https://support.hcltechsw.com/csm?id=kb_article&amp;sysparm_article=KB0113140" target="_blank">psirt@hcl.com</a></td>
</tr>
<tr>
<td>HCL Software--BigFix Platform<br> </td>
<td>Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23554&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23554" target="_blank">CVE-2024-23554</a><br><a href="https://support.hcltechsw.com/csm?id=kb_article&amp;sysparm_article=KB0113140" target="_blank">psirt@hcl.com</a></td>
</tr>
<tr>
<td>HCL Software--BigFix Platform<br> </td>
<td>SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23556&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23556" target="_blank">CVE-2024-23556</a><br><a href="https://support.hcltechsw.com/csm?id=kb_article&amp;sysparm_article=KB0113140" target="_blank">psirt@hcl.com</a></td>
</tr>
<tr>
<td>HCL Software--DRYiCE Lucy<br> </td>
<td>HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability. The mobile app is vulnerable to a CORS misconfiguration which could potentially allow unauthorized access to the application resources from any web domain and enable cache poisoning attacks.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37526&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37526" target="_blank">CVE-2023-37526</a><br><a href="https://support.hcltechsw.com/csm?id=kb_article&amp;sysparm_article=KB0113032" target="_blank">psirt@hcl.com</a></td>
</tr>
<tr>
<td>Harknell--AWSOM News Announcement<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Harknell AWSOM News Announcement allows Stored XSS.This issue affects AWSOM News Announcement: from n/a through 1.6.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34428&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34428" target="_blank">CVE-2024-34428</a><br><a href="https://patchstack.com/database/vulnerability/awsom-news-announcement/wordpress-awsom-news-announcement-plugin-1-6-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exists in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilites result in the ability to interrupt the normal operation of the affected Access Point.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31478&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31478" target="_blank">CVE-2024-31478</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Unauthenticated Denial of Service (DoS) vulnerabilities exist in the Central Communications service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31479&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31479" target="_blank">CVE-2024-31479</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31480&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31480" target="_blank">CVE-2024-31480</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31481&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31481" target="_blank">CVE-2024-31481</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected Access Point.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31482&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31482" target="_blank">CVE-2024-31482</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31483&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31483" target="_blank">CVE-2024-31483</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hidden Depth--Sticky banner<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidden Depth Sticky banner allows Stored XSS.This issue affects Sticky banner: from n/a through 1.2.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35170&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35170" target="_blank">CVE-2024-35170</a><br><a href="https://patchstack.com/database/vulnerability/sticky-banner/wordpress-sticky-banner-plugin-1-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Highfivery LLC--Zero Spam<br> </td>
<td>Client-Side Enforcement of Server-Side Security vulnerability in Highfivery LLC Zero Spam allows Removing Important Client Functionality.This issue affects Zero Spam: from n/a through 5.5.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32521&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32521" target="_blank">CVE-2024-32521</a><br><a href="https://patchstack.com/database/vulnerability/zero-spam/wordpress-zero-spam-for-wordpress-plugin-5-5-5-bypass-spam-protection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>The WindowManager module has a vulnerability in permission control. Impact: Successful exploitation of this vulnerability may affect confidentiality.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-52721&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52721" target="_blank">CVE-2023-52721</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32990&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32990" target="_blank">CVE-2024-32990</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Denial of service (DoS) vulnerability in the AMS module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32995&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32995" target="_blank">CVE-2024-32995</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32996&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32996" target="_blank">CVE-2024-32996</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32999&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32999" target="_blank">CVE-2024-32999</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4046&amp;vector=CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4046" target="_blank">CVE-2024-4046</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Out-of-bounds access vulnerability in the memory module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32993&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L" target="_blank" title="CVSS V3 Score">5.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32993" target="_blank">CVE-2024-32993</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>NULL pointer access vulnerability in the clock module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32998&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32998" target="_blank">CVE-2024-32998</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-52383&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52383" target="_blank">CVE-2023-52383</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-52384&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52384" target="_blank">CVE-2023-52384</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Race condition vulnerability in the soundtrigger module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-52720&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52720" target="_blank">CVE-2023-52720</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huseyin Berberoglu--WP Favorite Posts<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Huseyin Berberoglu WP Favorite Posts.This issue affects WP Favorite Posts: from n/a through 1.6.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34427&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34427" target="_blank">CVE-2024-34427</a><br><a href="https://patchstack.com/database/vulnerability/wp-favorite-posts/wordpress-wp-favorite-posts-plugin-1-6-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>IBM--App Connect Enterprise<br> </td>
<td>IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 285245.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28761&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28761" target="_blank">CVE-2024-28761</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/285245" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150847" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--App Connect Enterprise<br> </td>
<td>IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 dashboard is vulnerable to a denial of service due to improper restrictions of resource allocation. IBM X-Force ID: 285244.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28760&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28760" target="_blank">CVE-2024-28760</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/285244" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150845" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--QRadar SIEM<br> </td>
<td>IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive information across tenants. IBM X-Force ID: 284575.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27269&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27269" target="_blank">CVE-2024-27269</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/284575" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150684" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--SDK, Java Technology Edition<br> </td>
<td>The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters. IBM X-Force ID: 260578.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38264&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38264" target="_blank">CVE-2023-38264</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/260578" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150727" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--Security Guardium<br> </td>
<td>IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of service. IBM X-Force ID: 271690.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47717&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47717" target="_blank">CVE-2023-47717</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/271690" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7152469" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--Spectrum Fusion HCI<br> </td>
<td>IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43040&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43040" target="_blank">CVE-2023-43040</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/266807" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7151040" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--TXSeries for Multiplatforms<br> </td>
<td>IBM TXSeries for Multiplatforms 8.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 280191.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22344&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22344" target="_blank">CVE-2024-22344</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/280191" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150667" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--TXSeries for Multiplatforms<br> </td>
<td>IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. IBM X-Force ID: 280192.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22345&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22345" target="_blank">CVE-2024-22345</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/280192" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150667" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--TXSeries for Multiplatforms<br> </td>
<td>IBM TXSeries for Multiplatforms 8.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 280190.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22343&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22343" target="_blank">CVE-2024-22343</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/280190" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150667" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--UrbanCode Deploy<br> </td>
<td>IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4, and 8.0 through 8.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285654.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28781&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28781" target="_blank">CVE-2024-28781</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/285654" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150747" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>ITPison--OMICARD EDM<br> </td>
<td>ITPison OMICARD EDM fails to properly filter specific URL parameter, allowing unauthenticated remote attackers to modify the parameters and conduct Server-Side Request Forgery (SSRF) attacks. This vulnerability enables attackers to probe internal network information.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4894&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4894" target="_blank">CVE-2024-4894</a><br><a href="https://www.twcert.org.tw/en/cp-139-7803-c0f73-2.html" target="_blank">twcert@cert.org.tw</a><br><a href="https://www.twcert.org.tw/tw/cp-132-7802-18f3c-1.html" target="_blank">twcert@cert.org.tw</a></td>
</tr>
<tr>
<td>Imran Sayed--Headless CMS<br> </td>
<td>Missing Authorization vulnerability in Imran Sayed Headless CMS.This issue affects Headless CMS: from n/a through 2.0.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-34186&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-34186" target="_blank">CVE-2023-34186</a><br><a href="https://patchstack.com/database/vulnerability/headless-cms/wordpress-headless-cms-plugin-2-0-3-broken-authentication-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>JFrog--Artifactory<br> </td>
<td>A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim's user email.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2248&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2248" target="_blank">CVE-2024-2248</a><br><a href="https://jfrog.com/help/r/jfrog-release-information/jfrog-security-advisories" target="_blank">reefs@jfrog.com</a></td>
</tr>
<tr>
<td>JetBrains--TeamCity<br> </td>
<td>In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35301&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35301" target="_blank">CVE-2024-35301</a><br><a href="https://www.jetbrains.com/privacy-security/issues-fixed/" target="_blank">cve@jetbrains.com</a></td>
</tr>
<tr>
<td>JetBrains--TeamCity<br> </td>
<td>In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35302&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35302" target="_blank">CVE-2024-35302</a><br><a href="https://www.jetbrains.com/privacy-security/issues-fixed/" target="_blank">cve@jetbrains.com</a></td>
</tr>
<tr>
<td>JetBrains--YouTrack<br> </td>
<td>In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35299&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35299" target="_blank">CVE-2024-35299</a><br><a href="https://www.jetbrains.com/privacy-security/issues-fixed/" target="_blank">cve@jetbrains.com</a></td>
</tr>
<tr>
<td>Justin Silver--Remote Content Shortcode<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Justin Silver Remote Content Shortcode allows PHP Local File Inclusion.This issue affects Remote Content Shortcode: from n/a through 1.5.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45652&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45652" target="_blank">CVE-2023-45652</a><br><a href="https://patchstack.com/database/vulnerability/remote-content-shortcode/wordpress-remote-content-shortcode-plugin-1-5-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Justin Tadlock--Unique<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Unique allows Stored XSS.This issue affects Unique: from n/a through 0.3.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33952&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33952" target="_blank">CVE-2024-33952</a><br><a href="https://patchstack.com/database/vulnerability/unique/wordpress-unique-theme-0-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Kashipara College Management System 1.0. This affects an unknown part of the file view_each_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263919.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4799&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4799" target="_blank">CVE-2024-4799</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%202.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263919" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263919" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332544" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability has been found in Kashipara College Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file submit_student.php. The manipulation of the argument date_of_birth leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263920.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4800&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4800" target="_blank">CVE-2024-4800</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%203.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263920" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263920" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332545" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability was found in Kashipara College Management System 1.0 and classified as critical. This issue affects some unknown processing of the file submit_new_faculty.php. The manipulation of the argument address leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263921 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4801&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4801" target="_blank">CVE-2024-4801</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%204.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263921" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263921" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332552" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability was found in Kashipara College Management System 1.0. It has been classified as critical. Affected is an unknown function of the file submit_extracurricular_activity.php. The manipulation of the argument activity_datetime leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263922 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4802&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4802" target="_blank">CVE-2024-4802</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%205.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263922" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263922" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332553" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability was found in Kashipara College Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file submit_admin.php. The manipulation of the argument phone leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263923.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4803&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4803" target="_blank">CVE-2024-4803</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%206.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263923" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263923" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332554" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability was found in Kashipara College Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file edit_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263924.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4804&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4804" target="_blank">CVE-2024-4804</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%207.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263924" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263924" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332555" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability classified as critical has been found in Kashipara College Management System 1.0. This affects an unknown part of the file edit_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263925 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4805&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4805" target="_blank">CVE-2024-4805</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%208.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263925" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263925" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332556" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability classified as critical was found in Kashipara College Management System 1.0. This vulnerability affects unknown code of the file each_extracurricula_activities.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263926 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4806&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4806" target="_blank">CVE-2024-4806</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%209.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263926" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263926" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332557" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability, which was classified as critical, has been found in Kashipara College Management System 1.0. This issue affects some unknown processing of the file delete_user.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263927.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4807&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4807" target="_blank">CVE-2024-4807</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%2010.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263927" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263927" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332564" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Kashipara College Management System 1.0. Affected is an unknown function of the file delete_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263928.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4808&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4808" target="_blank">CVE-2024-4808</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%2011.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263928" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263928" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332565" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability classified as critical has been found in Kashipara College Management System 1.0. Affected is an unknown function of the file view_students_each_detail.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264438 is the identifier assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4905&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4905" target="_blank">CVE-2024-4905</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%201.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264438" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264438" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332543" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kiboko Labs--Arigato Autoresponder and Newsletter<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter.This issue affects Arigato Autoresponder and Newsletter: from n/a through 2.7.2.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34823&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34823" target="_blank">CVE-2024-34823</a><br><a href="https://patchstack.com/database/vulnerability/bft-autoresponder/wordpress-arigato-autoresponder-and-newsletter-plugin-2-7-2-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Kioware--Kioware<br> </td>
<td>KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as there are no mechanisms preventing a user from excessively guessing the number.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3461&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3461" target="_blank">CVE-2024-3461</a><br><a href="https://cert.pl/en/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://www.kioware.com/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Kubernetes--azure-file-csi-driver<br> </td>
<td>A security issue was discovered in azure-file-csi-driver where an actor with access to the driver logs could observe service account tokens. These tokens could then potentially be exchanged with external cloud providers to access secrets stored in cloud vault solutions. Tokens are only logged when TokenRequests is configured in the CSIDriver object and the driver is set to run at log level 2 or greater via the -v flag.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3744&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3744" target="_blank">CVE-2024-3744</a><br><a href="https://github.com/kubernetes/kubernetes/issues/124759" target="_blank">jordan@liggitt.net</a><br><a href="https://groups.google.com/g/kubernetes-security-announce/c/hcgZE2MQo1A/m/Y4C6q-CYAgAJ" target="_blank">jordan@liggitt.net</a></td>
</tr>
<tr>
<td>Linux--Linux kernel<br> </td>
<td>In register_device, the return value of ida_simple_get is unchecked, in witch ida_simple_get will use an invalid index value. To address this issue, index should be checked after ida_simple_get. When the index value is abnormal, a warning message should be printed, the port should be dropped, and the value should be recorded.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4810&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4810" target="_blank">CVE-2024-4810</a><br><a href="https://bugzilla.openanolis.cn/show_bug.cgi?id=9008" target="_blank">security@openanolis.org</a></td>
</tr>
<tr>
<td>LionScripts--IP Blocker Lite<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in LionScripts IP Blocker Lite allows Functionality Bypass.This issue affects IP Blocker Lite: from n/a through 11.1.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30479&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30479" target="_blank">CVE-2024-30479</a><br><a href="https://patchstack.com/database/vulnerability/ip-address-blocker/wordpress-lionscripts-ip-blocker-lite-plugin-11-1-1-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>LizardByte--Sunshine<br> </td>
<td>Sunshine is a self-hosted game stream host for Moonlight. Users who ran Sunshine versions 0.17.0 through 0.22.2 as a service on Windows may be impacted when terminating the service if an attacked placed a file named `C:\Program.exe`, `C:\Program.bat`, or `C:\Program.cmd` on the user's computer. This attack vector isn't exploitable unless the user has manually loosened ACLs on the system drive. If the user's system locale is not English, then the name of the executable will likely vary. Version 0.23.0 contains a patch for the issue. Some workarounds are available. One may identify and block potentially malicious software executed path interception by using application control tools, like Windows Defender Application Control, AppLocker, or Software Restriction Policies where appropriate. Alternatively, ensure that proper permissions and directory access control are set to deny users the ability to write files to the top-level directory `C:`. Require that all executables be placed in write-protected directories.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31226&amp;vector=CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31226" target="_blank">CVE-2024-31226</a><br><a href="https://github.com/LizardByte/Sunshine/commit/93e622342c4f3e9b34f5f265039b6775b8e33a7a" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/LizardByte/Sunshine/pull/2379" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/LizardByte/Sunshine/security/advisories/GHSA-r3rw-mx4q-7vfp" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Matt van Andel--Adventure Journal<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt van Andel Adventure Journal allows Stored XSS.This issue affects Adventure Journal: from n/a through 1.7.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33953&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33953" target="_blank">CVE-2024-33953</a><br><a href="https://patchstack.com/database/vulnerability/adventure-journal/wordpress-adventure-journal-theme-1-7-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Metagauss--EventPrime<br> </td>
<td>Missing Authorization vulnerability in Metagauss EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 2.8.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-33321&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-33321" target="_blank">CVE-2023-33321</a><br><a href="https://patchstack.com/database/vulnerability/eventprime-event-calendar-management/wordpress-eventprime-plugin-2-8-6-sensitive-data-exposure?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Metagauss--ProfileGrid<br> </td>
<td>Improper Restriction of Excessive Authentication Attempts vulnerability in Metagauss ProfileGrid allows Removing Important Client Functionality.This issue affects ProfileGrid : from n/a through 5.8.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32774&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32774" target="_blank">CVE-2024-32774</a><br><a href="https://patchstack.com/database/vulnerability/profilegrid-user-profiles-groups-and-communities/wordpress-profilegrid-plugin-5-8-2-group-members-limit-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Microchip--SAME70<br> </td>
<td>A voltage glitch during the startup of EEFC NVM controllers on Microchip SAM E70/S70/V70/V71 microcontrollers allows access to the memory bus via the debug interface even if the security bit is set.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4760&amp;vector=CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4760" target="_blank">CVE-2024-4760</a><br><a href="https://www.0x01team.com/hw_security/bypassing-microchip-atmel-sam-e70-s70-v70-v71-security/" target="_blank">dc3f6da9-85b5-4a73-84a2-2ec90b40fca5</a></td>
</tr>
<tr>
<td>Microsoft--.NET 7.0<br> </td>
<td>Visual Studio Denial of Service Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30046&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30046" target="_blank">CVE-2024-30046</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30046" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--.NET 8.0<br> </td>
<td>.NET and Visual Studio Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30045&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30045" target="_blank">CVE-2024-30045</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30045" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Azure Migrate<br> </td>
<td>Azure Migrate Cross-Site Scripting Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30053&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30053" target="_blank">CVE-2024-30053</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30053" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Microsoft Bing Search for iOS<br> </td>
<td>Microsoft Bing Search Spoofing Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30041&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30041" target="_blank">CVE-2024-30041</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30041" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Microsoft Edge (Chromium-based)<br> </td>
<td>Microsoft Edge (Chromium-based) Spoofing Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30055&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30055" target="_blank">CVE-2024-30055</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30055" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Microsoft Intune Mobile Application Management<br> </td>
<td>Microsoft Intune for Android Mobile Application Management Tampering Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30059&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30059" target="_blank">CVE-2024-30059</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30059" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Microsoft SharePoint Enterprise Server 2016<br> </td>
<td>Microsoft SharePoint Server Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30043&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30043" target="_blank">CVE-2024-30043</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30043" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--PowerBI-client JS SDK<br> </td>
<td>Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30054&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30054" target="_blank">CVE-2024-30054</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30054" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29997&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29997" target="_blank">CVE-2024-29997</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29997" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29998&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29998" target="_blank">CVE-2024-29998</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29998" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29999&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29999" target="_blank">CVE-2024-29999</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29999" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30000&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30000" target="_blank">CVE-2024-30000</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30000" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30001&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30001" target="_blank">CVE-2024-30001</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30001" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30002&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30002" target="_blank">CVE-2024-30002</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30002" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30003&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30003" target="_blank">CVE-2024-30003</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30003" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30004&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30004" target="_blank">CVE-2024-30004</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30004" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30005&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30005" target="_blank">CVE-2024-30005</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30005" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30012&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30012" target="_blank">CVE-2024-30012</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30012" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30021&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30021" target="_blank">CVE-2024-30021</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30021" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows DWM Core Library Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30008&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30008" target="_blank">CVE-2024-30008</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30008" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Cryptographic Services Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30016&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30016" target="_blank">CVE-2024-30016</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30016" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30034&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30034" target="_blank">CVE-2024-30034</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30034" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Remote Access Connection Manager Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30039&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30039" target="_blank">CVE-2024-30039</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30039" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mark of the Web Security Feature Bypass Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30050&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30050" target="_blank">CVE-2024-30050</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30050" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2019<br> </td>
<td>Windows Hyper-V Denial of Service Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30011&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30011" target="_blank">CVE-2024-30011</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30011" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2019<br> </td>
<td>DHCP Server Service Denial of Service Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30019&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30019" target="_blank">CVE-2024-30019</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30019" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2019<br> </td>
<td>Windows Deployment Services Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30036&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30036" target="_blank">CVE-2024-30036</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30036" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>MongoDB Inc--MongoDB Server<br> </td>
<td>An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object that exceeds certain memory sizes. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.16 and MongoDB Server v6.0 versions prior to and including 6.0.5.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3374&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3374" target="_blank">CVE-2024-3374</a><br><a href="https://jira.mongodb.org/browse/SERVER-75601" target="_blank">cna@mongodb.com</a></td>
</tr>
<tr>
<td>N/A--N/A<br> </td>
<td>The 'WordPress RSS Aggregator' WordPress Plugin, versions &lt; 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the  'notice_id'  GET parameter.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4860&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4860" target="_blank">CVE-2024-4860</a><br><a href="https://www.tenable.com/security/research/tra-2024-16" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>Nathan Vonnahme--Configure Login Timeout<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nathan Vonnahme Configure Login Timeout allows Stored XSS.This issue affects Configure Login Timeout: from n/a through 1.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34419&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34419" target="_blank">CVE-2024-34419</a><br><a href="https://patchstack.com/database/vulnerability/configure-login-timeout/wordpress-configure-login-timeout-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Ninja Team--Filebird<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team Filebird.This issue affects Filebird: from n/a through 5.6.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35166&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35166" target="_blank">CVE-2024-35166</a><br><a href="https://patchstack.com/database/vulnerability/filebird/wordpress-filebird-wordpress-media-library-folders-file-manager-plugin-5-6-3-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>OCDI--One Click Demo Import<br> </td>
<td>Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: from n/a through 3.2.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34433&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34433" target="_blank">CVE-2024-34433</a><br><a href="https://patchstack.com/database/vulnerability/one-click-demo-import/wordpress-one-click-demo-import-plugin-3-2-0-php-object-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>OceanicJS--Oceanic<br> </td>
<td>Oceanic is a NodeJS library for interfacing with Discord. Prior to version 1.10.4, input to functions such as `Client.rest.channels.removeBan` is not url-encoded, resulting in specially crafted input such as `../../../channels/{id}` being normalized into the url `/api/v10/channels/{id}`, and deleting a channel rather than removing a ban. Version 1.10.4 fixes this issue. Some workarounds are available. One may sanitize user input, ensuring strings are valid for the purpose they are being used for. One may also encode input with `encodeURIComponent` before providing it to the library.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34712&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34712" target="_blank">CVE-2024-34712</a><br><a href="https://github.com/OceanicJS/Oceanic/commit/8bf8ee8373b8c565fbdbf70a609aba4fbc1a1ffe" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/OceanicJS/Oceanic/security/advisories/GHSA-5h5v-hw44-f6gg" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Path Traversal found in OpenTextâ„¢ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3484&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3484" target="_blank">CVE-2024-3484</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Server Side Request Forgery vulnerability has been discovered in OpenTextâ„¢ iManager 3.2.6.0200. This could lead to senstive information disclosure.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3485&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3485" target="_blank">CVE-2024-3485</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>File Upload vulnerability in unauthenticated session found in OpenTextâ„¢ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3488&amp;vector=CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3488" target="_blank">CVE-2024-3488</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Server Side Request Forgery vulnerability has been discovered in OpenTextâ„¢ iManager 3.2.6.0200. This could lead to senstive information disclosure by directory traversal.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3970&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3970" target="_blank">CVE-2024-3970</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>Orchestrated--Corona Virus (COVID-19) Banner &amp; Live Data<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Orchestrated Corona Virus (COVID-19) Banner &amp; Live Data allows Stored XSS.This issue affects Corona Virus (COVID-19) Banner &amp; Live Data: from n/a through 1.8.0.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34429&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34429" target="_blank">CVE-2024-34429</a><br><a href="https://patchstack.com/database/vulnerability/corona-virus-covid-19-banner/wordpress-simple-website-banner-plugin-1-8-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PHOENIX CONTACT--CHARX SEC-3000<br> </td>
<td>A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28135&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28135" target="_blank">CVE-2024-28135</a><br><a href="https://cert.vde.com/en/advisories/VDE-2024-019" target="_blank">info@cert.vde.com</a></td>
</tr>
<tr>
<td>PHPGurukul--Online Course Registration System<br> </td>
<td>A vulnerability classified as critical was found in PHPGurukul Online Course Registration System 3.1. Affected by this vulnerability is an unknown functionality of the file /pincode-verification.php. The manipulation of the argument pincode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264925 was assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5066&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5066" target="_blank">CVE-2024-5066</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Online%20Course%20Registration%20System/Online%20Course%20Registration%20System%20-%20SQL%20Injection%20-%204.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264925" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264925" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336240" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>PaperCut--PaperCut NG, PaperCut MF<br> </td>
<td>An arbitrary file deletion vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This vulnerability requires local login/console access to the PaperCut NG/MF server (eg: member of a domain admin group).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3037&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3037" target="_blank">CVE-2024-3037</a><br><a href="https://www.papercut.com/kb/Main/security-bulletin-may-2024/" target="_blank">eb41dac7-0af8-4f84-9f6d-0272772514f4</a></td>
</tr>
<tr>
<td>PaperCut--PaperCut NG, PaperCut MF<br> </td>
<td>An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This vulnerability requires local login/console access to the PaperCut NG/MF server (eg: member of a domain admin group).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4712&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4712" target="_blank">CVE-2024-4712</a><br><a href="https://www.papercut.com/kb/Main/security-bulletin-may-2024/" target="_blank">eb41dac7-0af8-4f84-9f6d-0272772514f4</a></td>
</tr>
<tr>
<td>Phil Baylog--QuickieBar<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Baylog QuickieBar allows Stored XSS.This issue affects QuickieBar: from n/a through 1.8.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34425&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34425" target="_blank">CVE-2024-34425</a><br><a href="https://patchstack.com/database/vulnerability/quickiebar/wordpress-quickiebar-plugin-1-8-4-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PluginEver--Serial Numbers for WooCommerce License Manager<br> </td>
<td>Missing Authorization vulnerability in PluginEver Serial Numbers for WooCommerce - License Manager.This issue affects Serial Numbers for WooCommerce - License Manager: from n/a through 1.7.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35173&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35173" target="_blank">CVE-2024-35173</a><br><a href="https://patchstack.com/database/vulnerability/wc-serial-numbers/wordpress-wc-serial-numbers-plugin-1-7-2-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PrestaShop--PrestaShop<br> </td>
<td>PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by supplying a random secure_key parameter in the url. This issue is patched in version 8.1.6. No known workarounds are available.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34717&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34717" target="_blank">CVE-2024-34717</a><br><a href="https://github.com/PrestaShop/PrestaShop/releases/tag/8.1.6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-7pjr-2rgh-fc5g" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Progress Software Corporation--WhatsUp Gold<br> </td>
<td>In WhatsUp Gold versions released before 2023.1.2 , an SSRF vulnerability exists in Whatsup Gold's Issue exists in the HTTP Monitoring functionality.  Due to the lack of proper authorization, any authenticated user can access the HTTP monitoring functionality, what leads to the Server Side Request Forgery.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4562&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4562" target="_blank">CVE-2024-4562</a><br><a href="https://community.progress.com/s/article/Announcing-WhatsUp-Gold-v2023-1-2" target="_blank">security@progress.com</a><br><a href="https://www.progress.com/network-monitoring" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Progress Software Corporation--WhatsUp Gold<br> </td>
<td>In WhatsUp Gold versions released before 2023.1.2 , a blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker to send arbitrary HTTP requests on behalf of the vulnerable server.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4561&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4561" target="_blank">CVE-2024-4561</a><br><a href="https://community.progress.com/s/article/Announcing-WhatsUp-Gold-v2023-1-2" target="_blank">security@progress.com</a><br><a href="https://www.progress.com/network-monitoring" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Progress Software--Telerik Report Server<br> </td>
<td>An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4357&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4357" target="_blank">CVE-2024-4357</a><br><a href="https://docs.telerik.com/report-server/knowledge-base/xxe-vulnerability-cve-2024-4357" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Progress Software--Telerik Report Server<br> </td>
<td>In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via a trust boundary violation vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4837&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4837" target="_blank">CVE-2024-4837</a><br><a href="https://docs.telerik.com/report-server/knowledge-base/information-exposure-cve-2024-4837" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Proofpoint--Enterprise Protection<br> </td>
<td>The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains a Server-Side Request Forgery vulnerability that allows an authenticated user to relay HTTP requests from the Protection server to otherwise private network addresses.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0862&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0862" target="_blank">CVE-2024-0862</a><br><a href="https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2024-0001" target="_blank">security@proofpoint.com</a></td>
</tr>
<tr>
<td>QODE Interactive--Qi Addons For Elementor<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QODE Interactive Qi Addons For Elementor allows PHP Local File Inclusion.This issue affects Qi Addons For Elementor: from n/a through 1.6.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47679&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47679" target="_blank">CVE-2023-47679</a><br><a href="https://patchstack.com/database/vulnerability/qi-addons-for-elementor/wordpress-qi-addons-for-elementor-plugin-1-6-3-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>RadiusTheme--ShopBuilder Elementor WooCommerce Builder Addons<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in RadiusTheme ShopBuilder - Elementor WooCommerce Builder Addons.This issue affects ShopBuilder - Elementor WooCommerce Builder Addons: from n/a through 2.1.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34812&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34812" target="_blank">CVE-2024-34812</a><br><a href="https://patchstack.com/database/vulnerability/shopbuilder/wordpress-shopbuilder-plugin-2-1-8-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>RafflePress--Giveaways and Contests<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in RafflePress Giveaways and Contests allows Functionality Bypass.This issue affects Giveaways and Contests: from n/a through 1.12.7.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32827&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32827" target="_blank">CVE-2024-32827</a><br><a href="https://patchstack.com/database/vulnerability/rafflepress/wordpress-giveaways-and-contests-by-rafflepress-plugin-1-12-7-ip-restriction-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Rashed Latif--TT Custom Post Type Creator<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rashed Latif TT Custom Post Type Creator allows Stored XSS.This issue affects TT Custom Post Type Creator: from n/a through 1.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34430&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34430" target="_blank">CVE-2024-34430</a><br><a href="https://patchstack.com/database/vulnerability/tt-custom-post-type-creator/wordpress-tt-custom-post-type-creator-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Red Hat--Red Hat Advanced Cluster Management for Kubernetes 2<br> </td>
<td>A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5042&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N" target="_blank" title="CVSS V3 Score">6.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5042" target="_blank">CVE-2024-5042</a><br><a href="https://access.redhat.com/security/cve/CVE-2024-5042" target="_blank">secalert@redhat.com</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2280921" target="_blank">secalert@redhat.com</a><br><a href="https://github.com/advisories/GHSA-2rhx-qhxp-5jpw" target="_blank">secalert@redhat.com</a></td>
</tr>
<tr>
<td>Red Hat--Red Hat Enterprise Linux 6<br> </td>
<td>A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci.c). An improper release and use of the irqfd for vector 0 during the boot process leads to a guest triggerable crash via vhost_net_stop(). This flaw allows a malicious guest to crash the QEMU process on the host.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4693&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4693" target="_blank">CVE-2024-4693</a><br><a href="https://access.redhat.com/security/cve/CVE-2024-4693" target="_blank">secalert@redhat.com</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2279965" target="_blank">secalert@redhat.com</a></td>
</tr>
<tr>
<td>Red Hat--Red Hat OpenStack Platform 16.2<br> </td>
<td>An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored in log files, which can expose sensitive information to anyone with access to the logs.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4840&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4840" target="_blank">CVE-2024-4840</a><br><a href="https://access.redhat.com/security/cve/CVE-2024-4840" target="_blank">secalert@redhat.com</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2280249" target="_blank">secalert@redhat.com</a></td>
</tr>
<tr>
<td>Red Hat--Red Hat Satellite 6<br> </td>
<td>A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being checked. When the key changes, the Satellite still connects it because it uses "-o StrictHostKeyChecking=no". This flaw can lead to a man-in-the-middle attack (MITM), denial of service, leaking of secrets the remote execution job contains, or other issues that may arise from the attacker's ability to forge an SSH key. This issue does not directly allow unauthorized remote execution on the Satellite, although it can leak secrets that may lead to it.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4871&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4871" target="_blank">CVE-2024-4871</a><br><a href="https://access.redhat.com/security/cve/CVE-2024-4871" target="_blank">secalert@redhat.com</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2278627" target="_blank">secalert@redhat.com</a></td>
</tr>
<tr>
<td>Revmakx--WPCal.io Easy Meeting Scheduler<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io - Easy Meeting Scheduler.This issue affects WPCal.Io - Easy Meeting Scheduler: from n/a through 0.9.5.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34816&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34816" target="_blank">CVE-2024-34816</a><br><a href="https://patchstack.com/database/vulnerability/wpcal/wordpress-wpcal-io-plugin-0-9-5-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Ruijie--RG-UAC<br> </td>
<td>A vulnerability classified as critical has been found in Ruijie RG-UAC up to 20240506. Affected is an unknown function of the file /view/networkConfig/physicalInterface/interface_commit.php. The manipulation of the argument name leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-263934 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4813&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4813" target="_blank">CVE-2024-4813</a><br><a href="https://github.com/h0e4a0r1t/I_L-HxK-pF-uZ1-/blob/main/Ruijie%20RG-UAC%20Unified%20Internet%20Behavior%20Management%20Audit%20System%20Backend%20RCE%20Vulnerability-physicalInterface%3Ainterface_commit.php.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263934" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263934" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.330020" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Ruijie--RG-UAC<br> </td>
<td>A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240506. Affected by this vulnerability is an unknown functionality of the file /view/networkConfig/RouteConfig/StaticRoute/static_route_edit_commit.php. The manipulation of the argument oldipmask/oldgateway leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263935. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4814&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4814" target="_blank">CVE-2024-4814</a><br><a href="https://github.com/h0e4a0r1t/I_L-HxK-pF-uZ1-/blob/main/Ruijie%20RG-UAC%20Unified%20Internet%20Behavior%20Management%20Audit%20System%20Backend%20RCE%20Vulnerability-StaticRoute%3Astatic_route_edit_commit.php.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263935" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263935" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.330052" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Ruijie--RG-UAC<br> </td>
<td>A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240506. Affected by this issue is some unknown functionality of the file /view/bugSolve/viewData/detail.php. The manipulation of the argument filename leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263936. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4815&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4815" target="_blank">CVE-2024-4815</a><br><a href="https://github.com/h0e4a0r1t/I_L-HxK-pF-uZ1-/blob/main/Ruijie%20RG-UAC%20Unified%20Internet%20Behavior%20Management%20Audit%20System%20Backend%20RCE%20Vulnerability-view_bugSolve_viewData_detail.php.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263936" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263936" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.329966" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Ruijie--RG-UAC<br> </td>
<td>A vulnerability, which was classified as critical, was found in Ruijie RG-UAC up to 20240506. This affects an unknown part of the file /view/networkConfig/GRE/gre_add_commit.php. The manipulation of the argument name/remote/local/IP leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263937 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4816&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4816" target="_blank">CVE-2024-4816</a><br><a href="https://github.com/h0e4a0r1t/I_L-HxK-pF-uZ1-/blob/main/Ruijie%20RG-UAC%20Unified%20Internet%20Behavior%20Management%20Audit%20System%20Backend%20RCE%20Vulnerability-gre_add_commit.php.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263937" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263937" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.329953" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP BusinessObjects Business Intelligence Platform (Webservices)<br> </td>
<td>SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, the attacker can see the sensitive information through cache and can open the pages causing limited impact on Confidentiality, Integrity and Availability of the application.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33004&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33004" target="_blank">CVE-2024-33004</a><br><a href="https://me.sap.com/notes/3449093" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP Enable Now<br> </td>
<td>SAP Enable Now Manager does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker with the role 'Learner' could gain access to other user's data in manager which will lead to a high impact to the confidentiality of the application.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32730&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32730" target="_blank">CVE-2024-32730</a><br><a href="https://me.sap.com/notes/3441944" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP Global Label Management (GLM)<br> </td>
<td>SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted inputs to modify database commands resulting in the retrieval of additional information persisted by the system. This could lead to low impact on Confidentiality and Integrity of the application.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33009&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33009" target="_blank">CVE-2024-33009</a><br><a href="https://me.sap.com/notes/1938764" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP My Travel Requests <br> </td>
<td>SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker can upload a malicious attachment to a business trip request which will lead to a low impact on the confidentiality, integrity and availability of the application. </td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32731&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32731" target="_blank">CVE-2024-32731</a><br><a href="https://me.sap.com/notes/3447467" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP NetWeaver Application Server ABAP and ABAP Platform <br> </td>
<td>Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject malicious JavaScript code into the dynamically crafted web page. On successful exploitation the attacker can access or modify sensitive information with no impact on availability of the application</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32733&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32733" target="_blank">CVE-2024-32733</a><br><a href="https://me.sap.com/notes/3450286" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP NetWeaver Application server for ABAP and ABAP Platform<br> </td>
<td>SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker can control code that is executed within a user's browser, which could result in modification, deletion of data, including accessing or deleting files, or stealing session cookies which an attacker could use to hijack a user's session. Hence, this could have impact on Confidentiality, Integrity and Availability of the system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34687&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34687" target="_blank">CVE-2024-34687</a><br><a href="https://me.sap.com/notes/3448445" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP Replication Server <br> </td>
<td>SAP Replication Server allows an attacker to use gateway for executing some commands to RSSD. This could result in crashing the Replication Server due to memory corruption with high impact on Availability of the system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33008&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33008" target="_blank">CVE-2024-33008</a><br><a href="https://me.sap.com/notes/3349468" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP S/4 HANA (Manage Bank Statement Reprocessing Rules)<br> </td>
<td>Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can enable/disable the sharing rule of other users affecting the integrity of the application. Confidentiality and Availability are not affected.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4138&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4138" target="_blank">CVE-2024-4138</a><br><a href="https://me.sap.com/notes/3434666" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP S/4 HANA (Manage Bank Statement Reprocessing Rules)<br> </td>
<td>Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can delete rules of other users affecting the integrity of the application. Confidentiality and Availability are not affected.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4139&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4139" target="_blank">CVE-2024-4139</a><br><a href="https://me.sap.com/notes/3434666" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP S/4HANA (Document Service Handler for DPS)<br> </td>
<td>Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality and Integrity of the application.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33002&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33002" target="_blank">CVE-2024-33002</a><br><a href="https://me.sap.com/notes/3460772" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SKT Themes--SKT Addons for Elementor<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SKT Themes SKT Addons for Elementor allows Stored XSS.This issue affects SKT Addons for Elementor: from n/a through 1.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34436&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34436" target="_blank">CVE-2024-34436</a><br><a href="https://patchstack.com/database/vulnerability/skt-addons-for-elementor/wordpress-skt-addons-for-elementor-plugin-1-8-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SKT Themes--SKT Addons for Elementor<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SKT Themes SKT Addons for Elementor allows Stored XSS.This issue affects SKT Addons for Elementor: from n/a through 1.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34445&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34445" target="_blank">CVE-2024-34445</a><br><a href="https://patchstack.com/database/vulnerability/skt-addons-for-elementor/wordpress-skt-addons-for-elementor-plugin-1-8-cross-site-scripting-xss-vulnerability-2?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SailPoint--Identity Security Cloud<br> </td>
<td>An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3317&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3317" target="_blank">CVE-2024-3317</a><br><a href="https://www.sailpoint.com/security-advisories/" target="_blank">psirt@sailpoint.com</a></td>
</tr>
<tr>
<td>SailPoint--Identity Security Cloud<br> </td>
<td>A file path traversal vulnerability was identified in the DelimitedFileConnector Cloud Connector that allowed an authenticated administrator to set arbitrary connector attributes, including the "file" attribute, which in turn allowed the user to access files uploaded for other sources.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3318&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3318" target="_blank">CVE-2024-3318</a><br><a href="https://www.sailpoint.com/security-advisories/" target="_blank">psirt@sailpoint.com</a></td>
</tr>
<tr>
<td>SakuraIsayeki--WOWS-Karma<br> </td>
<td>WOWS Karma is a reputation system for Wargaming's World of Warships. A user is able to click multiple times on "create" on a post creation prompt before the modal closes, which triggers sending several post creation API requests at once. Due to timing, sending multiple posts simultaneously requests bypasses the cooldown validation, however are not refreshing a user's metrics more than once, due to concurrent karma updates. This issue is fixed in 0.17.4.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34695&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34695" target="_blank">CVE-2024-34695</a><br><a href="https://github.com/SakuraIsayeki/WOWS-Karma/commit/3210b516fa3551e30fe760c915f7656d9046e69a" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/SakuraIsayeki/WOWS-Karma/commit/6cb825976f28c68d79172aeda00e955bf5853de2" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/SakuraIsayeki/WOWS-Karma/security/advisories/GHSA-v6cc-v976-mj8g" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Salon Booking System--Salon booking system<br> </td>
<td>Improper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.This issue affects Salon booking system: from n/a through 8.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-48319&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-48319" target="_blank">CVE-2023-48319</a><br><a href="https://patchstack.com/database/vulnerability/salon-booking-system/wordpress-salon-booking-system-plugin-8-7-editor-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Samsung Open Source--Escargot<br> </td>
<td>Improper Input Validation vulnerability in Samsung Open Source escargot JavaScript engine allows Overflow Buffers. However, it occurs in the test code and does not include in the release. This issue affects escargot: 4.0.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32669&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32669" target="_blank">CVE-2024-32669</a><br><a href="https://github.com/Samsung/escargot/pull/1326" target="_blank">PSIRT@samsung.com</a></td>
</tr>
<tr>
<td>Samsung Open Source--Escargot<br> </td>
<td>A Segmentation Fault issue discovered in Samsung Open Source Escargot JavaScript engine allows remote attackers to cause a denial of service via crafted input. This issue affects Escargot: 4.0.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32672&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32672" target="_blank">CVE-2024-32672</a><br><a href="https://github.com/Samsung/escargot/pull/1322" target="_blank">PSIRT@samsung.com</a></td>
</tr>
<tr>
<td>Samuel Marshall--JCH Optimize<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samuel Marshall JCH Optimize.This issue affects JCH Optimize: from n/a through 4.2.0.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34808&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34808" target="_blank">CVE-2024-34808</a><br><a href="https://patchstack.com/database/vulnerability/jch-optimize/wordpress-jch-optimize-plugin-4-2-0-path-traversal-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ShortPixel--ShortPixel Adaptive Images<br> </td>
<td>Server-Side Request Forgery (SSRF) vulnerability in ShortPixel ShortPixel Adaptive Images.This issue affects ShortPixel Adaptive Images: from n/a through 3.8.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35172&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35172" target="_blank">CVE-2024-35172</a><br><a href="https://patchstack.com/database/vulnerability/shortpixel-adaptive-images/wordpress-shortpixel-adaptive-images-plugin-3-8-3-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ShortPixel--ShortPixel Adaptive Images<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in ShortPixel ShortPixel Adaptive Images.This issue affects ShortPixel Adaptive Images: from n/a through 3.8.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4689&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4689" target="_blank">CVE-2024-4689</a><br><a href="https://patchstack.com/database/vulnerability/shortpixel-adaptive-images/wordpress-shortpixel-adaptive-images-plugin-3-8-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SiAdmin--SiAdmin<br> </td>
<td>Vulnerability in SiAdmin 1.1 that allows XSS via the /show.php query parameter. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and thereby steal their cookie session credentials.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4993&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4993" target="_blank">CVE-2024-4993</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-siadmin" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Siemens--OPUPI0 AMQP/MQTT<br> </td>
<td>A vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions &lt; V5.30). The affected devices stores MQTT client passwords without sufficient protection on the devices. An attacker with remote shell access or physical access could retrieve the credentials leading to confidentiality loss.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31486&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31486" target="_blank">CVE-2024-31486</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-871704.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Polarion ALM<br> </td>
<td>A vulnerability has been identified in Polarion ALM (All versions &lt; V2404.0). The Apache Lucene based query engine in the affected application lacks proper access controls. This could allow an authenticated user to query items beyond the user's allowed projects.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33647&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33647" target="_blank">CVE-2024-33647</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-925850.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). Downloading files overwrites files with the same name in the installation directory of the affected systems. The filename for the target file can be specified, thus arbitrary files can be overwritten by an attacker with the required privileges.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27946&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27946" target="_blank">CVE-2024-27946</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems could allow log messages to be forwarded to a specific client under certain circumstances. An attacker could leverage this vulnerability to forward log messages to a specific compromised client.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27947&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27947" target="_blank">CVE-2024-27947</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--S7-PCT<br> </td>
<td>A vulnerability has been identified in S7-PCT (All versions), Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions), SIMATIC BATCH V9.1 (All versions), SIMATIC NET PC Software (All versions), SIMATIC PCS 7 V9.1 (All versions), SIMATIC PDM V9.2 (All versions), SIMATIC Route Control V9.1 (All versions), SIMATIC STEP 7 V5 (All versions), SIMATIC WinCC OA V3.17 (All versions), SIMATIC WinCC OA V3.18 (All versions &lt; V3.18 P025), SIMATIC WinCC OA V3.19 (All versions &lt; V3.19 P010), SIMATIC WinCC Runtime Advanced (All versions), SIMATIC WinCC Runtime Professional V16 (All versions), SIMATIC WinCC Runtime Professional V17 (All versions), SIMATIC WinCC Runtime Professional V18 (All versions), SIMATIC WinCC Runtime Professional V19 (All versions), SIMATIC WinCC Unified PC Runtime (All versions), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions), SIMATIC WinCC V8.0 (All versions), SINAMICS Startdrive (All versions &lt; V19 SP1), SINUMERIK ONE virtual (All versions &lt; V6.23), SINUMERIK PLC Programming Tool (All versions), TIA Portal Cloud Connector (All versions &lt; V2.0), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions &lt; V19 Update 2). The affected applications contain an out of bounds read vulnerability. This could allow an attacker to cause a Blue Screen of Death (BSOD) crash of the underlying Windows kernel.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46280&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46280" target="_blank">CVE-2023-46280</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-962515.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). The "DBTest" tool of SIMATIC RTLS Locating Manager does not properly enforce access restriction. This could allow an authenticated local attacker to extract sensitive information from memory.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30208&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30208" target="_blank">CVE-2024-30208</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected components do not properly authenticate heartbeat messages. This could allow an unauthenticated remote attacker to affected the availability of secondary RTLS systems configured using a TeeRevProxy service and potentially cause loss of data generated during the time the attack is ongoing.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33494&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33494" target="_blank">CVE-2024-33494</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). The affected application does not properly limit the size of specific logs. This could allow an unauthenticated remote attacker to exhaust system resources by creating a great number of log entries which could potentially lead to a denial of service condition. A successful exploitation requires the attacker to have access to specific SIMATIC RTLS Locating Manager Clients in the deployment.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33495&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33495" target="_blank">CVE-2024-33495</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected SIMATIC RTLS Locating Manager Report Clients do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to escalate their access rights from the Manager to the Systemadministrator role.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33496&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33496" target="_blank">CVE-2024-33496</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected SIMATIC RTLS Locating Manager Track Viewer Client do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to escalate their access rights from the Manager to the Systemadministrator role.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33497&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33497" target="_blank">CVE-2024-33497</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected applications do not properly release memory that is allocated when handling specifically crafted incoming packets. This could allow an unauthenticated remote attacker to cause a denial of service condition by crashing the service when it runs out of memory. The service is restarted automatically after a short time.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33498&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33498" target="_blank">CVE-2024-33498</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>SourceCodester--Best Courier Management System<br> </td>
<td>A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file view_parcel.php. The manipulation of the argument id leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264480.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4945&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4945" target="_blank">CVE-2024-4945</a><br><a href="https://github.com/CveSecLook/cve/issues/28" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264480" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264480" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333960" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Employee and Visitor Gate Pass Logging System<br> </td>
<td>A vulnerability classified as critical has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is an unknown function of the file /employee_gatepass/classes/Users.php?f=ssave. The manipulation of the argument img leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264456.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4921&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4921" target="_blank">CVE-2024-4921</a><br><a href="https://github.com/I-Schnee-I/cev/blob/main/upload.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264456" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264456" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333662" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Gas Agency Management System<br> </td>
<td>A vulnerability has been found in SourceCodester Gas Agency Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file edituser.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264748.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5051&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5051" target="_blank">CVE-2024-5051</a><br><a href="https://github.com/HuoMingZ/aoligei/blob/main/Gas.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264748" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264748" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336010" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Interactive Map with Marker<br> </td>
<td>A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete-mark.php. The manipulation of the argument mark leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264535.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4967&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4967" target="_blank">CVE-2024-4967</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Interactive%20Map%20App/Interactive%20Map%20App%20-%20SQL%20Injection.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264535" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264535" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335190" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Art Gallery Management System<br> </td>
<td>A vulnerability was found in SourceCodester Online Art Gallery Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file admin/adminHome.php. The manipulation of the argument sliderpic leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264481 was assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4946&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4946" target="_blank">CVE-2024-4946</a><br><a href="https://github.com/CveSecLook/cve/issues/29" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264481" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264481" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.334215" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Birth Certificate Management System<br> </td>
<td>A vulnerability was found in SourceCodester Online Birth Certificate Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin. The manipulation leads to files or directories accessible. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264742 is the identifier assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5045&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5045" target="_blank">CVE-2024-5045</a><br><a href="https://github.com/HuoMingZ/aoligei/blob/main/yuzu.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264742" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264742" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335384" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Computer and Laptop Store<br> </td>
<td>A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown functionality of the file /admin/maintenance/manage_brand.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263918 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4798&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4798" target="_blank">CVE-2024-4798</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/sql5.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263918" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263918" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332784" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Computer and Laptop Store<br> </td>
<td>A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /classes/SystemSettings.php?f=update_settings. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263941 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4820&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4820" target="_blank">CVE-2024-4820</a><br><a href="https://github.com/jxm68868/cve/blob/main/upload.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263941" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263941" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333272" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Open Source Clinic Management System<br> </td>
<td>A vulnerability has been found in SourceCodester Open Source Clinic Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file setting.php. The manipulation of the argument logo leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263929 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4809&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4809" target="_blank">CVE-2024-4809</a><br><a href="https://github.com/CveSecLook/cve/issues/26" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263929" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263929" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332581" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--School Intramurals Student Attendance Management System<br> </td>
<td>A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /intrams_sams/manage_course.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264461 was assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4925&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4925" target="_blank">CVE-2024-4925</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/sql6.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264461" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264461" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333875" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--School Intramurals Student Attendance Management System<br> </td>
<td>A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /intrams_sams/manage_student.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264462 is the identifier assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4926&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4926" target="_blank">CVE-2024-4926</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/sql7.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264462" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264462" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333879" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /simple-online-bidding-system/admin/ajax.php?action=save_product. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264463.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4927&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4927" target="_blank">CVE-2024-4927</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/upload2.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264463" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264463" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333891" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /simple-online-bidding-system/admin/ajax.php?action=delete_category. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264464.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4928&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4928" target="_blank">CVE-2024-4928</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/sql8.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264464" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264464" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333893" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability classified as critical was found in SourceCodester Simple Online Bidding System 1.0. This vulnerability affects unknown code of the file /simple-online-bidding-system/index.php?page=view_prod. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264466 is the identifier assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4930&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4930" target="_blank">CVE-2024-4930</a><br><a href="https://github.com/rockersiyuan/CVE/blob/main/SourceCodester%20Simple%20Online%20Bidding%20System%20Sql%20Inject-1.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264466" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264466" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335343" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability, which was classified as critical, has been found in SourceCodester Simple Online Bidding System 1.0. This issue affects some unknown processing of the file /simple-online-bidding-system/admin/index.php?page=view_udet. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264467.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4931&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4931" target="_blank">CVE-2024-4931</a><br><a href="https://github.com/rockersiyuan/CVE/blob/main/SourceCodester%20Simple%20Online%20Bidding%20System%20Sql%20Inject-2.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264467" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264467" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335365" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability, which was classified as critical, was found in SourceCodester Simple Online Bidding System 1.0. Affected is an unknown function of the file /simple-online-bidding-system/admin/index.php?page=manage_user. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264468.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4932&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4932" target="_blank">CVE-2024-4932</a><br><a href="https://github.com/rockersiyuan/CVE/blob/main/SourceCodester%20Simple%20Online%20Bidding%20System%20Sql%20Inject-3.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264468" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264468" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335366" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability has been found in SourceCodester Simple Online Bidding System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /simple-online-bidding-system/admin/index.php?page=manage_product. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264469 was assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4933&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4933" target="_blank">CVE-2024-4933</a><br><a href="https://github.com/rockersiyuan/CVE/blob/main/SourceCodester%20Simple%20Online%20Bidding%20System%20Sql%20Inject-4.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264469" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264469" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335367" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability classified as problematic has been found in SourceCodester Simple Online Bidding System 1.0. This affects an unknown part of the file /simple-online-bidding-system/admin/ajax.php?action=save_user. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264465 was assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4929&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4929" target="_blank">CVE-2024-4929</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/csrf.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264465" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264465" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333894" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Mens Salon Management System<br> </td>
<td>A vulnerability, which was classified as critical, has been found in SourceCodester Simple Online Mens Salon Management System 1.0. Affected by this issue is some unknown functionality of the file view_service.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264926 is the identifier assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5069&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5069" target="_blank">CVE-2024-5069</a><br><a href="https://github.com/menxin996/Cvehub/blob/main/Men&amp;apos;s%20Salon%20Management%20System%20%20view_service.php%20has%20Sqlinjection.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264926" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264926" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336842" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Sparkle WP--Editorialmag<br> </td>
<td>Missing Authorization vulnerability in Sparkle WP Editorialmag editorialmag.This issue affects Editorialmag: from n/a through 1.1.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-32129&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-32129" target="_blank">CVE-2023-32129</a><br><a href="https://patchstack.com/database/vulnerability/editorialmag/wordpress-editorialmag-theme-1-1-9-authenticated-arbitrary-plugin-activation?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Stefano Lissa &amp; The Newsletter Team--Newsletter<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in Stefano Lissa &amp; The Newsletter Team Newsletter allows Functionality Bypass.This issue affects Newsletter: from n/a through 8.2.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30522&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30522" target="_blank">CVE-2024-30522</a><br><a href="https://patchstack.com/database/vulnerability/newsletter/wordpress-newsletter-plugin-8-2-0-ip-blacklist-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Strategy11 Form Builder Team--Formidable Forms<br> </td>
<td>Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder Team Formidable Forms allows Code Injection.This issue affects Formidable Forms: from n/a through 6.7.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23522&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23522" target="_blank">CVE-2024-23522</a><br><a href="https://patchstack.com/database/vulnerability/formidable/wordpress-formidable-forms-plugin-6-7-content-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>StylemixThemes--Cost Calculator Builder PRO<br> </td>
<td>Cost Calculator Builder Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3.1.72, via the send_demo_webhook() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4789&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4789" target="_blank">CVE-2024-4789</a><br><a href="https://stylemixthemes.com/cost-calculator-plugin/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c6840350-7ff4-4ec2-bf2b-94ce6f782537?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Supsystic--Pricing Table by Supsystic<br> </td>
<td>Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Supsystic Pricing Table by Supsystic allows Code Injection.This issue affects Pricing Table by Supsystic: from n/a through 1.9.12.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32790&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32790" target="_blank">CVE-2024-32790</a><br><a href="https://patchstack.com/database/vulnerability/pricing-table-by-supsystic/wordpress-pricing-table-by-supsystic-plugin-1-9-12-content-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Swift Ideas--Swift Framework<br> </td>
<td>The Swift Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sf_edit_directory_item() function in all versions up to, and including, 2.7.31. This makes it possible for unauthenticated attackers to update arbitrary posts with arbitrary content. Unfortunately, we did not receive a response from the vendor to send over the vulnerability details.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3915&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3915" target="_blank">CVE-2024-3915</a><br><a href="https://swiftideas.com/swift-framework/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/855055d5-362e-4a92-9e9d-97eab328dcc3?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Swift Ideas--Swift Framework<br> </td>
<td>The Swift Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 2.7.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Unfortunately, we did not receive a response from the vendor to send over the vulnerability details.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3916&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3916" target="_blank">CVE-2024-3916</a><br><a href="https://swiftideas.com/swift-framework/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/57103f8e-0874-4e56-8571-254607ada21c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Sylius--Sylius<br> </td>
<td>Sylius is an open source eCommerce platform. Prior to 1.12.16 and 1.13.1, there is a possibility to execute javascript code in the Admin panel. In order to perform an XSS attack input a script into Name field in which of the resources: Taxons, Products, Product Options or Product Variants. The code will be executed while using an autocomplete field with one of the listed entities in the Admin Panel. Also for the taxons in the category tree on the product form.The issue is fixed in versions: 1.12.16, 1.13.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34349&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34349" target="_blank">CVE-2024-34349</a><br><a href="https://github.com/Sylius/Sylius/commit/ba4b66da5af88cdb1bba6174de8bdf42f4853e12" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Sylius/Sylius/security/advisories/GHSA-v2f9-rv6w-vw8r" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Synaptics--Synaptics Fingerprint Driver<br> </td>
<td>Missing lock check in SynHsaService may create a use-after-free condition which causes abnormal termination of the service, resulting in denial of service for the Synaptics Hardware Support App.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5447&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5447" target="_blank">CVE-2023-5447</a><br><a href="https://www.synaptics.com/sites/default/files/2023-10/fingerprint-driver-HSAService-security-brief-2023-10-13.pdf" target="_blank">PSIRT@synaptics.com</a></td>
</tr>
<tr>
<td>TIBCO--Hawk<br> </td>
<td>Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user's Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3182&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3182" target="_blank">CVE-2024-3182</a><br><a href="https://community.tibco.com/advisories/tibco-security-advisory-may-14-2024-tibco-hawk-cve-2024-3182-r213/" target="_blank">security@tibco.com</a></td>
</tr>
<tr>
<td>TYPO3--typo3<br> </td>
<td>TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the form manager backend module is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to the form module. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1 fix the problem described.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34356&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34356" target="_blank">CVE-2024-34356</a><br><a href="https://github.com/TYPO3/typo3/commit/2832e2f51f929aeddb5de7d667538a33ceda8156" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/d0393a879a32fb4e3569acad6bdb5cda776be1e5" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/e95a1224719efafb9cab2d85964f240fd0356e64" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/security/advisories/GHSA-v6mw-h7w6-59w3" target="_blank">security-advisories@github.com</a><br><a href="https://typo3.org/security/advisory/typo3-core-sa-2024-008" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>TYPO3--typo3<br> </td>
<td>TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, failing to properly encode user-controlled values in file entities, the `ShowImageController` (`_eID tx_cms_showpic_`) is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to file entities. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34357&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34357" target="_blank">CVE-2024-34357</a><br><a href="https://github.com/TYPO3/typo3/commit/376474904f6b9a54dc1b785a2e45277cbd13b0d7" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/b31d05d1da3eeaeead2d19eb43b1c3f9c88e15ee" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/d774642381354d3bf5095a5a26e18acd2767f0b1" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/security/advisories/GHSA-hw6c-6gwq-3m3m" target="_blank">security-advisories@github.com</a><br><a href="https://typo3.org/security/advisory/typo3-core-sa-2024-009" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>TYPO3--typo3<br> </td>
<td>TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the `ShowImageController` (`_eID tx_cms_showpic_`) lacks a cryptographic HMAC-signature on the `frame` HTTP query parameter (e.g. `/index.php?eID=tx_cms_showpic?file=3&amp;...&amp;frame=12345`). This allows adversaries to instruct the system to produce an arbitrary number of thumbnail images on the server side. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34358&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34358" target="_blank">CVE-2024-34358</a><br><a href="https://github.com/TYPO3/typo3/commit/05c95fed869a1a6dcca06c7077b83b6ea866ff14" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/1e70ebf736935413b0531004839362b4fb0755a5" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/df7909b6a1cf0f12a42994d0cc3376b607746142" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/security/advisories/GHSA-36g8-62qv-5957" target="_blank">security-advisories@github.com</a><br><a href="https://typo3.org/security/advisory/typo3-core-sa-2024-010" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Tech9logy Creators--WPCS ( WordPress Custom Search )<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tech9logy Creators WPCS ( WordPress Custom Search ) allows Stored XSS.This issue affects WPCS ( WordPress Custom Search ): from n/a through 1.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34418&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34418" target="_blank">CVE-2024-34418</a><br><a href="https://patchstack.com/database/vulnerability/wpcs-wp-custom-search/wordpress-wpcs-wordpress-custom-search-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>The Events Calendar--BookIt<br> </td>
<td>Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidden Fields.This issue affects BookIt: from n/a through 2.4.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24715&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24715" target="_blank">CVE-2024-24715</a><br><a href="https://patchstack.com/database/vulnerability/bookit/wordpress-wordpress-bookit-plugin-plugin-2-4-0-price-bypass-vulnerability-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Theme Freesia--Freesia Empire<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Freesia Freesia Empire allows Stored XSS.This issue affects Freesia Empire: from n/a through 1.4.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33955&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33955" target="_blank">CVE-2024-33955</a><br><a href="https://patchstack.com/database/vulnerability/freesia-empire/wordpress-freesia-empire-theme-1-4-1-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThemeFuse--Unyson<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in ThemeFuse Unyson.This issue affects Unyson: from n/a through 2.7.29.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34814&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34814" target="_blank">CVE-2024-34814</a><br><a href="https://patchstack.com/database/vulnerability/unyson/wordpress-unyson-plugin-2-7-29-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThemeLocation--Custom WooCommerce Checkout Fields Editor<br> </td>
<td>Missing Authorization vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33956&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33956" target="_blank">CVE-2024-33956</a><br><a href="https://patchstack.com/database/vulnerability/add-fields-to-checkout-page-woocommerce/wordpress-custom-woocommerce-checkout-fields-editor-plugin-1-3-0-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThemeNectar--Salient Shortcodes<br> </td>
<td>The Salient Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'icon' shortcode in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3811&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3811" target="_blank">CVE-2024-3811</a><br><a href="https://themeforest.net/item/salient-responsive-multipurpose-theme/4363266" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/70682a2d-16f6-4d7e-bf69-f0f3999f03de?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>ThimPress--Thim Elementor Kit<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Thim Elementor Kit allows Stored XSS.This issue affects Thim Elementor Kit: from n/a through 1.1.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34415&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34415" target="_blank">CVE-2024-34415</a><br><a href="https://patchstack.com/database/vulnerability/thim-elementor-kit/wordpress-thim-elementor-kit-plugin-1-1-8-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThroughTek--Kalay SDK<br> </td>
<td>ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6323&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6323" target="_blank">CVE-2023-6323</a><br><a href="https://bitdefender.com/blog/labs/notes-on-throughtek-kalay-vulnerabilities-and-their-impact/" target="_blank">cve-requests@bitdefender.com</a></td>
</tr>
<tr>
<td>Toidicode.com (thanhtaivtt)--Viet Nam Affiliate<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Toidicode.Com (thanhtaivtt) Viet Nam Affiliate allows Stored XSS.This issue affects Viet Nam Affiliate: from n/a through 1.0.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34417&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34417" target="_blank">CVE-2024-34417</a><br><a href="https://patchstack.com/database/vulnerability/viet-nam-affiliate/wordpress-viet-nam-affiliate-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Tongda--OA<br> </td>
<td>A vulnerability was found in Tongda OA 2017. It has been declared as critical. This vulnerability affects unknown code of the file /general/meeting/manage/delete.php. The manipulation of the argument M_ID_STR leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264436. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4903&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4903" target="_blank">CVE-2024-4903</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/sql3.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264436" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264436" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.330632" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Trellix--ePolicy Orchestrator<br> </td>
<td>ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow a least privileged user to manipulate the client task and client task assignments, hence escalating his/her privilege.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4843&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4843" target="_blank">CVE-2024-4843</a><br><a href="https://thrive.trellix.com/s/article/000013505" target="_blank">trellixpsirt@trellix.com</a></td>
</tr>
<tr>
<td>UkrSolution--Barcode Scanner with Inventory &amp; Order Manager<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in UkrSolution Barcode Scanner with Inventory &amp; Order Manager.This issue affects Barcode Scanner with Inventory &amp; Order Manager: from n/a through 1.5.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34556&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34556" target="_blank">CVE-2024-34556</a><br><a href="https://patchstack.com/database/vulnerability/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/wordpress-barcode-scanner-with-inventory-order-manager-plugin-1-5-4-sensitive-data-exposure-via-exported-file-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>UkrSolution--Barcode Scanner with Inventory &amp; Order Manager<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in UkrSolution Barcode Scanner with Inventory &amp; Order Manager.This issue affects Barcode Scanner with Inventory &amp; Order Manager: from n/a through 1.5.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34557&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34557" target="_blank">CVE-2024-34557</a><br><a href="https://patchstack.com/database/vulnerability/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/wordpress-barcode-scanner-with-inventory-order-manager-plugin-1-5-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Uniform Server Zero--Uniform Server Zero<br> </td>
<td>vulnerability in Uniform Server Zero, version 10.2.5, consisting of an XSS through the /us_extra/phpinfo.php page. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and partially take over their session details.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5052&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5052" target="_blank">CVE-2023-5052</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-xss-uniform-server-zero" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Valiano--Unite Gallery Lite<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Valiano Unite Gallery Lite allows PHP Local File Inclusion.This issue affects Unite Gallery Lite: from n/a through 1.7.59.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-33310&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-33310" target="_blank">CVE-2023-33310</a><br><a href="https://patchstack.com/database/vulnerability/unite-gallery-lite/wordpress-unite-gallery-lite-plugin-1-7-59-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ValvePress--WordPress Automatic Plugin<br> </td>
<td>The WordPress Automatic Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'autoplay' parameter in all versions up to, and including, 3.94.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4849&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4849" target="_blank">CVE-2024-4849</a><br><a href="https://codecanyon.net/item/wordpress-automatic-plugin/1904470" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4be58bfa-d489-45f5-9169-db8bab718175?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>VeronaLabs--WP SMS<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.5.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34811&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34811" target="_blank">CVE-2024-34811</a><br><a href="https://patchstack.com/database/vulnerability/wp-sms/wordpress-wp-sms-plugin-6-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Visualmodo--Borderless Widgets, Elements, Templates and Toolkit for Elementor &amp; Gutenberg<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Visualmodo Borderless - Widgets, Elements, Templates and Toolkit for Elementor &amp; Gutenberg allows Stored XSS.This issue affects Borderless - Widgets, Elements, Templates and Toolkit for Elementor &amp; Gutenberg: from n/a through 1.5.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34757&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34757" target="_blank">CVE-2024-34757</a><br><a href="https://patchstack.com/database/vulnerability/borderless/wordpress-borderless-widgets-elements-templates-and-toolkit-for-elementor-gutenberg-plugin-1-5-3-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>W3 Eden Inc.--Download Manager<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Bypass.This issue affects Download Manager: from n/a through 3.2.82.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32131&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32131" target="_blank">CVE-2024-32131</a><br><a href="https://patchstack.com/database/vulnerability/download-manager/wordpress-download-manager-plugin-3-2-82-file-password-lock-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 disks (/admin/DeviceS3). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3787&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3787" target="_blank">CVE-2024-3787</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through License (/admin/CDPUsers). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3788&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3788" target="_blank">CVE-2024-3788</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Uncontrolled resource consumption vulnerability in White Bear Solutions WBSAirback, version 21.02.04. This vulnerability could allow an attacker to send multiple command injection payloads to influence the amount of resources consumed.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3789&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3789" target="_blank">CVE-2024-3789</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemUsers, login / description fields, passwd1/ passwd2 parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3790&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3790" target="_blank">CVE-2024-3790</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemConfiguration, name / free memory limit fields , type / password parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3791&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3791" target="_blank">CVE-2024-3791</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/DeviceReplication, execution range field, all parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3792&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3792" target="_blank">CVE-2024-3792</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/CloudAccounts, account name / user password / server fields, all parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3793&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3793" target="_blank">CVE-2024-3793</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/AdvancedSystem, description field, all parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3794&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3794" target="_blank">CVE-2024-3794</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupTemplate, name / description fields. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3795&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3795" target="_blank">CVE-2024-3795</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupSchedule, description field. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3796&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3796" target="_blank">CVE-2024-3796</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WP Club Manager--WP Club Manager<br> </td>
<td>Missing Authorization vulnerability in WP Club Manager.This issue affects WP Club Manager: from n/a through 2.2.11.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32719&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32719" target="_blank">CVE-2024-32719</a><br><a href="https://patchstack.com/database/vulnerability/wp-club-manager/wordpress-wp-club-manager-plugin-2-2-11-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Happy Coders--Comments Like Dislike<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in WP Happy Coders Comments Like Dislike allows Functionality Bypass.This issue affects Comments Like Dislike: from n/a through 1.2.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25906&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25906" target="_blank">CVE-2024-25906</a><br><a href="https://patchstack.com/database/vulnerability/comments-like-dislike/wordpress-comments-like-dislike-plugin-1-2-1-ip-restriction-bypass-vulnerability-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Royal--Royal Elementor Addons<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in WP Royal Royal Elementor Addons allows Functionality Bypass.This issue affects Royal Elementor Addons: from n/a through 1.3.93.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32786&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32786" target="_blank">CVE-2024-32786</a><br><a href="https://patchstack.com/database/vulnerability/royal-elementor-addons/wordpress-royal-elementor-addons-and-templates-plugin-1-3-93-ip-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPBlockart--Magazine Blocks<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPBlockart Magazine Blocks allows Stored XSS.This issue affects Magazine Blocks: from n/a through 1.3.6.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34760&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34760" target="_blank">CVE-2024-34760</a><br><a href="https://patchstack.com/database/vulnerability/magazine-blocks/wordpress-magazine-blocks-plugin-1-3-6-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPDeveloper--SchedulePress<br> </td>
<td>Missing Authorization vulnerability in WPDeveloper SchedulePress.This issue affects SchedulePress: from n/a through 5.0.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32717&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32717" target="_blank">CVE-2024-32717</a><br><a href="https://patchstack.com/database/vulnerability/wp-scheduled-posts/wordpress-schedulepress-plugin-5-0-8-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPMU DEV--Defender Security<br> </td>
<td>Insecure Storage of Sensitive Information vulnerability in WPMU DEV Defender Security allows : Screen Temporary Files for Sensitive Information.This issue affects Defender Security: from n/a through 3.3.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-44581&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-44581" target="_blank">CVE-2022-44581</a><br><a href="https://patchstack.com/database/vulnerability/defender-security/wordpress-defender-security-plugin-3-3-2-broken-authentication-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPMU DEV--Defender Security<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in WPMU DEV Defender Security allows Functionality Bypass.This issue affects Defender Security: from n/a through 4.4.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25595&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25595" target="_blank">CVE-2024-25595</a><br><a href="https://patchstack.com/database/vulnerability/defender-security/wordpress-defender-security-plugin-4-4-1-ip-restriction-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Wangshen--SecGate 3600<br> </td>
<td>A vulnerability, which was classified as critical, was found in Wangshen SecGate 3600 up to 20240516. This affects an unknown part of the file /?g=log_import_save. The manipulation of the argument reqfile leads to unrestricted upload. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-264747.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5050&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5050" target="_blank">CVE-2024-5050</a><br><a href="https://github.com/h0e4a0r1t/h0e4a0r1t.github.io/blob/master/2024/s%40%23NGfP%7B4%5Et(%7C%5Dd9/Wangshen%20SecGata%203600%20Firewall%20log_import_save%20arbitrary%20file%20upload%20vulnerability.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264747" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264747" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335968" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Warfare Plugins--Social Warfare<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Warfare Plugins Social Warfare.This issue affects Social Warfare: from n/a through 4.4.5.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34825&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34825" target="_blank">CVE-2024-34825</a><br><a href="https://patchstack.com/database/vulnerability/social-warfare/wordpress-social-warfare-plugin-4-4-5-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Web-Settler--Landing Page Builder Free Landing Page Templates<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Web-Settler Landing Page Builder - Free Landing Page Templates allows Path Traversal.This issue affects Landing Page Builder - Free Landing Page Templates: from n/a through 3.1.9.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-24379&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-24379" target="_blank">CVE-2023-24379</a><br><a href="https://patchstack.com/database/vulnerability/ultimate-landing-page/wordpress-landing-page-builder-free-landing-page-templates-plugin-3-1-9-8-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WebToffee--Order Export &amp; Order Import for WooCommerce<br> </td>
<td>Deserialization of Untrusted Data vulnerability in WebToffee Order Export &amp; Order Import for WooCommerce.This issue affects Order Export &amp; Order Import for WooCommerce: from n/a through 2.4.9.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34751&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34751" target="_blank">CVE-2024-34751</a><br><a href="https://patchstack.com/database/vulnerability/order-import-export-for-woocommerce/wordpress-order-export-order-import-for-woocommerce-plugin-2-4-9-php-object-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Webvitaly--iFrame<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webvitaly iFrame allows Stored XSS.This issue affects iFrame: from n/a through 5.0.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34805&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34805" target="_blank">CVE-2024-34805</a><br><a href="https://patchstack.com/database/vulnerability/iframe/wordpress-iframe-plugin-5-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Wireshark Foundation--Wireshark<br> </td>
<td>MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4854&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4854" target="_blank">CVE-2024-4854</a><br><a href="https://gitlab.com/wireshark/wireshark/-/issues/19726" target="_blank">cve@gitlab.com</a><br><a href="https://gitlab.com/wireshark/wireshark/-/merge_requests/15047" target="_blank">cve@gitlab.com</a><br><a href="https://gitlab.com/wireshark/wireshark/-/merge_requests/15499" target="_blank">cve@gitlab.com</a><br><a href="https://www.wireshark.org/security/wnpa-sec-2024-07.html" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>WordPlus--BP Better Messages<br> </td>
<td>Missing Authorization vulnerability in WordPlus BP Better Messages allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BP Better Messages: from n/a through 2.4.32.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32802&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32802" target="_blank">CVE-2024-32802</a><br><a href="https://patchstack.com/database/vulnerability/bp-better-messages/wordpress-better-messages-plugin-2-4-32-broken-authentication-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Wpmet--Wp Ultimate Review<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.3.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21746&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21746" target="_blank">CVE-2024-21746</a><br><a href="https://patchstack.com/database/vulnerability/wp-ultimate-review/wordpress-wp-ultimate-review-plugin-2-2-5-ip-limit-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Wpmet--Wp Ultimate Review<br> </td>
<td>Client-Side Enforcement of Server-Side Security vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.2.5.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32685&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32685" target="_blank">CVE-2024-32685</a><br><a href="https://patchstack.com/database/vulnerability/wp-ultimate-review/wordpress-wp-ultimate-review-plugin-2-2-5-review-score-manipulation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Zoom Video Communications, Inc.--Zoom Workplace VDI App for Windows<br> </td>
<td>Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27244&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27244" target="_blank">CVE-2024-27244</a><br><a href="https://www.zoom.com/en/trust/security-bulletin/zsb-24015/" target="_blank">security@zoom.us</a></td>
</tr>
<tr>
<td>Zoom Video Communications, Inc.--see references<br> </td>
<td>Buffer overflow in some Zoom Workplace Apps and SDK's may allow an authenticated user to conduct a denial of service via network access.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27243&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27243" target="_blank">CVE-2024-27243</a><br><a href="https://www.zoom.com/en/trust/security-bulletin/zsb-24014/" target="_blank">security@zoom.us</a></td>
</tr>
<tr>
<td>abuhayat--HTML5 Audio Player- Best WordPress Audio Player Plugin<br> </td>
<td>The HTML5 Audio Player- Best WordPress Audio Player Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.2.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4398&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4398" target="_blank">CVE-2024-4398</a><br><a href="https://plugins.trac.wordpress.org/browser/html5-audio-player/trunk/inc/Elementor/Widgets/Simple.php#L237" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/html5-audio-player/trunk/inc/elementor-widgets/fusion-audio-player.php#L275" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/html5-audio-player/trunk/inc/elementor-widgets/playlist.php#L541" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/html5-audio-player/trunk/inc/elementor-widgets/stamp-audio-player.php#L286" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ca646202-b9e2-4272-b0e2-d39cd748fb8e?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>aio-libs--aiosmtpd<br> </td>
<td>aiosmptd is a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted connection. This could be exploited by a man-in-the-middle attack. Version 1.4.6 contains a patch for the issue.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34083&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34083" target="_blank">CVE-2024-34083</a><br><a href="https://github.com/aio-libs/aiosmtpd/commit/b3a4a2c6ecfd228856a20d637dc383541fcdbfda" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/aio-libs/aiosmtpd/security/advisories/GHSA-wgjv-9j3q-jhg8" target="_blank">security-advisories@github.com</a><br><a href="https://nostarttls.secvuln.info/" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>argoproj--argo-cd<br> </td>
<td>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. This vulnerability has been patched in version(s) 2.10.7, 2.9.12 and 2.8.16.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32476&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32476" target="_blank">CVE-2024-32476</a><br><a href="https://github.com/argoproj/argo-cd/commit/7893979a1e78d59cedd0ba790ded24e30bb40657" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/argoproj/argo-cd/commit/9e5cc5a26ff0920a01816231d59fdb5eae032b5a" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/argoproj/argo-cd/commit/e2df7315fb7d96652186bf7435773a27be330cac" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/argoproj/argo-cd/security/advisories/GHSA-9m6p-x4h2-6frq" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>asterisk--asterisk<br> </td>
<td>Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35190&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35190" target="_blank">CVE-2024-35190</a><br><a href="https://github.com/asterisk/asterisk/commit/85241bd22936cc15760fd1f65d16c98be7aeaf6d" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/asterisk/asterisk/pull/600" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/asterisk/asterisk/pull/602" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/asterisk/asterisk/security/advisories/GHSA-qqxj-v78h-hrf9" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>athemes--Sydney Toolbox<br> </td>
<td>The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget in all versions up to, and including, 1.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4473&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4473" target="_blank">CVE-2024-4473</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082233/sydney-toolbox" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/60f16abd-951b-48a0-a363-0221f7e0957d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>automattic--Jetpack WP Security, Backup, Speed, &amp; Growth<br> </td>
<td>The Jetpack - WP Security, Backup, Speed, &amp; Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all versions up to, and including, 13.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4392&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4392" target="_blank">CVE-2024-4392</a><br><a href="https://plugins.trac.wordpress.org/browser/jetpack/tags/13.3.1/modules/videopress/class.videopress-player.php#L335" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/11dceac7-7ff8-4384-9046-919c38947c32?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>avimegladon--Custom Post Type Attachment<br> </td>
<td>The Custom Post Type Attachment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pdf_attachment' shortcode in all versions up to, and including, 3.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4546&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4546" target="_blank">CVE-2024-4546</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087121/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f6ba2907-36f4-4c4d-9e25-d13d32e28690?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>bdthemes--Prime Slider Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider)<br> </td>
<td>The Prime Slider - Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the General widget in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4339&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4339" target="_blank">CVE-2024-4339</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3080132%40bdthemes-prime-slider-lite%2Ftrunk&amp;old=3079066%40bdthemes-prime-slider-lite%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6eba6056-e087-4347-ad36-96501ceb4cdd?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>blakeblackshear--frigate<br> </td>
<td>Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Below 0.13.2 Release, when uploading a file or retrieving the filename, a user may intentionally use a large Unicode filename which would lead to a application-level denial of service. This is due to no limitation set on the length of the filename and the costy use of the Unicode normalization with the form NFKD under the hood of `secure_filename()`.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32874&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32874" target="_blank">CVE-2024-32874</a><br><a href="https://github.com/blakeblackshear/frigate/commit/cc851555e4029647986dccc8b8ecf54afee31442" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/blakeblackshear/frigate/security/advisories/GHSA-w4h6-9wrp-v5jq" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>blocksera--Image Hover Effects Elementor Addon<br> </td>
<td>The Image Hover Effects - Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Hover Effects Widget in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1166&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1166" target="_blank">CVE-2024-1166</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3068751%40image-hover-effects-addon-for-elementor&amp;new=3068751%40image-hover-effects-addon-for-elementor&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4d72a57f-9acc-43e4-af81-024bc6e0d3fd?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>boldgrid--Post and Page Builder by BoldGrid Visual Drag and Drop Editor<br> </td>
<td>The Post and Page Builder by BoldGrid - Visual Drag and Drop Editor plguin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 1.26.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4400&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4400" target="_blank">CVE-2024-4400</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087230/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9bb6683a-b8e6-4776-880f-5b48966fc5c6?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>brainstormforce--Elementor Header &amp; Footer Builder<br> </td>
<td>The Elementor Header &amp; Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hfe_svg_mime_types' function in versions up to, and including, 1.6.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4634&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4634" target="_blank">CVE-2024-4634</a><br><a href="https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/1.6.28/inc/widgets-manager/class-widgets-loader.php#L156" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086402/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f44bb823-bbf3-413b-82b5-a351609270bf?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>brainstormforce--Elementor Header &amp; Footer Builder<br> </td>
<td>The Elementor Header &amp; Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary HTML in pages that will be shown whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2619&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2619" target="_blank">CVE-2024-2619</a><br><a href="https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/1.6.25/admin/class-hfe-admin.php#L220" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/1.6.25/admin/class-hfe-admin.php#L74" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3070659%40header-footer-elementor%2Ftrunk&amp;old=3053177%40header-footer-elementor%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/689eb95b-2f72-4aa4-9f21-6ae186346061?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>brainstormforce--Starter Templates Elementor, WordPress &amp; Beaver Builder Templates<br> </td>
<td>The Starter Templates - Elementor, WordPress &amp; Beaver Builder Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_upload_mimes' function in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4630&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4630" target="_blank">CVE-2024-4630</a><br><a href="https://plugins.trac.wordpress.org/browser/astra-sites/tags/4.2.0/inc/importers/wxr-importer/class-astra-wxr-importer.php#L416" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084334/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/25edb9e8-65ea-41d1-a95f-09be110ec1d2?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>brainstormforce--Starter Templates Elementor, WordPress &amp; Beaver Builder Templates<br> </td>
<td>The Starter Templates - Elementor, WordPress &amp; Beaver Builder Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.6 via the ai_api_request(). This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1467&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1467" target="_blank">CVE-2024-1467</a><br><a href="https://plugins.trac.wordpress.org/changeset/3074863/astra-sites/tags/4.1.7/inc/classes/class-astra-sites-importer.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3074863/astra-sites/tags/4.1.7/inc/classes/class-astra-sites.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cf5075f9-9658-4a09-bd38-34a72f6560f4?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>britner--Gutenberg Blocks with AI by Kadence WP Page Builder Features<br> </td>
<td>The Gutenberg Blocks with AI by Kadence WP - Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the typer effect in the advanced heading widget in all versions up to, and including, 3.2.37 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4208&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4208" target="_blank">CVE-2024-4208</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3084683%40kadence-blocks&amp;new=3084683%40kadence-blocks&amp;sfp_email=&amp;sfph_mail=#file2" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7ea2bb8c-cc8b-49de-9c8e-2c8c0569f4ac?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>britner--Gutenberg Blocks with AI by Kadence WP Page Builder Features<br> </td>
<td>The Gutenberg Blocks with AI by Kadence WP - Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown timer in all versions up to, and including, 3.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4209&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4209" target="_blank">CVE-2024-4209</a><br><a href="https://plugins.trac.wordpress.org/browser/kadence-blocks/trunk/includes/blocks/class-kadence-blocks-countdown-block.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083616/kadence-blocks/trunk/dist/blocks-countdown.js" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cff2e5be-0de0-4e62-a881-6156760b7d99?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>britner--Gutenberg Blocks with AI by Kadence WP Page Builder Features<br> </td>
<td>The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the plugin's blocks in all versions up to, and including, 3.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4481&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4481" target="_blank">CVE-2024-4481</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083616/kadence-blocks/trunk/includes/blocks/class-kadence-blocks-advanced-heading-block.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ad0e4292-d890-499b-b70a-ed638d5b8ee9?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>britner--Gutenberg Blocks with AI by Kadence WP Page Builder Features<br> </td>
<td>The Gutenberg Blocks by Kadence Blocks - Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Testimonial', 'Progress Bar', 'Lottie Animations', 'Row Layout', 'Google Maps', and 'Advanced Gallery' blocks in all versions up to, and including, 3.2.37 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3189&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3189" target="_blank">CVE-2024-3189</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083616/kadence-blocks/trunk/includes/blocks/class-kadence-blocks-lottie-block.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3076712%40kadence-blocks&amp;new=3076712%40kadence-blocks&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3084683%40kadence-blocks&amp;new=3084683%40kadence-blocks&amp;sfp_email=&amp;sfph_mail=#file2" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/766b0bde-c555-40c1-b174-20045bd89c11?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>buddypress--BuddyPress<br> </td>
<td>The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_name' parameter in versions up to, and including, 12.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3974&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3974" target="_blank">CVE-2024-3974</a><br><a href="https://plugins.trac.wordpress.org/browser/buddypress/trunk/bp-members/bp-members-admin.php#L145" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/buddypress/trunk/bp-members/bp-members-blocks.php#L347" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3079691/buddypress" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3657384e-025a-44ad-8b7e-1a2fea17dcc3?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>carazo--Import and export users and customers<br> </td>
<td>The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4656&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4656" target="_blank">CVE-2024-4656</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3085346%40import-users-from-csv-with-meta%2Ftrunk&amp;old=3078277%40import-users-from-csv-with-meta%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/af742451-b2d6-445a-9a10-e950490f6c7c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>carazo--Import and export users and customers<br> </td>
<td>The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4734&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4734" target="_blank">CVE-2024-4734</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3085346%40import-users-from-csv-with-meta%2Ftrunk&amp;old=3078277%40import-users-from-csv-with-meta%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0dca168f-a383-42fc-91ba-d78a5d7e6724?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>code-projects--Budget Management<br> </td>
<td>A vulnerability classified as critical was found in code-projects Budget Management 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument edit leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264745 was assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5048&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5048" target="_blank">CVE-2024-5048</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Budget%20Management%20App/Budget%20Management%20App%20-%20SQL%20Injection%20-%201.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264745" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264745" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335666" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>code-projects--Simple Chat System<br> </td>
<td>A vulnerability classified as critical has been found in code-projects Simple Chat System 1.0. This affects an unknown part of the file /login.php. The manipulation of the argument email/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264537 was assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4972&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4972" target="_blank">CVE-2024-4972</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Simple%20Chat%20App/Simple%20Chat%20App%20-%20SQL%20Injection%20-%201.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264537" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264537" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335199" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>code-projects--Simple Chat System<br> </td>
<td>A vulnerability classified as critical was found in code-projects Simple Chat System 1.0. This vulnerability affects unknown code of the file /register.php. The manipulation of the argument name/number/address leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264538 is the identifier assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4973&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4973" target="_blank">CVE-2024-4973</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Simple%20Chat%20App/Simple%20Chat%20App%20-%20SQL%20Injection%20-%202.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264538" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264538" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335200" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>codename065--Sliding Widgets<br> </td>
<td>Missing Authorization vulnerability in codename065 Sliding Widgets allows Cross-Site Scripting (XSS).This issue affects Sliding Widgets: from n/a through 1.5.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33938&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33938" target="_blank">CVE-2024-33938</a><br><a href="https://patchstack.com/database/vulnerability/sliding-widgets/wordpress-sliding-widgets-plugin-1-5-0-broken-access-control-to-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>codewoogeek--Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro<br> </td>
<td>The The Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.3.1. This is due to the plugin for WordPress allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4038&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4038" target="_blank">CVE-2024-4038</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3080830%40back-in-stock-notifier-for-woocommerce&amp;new=3080830%40back-in-stock-notifier-for-woocommerce&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d7f59489-9bff-4d22-8f99-6ea52d702ecf?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>creativethemeshq--Blocksy Companion<br> </td>
<td>The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG uploads in versions up to, and including, 2.0.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4487&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4487" target="_blank">CVE-2024-4487</a><br><a href="https://plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.0.45/framework/features/svg.php#L20" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084198/#file18" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5208529c-4ac3-42a4-82d0-7f4d2e486236?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>creativethemeshq--Blocksy<br> </td>
<td>The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tagName' parameter in versions up to, and including, 2.0.42 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4158&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4158" target="_blank">CVE-2024-4158</a><br><a href="https://themes.trac.wordpress.org/changeset/226440/blocksy" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22d1ccf3-ac1a-4dfc-81c3-b8eb88795bc1?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>croixhaug--Appointment Booking Calendar Simply Schedule Appointments Booking Plugin<br> </td>
<td>The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter in versions up to, and including, 1.6.7.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4288&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4288" target="_blank">CVE-2024-4288</a><br><a href="https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/trunk/includes/class-shortcodes.php#L677" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087297/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/84262b4a-a662-4aaf-9eae-f5cca8f6cd06?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>daext--Soccer Engine Soccer Plugin for WordPress<br> </td>
<td>The Soccer Engine - Soccer Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12. This is due to missing or incorrect nonce validation when saving match and team settings. This makes it possible for unauthenticated attackers to change plugin settings as well as teams, players, etc. via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4312&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4312" target="_blank">CVE-2024-4312</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3081944%40soccer-engine-lite%2Ftrunk&amp;old=3066918%40soccer-engine-lite%2Ftrunk" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/57e84624-98ab-495b-b985-908302527b3a?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>davidanderson--Testimonial Slider<br> </td>
<td>The Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'testimonialcategory' shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4193&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4193" target="_blank">CVE-2024-4193</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3080579%40testimonial-slider&amp;new=3080579%40testimonial-slider&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cd7ed687-4049-4957-86e9-b2f59621c747?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>deTheme--DethemeKit For Elementor<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in deTheme DethemeKit For Elementor allows Stored XSS.This issue affects DethemeKit For Elementor: from n/a through 2.1.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34575&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34575" target="_blank">CVE-2024-34575</a><br><a href="https://patchstack.com/database/vulnerability/dethemekit-for-elementor/wordpress-dethemekit-for-elementor-plugin-2-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>detheme--DethemeKit For Elementor<br> </td>
<td>The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4374&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4374" target="_blank">CVE-2024-4374</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3088000%40dethemekit-for-elementor&amp;new=3088000%40dethemekit-for-elementor&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bcd9384c-5af3-4544-8179-c2f5550dd152?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>devitemsllc--HT Mega Absolute Addons For Elementor<br> </td>
<td>The HT Mega - Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gallery Justify Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3989&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3989" target="_blank">CVE-2024-3989</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3074490%40ht-mega-for-elementor&amp;new=3074490%40ht-mega-for-elementor&amp;sfp_email=&amp;sfph_mail=#file3" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/03fba6bb-ff30-42bb-936b-93c009a7e3f7?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>devitemsllc--HT Mega Absolute Addons For Elementor<br> </td>
<td>The HT Mega - Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tooltip &amp; Popover Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3990&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3990" target="_blank">CVE-2024-3990</a><br><a href="https://plugins.trac.wordpress.org/browser/ht-mega-for-elementor/tags/2.5.0/includes/widgets/htmega_tooltip.php#L620" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3074490%40ht-mega-for-elementor&amp;new=3074490%40ht-mega-for-elementor&amp;sfp_email=&amp;sfph_mail=#file4" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3074490%40ht-mega-for-elementor&amp;new=3074490%40ht-mega-for-elementor&amp;sfp_email=&amp;sfph_mail=#file5" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/98e74a23-b586-4d6a-b1ab-78838b0eed61?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>devitemsllc--ShopLentor WooCommerce Builder for Elementor &amp; Gutenberg +12 Modules All in One Solution (formerly WooLentor)<br> </td>
<td>The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchased_new_products function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to view all products purchased in the past week, along with the users that purchased them.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6327&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6327" target="_blank">CVE-2023-6327</a><br><a href="https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/2.7.4/includes/modules/sales-notification/class.sale_notification.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3080097/woolentor-addons/trunk/includes/modules/sales-notification/class.sale_notification.php?contextall=1&amp;old=3061864&amp;old_path=%2Fwoolentor-addons%2Ftrunk%2Fincludes%2Fmodules%2Fsales-notification%2Fclass.sale_notification.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/263324cb-31b7-40ad-ad7d-4582e128cd75?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>directus--directus<br> </td>
<td>Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.0, session tokens function like the other JWT tokens where they are not actually invalidated when logging out. The `directus_session` gets destroyed and the cookie gets deleted but if the cookie value is captured, it will still work for the entire expiry time which is set to 1 day by default. Making it effectively a long lived unrevokable stateless token instead of the stateful session token it was meant to be. This vulnerability is fixed in 10.11.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34709&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34709" target="_blank">CVE-2024-34709</a><br><a href="https://github.com/directus/directus/commit/a6172f8a6a0f31a6bf4305a090de172ebfb63bcf" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/directus/directus/security/advisories/GHSA-g65h-35f3-x2w3" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>directus--directus<br> </td>
<td>Directus is a real-time API and App dashboard for managing SQL database content. A user with permission to view any collection using redacted hashed fields can get access the raw stored version using the `alias` functionality on the API. Normally, these redacted fields will return `**********` however if we change the request to `?alias[workaround]=redacted` we can instead retrieve the plain text value for the field. This can be avoided by removing permission to view the sensitive fields entirely from users or roles that should not be able to see them. This vulnerability is fixed in 10.11.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34708&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34708" target="_blank">CVE-2024-34708</a><br><a href="https://github.com/directus/directus/commit/e70a90c267bea695afce6545174c2b77517d617b" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/directus/directus/security/advisories/GHSA-p8v3-m643-4xqx" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>divSpot--DS Site Message<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in divSpot DS Site Message.This issue affects DS Site Message: from n/a through 1.14.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34439&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34439" target="_blank">CVE-2024-34439</a><br><a href="https://patchstack.com/database/vulnerability/ds-site-message/wordpress-ds-site-message-plugin-1-14-4-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>envothemes--Envo Extra<br> </td>
<td>The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 1.8.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4385&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4385" target="_blank">CVE-2024-4385</a><br><a href="https://plugins.trac.wordpress.org/browser/envo-extra/trunk/lib/elementor/widgets/button/button.php#L679" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/envo-extra/trunk/lib/elementor/widgets/counter/counter.php#L754" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/envo-extra/trunk/lib/elementor/widgets/icon-box/icon-box.php#L909" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/envo-extra/trunk/lib/elementor/widgets/team/team.php#L1189" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/envo-extra/trunk/lib/elementor/widgets/testimonial/testimonial.php#L899" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3080715/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/83d78ff7-bd59-431e-b579-156e23ede053?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>fluxcd--source-controller<br> </td>
<td>The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. The source-controller implements the source.toolkit.fluxcd.io API and is a core component of the GitOps toolkit. Prior to version 1.2.5, when source-controller was configured to use an Azure SAS token when connecting to Azure Blob Storage, the token was logged along with the Azure URL when the controller encountered a connection error. An attacker with access to the source-controller logs could use the token to gain access to the Azure Blob Storage until the token expires. This vulnerability was fixed in source-controller v1.2.5. There is no workaround for this vulnerability except for using a different auth mechanism such as Azure Workload Identity.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31216&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31216" target="_blank">CVE-2024-31216</a><br><a href="https://github.com/fluxcd/source-controller/commit/915d1a072a4f37dd460ba33079dc094aa6e72fa9" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/fluxcd/source-controller/pull/1430" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/fluxcd/source-controller/security/advisories/GHSA-v554-xwgw-hc3w" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>frappe--frappe<br> </td>
<td>Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external URls. This behaviour can be used by malicious actors for phishing. This vulnerability is fixed in 15.26.0 and 14.74.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34074&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34074" target="_blank">CVE-2024-34074</a><br><a href="https://github.com/frappe/frappe/commit/65b3c42635038cdff17d3109be6c373bac004829" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/frappe/frappe/pull/26304" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/frappe/frappe/security/advisories/GHSA-7g27-q225-j894" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>freescout-helpdesk--freescout<br> </td>
<td>FreeScout is a free, self-hosted help desk and shared mailbox. Versions of FreeScout prior to 1.8.139 contain a Prototype Pollution vulnerability in the `/public/js/main.js` source file. The Prototype Pollution arises because the `getQueryParam` Function recursively merges an object containing user-controllable properties into an existing object (For URL Query Parameters Parsing), without first sanitizing the keys. This can allow an attacker to inject a property with a key `__proto__`, along with arbitrarily nested properties. The merge operation assigns the nested properties to the `params` object's prototype instead of the target object itself. As a result, the attacker can pollute the prototype with properties containing harmful values, which are then inherited by user-defined objects and subsequently used by the application dangerously. The vulnerability lets an attacker control properties of objects that would otherwise be inaccessible. If the application subsequently handles an attacker-controlled property in an unsafe way, this can potentially be chained with other vulnerabilities like DOM-based XSS, Open Redirection, Cookie Manipulation, Link Manipulation, HTML Injection, etc. Version 1.8.139 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34698&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">4.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34698" target="_blank">CVE-2024-34698</a><br><a href="https://github.com/freescout-helpdesk/freescout/commit/2614514bc6d6c4ad563202a1c9cae5a97b195cc5" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/freescout-helpdesk/freescout/security/advisories/GHSA-rx6j-4c33-9h3r" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>giuliopanda--ADFO Custom data in admin dashboard<br> </td>
<td>The ADFO - Custom data in admin dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dbp_id' parameter in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4104&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4104" target="_blank">CVE-2024-4104</a><br><a href="https://plugins.trac.wordpress.org/browser/admin-form/trunk/admin/class-af-list-admin.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3081090%40admin-form&amp;new=3081090%40admin-form&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e61110fc-cc2d-4207-97b6-b21459334216?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>giuliopanda--ADFO Custom data in admin dashboard<br> </td>
<td>The ADFO - Custom data in admin dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.0. This is due to missing or incorrect nonce validation on several functions hooked via the controller() function. This makes it possible for unauthenticated attackers to edit the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4103&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4103" target="_blank">CVE-2024-4103</a><br><a href="https://plugins.trac.wordpress.org/changeset/3081090/admin-form/trunk/admin/class-af-list-admin.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8d797238-f8f3-44d7-8c16-bee23ce12ae0?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>https://elementor.com/--Elementor Website Builder Pro<br> </td>
<td>The Elementor Website Builder - More than Just a Page Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in versions up to, and including, 3.21.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4107&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4107" target="_blank">CVE-2024-4107</a><br><a href="https://doc.clickup.com/9011113249/d/h/8chnb91-5091/3951e6f2afbd388" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0d5d47bd-4f05-4dc7-84c1-f7bc1196ee16?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>iePlexus--Featured Content Gallery<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iePlexus Featured Content Gallery allows Stored XSS.This issue affects Featured Content Gallery: from n/a through 3.2.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34424&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34424" target="_blank">CVE-2024-34424</a><br><a href="https://patchstack.com/database/vulnerability/featured-content-gallery/wordpress-featured-content-gallery-plugin-3-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>iqonicdesign--Graphina Elementor Charts and Graphs<br> </td>
<td>The Graphina - Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4574&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4574" target="_blank">CVE-2024-4574</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/area/widget/area_chart.php#L457" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/bubble/widget/bubble_chart.php#L685" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/candle/widget/candle_chart.php#L517" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/column/widget/column_chart.php#L531" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/distributed_column/widget/Distributed_Column_chart.php#L464" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/donut/widget/donut_chart.php#L325" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/heatmap/widget/heatmap_chart.php#L448" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/line/widget/line_chart.php#L426" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/pie/widget/pie_chart.php#L279" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/polar/widget/polar_chart.php#L413" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/radar/widget/radar_chart.php#L546" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/radial/widget/radial_chart.php#L417" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/scatter/widget/scatter_chart.php#L419" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/timeline/widget/timeline_chart.php#L462" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/area/widget/area_google_chart.php#L570" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/bar/widget/bar_google_chart.php#L524" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/column/widget/column_google_chart.php#L536" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/donut/widget/donut_google_chart.php#L384" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/line/widget/line_google_chart.php#L578" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/pie/widget/pie_google_chart.php#L391" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1febe2d8-d354-4c78-a611-c1bb0937e53d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>ithemelandco--Bulk Posts Editing For WordPress<br> </td>
<td>The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on the plugin's AJAX actions in all versions up to, and including, 4.2.3. This makes it possible for authenticated attackers, with subscriber access and higher, to invoke their corresponding functions. This may lead to post creation and duplication, post content retrieval, post taxonomy manipulation.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4199&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4199" target="_blank">CVE-2024-4199</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3085134%40ithemeland-bulk-posts-editing-lite%2Ftrunk&amp;old=2946926%40ithemeland-bulk-posts-editing-lite%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/683131a0-eec3-4251-b322-5c2088855687?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>ithemelandco--Bulk Posts Editing For WordPress<br> </td>
<td>The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to missing or incorrect nonce validation on the plugin's AJAX actions.. This makes it possible for unauthenticated attackers to create and duplicate posts, retrieve post content, and modify post taxonomy among other things via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4204&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4204" target="_blank">CVE-2024-4204</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3085134%40ithemeland-bulk-posts-editing-lite%2Ftrunk&amp;old=2946926%40ithemeland-bulk-posts-editing-lite%2Ftrunk&amp;sfp_email=&amp;sfph_mail=#file51" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/34b39462-32c5-4f7d-b54f-d95f40b6ed92?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>justinbusa--Beaver Builder WordPress Page Builder<br> </td>
<td>The Beaver Builder - WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_target parameter in all versions up to, and including, 2.8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3923&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3923" target="_blank">CVE-2024-3923</a><br><a href="https://plugins.trac.wordpress.org/browser/beaver-builder-lite-version/tags/2.8.0.7/modules/button/includes/frontend.php#L14" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3078825%40beaver-builder-lite-version%2Ftrunk&amp;old=3062187%40beaver-builder-lite-version%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/99960ff7-62e1-4c44-ae8e-ebda3e075781?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>justinbusa--Beaver Builder WordPress Page Builder<br> </td>
<td>The Beaver Builder - WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the photo widget crop attribute in all versions up to, and including, 2.8.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4430&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4430" target="_blank">CVE-2024-4430</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3083534%40beaver-builder-lite-version%2Ftrunk&amp;old=3078825%40beaver-builder-lite-version%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cd6ed285-f215-44d3-9db9-9b2bfffee60a?source=cve" target="_blank">security@wordfence.com</a><br><a href="https://www.wpbeaverbuilder.com/change-logs/?utm_medium=bb-lite&amp;utm_source=repo-readme&amp;utm_campaign=repo-changelog-page" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>kraftplugins--Mega Elements Addons for Elementor<br> </td>
<td>The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4702&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4702" target="_blank">CVE-2024-4702</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085457/mega-elements-addons-for-elementor" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3808ca2a-e78e-4118-890b-c22a71f8e855?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>levelfourstorefront--Shopping Cart &amp; eCommerce Store<br> </td>
<td>The Shopping Cart &amp; eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.4 via the order report functionality. This makes it possible for unauthenticated attackers to extract sensitive data including order details such as payment details, addresses and other PII.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4213&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4213" target="_blank">CVE-2024-4213</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084202/wp-easycart/trunk/admin/inc/wp_easycart_admin.php?old=3068711&amp;old_path=wp-easycart%2Ftrunk%2Fadmin%2Finc%2Fwp_easycart_admin.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/93daab72-1243-4a05-91d3-9254a1aac727?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>litonice13--Master Addons Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor<br> </td>
<td>The Master Addons - Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title_html_tag attribute in all versions up to, and including, 2.0.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3134&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3134" target="_blank">CVE-2024-3134</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3087193%40master-addons%2Ftrunk&amp;old=3078134%40master-addons%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6106c972-5475-4c19-8630-3a01edc616ad?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>litonice13--Master Addons Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor<br> </td>
<td>The Master Addons - Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.0.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4580&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4580" target="_blank">CVE-2024-4580</a><br><a href="https://plugins.trac.wordpress.org/browser/master-addons/trunk/addons/ma-image-hover-effects/ma-image-hover-effects.php#L1546" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/master-addons/trunk/addons/ma-tabs/ma-tabs.php#L1068" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087193/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e3e3ac84-dd82-42b0-80b9-c876731170d5?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>mantisbt--mantisbt<br> </td>
<td>MantisBT (Mantis Bug Tracker) is an open source issue tracker. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when resolving or closing issues (`bug_change_status_page.php`) belonging to a project linking said custom field, viewing issues (`view_all_bug_page.php`) when the custom field is displayed as a column, or printing issues (`print_all_bug_page.php`) when the custom field is displayed as a column. Version 2.26.2 contains a patch for the issue. As a workaround, ensure Custom Field Names do not contain HTML tags.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34081&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34081" target="_blank">CVE-2024-34081</a><br><a href="https://github.com/mantisbt/mantisbt/commit/447a521aae0f82f791b8116a14a20e276df739be" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/mantisbt/mantisbt/security/advisories/GHSA-wgx7-jp56-65mq" target="_blank">security-advisories@github.com</a><br><a href="https://mantisbt.org/bugs/view.php?id=34432" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>mantisbt--mantisbt<br> </td>
<td>MantisBT (Mantis Bug Tracker) is an open source issue tracker. If an issue references a note that belongs to another issue that the user doesn't have access to, then it gets hyperlinked. Clicking on the link gives an access denied error as expected, yet some information remains available via the link, link label, and tooltip. This can result in disclosure of the existence of the note, the note author name, the note creation timestamp, and the issue id the note belongs to. Version 2.26.2 contains a patch for the issue. No known workarounds are available.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34080&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34080" target="_blank">CVE-2024-34080</a><br><a href="https://github.com/mantisbt/mantisbt/commit/0a50562369d823689c9b946066d1e49d3c2df226" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/mantisbt/mantisbt/pull/2000" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/mantisbt/mantisbt/security/advisories/GHSA-99jc-wqmr-ff2q" target="_blank">security-advisories@github.com</a><br><a href="https://mantisbt.org/bugs/view.php?id=34434" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>matrix-org--matrix-sdk-crypto<br> </td>
<td>The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption state machine in Rust. In Matrix, the server-side `key backup` stores encrypted copies of Matrix message keys. This facilitates key sharing between a user's devices and provides a redundant copy in case all devices are lost. The key backup uses asymmetric cryptography, with each server-side key backup assigned a unique public-private key pair. Due to a logic bug introduced in commit 71136e44c03c79f80d6d1a2446673bc4d53a2067, matrix-sdk-crypto version 0.7.0 will sometimes log the private part of the backup key pair to Rust debug logs (using the `tracing` crate). This issue has been resolved in matrix-sdk-crypto version 0.7.1. No known workarounds are available.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34353&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34353" target="_blank">CVE-2024-34353</a><br><a href="https://crates.io/crates/matrix-sdk-crypto/0.7.1" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/matrix-org/matrix-rust-sdk/commit/71136e44c03c79f80d6d1a2446673bc4d53a2067" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/matrix-org/matrix-rust-sdk/commit/fa10bbb5dd0f9120a51aa1854cec752e25790bb0" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/matrix-org/matrix-rust-sdk/releases/tag/matrix-sdk-crypto-0.7.1" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/matrix-org/matrix-rust-sdk/security/advisories/GHSA-9ggc-845v-gcgv" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>matter-labs--era-compiler-solidity<br> </td>
<td>era-compiler-solidity is the ZKsync compiler for Solidity. The problem occurred during instruction selection in the `DAGCombine` phase while visiting the XOR operation. The issue arises when attempting to fold the expression `!(x cc y)` into `(x !cc y)`. To perform this transformation, the second operand of XOR should be a constant representing the true value. However, it was incorrectly assumed that -1 represents the true value, when in fact, 1 is the correct representation, so this transformation for this case should be skipped. This vulnerability is fixed in 1.4.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34704&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34704" target="_blank">CVE-2024-34704</a><br><a href="https://github.com/matter-labs/era-compiler-solidity/security/advisories/GHSA-22pj-7cvw-r3gc" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>mgibbs189--Custom Field Suite<br> </td>
<td>The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' parameter in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3068&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3068" target="_blank">CVE-2024-3068</a><br><a href="https://plugins.trac.wordpress.org/browser/custom-field-suite/trunk/templates/field_html.php?order=date&amp;desc=1#L46" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3080330%40custom-field-suite%2Ftrunk&amp;old=3042177%40custom-field-suite%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0ab546cc-b099-4d26-bf42-785952fcfd8c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>mihdan--Mihdan: Yandex Turbo Feed<br> </td>
<td>The Mihdan: Yandex Turbo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.6.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4411&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4411" target="_blank">CVE-2024-4411</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3081039%40mihdan-yandex-turbo-feed%2Ftrunk&amp;old=3005548%40mihdan-yandex-turbo-feed%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6ecf99ef-f879-426f-8a05-129be77f1157?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>miraheze--CreateWiki<br> </td>
<td>CreateWiki is Miraheze's MediaWiki extension for requesting &amp; creating wikis. It is possible for users to be considered as the requester of a specific wiki request if their local user ID on any wiki in a wiki farm matches the local ID of the requester at the wiki where the wiki request was made. This allows them to go to that request entry's on Special:RequestWikiQueue on the wiki where their local user ID matches and take any actions that the wiki requester is allowed to take from there. Commit 02e0f298f8d35155c39aa74193cb7b867432c5b8 fixes the issue. Important note about the fix: This vulnerability has been fixed by disabling access to the REST API and special pages outside of the wiki configured as the "global wiki" in `$wgCreateWikiGlobalWiki` in a user's MediaWiki settings. As a workaround, it is possible to disable the special pages outside of one's own global wiki by doing something similar to `miraheze/mw-config` commit e5664995fbb8644f9a80b450b4326194f20f9ddc that is adapted to one's own setup. As for the REST API, before the fix, there wasn't any REST endpoint that allowed one to make writes. Regardless, it is possible to also disable it outside of the global wiki by using `$wgCreateWikiDisableRESTAPI` and `$wgConf` in the configuration for one's own wiki farm..</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34701&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34701" target="_blank">CVE-2024-34701</a><br><a href="https://github.com/miraheze/CreateWiki/commit/02e0f298f8d35155c39aa74193cb7b867432c5b8" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/miraheze/CreateWiki/security/advisories/GHSA-89fx-77w7-rc64" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/miraheze/mw-config/commit/1798e53901a202b62edab32f8bcd5c6b9e574191" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/miraheze/mw-config/commit/e5664995fbb8644f9a80b450b4326194f20f9ddc" target="_blank">security-advisories@github.com</a><br><a href="https://issue-tracker.miraheze.org/T12011" target="_blank">security-advisories@github.com</a><br><a href="https://issue-tracker.miraheze.org/T12102" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>monetizemore--Advanced Ads  Ad Manager &amp; AdSense<br> </td>
<td>The Advanced Ads - Ad Manager &amp; AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Ad widget in all versions up to, and including, 1.52.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3952&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3952" target="_blank">CVE-2024-3952</a><br><a href="https://plugins.trac.wordpress.org/browser/advanced-ads/tags/1.52.1/modules/gutenberg/includes/class-gutenberg.php#L224" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3081914%40advanced-ads&amp;new=3081914%40advanced-ads&amp;sfp_email=&amp;sfph_mail=#file4" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4ea634b5-72db-428c-96b4-15ef6025ab1d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>mra13--Simple Membership<br> </td>
<td>The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4383&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4383" target="_blank">CVE-2024-4383</a><br><a href="https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.4.3/classes/shortcode-related/class.swpm-shortcodes-handler.php#L228" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3081024/simple-membership/trunk/classes/shortcode-related/class.swpm-shortcodes-handler.php?old=3010737&amp;old_path=%2Fsimple-membership%2Ftrunk%2Fclasses%2Fshortcode-related%2Fclass.swpm-shortcodes-handler.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/56fdbf80-8ea2-412a-b166-b7c27de88e70?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>n/a--DedeCMS<br> </td>
<td>A vulnerability classified as problematic has been found in DedeCMS 5.7.114. This affects an unknown part of the file /sys_verifies.php?action=view. The manipulation of the argument filename with the input ../../../../../etc/passwd leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263889 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4790&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4790" target="_blank">CVE-2024-4790</a><br><a href="https://github.com/gatsby2003/DedeCms/blob/main/Directory_traversal_arbitrary_file_read.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263889" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263889" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.329483" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>n/a--Emlog Pro<br> </td>
<td>A vulnerability was found in Emlog Pro 2.3.4 and classified as critical. Affected by this issue is some unknown functionality of the file admin/setting.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264740. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5043&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5043" target="_blank">CVE-2024-5043</a><br><a href="https://github.com/ssteveez/emlog/blob/main/emlog%20pro%20version%202.3.4%20Admin%20side%20can%20upload%20arbitrary%20files%20and%20getshell.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264740" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264740" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331854" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>n/a--Endurance Gaming Mode software installers<br> </td>
<td>Incorrect default permissions in some Endurance Gaming Mode software installers before version 1.3.937.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-42433&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-42433" target="_blank">CVE-2023-42433</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00965.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Advisor software<br> </td>
<td>Uncontrolled search path in some Intel(R) Advisor software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21772&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21772" target="_blank">CVE-2024-21772</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01047.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) BIOS PPAM firmware<br> </td>
<td>Improper conditions check in some Intel(R) BIOS PPAM firmware may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-28383&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-28383" target="_blank">CVE-2023-28383</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00814.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) CST software<br> </td>
<td>Uncontrolled search path for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-40155&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40155" target="_blank">CVE-2023-40155</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01021.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) CST software<br> </td>
<td>Improper access control for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-39433&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-39433" target="_blank">CVE-2023-39433</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01021.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) CST software<br> </td>
<td>Null pointer dereference for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41082&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41082" target="_blank">CVE-2023-41082</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01021.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) CST<br> </td>
<td>Improper access control in some Intel(R) CST before version 2.1.10300 may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43487&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43487" target="_blank">CVE-2023-43487</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01021.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Chipset Device Software<br> </td>
<td>Uncontrolled search path for some Intel(R) Chipset Device Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21814&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21814" target="_blank">CVE-2024-21814</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01032.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Computing Improvement Program software<br> </td>
<td>Uncontrolled search path for some Intel(R) Computing Improvement Program software before version 2.4.0.10654 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21843&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21843" target="_blank">CVE-2024-21843</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01059.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Core(TM) Ultra Processors<br> </td>
<td>Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46103&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46103" target="_blank">CVE-2023-46103</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01052.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) DLB driver software<br> </td>
<td>Improper input validation for some Intel(R) DLB driver software before version 8.5.0 may allow an authenticated user to potentially denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22015&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22015" target="_blank">CVE-2024-22015</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00996.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) DSA and Intel(R) IAA for some Intel(R) 4th or 5th generation Xeon(R) processors<br> </td>
<td>Hardware logic with insecure de-synchronization in Intel(R) DSA and Intel(R) IAA for some Intel(R) 4th or 5th generation Xeon(R) processors may allow an authorized user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21823&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21823" target="_blank">CVE-2024-21823</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01084.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) DSA software uninstallers<br> </td>
<td>Uncontrolled search path in some Intel(R) DSA software uninstallers before version 23.4.39.10 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45743&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45743" target="_blank">CVE-2023-45743</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01031.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Data Center GPU Max Series 1100 and 1550 products<br> </td>
<td>Improper conditions check in the Intel(R) Data Center GPU Max Series 1100 and 1550 products may allow an privileged user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47165&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47165" target="_blank">CVE-2023-47165</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01041.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Distribution for GDB software<br> </td>
<td>Uncontrolled search path for some Intel(R) Distribution for GDB software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21841&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21841" target="_blank">CVE-2024-21841</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01042.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Ethernet Controller Administrative Tools software<br> </td>
<td>Improper access control in some Intel(R) Ethernet Controller Administrative Tools software before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21828&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21828" target="_blank">CVE-2024-21828</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01056.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) FPGA products<br> </td>
<td>Out of bounds write in firmware for some Intel(R) FPGA products before version 2.9.0 may allow escalation of privilege and information disclosure.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-49614&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-49614" target="_blank">CVE-2023-49614</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01050.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) FPGA products<br> </td>
<td>Improper input validation in firmware for some Intel(R) FPGA products before version 2.9.1 may allow denial of service.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22390&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22390" target="_blank">CVE-2024-22390</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01050.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA Framework software<br> </td>
<td>Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-35192&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-35192" target="_blank">CVE-2023-35192</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA Framework software<br> </td>
<td>Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21861&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21861" target="_blank">CVE-2024-21861</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01067.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA software<br> </td>
<td>Uncontrolled search path in some Intel(R) GPA software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41961&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41961" target="_blank">CVE-2023-41961</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA software<br> </td>
<td>Uncontrolled search path in some Intel(R) GPA software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21788&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21788" target="_blank">CVE-2024-21788</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01067.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Graphics Windows DCH driver software<br> </td>
<td>Uncontrolled search path in Intel(R) Graphics Command Center Service bundled in some Intel(R) Graphics Windows DCH driver software before versions 31.0.101.3790/31.0.101.2114 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43751&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43751" target="_blank">CVE-2023-43751</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00937.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Inspector software<br> </td>
<td>Uncontrolled search path in some Intel(R) Inspector software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22379&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22379" target="_blank">CVE-2024-22379</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01043.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Media SDK software<br> </td>
<td>Improper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-48368&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-48368" target="_blank">CVE-2023-48368</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Media SDK<br> </td>
<td>Improper buffer restrictions in Intel(R) Media SDK all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45221&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45221" target="_blank">CVE-2023-45221</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Neural Compressor software<br> </td>
<td>Time-of-check Time-of-use race condition in Intel(R) Neural Compressor software before version 2.5.0 may allow an authenticated user to potentially enable information disclosure via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21792&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21792" target="_blank">CVE-2024-21792</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01109.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) PCM software<br> </td>
<td>Uncontrolled search path in some Intel(R) PCM software before version 202311 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21818&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21818" target="_blank">CVE-2024-21818</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01035.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) PROSet/Wireless WiFi software for Windows<br> </td>
<td>Race condition for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-40536&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40536" target="_blank">CVE-2023-40536</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) PROSet/Wireless WiFi software for linux<br> </td>
<td>Improper input validation for some Intel(R) PROSet/Wireless WiFi software for linux before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47210&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47210" target="_blank">CVE-2023-47210</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) PROSet/Wireless WiFi software<br> </td>
<td>Improper input validation for some Intel(R) PROSet/Wireless WiFi software before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38417&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38417" target="_blank">CVE-2023-38417</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>Insecure inherited permissions in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45736&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45736" target="_blank">CVE-2023-45736</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>NULL pointer dereference in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41234&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41234" target="_blank">CVE-2023-41234</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windwos<br> </td>
<td>Improper initialization in some Intel(R) Power Gadget software for Windwos all versions may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45315&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45315" target="_blank">CVE-2023-45315</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for macOS<br> </td>
<td>Incomplete cleanup in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45846&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45846" target="_blank">CVE-2023-45846</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Processor Diagnostic Tool software<br> </td>
<td>Uncontrolled search path in some Intel(R) Processor Diagnostic Tool software before version 4.1.9.41 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21831&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21831" target="_blank">CVE-2024-21831</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01069.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Processor Identification Utility software<br> </td>
<td>Uncontrolled search path in some Intel(R) Processor Identification Utility software before versions 6.10.34.1129, 7.1.6 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21774&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21774" target="_blank">CVE-2024-21774</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01054.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Quartus(R) Prime Lite Edition Design software<br> </td>
<td>Improper conditions check for some Intel(R) Quartus(R) Prime Lite Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21809&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21809" target="_blank">CVE-2024-21809</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01055.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Quartus(R) Prime Lite Edition Design software<br> </td>
<td>Uncontrolled search path in some Intel(R) Quartus(R) Prime Lite Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21837&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21837" target="_blank">CVE-2024-21837</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01055.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Quartus(R) Prime Pro Edition Design software<br> </td>
<td>Uncontrolled search path in some Intel(R) Quartus(R) Prime Pro Edition Design software before version 23.4 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21777&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21777" target="_blank">CVE-2024-21777</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01055.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Quartus(R) Prime Standard Edition Design software<br> </td>
<td>Uncontrolled search path in some Intel(R) Quartus(R) Prime Standard Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21862&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21862" target="_blank">CVE-2024-21862</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01055.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) TDX module software<br> </td>
<td>Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47855&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47855" target="_blank">CVE-2023-47855</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01036.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) VTune(TM) Profiler software<br> </td>
<td>Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45320&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45320" target="_blank">CVE-2023-45320</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01034.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Wireless Bluetooth products for Windows<br> </td>
<td>Improper access control for some Intel(R) Wireless Bluetooth products for Windows before version 23.20 may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47859&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47859" target="_blank">CVE-2023-47859</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Wireless Bluetooth(R) products for Windows<br> </td>
<td>Improper conditions check for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.20 may allow a privileged user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45845&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45845" target="_blank">CVE-2023-45845</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) XTU software<br> </td>
<td>Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21835&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21835" target="_blank">CVE-2024-21835</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01066.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Libva software maintained by Intel(R)<br> </td>
<td>Uncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-39929&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-39929" target="_blank">CVE-2023-39929</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01012.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--UEFI firmware for some Intel(R) Server Board S2600BP products<br> </td>
<td>Improper input validation of EpsdSrMgmtConfig in UEFI firmware for some Intel(R) Server Board S2600BP products may allow a privileged user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-22662&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">5.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-22662" target="_blank">CVE-2023-22662</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary file permission writes. (The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31952&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31952" target="_blank">CVE-2024-31952</a><br><a href="https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31952/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31953&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31953" target="_blank">CVE-2024-31953</a><br><a href="https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31953/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A crafted network packet may cause a buffer overrun in Wind River VxWorks 7 through 23.09.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28759&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28759" target="_blank">CVE-2024-28759</a><br><a href="https://support2.windriver.com/index.php?page=cve&amp;on=view&amp;id=CVE-2024-28759" target="_blank">cve@mitre.org</a><br><a href="https://windriver.com/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--onboard video driver software for Intel(R) Server Boards based on Intel(R) 62X Chipset<br> </td>
<td>Incorrect default permissions in some onboard video driver software before version 1.14 for Intel(R) Server Boards based on Intel(R) 62X Chipset may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-42668&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-42668" target="_blank">CVE-2023-42668</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00962.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>nalam-1--Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )<br> </td>
<td>The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text effect widget in all versions up to, and including, 1.1.37 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2923&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2923" target="_blank">CVE-2024-2923</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3078558%40magical-addons-for-elementor&amp;new=3078558%40magical-addons-for-elementor&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/733f5ded-e8cb-4895-b938-889cea32f027?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>nko--Visual Portfolio, Photo Gallery &amp; Post Grid<br> </td>
<td>The Visual Portfolio, Photo Gallery &amp; Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4363&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4363" target="_blank">CVE-2024-4363</a><br><a href="https://plugins.trac.wordpress.org/browser/visual-portfolio/trunk/templates/items-list/item-parts/title.php#L22" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/visual-portfolio/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ab5e09d8-6fa3-4a5b-bee1-6648df4f4b3b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>nocodb--nocodb<br> </td>
<td>NocoDB is software for building databases as spreadsheets. Prior to version 0.202.10, an authenticated attacker with create access could conduct a SQL Injection attack on MySQL DB using unescaped `table_name`. This vulnerability may result in leakage of sensitive data in the database. Version 0.202.10 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-50718&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-50718" target="_blank">CVE-2023-50718</a><br><a href="https://github.com/nocodb/nocodb/security/advisories/GHSA-8fxg-mr34-jqr8" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>nocodb--nocodb<br> </td>
<td>NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html file with malicious content. If user tries to open that file in browser malicious scripts can be executed leading stored cross-site scripting attack. This allows remote attacker to execute JavaScript code in the context of the user accessing the vector. An attacker could have used this vulnerability to execute requests in the name of a logged-in user or potentially collect information about the attacked user by displaying a malicious form. Version 0.202.10 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-50717&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-50717" target="_blank">CVE-2023-50717</a><br><a href="https://github.com/nocodb/nocodb/security/advisories/GHSA-qg73-g3cf-vhhh" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>nvidia--ChatRTX<br> </td>
<td>NVIDIA ChatRTX for Windows contains a vulnerability in the ChatRTX UI and backend, where a user can cause a clear-text transmission of sensitive information issue by data sniffing. A successful exploit of this vulnerability might lead to information disclosure.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0098&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0098" target="_blank">CVE-2024-0098</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5533" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>nvidia--NVIDIA Triton Inference Server<br> </td>
<td>NVIDIA Triton Inference Server for Linux contains a vulnerability in the tracing API, where a user can corrupt system files. A successful exploit of this vulnerability might lead to denial of service and data tampering.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0100&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0100" target="_blank">CVE-2024-0100</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5535" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>nvidia--NVIDIA Triton Inference Server<br> </td>
<td>NVIDIA Triton Inference Server for Linux contains a vulnerability in shared memory APIs, where a user can cause an improper memory access issue by a network API. A successful exploit of this vulnerability might lead to denial of service and data tampering.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0088&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0088" target="_blank">CVE-2024-0088</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5535" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>optimole--Image Optimization by Optimole Lazy Load, CDN, Convert WebP &amp; AVIF<br> </td>
<td>The Image Optimization by Optimole - Lazy Load, CDN, Convert WebP &amp; AVIF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allow_meme_types' function in versions up to, and including, 3.12.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4636&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4636" target="_blank">CVE-2024-4636</a><br><a href="https://plugins.trac.wordpress.org/browser/optimole-wp/tags/3.12.10/inc/admin.php#L1828" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086306/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/be88566d-fc84-442d-bb34-834ad9f4465b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>paperless-ngx--paperless-ngx<br> </td>
<td>Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prior to version 2.8.6, remote user authentication allows API access even if API access is explicitly disabled. Version 2.8.6 contains a patchc for the issue.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35184&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35184" target="_blank">CVE-2024-35184</a><br><a href="https://github.com/paperless-ngx/paperless-ngx/commit/ed05b40ba461641b1b59b0a92f51f3f6a66ce180" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/paperless-ngx/paperless-ngx/pull/6739" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/paperless-ngx/paperless-ngx/releases/tag/v2.8.6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/paperless-ngx/paperless-ngx/security/advisories/GHSA-72w4-hxqq-c256" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>phpbits--Forty Four 404 Plugin for WordPress<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phpbits Forty Four - 404 Plugin for WordPress allows Stored XSS.This issue affects Forty Four - 404 Plugin for WordPress: from n/a through 1.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34423&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34423" target="_blank">CVE-2024-34423</a><br><a href="https://patchstack.com/database/vulnerability/forty-four/wordpress-forty-four-404-plugin-for-wordpress-plugin-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>piotnetdotcom--Piotnet Addons For Elementor<br> </td>
<td>The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.4.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4432&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4432" target="_blank">CVE-2024-4432</a><br><a href="https://plugins.trac.wordpress.org/browser/piotnet-addons-for-elementor/trunk/widgets/pafe-before-after-image-comparison-slider.php#L195" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/piotnet-addons-for-elementor/trunk/widgets/pafe-table.php#L195" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087322/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4f65a7df-acb5-4b5b-8867-986ce9930e3f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>posimyththemes--The Plus Addons for Elementor Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce<br> </td>
<td>The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's element attributes in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-34373 is likely a duplicate of this issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0445&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0445" target="_blank">CVE-2024-0445</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.3.4/modules/widgets/tp_flip_box.php#L2323" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.3.4/modules/widgets/tp_info_box.php#L2928" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.3.4/modules/widgets/tp_pricing_table.php#L2942" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.5.0/modules/widgets/tp_flip_box.php#L2388" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.5.0/modules/widgets/tp_info_box.php#L2997" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.5.0/modules/widgets/tp_pricing_table.php#L2960" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a412e682-869a-46ba-a2d0-d84ed542adc9?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>posimyththemes--The Plus Addons for Elementor Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce<br> </td>
<td>The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate widget in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2785&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2785" target="_blank">CVE-2024-2785</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.5.0/modules/widgets/tp_age_gate.php?annotate=blame#L2389" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3076733%40the-plus-addons-for-elementor-page-builder&amp;new=3076733%40the-plus-addons-for-elementor-page-builder&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d0117436-7a2a-42f3-8c05-75dfddfb9d09?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>prasunsen--Hostel<br> </td>
<td>The Hostel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5.3. This is due to missing or incorrect nonce validation when managing rooms. This makes it possible for unauthenticated attackers to create and delete rooms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4314&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4314" target="_blank">CVE-2024-4314</a><br><a href="https://plugins.trac.wordpress.org/changeset/3079755/hostel/trunk?contextall=1&amp;old=3070681&amp;old_path=%2Fhostel%2Ftrunk" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6a8c5d9b-4535-4edb-a92e-a9b83a0d22c3?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>pt-guy--Content Views Post Grid &amp; Filter, Recent Posts, Category Posts, &amp; More (Gutenberg Blocks and Shortcode)<br> </td>
<td>The Content Views - Post Grid &amp; Filter, Recent Posts, Category Posts, &amp; More (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagingType' parameter in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4446&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4446" target="_blank">CVE-2024-4446</a><br><a href="https://plugins.trac.wordpress.org/browser/content-views-query-and-display-post-page/tags/3.7.1/includes/html.php#L803" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/65504747-7f1b-43f9-be4d-48b9547e7c45?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>pure-chat--Pure Chat Live Chat Plugin &amp; More!<br> </td>
<td>The Pure Chat - Live Chat Plugin &amp; More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the purechatwid and purechatwname parameter in all versions up to, and including, 2.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3595&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3595" target="_blank">CVE-2024-3595</a><br><a href="https://wordpress.org/plugins/pure-chat/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5d03c798-dc77-407c-8674-d0bd2f1ada8c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>rankmath--Rank Math SEO with AI Best SEO Tools<br> </td>
<td>The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'textAlign' parameter in versions up to, and including, 1.0.217 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4335&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4335" target="_blank">CVE-2024-4335</a><br><a href="https://plugins.trac.wordpress.org/browser/seo-by-rank-math/tags/1.0.217/includes/modules/schema/blocks/class-block.php#L64" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3080259/#file26" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/96eba67c-58e7-4eea-84d4-9b3bb275b42d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>rankmath--Rank Math SEO with AI Best SEO Tools<br> </td>
<td>The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in versions up to, and including, 1.0.218 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4617&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4617" target="_blank">CVE-2024-4617</a><br><a href="https://plugins.trac.wordpress.org/browser/seo-by-rank-math/trunk/includes/modules/schema/blocks/class-block-faq.php#L183" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084351/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/474fdbcb-fe3c-4a79-a847-363f81b300c2?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>realmag777--WordPress Meta Data and Taxonomies Filter (MDTF)<br> </td>
<td>Incorrect Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Inclusion, Functionality Misuse.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34434&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34434" target="_blank">CVE-2024-34434</a><br><a href="https://patchstack.com/database/vulnerability/wp-meta-data-filter-and-taxonomy-filter/wordpress-mdtf-meta-data-and-taxonomies-filter-plugin-1-3-3-2-arbitrary-shortcode-execution-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>redbitcz--SimpleShop<br> </td>
<td>The SimpleShop plugin for WordPress is vulnerable to unauthorized disconnection from SimpleShop due to a missing capability check on the maybe_disconnect_simpleshop function in all versions up to, and including, 2.10.2. This makes it possible for unauthenticated attackers to disconnect the SimpleShop.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1229&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1229" target="_blank">CVE-2024-1229</a><br><a href="https://plugins.trac.wordpress.org/browser/simpleshop-cz/trunk/src/Settings.php?rev=3019145#L341" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3080151%40simpleshop-cz&amp;new=3080151%40simpleshop-cz&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4dc39c47-3b99-4e43-b25d-a025f3d228b5?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>redbitcz--SimpleShop<br> </td>
<td>The SimpleShop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.0. This is due to missing or incorrect nonce validation on the maybe_disconnect_simpleshop function. This makes it possible for unauthenticated attackers to disconnect the site from simpleshop via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1230&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1230" target="_blank">CVE-2024-1230</a><br><a href="https://github.com/redbitcz/simpleshop-wp-plugin/commit/8b04c95bb29036658e6a5b1ef735440646e3199b" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/simpleshop-cz/trunk/src/Settings.php?rev=3019145#L341" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9870db7f-0c8e-44a4-aa0f-13709d773756?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>reviewx--ReviewX Multi-criteria Rating &amp; Reviews for WooCommerce<br> </td>
<td>The ReviewX - Multi-criteria Rating &amp; Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all versions up to, and including, 1.6.27. This makes it possible for authenticated attackers, with subscriber access and above, to delete attachments.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3609&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3609" target="_blank">CVE-2024-3609</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3086273%40reviewx%2Ftrunk&amp;old=3054184%40reviewx%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f8152adf-1ca9-4a19-b539-39e257ab94c8?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>ruby--rexml<br> </td>
<td>REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `&lt;`s in an attribute value. Those who need to parse untrusted XMLs may be impacted to this vulnerability. The REXML gem 3.2.7 or later include the patch to fix this vulnerability. As a workaround, don't parse untrusted XMLs.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35176&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35176" target="_blank">CVE-2024-35176</a><br><a href="https://github.com/ruby/rexml/commit/4325835f92f3f142ebd91a3fdba4e1f1ab7f1cfb" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh" target="_blank">security-advisories@github.com</a><br><a href="https://www.ruby-lang.org/en/news/2024/05/16/dos-rexml-cve-2024-35176" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>sbouey--Falang multilanguage for WordPress<br> </td>
<td>The Falang multilanguage for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.3.49 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4417&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4417" target="_blank">CVE-2024-4417</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3082466%40falang%2Ftrunk&amp;old=3059173%40falang%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b62949fd-d73f-4c42-82c7-c29986bca1da?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>sc0ttkclark--Pods Custom Content Types and Fields<br> </td>
<td>The Pods - Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pod Form widget in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3956&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3956" target="_blank">CVE-2024-3956</a><br><a href="https://plugins.trac.wordpress.org/browser/pods/tags/3.2.1/ui/front/form.php#L105" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083418/pods/tags/3.1.4.1/includes/data.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083418/pods/tags/3.1.4.1/ui/front/form.php" target="_blank">security@wordfence.com</a><br><a href="https://pods.io/2024/05/08/pods-3-2-1-1-security-release/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a0707c92-96e9-444a-8a13-52d49c9e3f5c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>shaonsina--Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets &amp; Elementor Templates)<br> </td>
<td>The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets &amp; Elementor Templates) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via several parameters in versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4333&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4333" target="_blank">CVE-2024-4333</a><br><a href="https://plugins.trac.wordpress.org/browser/sina-extension-for-elementor/trunk/assets/js/jquery.countdown.min.js" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/sina-extension-for-elementor/trunk/assets/js/typed.min.js" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085825/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f616df94-7839-49db-baa5-88f8f1de208f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>shaonsina--Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets &amp; Elementor Templates)<br> </td>
<td>The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets &amp; Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sina Particle Layer widget in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4373&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4373" target="_blank">CVE-2024-4373</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3085825%40sina-extension-for-elementor&amp;new=3085825%40sina-extension-for-elementor&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/eee04b1d-188a-4b92-a6f3-dfa843ca20d7?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>smartersite--WP Compress Image Optimizer [All-In-One]<br> </td>
<td>The WP Compress - Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the several functions in versions up to, and including, 6.20.01. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit plugin settings, including storing cross-site scripting, in multisite environments.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4445&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4445" target="_blank">CVE-2024-4445</a><br><a href="https://plugins.trac.wordpress.org/browser/wp-compress-image-optimizer/trunk/classes/mu.class.php?rev=2946135" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082085/#file655" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/830f53a4-da3b-4a95-99f1-c4a4c8e6944c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>smartersite--WP Compress Image Optimizer [All-In-One]<br> </td>
<td>The WP Compress - Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.20.01. This is due to insufficient validation on the redirect url supplied via the 'css' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6812&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6812" target="_blank">CVE-2023-6812</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082085/wp-compress-image-optimizer/trunk/fixCss.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cbbf9fbb-74fd-42eb-a781-2a720fe56b13?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>smartypants--SP Project &amp; Document Manager<br> </td>
<td>The SP Project &amp; Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cdm_save_category AJAX action in all versions up to, and including, 4.70. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary folder name that do not belong to them.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1693&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1693" target="_blank">CVE-2024-1693</a><br><a href="https://plugins.trac.wordpress.org/browser/sp-client-document-manager/trunk/classes/ajax.php#L786" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1951ad6c-17b5-44ae-85e2-376b99df742e?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>solidus--solidus<br> </td>
<td>Solidus &lt;= 4.3.4 is affected by a Stored Cross-Site Scripting vulnerability in the order tracking URL.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4859&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4859" target="_blank">CVE-2024-4859</a><br><a href="https://www.tenable.com/security/research/tra-2024-15" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>squelch--Squelch Tabs and Accordions Shortcodes<br> </td>
<td>The Squelch Tabs and Accordions Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.4.7. This is due to missing or incorrect nonce validation when saving plugin settings. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4463&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4463" target="_blank">CVE-2024-4463</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3082482%40squelch-tabs-and-accordions-shortcodes%2Ftrunk&amp;old=3067680%40squelch-tabs-and-accordions-shortcodes%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cd9490f2-ad52-477e-ae3b-be49984e8189?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>stacklok--minder<br> </td>
<td>Minder is a software supply chain security platform. Prior to version 0.0.49, the Minder REST ingester is vulnerable to a denial of service attack via an attacker-controlled REST endpoint that can crash the Minder server. The REST ingester allows users to interact with REST endpoints to fetch data for rule evaluation. When fetching data with the REST ingester, Minder sends a request to an endpoint and will use the data from the body of the response as the data to evaluate against a certain rule. If the response is sufficiently large, it can drain memory on the machine and crash the Minder server. The attacker can control the remote REST endpoints that Minder sends requests to, and they can configure the remote REST endpoints to return responses with large bodies. They would then instruct Minder to send a request to their configured endpoint that would return the large response which would crash the Minder server. Version 0.0.49 fixes this issue.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35185&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35185" target="_blank">CVE-2024-35185</a><br><a href="https://github.com/stacklok/minder/commit/065049336aac0621ee00a0bb2211f8051d47c14b" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/stacklok/minder/security/advisories/GHSA-fjw8-3gp8-4cvx" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>stalwartlabs--mail-server<br> </td>
<td>Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, when using `RUN_AS_USER`, the specified user (and therefore, web interface admins) can read arbitrary files as root. This issue affects admins who have set up to run stalwart with `RUN_AS_USER` who handed out admin credentials to the mail server but expect these to only grant access according to the `RUN_AS_USER` and are attacked where the attackers managed to achieve Arbitrary Code Execution using another vulnerability. Version 0.8.0 contains a patch for the issue.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35179&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35179" target="_blank">CVE-2024-35179</a><br><a href="https://github.com/stalwartlabs/mail-server/security/advisories/GHSA-5pfx-j27j-4c6h" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>stellar--stellar-core<br> </td>
<td>Stellar-core is a reference implementation for the peer-to-peer agent that manages the Stellar network. Prior to 20.4.0, core nodes could be randomly crashed due to a race condition with a 3rd party library. The likelihood of affecting the network is low since crashed nodes come back up online right away. Code fix mitigation is part of Stellar-core v20.4.0 release</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32985&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32985" target="_blank">CVE-2024-32985</a><br><a href="https://github.com/stellar/stellar-core/security/advisories/GHSA-mgx8-frjx-x33m" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>swte--Swift Performance Lite<br> </td>
<td>The Swift Performance Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_handler() function in all versions up to, and including, 2.3.6.18. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve and modify settings.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3722&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3722" target="_blank">CVE-2024-3722</a><br><a href="https://plugins.trac.wordpress.org/browser/swift-performance-lite/trunk/includes/setup/setup.php#L97" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/58b7736a-e3e0-4ecd-9adf-284568b02ef7?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>talspotim--Comments Evolved for WordPress<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in talspotim Comments Evolved for WordPress allows Stored XSS.This issue affects Comments Evolved for WordPress: from n/a through 1.6.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34420&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34420" target="_blank">CVE-2024-34420</a><br><a href="https://patchstack.com/database/vulnerability/gplus-comments/wordpress-comments-evolved-for-wordpress-plugin-1-6-3-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>techjewel--Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder<br> </td>
<td>The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in all versions up to, and including, 5.1.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to the Fluent Forms settings, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This can be chained with CVE-2024-2771 for a low-privileged user to inject malicious web scripts.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2772&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2772" target="_blank">CVE-2024-2772</a><br><a href="https://plugins.trac.wordpress.org/changeset/3073857" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2ccba77c-fb90-4906-b0fe-77607ec5df1f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>tg123--sshpiper<br> </td>
<td>sshpiper is a reverse proxy for sshd. Starting in version 1.0.50 and prior to version 1.3.0, the way the proxy protocol listener is implemented in sshpiper can allow an attacker to forge their connecting address. Commit 2ddd69876a1e1119059debc59fe869cb4e754430 added the proxy protocol listener as the only listener in sshpiper, with no option to toggle this functionality off. This means that any connection that sshpiper is directly (or in some cases indirectly) exposed to can use proxy protocol to forge its source address. Any users of sshpiper who need logs from it for whitelisting/rate limiting/security investigations could have them become much less useful if an attacker is sending a spoofed source address. Version 1.3.0 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35175&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35175" target="_blank">CVE-2024-35175</a><br><a href="https://github.com/tg123/sshpiper/commit/2ddd69876a1e1119059debc59fe869cb4e754430" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/tg123/sshpiper/commit/70fb830dca26bea7ced772ce5d834a3e88ae7f53" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/tg123/sshpiper/security/advisories/GHSA-4w53-6jvp-gg52" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>thehappymonster--Happy Addons for Elementor<br> </td>
<td>The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4391&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4391" target="_blank">CVE-2024-4391</a><br><a href="https://plugins.trac.wordpress.org/browser/happy-elementor-addons/trunk/widgets/event-calendar/widget.php#L1811" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083138/happy-elementor-addons/trunk/widgets/event-calendar/widget.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e75f7e1a-f3bb-4b24-bf04-b83d0e572551?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thehappymonster--Happy Addons for Elementor<br> </td>
<td>The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied 'tooltip_position' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4478&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4478" target="_blank">CVE-2024-4478</a><br><a href="https://plugins.trac.wordpress.org/browser/happy-elementor-addons/tags/3.10.7/widgets/image-stack-group/widget.php#L611" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083138/#file584" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/happy-elementor-addons/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c7243f40-5cca-475a-bb27-44fab965bb0e?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thehappymonster--Happy Addons for Elementor<br> </td>
<td>The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_id' parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4865&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4865" target="_blank">CVE-2024-4865</a><br><a href="https://plugins.trac.wordpress.org/browser/happy-elementor-addons/trunk/widgets/skills/widget.php#L359" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087575/happy-elementor-addons/trunk/widgets/skills/widget.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2fdf2020-ad80-44c3-89b6-fc2ba067cd33?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thehappymonster--Happy Addons for Elementor<br> </td>
<td>The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_id' parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5088&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5088" target="_blank">CVE-2024-5088</a><br><a href="https://plugins.trac.wordpress.org/browser/happy-elementor-addons/trunk/widgets/skills/widget.php#L360" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087575/happy-elementor-addons/trunk/widgets/skills/widget.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/203ab09f-7344-4cab-86bf-0c1ec545d78f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themeisle--Menu Icons by ThemeIsle<br> </td>
<td>The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_mime_type' function in versions up to, and including, 0.13.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4635&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4635" target="_blank">CVE-2024-4635</a><br><a href="https://plugins.trac.wordpress.org/browser/menu-icons/tags/0.13.13/vendor/codeinwp/icon-picker/includes/types/svg.php#L69" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086753/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/90284576-6570-4e4c-8eb3-743bc402ea1b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themelooks--Enter Addons Ultimate Template Builder for Elementor<br> </td>
<td>The Enter Addons - Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Animation Title widget's img tag in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3680&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3680" target="_blank">CVE-2024-3680</a><br><a href="https://wordpress.org/plugins/enteraddons/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/29cc82cb-f3fd-4de5-9731-7ceb1212b0f9?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themelooks--Enter Addons Ultimate Template Builder for Elementor<br> </td>
<td>The Enter Addons - Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3831&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3831" target="_blank">CVE-2024-3831</a><br><a href="https://wordpress.org/plugins/enteraddons/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/62a4dd6a-f970-483e-b1a8-d57f604b7b66?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themeum--Tutor LMS eLearning and online course solution<br> </td>
<td>The Tutor LMS - eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Deletion in versions up to, and including, 2.7.0 via the 'tutor_course_delete' function due to missing validation on a user controlled key. This can allow authenticated attackers, with Instructor-level permissions and above, to delete any course.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4279&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4279" target="_blank">CVE-2024-4279</a><br><a href="https://plugins.trac.wordpress.org/browser/tutor/trunk/classes/Course_List.php#L357" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086489/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/45d04643-e43a-4732-91bf-e4af7b622e33?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themifyme--Themify Shortcodes<br> </td>
<td>The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themify_button shortcode in all versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4567&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4567" target="_blank">CVE-2024-4567</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082885/themify-shortcodes" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c63ff9d7-6a14-4186-8550-4e5c50855e7f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thimpress--LearnPress WordPress LMS Plugin<br> </td>
<td>The LearnPress - WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_html' parameter in all versions up to, and including, 4.2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4277&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4277" target="_blank">CVE-2024-4277</a><br><a href="https://plugins.trac.wordpress.org/browser/learnpress/tags/4.2.6.5/inc/ExternalPlugin/Elementor/Widgets/Instructor/ListInstructorsElementor.php?order=date#L96" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/46693edf-bcc6-4af8-9f26-5ede865f4694?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thimpress--LearnPress WordPress LMS Plugin<br> </td>
<td>The LearnPress - WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5. This is due to missing checks in the 'create_account' function in the checkout. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4444&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4444" target="_blank">CVE-2024-4444</a><br><a href="https://inky-knuckle-2c2.notion.site/Improper-Authentication-in-checkout-leads-privilege-escalation-of-unauthenticated-to-create-accoun-09da24a043884219a891dd1a0fc01af6" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/learnpress/tags/4.2.6.5/inc/class-lp-checkout.php#L79" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082204/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c9e1410f-10c9-4654-8b61-cfcdde696da7?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thimpress--Thim Elementor Kit<br> </td>
<td>The Thim Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4329&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4329" target="_blank">CVE-2024-4329</a><br><a href="https://plugins.trac.wordpress.org/browser/thim-elementor-kit/tags/1.1.9.1/inc/elementor/widgets/global/search-form.php#L819" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3275c47d-caf5-49e6-8aa2-20a6d8106f26?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>tigroumeow--Gallery Block (Meow Gallery)<br> </td>
<td>The Gallery Block (Meow Gallery) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_atts' parameter in versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4386&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4386" target="_blank">CVE-2024-4386</a><br><a href="https://plugins.trac.wordpress.org/browser/meow-gallery/trunk/classes/core.php#L273" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082976/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/477b41a5-b2ff-4b94-9622-824146a0e2ed?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>timstrifler--Exclusive Addons for Elementor<br> </td>
<td>The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Member widget in all versions up to, and including, 2.6.9.6 due to insufficient input sanitization and output escaping on user supplied 'url' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4618&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4618" target="_blank">CVE-2024-4618</a><br><a href="https://plugins.trac.wordpress.org/browser/exclusive-addons-for-elementor/tags/2.6.9.6/elements/team-member/team-member.php#L1696" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083582/#file4" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/exclusive-addons-for-elementor/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2e82478c-e476-4cdf-ab72-f578331058e2?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>trinhtuantai--Viet Affiliate Link<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in trinhtuantai Viet Affiliate Link allows Stored XSS.This issue affects Viet Affiliate Link: from n/a through 1.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34422&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34422" target="_blank">CVE-2024-34422</a><br><a href="https://patchstack.com/database/vulnerability/viet-affiliate-link/wordpress-viet-affiliate-link-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>uapp--Testimonial Carousel For Elementor<br> </td>
<td>The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'show_line_text ' and 'slide_button_hover_animation' parameters in versions up to, and including, 10.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4698&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4698" target="_blank">CVE-2024-4698</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel-blog.php#L1076" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel-bottom.php#L1478" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel-centered.php#L1619" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel-gallery-coverflow.php#L1876" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel-logo.php#L1715" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel.php#L1847" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087862/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4542b0f8-c9ee-4992-b737-e5f727c7b5b0?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>unitecms--Unlimited Elements For Elementor (Free Widgets, Addons, Templates)<br> </td>
<td>The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_connect_error' parameter in all versions up to, and including, 1.5.102 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3547&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3547" target="_blank">CVE-2024-3547</a><br><a href="https://plugins.trac.wordpress.org/changeset/3071404/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_settings_output.class.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f629fc93-84ce-4c33-b1c0-3a3194aac477?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>upwerd--Visual Footer Credit Remover<br> </td>
<td>The Visual Footer Credit Remover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'selector' parameter in all versions up to, and including, 2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2846&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2846" target="_blank">CVE-2024-2846</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3081401%40visual-footer-credit-remover&amp;new=3081401%40visual-footer-credit-remover&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9fcb65a0-4218-4728-9c29-0d1a03f438a6?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>videousermanuals--White Label CMS<br> </td>
<td>The White Label CMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_plugin function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to reset plugin settings.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4280&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4280" target="_blank">CVE-2024-4280</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082887/white-label-cms" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/13a206ea-0890-4535-9da7-54a7a45f0452?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>villatheme--Orders Tracking for WooCommerce<br> </td>
<td>The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.10. This is due to the plugin allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. A partial patch was released in 1.2.10, and a complete patch was released in 1.2.11.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4039&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4039" target="_blank">CVE-2024-4039</a><br><a href="https://plugins.trac.wordpress.org/browser/woo-orders-tracking/trunk/includes/frontend/frontend.php#L55" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3083652%40woo-orders-tracking&amp;new=3083652%40woo-orders-tracking&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/991ab188-869c-4875-80f3-940000a1717b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>visualmodo--Borderless Widgets, Elements, Templates and Toolkit for Elementor &amp; Gutenberg<br> </td>
<td>The Borderless - Widgets, Elements, Templates and Toolkit for Elementor &amp; Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4666&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4666" target="_blank">CVE-2024-4666</a><br><a href="https://plugins.trac.wordpress.org/browser/borderless/trunk/modules/elementor/widgets/circular-progress-bar.php#L427" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/borderless/trunk/modules/elementor/widgets/progress-bar.php#L412" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/borderless/trunk/modules/elementor/widgets/semi-circular-progress-bar.php#L403" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/borderless/trunk/modules/elementor/widgets/team-member.php#L1101" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/borderless/trunk/modules/elementor/widgets/testimonial.php#L905" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085856/" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/borderless/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b6840637-9b0f-4f3d-bb73-9e4527a5f326?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>weForms--weForms<br> </td>
<td>Client-Side Enforcement of Server-Side Security vulnerability in weForms allows Removing Important Client Functionality.This issue affects weForms: from n/a through 1.6.20.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32512&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32512" target="_blank">CVE-2024-32512</a><br><a href="https://patchstack.com/database/vulnerability/weforms/wordpress-weforms-plugin-1-6-20-form-submission-restriction-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>webdevmattcrom--GiveWP Donation Plugin and Fundraising Platform<br> </td>
<td>The GiveWP - Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode when used with a legacy form in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3714&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3714" target="_blank">CVE-2024-3714</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083390/give/tags/3.11.0/includes/class-give-donate-form.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dd8f5cfa-3431-4617-b2cd-d5a8ce4530f4?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>webtechideas--WTI Like Post<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in webtechideas WTI Like Post allows Functionality Bypass.This issue affects WTI Like Post: from n/a through 1.4.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33917&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33917" target="_blank">CVE-2024-33917</a><br><a href="https://patchstack.com/database/vulnerability/wti-like-post/wordpress-wti-like-post-plugin-1-4-6-ip-restriction-bypass-vulnerability-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>wolfi-dev--wolfictl<br> </td>
<td>wolfictl is a command line tool for working with Wolfi. A git authentication issue in versions prior to 0.16.10 allows a local user's GitHub token to be sent to remote servers other than `github.com`. Most git-dependent functionality in wolfictl relies on its own `git` package, which contains centralized logic for implementing interactions with git repositories. Some of this functionality requires authentication in order to access private repositories. A central function `GetGitAuth` looks for a GitHub token in the environment variable `GITHUB_TOKEN` and returns it as an HTTP basic auth object to be used with the `github.com/go-git/go-git/v5` library. Most callers (direct or indirect) of `GetGitAuth` use the token to authenticate to github.com only; however, in some cases callers were passing this authentication without checking that the remote git repository was hosted on github.com. This behavior has existed in one form or another since commit 0d06e1578300327c212dda26a5ab31d09352b9d0 - committed January 25, 2023. This impacts anyone who ran the `wolfictl check update` commands with a Melange configuration that included a `git-checkout` directive step that referenced a git repository not hosted on github.com. This also impacts anyone who ran `wolfictl update &lt;url&gt;` with a remote URL outside of github.com. Additionally, these subcommands must have run with the `GITHUB_TOKEN` environment variable set to a valid GitHub token. Users should upgrade to version 0.16.10 to receive a patch.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35183&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35183" target="_blank">CVE-2024-35183</a><br><a href="https://github.com/wolfi-dev/wolfictl/blob/488b53823350caa706de3f01ec0eded9350c7da7/pkg/update/update.go#L143" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/wolfi-dev/wolfictl/blob/4dd6c95abb4bc0f9306350a8601057bd7a92bded/pkg/update/deps/cleanup.go#L49" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/wolfi-dev/wolfictl/blob/6d99909f7b1aa23f732d84dad054b02a61f530e6/pkg/git/git.go#L22" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/wolfi-dev/wolfictl/commit/0d06e1578300327c212dda26a5ab31d09352b9d0" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/wolfi-dev/wolfictl/commit/403e93569f46766b4e26e06cf9cd0cae5ee0c2a2" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/wolfi-dev/wolfictl/security/advisories/GHSA-8fg7-hp93-qhvr" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>wpdevteam--EmbedPress Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps &amp; Embed Any Documents in Gutenberg &amp; Elementor<br> </td>
<td>The EmbedPress - Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps &amp; Embed Any Documents in Gutenberg &amp; Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 3.9.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4316&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4316" target="_blank">CVE-2024-4316</a><br><a href="https://plugins.trac.wordpress.org/browser/embedpress/trunk/EmbedPress/Elementor/Widgets/Embedpress_Elementor.php#L3076" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2af03168-9344-4db0-9b69-2ad1fdb6d472?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpdevteam--Essential Addons for Elementor Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders<br> </td>
<td>The Essential Addons for Elementor - Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Interactive Circle widget in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4275&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4275" target="_blank">CVE-2024-4275</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083162/essential-addons-for-elementor-lite/tags/5.9.20/includes/Elements/Interactive_Circle.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/91f50b65-f001-4c73-bfe3-1aed3fc10d26?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpdevteam--Essential Addons for Elementor Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders<br> </td>
<td>The Essential Addons for Elementor - Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Dual Color Header', 'Event Calendar', &amp; 'Advanced Data Table' widgets in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4448&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4448" target="_blank">CVE-2024-4448</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083162/essential-addons-for-elementor-lite/tags/5.9.20/includes/Elements/Advanced_Data_Table.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083162/essential-addons-for-elementor-lite/tags/5.9.20/includes/Elements/Dual_Color_Header.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083162/essential-addons-for-elementor-lite/tags/5.9.20/includes/Elements/Event_Calendar.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/21e12c72-7898-4896-9852-ebb10e5f9a3b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpdevteam--Essential Addons for Elementor Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders<br> </td>
<td>The Essential Addons for Elementor - Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Fancy Text', 'Filter Gallery', 'Sticky Video', 'Content Ticker', 'Woo Product Gallery', &amp; 'Twitter Feed' widgets in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4449&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4449" target="_blank">CVE-2024-4449</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3083162%40essential-addons-for-elementor-lite&amp;new=3083162%40essential-addons-for-elementor-lite&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/57ed6c7e-ca8d-476d-adce-905b2cd2eda8?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpdevteam--Essential Addons for Elementor Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders<br> </td>
<td>The Essential Addons for Elementor - Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eael_ext_toc_title_tag' parameter in versions up to, and including, 5.9.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4624&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4624" target="_blank">CVE-2024-4624</a><br><a href="https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/5.9.19/includes/Traits/Elements.php#L550" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085420/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bedad627-0ccb-41c1-be8d-753f57be618f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpdevteam--Essential Blocks Page Builder Gutenberg Blocks, Patterns &amp; Templates<br> </td>
<td>The Essential Blocks - Page Builder Gutenberg Blocks, Patterns &amp; Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tagName' parameter in versions up to, and including, 4.5.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4891&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4891" target="_blank">CVE-2024-4891</a><br><a href="https://plugins.trac.wordpress.org/browser/essential-blocks/trunk/blocks/AdvancedHeading.php#L115" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087677/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e1bcebb3-920b-40cc-aa5c-24a1f729b28d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpexpertsio--Password Protected Ultimate Plugin to Password Protect Your WordPress Content with Ease<br> </td>
<td>The Password Protected - Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the API. This makes it possible for authenticated attackers, with subscriber access or higher, to extract post titles and content, thus bypassing the plugin's password protection.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0437&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0437" target="_blank">CVE-2024-0437</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3034934%40password-protected%2Ftrunk&amp;old=3005632%40password-protected%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f3045ebf-70af-4124-9116-42c07f64a3bf?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpjoli--Joli FAQ SEO WordPress FAQ Plugin<br> </td>
<td>The Joli FAQ SEO - WordPress FAQ Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing or incorrect nonce validation when saving settings. This makes it possible for unauthenticated attackers to change the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4082&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4082" target="_blank">CVE-2024-4082</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3081648%40joli-faq-seo%2Ftrunk&amp;old=3076380%40joli-faq-seo%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c45b6163-7ebf-4f18-afd6-735d02d9170d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpkube--Simple Basic Contact Form<br> </td>
<td>The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 20240502. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on the functionality of other plugins installed in the environment.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4144&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4144" target="_blank">CVE-2024-4144</a><br><a href="https://plugins.trac.wordpress.org/browser/simple-basic-contact-form/trunk/simple-basic-contact-form.php#L543" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085036/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ded1944f-662d-4d25-8277-4b1dc63b2144?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpkube--Simple Basic Contact Form<br> </td>
<td>The Simple Basic Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'scf_email' parameter in versions up to, and including, 20221201 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4150&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4150" target="_blank">CVE-2024-4150</a><br><a href="https://plugins.trac.wordpress.org/browser/simple-basic-contact-form/trunk/simple-basic-contact-form.php#L122" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3080540" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22074d7a-5dbd-4a0c-bc5d-e4c983e5edb4?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wproyal--Royal Elementor Addons and Templates<br> </td>
<td>The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form Builder widget in all versions up to, and including, 1.3.974 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3887&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3887" target="_blank">CVE-2024-3887</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3086890%40royal-elementor-addons&amp;old=3081886%40royal-elementor-addons&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5122800d-f274-4129-84d4-02380269502c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpsurface--BlogLentor<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsurface BlogLentor allows Stored XSS.This issue affects BlogLentor: from n/a through 1.0.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34421&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34421" target="_blank">CVE-2024-34421</a><br><a href="https://patchstack.com/database/vulnerability/bloglentor-for-elementor/wordpress-bloglentor-blog-designer-pack-for-elementor-plugin-1-0-8-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>wpzoom--WPZOOM Addons for Elementor (Templates, Widgets)<br> </td>
<td>The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget Image Box in all versions up to, and including, 1.1.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4370&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4370" target="_blank">CVE-2024-4370</a><br><a href="https://plugins.trac.wordpress.org/browser/wpzoom-elementor-addons/trunk/includes/widgets/image-box/image-box.php#L1229" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084540" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/wpzoom-elementor-addons/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c7aaff3e-0c81-4fe7-b162-569c517f6c49?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>xpro--140+ Widgets | Best Addons For Elementor FREE<br> </td>
<td>The 140+ Widgets | Best Addons For Elementor - FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4440&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4440" target="_blank">CVE-2024-4440</a><br><a href="https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/contact-form/contact-form.php#L1438" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/course-grid/course-grid.php#L1918" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/custom-field/custom-field.php#L1150" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/post-grid/post-grid.php#L1829" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/woo-product-grid/woo-product-grid.php#L3812" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5596197e-149d-4072-9fa4-424c9ffd6059?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>yithemes--YITH WooCommerce Gift Cards<br> </td>
<td>The YITH WooCommerce Gift Cards plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_mail_status' and 'save_email_settings' functions in all versions up to, and including, 4.12.0. This makes it possible for unauthenticated attackers to modify WooCommerce settings.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0870&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0870" target="_blank">CVE-2024-0870</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084519/yith-woocommerce-gift-cards/trunk/includes/admin/class-ywgc-admin.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ca1f0dc6-c0bc-4e9f-b3b6-d6274aa7a7db?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>yoast--Yoast SEO<br> </td>
<td>The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 22.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4041&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4041" target="_blank">CVE-2024-4041</a><br><a href="https://plugins.trac.wordpress.org/browser/wordpress-seo/trunk/inc/class-wpseo-admin-bar-menu.php#L601" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/wordpress-seo/trunk/inc/class-wpseo-shortlinker.php#L20" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/wordpress-seo/trunk/src/helpers/short-link-helper.php#L105" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/wordpress-seo/trunk/src/helpers/short-link-helper.php#L45" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3078555/wordpress-seo/trunk#file129" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4e04b161-3cd0-454d-869c-56f42bd8afb0?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>yoast--Yoast SEO<br> </td>
<td>The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name' author meta in all versions up to, and including, 22.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4984&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4984" target="_blank">CVE-2024-4984</a><br><a href="https://developer.yoast.com/changelog/yoast-seo/22.7/" target="_blank">security@wordfence.com</a><br><a href="https://github.com/Yoast/wordpress-seo/pull/21334" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3079234/wordpress-seo/trunk/src/presenters/slack/enhanced-data-presenter.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/59bcd246-ca2f-4336-9a6e-89afe873ed25?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
</tbody>
</table>
<p><a href="https://www.cisa.gov/#top">Back to top</a></p>
</div>
<div>
<h2>Low Vulnerabilities</h2>
<table summary="Low Vulnerabilities" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th scope="col" role="columnheader" data-tablesaw-priority="persist">Primary<br>Vendor -- Product</th>
<th scope="col" role="columnheader">Description</th>
<th scope="col" role="columnheader">Published</th>
<th scope="col" role="columnheader">CVSS Score</th>
<th scope="col" role="columnheader">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>Bill Minozzi--Car Dealer<br> </td>
<td>Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Bill Minozzi Car Dealer allows Code Injection.This issue affects Car Dealer: from n/a through 4.15.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4214&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">2.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4214" target="_blank">CVE-2024-4214</a><br><a href="https://patchstack.com/database/vulnerability/cardealer/wordpress-cardealer-plugin-4-15-content-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view/show_student_subject.php. The manipulation of the argument id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263593 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4672&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4672" target="_blank">CVE-2024-4672</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2022.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263593" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263593" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331307" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. Affected by this issue is some unknown functionality of the file /view/show_student_grade_subject.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263594 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4673&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4673" target="_blank">CVE-2024-4673</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2023.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263594" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263594" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331308" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /view/show_friend_request.php. The manipulation of the argument my_index leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263595.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4674&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4674" target="_blank">CVE-2024-4674</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2024.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263595" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263595" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331310" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /view/show_events.php. The manipulation of the argument event_id leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263596.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4675&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4675" target="_blank">CVE-2024-4675</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2025.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263596" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263596" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331312" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /view/range_grade_text.php. The manipulation of the argument count leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263597 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4676&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4676" target="_blank">CVE-2024-4676</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2026.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263597" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263597" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331313" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /view/my_student_exam_marks1.php. The manipulation of the argument year leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263598 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4677&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4677" target="_blank">CVE-2024-4677</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2027.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263598" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263598" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331314" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /view/find_friends.php. The manipulation of the argument my_type leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263599.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4678&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4678" target="_blank">CVE-2024-4678</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2028.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263599" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263599" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331315" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /view/exam_timetable_update_form.php. The manipulation of the argument exam leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263623.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4682&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4682" target="_blank">CVE-2024-4682</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2029.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263623" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263623" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331772" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /view/exam_timetable_insert_form.php. The manipulation of the argument exam leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263624.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4683&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4683" target="_blank">CVE-2024-4683</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2030.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263624" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263624" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331773" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /view/exam_timetable_grade_wise.php. The manipulation of the argument exam leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263625 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4684&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4684" target="_blank">CVE-2024-4684</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2031.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263625" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263625" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331774" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /view/exam_timetable.php. The manipulation of the argument exam leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263626 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4685&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4685" target="_blank">CVE-2024-4685</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2032.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263626" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263626" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331775" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /view/emarks_range_grade_update_form.php. The manipulation of the argument grade leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263627.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4686&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4686" target="_blank">CVE-2024-4686</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2033.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263627" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263627" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331776" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/create_events.php. The manipulation of the argument my_index leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263628.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4687&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4687" target="_blank">CVE-2024-4687</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2034.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263628" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263628" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331777" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view/conversation_history_admin.php. The manipulation of the argument conversation_id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263629 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4688&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4688" target="_blank">CVE-2024-4688</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2035.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263629" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263629" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331778" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view/all_teacher.php. The manipulation of the argument page leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263791.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4713&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4713" target="_blank">CVE-2024-4713</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2036.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263791" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263791" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331879" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. Affected by this issue is some unknown functionality of the file /model/update_subject.php. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263792.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4714&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4714" target="_blank">CVE-2024-4714</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2037.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263792" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263792" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331880" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /model/update_grade.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263793 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4715&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4715" target="_blank">CVE-2024-4715</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2038.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263793" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263793" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331881" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /model/update_exam.php. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263794 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4716&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4716" target="_blank">CVE-2024-4716</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2039.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263794" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263794" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331882" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /model/update_classroom.php. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263795.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4717&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4717" target="_blank">CVE-2024-4717</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2040.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263795" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263795" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331883" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /model/delete_student_grade_subject.php. The manipulation of the argument index leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263796.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4718&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4718" target="_blank">CVE-2024-4718</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2041.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263796" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263796" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331884" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /model/delete_record.php. The manipulation of the argument page leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263797 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4719&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4719" target="_blank">CVE-2024-4719</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2042.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263797" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263797" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331885" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /model/approve_petty_cash.php. The manipulation of the argument admin_index leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263798 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4720&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4720" target="_blank">CVE-2024-4720</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2043.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263798" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263798" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331886" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /model/add_student_subject.php. The manipulation of the argument index leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263799.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4721&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4721" target="_blank">CVE-2024-4721</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2044.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263799" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263799" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331887" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argument category leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263800.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4722&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4722" target="_blank">CVE-2024-4722</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2045.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263800" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263800" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331888" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability, which was classified as problematic, has been found in Campcodes Legal Case Management System 1.0. This issue affects some unknown processing of the file /admin/case-status. The manipulation of the argument case_status leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263801 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4723&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4723" target="_blank">CVE-2024-4723</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_case-status.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263801" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263801" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331982" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability, which was classified as problematic, was found in Campcodes Legal Case Management System 1.0. Affected is an unknown function of the file /admin/case-type. The manipulation of the argument case_type_name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263802 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4724&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4724" target="_blank">CVE-2024-4724</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_case-type.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263802" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263802" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331983" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability has been found in Campcodes Legal Case Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/client_user. The manipulation of the argument f_name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263803.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4725&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4725" target="_blank">CVE-2024-4725</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_client_user.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263803" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263803" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331988" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/clients. The manipulation of the argument f_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263804.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4726&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4726" target="_blank">CVE-2024-4726</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_clients.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263804" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263804" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331989" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/court-type. The manipulation of the argument court_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263805 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4727&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4727" target="_blank">CVE-2024-4727</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_court-type.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263805" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263805" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331990" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/court. The manipulation of the argument court_name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263806 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4728&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4728" target="_blank">CVE-2024-4728</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_court.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263806" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263806" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331992" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/expense-type. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263807.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4729&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4729" target="_blank">CVE-2024-4729</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_expense-type.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263807" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263807" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331993" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability classified as problematic has been found in Campcodes Legal Case Management System 1.0. Affected is an unknown function of the file /admin/judge. The manipulation of the argument judge_name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263808.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4730&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4730" target="_blank">CVE-2024-4730</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_judge.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263808" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263808" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331994" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability classified as problematic was found in Campcodes Legal Case Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/role. The manipulation of the argument slug leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263809 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4731&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4731" target="_blank">CVE-2024-4731</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_role.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263809" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263809" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331995" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability, which was classified as problematic, has been found in Campcodes Legal Case Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/service. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263810 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4732&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4732" target="_blank">CVE-2024-4732</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_service.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263810" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263810" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331996" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability has been found in Campcodes Legal Case Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/tasks. The manipulation of the argument task_subject leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263821 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4735&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4735" target="_blank">CVE-2024-4735</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_tasks.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263821" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263821" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332408" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/tax. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263822 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4736&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4736" target="_blank">CVE-2024-4736</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_tax.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263822" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263822" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332409" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/vendor. The manipulation of the argument company_name/mobile leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263823.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4737&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4737" target="_blank">CVE-2024-4737</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_vendor.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263823" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263823" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332411" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code. The manipulation of the argument new_client leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263824.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4738&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4738" target="_blank">CVE-2024-4738</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_appointment.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263824" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263824" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332412" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /ajax.php. The manipulation of the argument name/customer_name/username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263896.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4797&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4797" target="_blank">CVE-2024-4797</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/xss_action.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263896" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263896" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332539" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Filipe Seabra--WordPress Manuteno<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in Filipe Seabra WordPress ManutenÃ§Ã£o allows Functionality Bypass.This issue affects WordPress ManutenÃ§Ã£o: from n/a through 1.0.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22139&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22139" target="_blank">CVE-2024-22139</a><br><a href="https://patchstack.com/database/vulnerability/wp-manutencao/wordpress-wordpress-manutencao-plugin-1-0-6-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Insufficient verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32989&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">3.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32989" target="_blank">CVE-2024-32989</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>IBM--Security Guardium<br> </td>
<td>IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force ID: 271526.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47711&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">2.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47711" target="_blank">CVE-2023-47711</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/271526" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150840" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>JetBrains--TeamCity<br> </td>
<td>In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35300&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35300" target="_blank">CVE-2024-35300</a><br><a href="https://www.jetbrains.com/privacy-security/issues-fixed/" target="_blank">cve@jetbrains.com</a></td>
</tr>
<tr>
<td>Nozomi Networks--Arc<br> </td>
<td>On Windows systems, the Arc configuration files resulted to be world-readable. This can lead to information disclosure by local attackers, via exfiltration of sensitive data from configuration files.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5937&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5937" target="_blank">CVE-2023-5937</a><br><a href="https://security.nozominetworks.com/NN-2023:15-01" target="_blank">prodsec@nozominetworks.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Broken Authentication vulnerability discovered in OpenTextâ„¢ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain parameters to bypass authentication.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3487&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3487" target="_blank">CVE-2024-3487</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>Pippin Williamson--CGC Maintenance Mode<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in Pippin Williamson CGC Maintenance Mode allows Functionality Bypass.This issue affects CGC Maintenance Mode: from n/a through 1.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30480&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30480" target="_blank">CVE-2024-30480</a><br><a href="https://patchstack.com/database/vulnerability/cgc-maintenance-mode/wordpress-cgc-maintenance-mode-plugin-1-2-ip-filtering-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP Bank Account Management<br> </td>
<td>SAP Bank Account Management does not perform necessary authorization check for an authorized user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality to the system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33000&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33000" target="_blank">CVE-2024-33000</a><br><a href="https://me.sap.com/notes/3392049" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAPUI5 (PDFViewer)<br> </td>
<td>PDFViewer is a control delivered as part of SAPUI5 product which shows the PDF content in an embedded mode by default. If a PDF document contains embedded JavaScript (or any harmful client-side script), the PDFViewer will execute the JavaScript embedded in the PDF which can cause a potential security threat.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33007&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33007" target="_blank">CVE-2024-33007</a><br><a href="https://me.sap.com/notes/3446076" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>Siemens--Parasolid V35.1<br> </td>
<td>A vulnerability has been identified in Parasolid V35.1 (All versions &lt; V35.1.256), Parasolid V36.0 (All versions &lt; V36.0.208), Parasolid V36.1 (All versions &lt; V36.1.173). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted X_T files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32637&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">3.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32637" target="_blank">CVE-2024-32637</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-046364.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected application contains a hidden configuration item to enable debug functionality. This could allow an authenticated local attacker to gain insight into the internal configuration of the deployment.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33583&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33583" target="_blank">CVE-2024-33583</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>SourceCodester--Interactive Map with Marker<br> </td>
<td>A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file Marker Name of the component Add Marker. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264536.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4968&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4968" target="_blank">CVE-2024-4968</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Interactive%20Map%20App/Interactive%20Map%20App%20-%20Cross-Site-Scripting.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264536" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264536" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335191" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Image Stack Website<br> </td>
<td>A vulnerability, which was classified as problematic, was found in SourceCodester Simple Image Stack Website 1.0. This affects an unknown part. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264459.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4922&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4922" target="_blank">CVE-2024-4922</a><br><a href="https://github.com/HuoMingZ/aoligei/blob/main/ceshi.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264459" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264459" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333760" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>TYPO3--typo3<br> </td>
<td>TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history backend module is vulnerable to HTML injection. Although Content-Security-Policy headers effectively prevent JavaScript execution, adversaries can still inject malicious HTML markup. Exploiting this vulnerability requires a valid backend user account. TYPO3 version 13.1.1 fixes the problem described.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34355&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34355" target="_blank">CVE-2024-34355</a><br><a href="https://github.com/TYPO3/typo3/commit/56afa304ba8b5ad302e15df5def71bcc8d820375" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/security/advisories/GHSA-xjwx-78x7-q6jc" target="_blank">security-advisories@github.com</a><br><a href="https://typo3.org/security/advisory/typo3-core-sa-2024-007" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Wireshark Foundation--editcap<br> </td>
<td>Memory handling issue in editcap could cause denial of service via crafted capture file</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4853&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">3.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4853" target="_blank">CVE-2024-4853</a><br><a href="https://gitlab.com/wireshark/wireshark/-/issues/19724" target="_blank">cve@gitlab.com</a><br><a href="https://www.wireshark.org/security/wnpa-sec-2024-08.html" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>Wireshark Foundation--editcap<br> </td>
<td>Use after free issue in editcap could cause denial of service via crafted capture file</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4855&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">3.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4855" target="_blank">CVE-2024-4855</a><br><a href="https://gitlab.com/wireshark/wireshark/-/issues/19782" target="_blank">cve@gitlab.com</a><br><a href="https://gitlab.com/wireshark/wireshark/-/issues/19783" target="_blank">cve@gitlab.com</a><br><a href="https://gitlab.com/wireshark/wireshark/-/issues/19784" target="_blank">cve@gitlab.com</a><br><a href="https://www.wireshark.org/security/wnpa-sec-2024-08.html" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>cea-hpc--sshproxy<br> </td>
<td>sshproxy is used on a gateway to transparently proxy a user SSH connection on the gateway to an internal host via SSH. Prior to version 1.6.3, any user authorized to connect to a ssh server using `sshproxy` can inject options to the `ssh` command executed by `sshproxy`. All versions of `sshproxy` are impacted. The problem is patched starting in version 1.6.3. The only workaround is to use the `force_command` option in `sshproxy.yaml`, but it's rarely relevant.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34713&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34713" target="_blank">CVE-2024-34713</a><br><a href="https://github.com/cea-hpc/sshproxy/commit/f7eabd05d5f0f951e160293692327cad9a7d9580" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/cea-hpc/sshproxy/security/advisories/GHSA-jmqp-37m5-49wh" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>code-projects--Simple Chat System<br> </td>
<td>A vulnerability, which was classified as problematic, was found in code-projects Simple Chat System 1.0. Affected is an unknown function of the file /register.php. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264540.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4974&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4974" target="_blank">CVE-2024-4974</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Simple%20Chat%20App/Simple%20Chat%20App%20-%20Cross-Site-Scripting-1.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264540" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264540" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335205" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>code-projects--Simple Chat System<br> </td>
<td>A vulnerability, which was classified as problematic, has been found in code-projects Simple Chat System 1.0. This issue affects some unknown processing of the component Message Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264539.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4975&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4975" target="_blank">CVE-2024-4975</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Simple%20Chat%20App/Simple%20Chat%20App%20-%20Cross-Site-Scripting-2.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264539" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264539" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335206" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>git--git<br> </td>
<td>Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, local clones may end up hardlinking files into the target repository's object database when source and target repository reside on the same disk. If the source repository is owned by a different user, then those hardlinked files may be rewritten at any point in time by the untrusted user. Cloning local repositories will cause Git to either copy or hardlink files of the source repository into the target repository. This significantly speeds up such local clones compared to doing a "proper" clone and saves both disk space and compute time. When cloning a repository located on the same disk that is owned by a different user than the current user we also end up creating such hardlinks. These files will continue to be owned and controlled by the potentially-untrusted user and can be rewritten by them at will in the future. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32020&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">3.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32020" target="_blank">CVE-2024-32020</a><br><a href="https://github.com/git/git/commit/1204e1a824c34071019fe106348eaa6d88f9528d" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/commit/9e65df5eab274bf74c7b570107aacd1303a1e703" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/security/advisories/GHSA-5rfh-556j-fhgj" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>git--git<br> </td>
<td>Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, when cloning a local source repository that contains symlinks via the filesystem, Git may create hardlinks to arbitrary user-readable files on the same filesystem as the target repository in the `objects/` directory. Cloning a local repository over the filesystem may creating hardlinks to arbitrary user-owned files on the same filesystem in the target Git repository's `objects/` directory. When cloning a repository over the filesystem (without explicitly specifying the `file://` protocol or `--no-local`), the optimizations for local cloning will be used, which include attempting to hard link the object files instead of copying them. While the code includes checks against symbolic links in the source repository, which were added during the fix for CVE-2022-39253, these checks can still be raced because the hard link operation ultimately follows symlinks. If the object on the filesystem appears as a file during the check, and then a symlink during the operation, this will allow the adversary to bypass the check and create hardlinks in the destination objects directory to arbitrary, user-readable files. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32021&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">3.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32021" target="_blank">CVE-2024-32021</a><br><a href="https://github.com/git/git/security/advisories/GHSA-mvxm-9j2h-qjx7" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>gocd--gocd<br> </td>
<td>GoCD is a continuous delivery server. GoCD versions from 19.4.0 to 23.5.0 (inclusive) are potentially vulnerable to a reflected cross-site scripting vulnerability on the loading page displayed while GoCD is starting, via abuse of a `redirect_to` query parameter with inadequate validation. Attackers could theoretically abuse the query parameter to steal session tokens or other values from the user's browser. In practice exploiting this to perform privileged actions is likely rather difficult to exploit because the target user would need to be triggered to open an attacker-crafted link in the period where the server is starting up (but not completely started), requiring chaining with a separate denial-of-service vulnerability. Additionally, GoCD server restarts invalidate earlier session tokens (i.e GoCD does not support persistent sessions), so a stolen session token would be unusable once the server has completed restart, and executed XSS would be done within a logged-out context. The issue is fixed in GoCD 24.1.0. As a workaround, it is technically possible in earlier GoCD versions to override the loading page with an earlier version which is not vulnerable, by starting GoCD with the Java system property override as either `-Dloading.page.resource.path=/loading_pages/default.loading.page.html` (simpler early version of loading page without GoCD introduction) or `-Dloading.page.resource.path=/does_not_exist.html` (to display a simple message with no interactivity).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28866&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28866" target="_blank">CVE-2024-28866</a><br><a href="https://github.com/gocd/gocd/commit/388d8893ec4cac51d2b76e923cc9b55c7703e402" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/gocd/gocd/releases/tag/24.1.0" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/gocd/gocd/security/advisories/GHSA-q882-q6mm-mgvh" target="_blank">security-advisories@github.com</a><br><a href="https://www.gocd.org/releases/#24-1-0" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>helderk--Maintenance Mode<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in helderk Maintenance Mode allows Functionality Bypass.This issue affects Maintenance Mode: from n/a through 3.0.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32708&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32708" target="_blank">CVE-2024-32708</a><br><a href="https://patchstack.com/database/vulnerability/hkdev-maintenance-mode/wordpress-maintenance-mode-plugin-3-0-1-ip-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>n/a--Emlog Pro<br> </td>
<td>A vulnerability was found in Emlog Pro 2.3.4. It has been classified as problematic. This affects an unknown part of the component Cookie Handler. The manipulation of the argument AuthCookie leads to improper authentication. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-264741 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5044&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5044" target="_blank">CVE-2024-5044</a><br><a href="https://github.com/ssteveez/emlog/blob/main/emlog%20pro%20version%202.3.4%20has%20session(AuthCookie)%20persistence%20and%20any%20user%20login%20vulnerability.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264741" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264741" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331857" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) CBI software<br> </td>
<td>Improper input validation in some Intel(R) CBI software before version 1.1.0 may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43745&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">2.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43745" target="_blank">CVE-2023-43745</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01013.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Media SDK and some Intel(R) oneVPL software<br> </td>
<td>Out-of-bounds read in Intel(R) Media SDK and some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-22656&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">3.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-22656" target="_blank">CVE-2023-22656</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Media SDK software<br> </td>
<td>Improper buffer restrictions in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47169&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">3.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47169" target="_blank">CVE-2023-47169</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for macOS<br> </td>
<td>Improper conditions check in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable information disclosure via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38420&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38420" target="_blank">CVE-2023-38420</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Processors<br> </td>
<td>Hardware logic contains race conditions in some Intel(R) Processors may allow an authenticated user to potentially enable partial information disclosure via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45733&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">2.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45733" target="_blank">CVE-2023-45733</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01051.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Trace Analyzer and Collector software<br> </td>
<td>Out-of-bounds read for some Intel(R) Trace Analyzer and Collector software before version 2022.0.0 published Nov 2023 may allow an authenticated user to potentially enable information disclosure via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22384&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">2.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22384" target="_blank">CVE-2024-22384</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00983.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) oneVPL software<br> </td>
<td>Out-of-bounds write in Intel(R) Media SDK all versions and some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47282&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">3.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47282" target="_blank">CVE-2023-47282</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) oneVPL software<br> </td>
<td>NULL pointer dereference in some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable information disclosure via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-48727&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-48727" target="_blank">CVE-2023-48727</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--PostgreSQL<br> </td>
<td>Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 are affected. Versions before PostgreSQL 14 are unaffected.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4317&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4317" target="_blank">CVE-2024-4317</a><br><a href="https://www.postgresql.org/support/security/CVE-2024-4317/" target="_blank">f86ef6dc-4d3a-42ad-8f28-e6d5547a5007</a></td>
</tr>
<tr>
<td>octo-sts--app<br> </td>
<td>octo-sts is a GitHub App that acts like a Security Token Service (STS) for the Github API. This vulnerability can spike the resource utilization of the STS service, and combined with a significant traffic volume could potentially lead to a denial of service. This vulnerability is fixed in 0.1.0</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34079&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">3.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34079" target="_blank">CVE-2024-34079</a><br><a href="https://github.com/octo-sts/app/commit/74ba874c017cf973edd6711144cf4399a9fcff57" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/octo-sts/app/security/advisories/GHSA-75r6-6jg8-pfcq" target="_blank">security-advisories@github.com</a></td>
</tr>
</tbody>
</table>
<p><a href="https://www.cisa.gov/#top">Back to top</a></p>
</div>
<div>
<h2>Severity Not Yet Assigned</h2>
<table summary="Severity Not Yet Assigned" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th scope="col" role="columnheader" data-tablesaw-priority="persist">Primary<br>Vendor -- Product</th>
<th scope="col" role="columnheader">Description</th>
<th scope="col" role="columnheader">Published</th>
<th scope="col" role="columnheader">CVSS Score</th>
<th scope="col" role="columnheader">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>Aidin--Phormer<br> </td>
<td>Phormer prior to version 3.35 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote unauthenticated attacker may execute an arbitrary script on the web browser of the user.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34749" target="_blank">CVE-2024-34749</a><br><a href="http://p.horm.org/er/" target="_blank">vultures@jpcert.or.jp</a><br><a href="https://github.com/eyedean/phormer" target="_blank">vultures@jpcert.or.jp</a><br><a href="https://jvn.jp/en/jp/JVN61054671/" target="_blank">vultures@jpcert.or.jp</a><br><a href="https://sourceforge.net/projects/rephormer/" target="_blank">vultures@jpcert.or.jp</a></td>
</tr>
<tr>
<td>Ant Media--Ant Media Server Community Edition<br> </td>
<td>Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorization, leading to a possible use of non-administrative API calls reserved only for authorized users.  All versions up to 2.9.0 (tested) and possibly newer ones are believed to be vulnerable as the vendor has not confirmed releasing a patch.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3462" target="_blank">CVE-2024-3462</a><br><a href="https://antmedia.io/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/en/posts/2024/05/CVE-2024-3462" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/05/CVE-2024-3462" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Apache Software Foundation--Apache Airflow<br> </td>
<td>Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.  Users are recommended to upgrade to version 2.9.1, which fixes this issue.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32077" target="_blank">CVE-2024-32077</a><br><a href="https://github.com/apache/airflow/pull/38882" target="_blank">security@apache.org</a><br><a href="https://lists.apache.org/thread/gsjmnrqb3m5fzp0vgpty1jxcywo91v77" target="_blank">security@apache.org</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Ventura 13.6.7, macOS Sonoma 14.4. An app may be able to access user-sensitive data.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27789" target="_blank">CVE-2024-27789</a><br><a href="https://support.apple.com/en-us/HT214084" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214100" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214105" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214107" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An attacker may be able to elevate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27796" target="_blank">CVE-2024-27796</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A permissions issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access may be able to share items from the lock screen.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27803" target="_blank">CVE-2024-27803</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An app may be able to execute arbitrary code with kernel privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27804" target="_blank">CVE-2024-27804</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214102" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214104" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An app may be able to read sensitive location information.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27810" target="_blank">CVE-2024-27810</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214102" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214104" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A logic issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An attacker may be able to access user data.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27816" target="_blank">CVE-2024-27816</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214102" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214104" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An attacker may be able to cause unexpected app termination or arbitrary code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27818" target="_blank">CVE-2024-27818</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. A shortcut may output sensitive user data without consent.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27821" target="_blank">CVE-2024-27821</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214104" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, Safari 17.5, watchOS 10.5, macOS Sonoma 14.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27834" target="_blank">CVE-2024-27834</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214102" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214103" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214104" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device may be able to access notes from the lock screen.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27835" target="_blank">CVE-2024-27835</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 17.5 and iPadOS 17.5. A malicious application may be able to determine a user's current location.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27839" target="_blank">CVE-2024-27839</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to disclose kernel memory.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27841" target="_blank">CVE-2024-27841</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>This issue was addressed with improved checks This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to bypass Privacy preferences.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27847" target="_blank">CVE-2024-27847</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A privacy issue was addressed with improved client ID handling for alternative app marketplaces. This issue is fixed in iOS 17.5 and iPadOS 17.5. A maliciously crafted webpage may be able to distribute a script that tracks users on other webpages.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27852" target="_blank">CVE-2024-27852</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iTunes for Windows<br> </td>
<td>The issue was addressed with improved checks. This issue is fixed in iTunes 12.13.2 for Windows. Parsing a file may lead to an unexpected app termination or arbitrary code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27793" target="_blank">CVE-2024-27793</a><br><a href="https://support.apple.com/en-us/HT214099" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.5, macOS Ventura 13.6.5, macOS Sonoma 14.4. A malicious application may be able to access Find My data.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23229" target="_blank">CVE-2024-23229</a><br><a href="https://support.apple.com/en-us/HT214084" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214085" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214105" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to read arbitrary files.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23236" target="_blank">CVE-2024-23236</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>An authorization issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.5. An attacker may be able to elevate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27798" target="_blank">CVE-2024-27798</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27813" target="_blank">CVE-2024-27813</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to gain root privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27822" target="_blank">CVE-2024-27822</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.5. An app may be able to elevate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27824" target="_blank">CVE-2024-27824</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to bypass certain Privacy preferences.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27825" target="_blank">CVE-2024-27825</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.5. An app may be able to read arbitrary files.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27827" target="_blank">CVE-2024-27827</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.5. Processing a file may lead to unexpected app termination or arbitrary code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27829" target="_blank">CVE-2024-27829</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. A local attacker may gain access to Keychain items.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27837" target="_blank">CVE-2024-27837</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to execute arbitrary code with kernel privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27842" target="_blank">CVE-2024-27842</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to elevate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27843" target="_blank">CVE-2024-27843</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>CEMI Tomasz Paweek--CemiPark<br> </td>
<td>The access control in CemiPark software does not properly validate user-entered data, which allows the authentication bypass. An attacker who has network access to the login panel can log in with administrator rights to the application.This issue affects CemiPark software: 4.5, 4.7, 5.03 and potentially others. The vendor refused to provide the specific range of affected products.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4423" target="_blank">CVE-2024-4423</a><br><a href="http://cemi.pl/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/en/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>CEMI Tomasz Paweek--CemiPark<br> </td>
<td>The access control in CemiPark software does not properly validate user-entered data, which allows the stored cross-site scripting (XSS) attack. The parameters used to enter data into the system do not have appropriate validation, which makes possible to smuggle in HTML/JavaScript code. This code will be executed in the user's browser space.This issue affects CemiPark software: 4.5, 4.7, 5.03 and potentially others. The vendor refused to provide the specific range of affected products.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4424" target="_blank">CVE-2024-4424</a><br><a href="http://cemi.pl/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/en/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>CEMI Tomasz Paweek--CemiPark<br> </td>
<td>The access control in CemiPark software stores integration (e.g. FTP or SIP) credentials in plain-text. An attacker who gained unauthorized access to the device can retrieve clear text passwords used by the system.This issue affects CemiPark software: 4.5, 4.7, 5.03 and potentially others. The vendor refused to provide the specific range of affected products.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4425" target="_blank">CVE-2024-4425</a><br><a href="http://cemi.pl/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/en/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Claris--FileMaker Server<br> </td>
<td>Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by eliminating the send of Admin Role passwords in the Node.js socket.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-42955" target="_blank">CVE-2023-42955</a><br><a href="https://support.claris.com/s/article/Administrator-role-passwords-being-exposed-when-logged-into-the-Admin-Console?language=en_US" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Claris--FileMaker Server<br> </td>
<td>Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. This issue has been fixed in FileMaker Server 20.3.2 by validating transactions before replying to client requests.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27790" target="_blank">CVE-2024-27790</a><br><a href="https://support.claris.com/s/answerview?anum=000041674&amp;language=en_US" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Devolutions--Server<br> </td>
<td>Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the PAM JIT elevation feature to manipulate the LDAP filter query via a specially crafted request.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5072" target="_blank">CVE-2024-5072</a><br><a href="https://devolutions.net/security/advisories/DEVO-2024-0007" target="_blank">security@devolutions.net</a></td>
</tr>
<tr>
<td>Digisol--Digisol Router DG-GR1321<br> </td>
<td>This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to improper implementation of password policies. An attacker with physical access could exploit this by creating password that do not adhere to the defined security standards/policy on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to expose the router to potential security threats.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2257" target="_blank">CVE-2024-2257</a><br><a href="https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&amp;VLCODE=CIVN-2024-0158" target="_blank">vdisclose@cert-in.org.in</a></td>
</tr>
<tr>
<td>Digisol--Digisol Router DG-GR1321<br> </td>
<td>This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by identifying UART pins and accessing the root shell on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to access the sensitive information on the targeted system.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4231" target="_blank">CVE-2024-4231</a><br><a href="https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&amp;VLCODE=CIVN-2024-0158" target="_blank">vdisclose@cert-in.org.in</a></td>
</tr>
<tr>
<td>Digisol--Digisol Router DG-GR1321<br> </td>
<td>This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by identifying UART pins and accessing the root shell on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to access the sensitive information on the targeted system.This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to lack of encryption or hashing in storing of passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext passwords on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4232" target="_blank">CVE-2024-4232</a><br><a href="https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&amp;VLCODE=CIVN-2024-0158" target="_blank">vdisclose@cert-in.org.in</a></td>
</tr>
<tr>
<td>Google--Chrome<br> </td>
<td>Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4761" target="_blank">CVE-2024-4761</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_13.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/339458194" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>Google--Chrome<br> </td>
<td>Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4947" target="_blank">CVE-2024-4947</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/340221135" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>Google--Chrome<br> </td>
<td>Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4948" target="_blank">CVE-2024-4948</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/333414294" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>Google--Chrome<br> </td>
<td>Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4949" target="_blank">CVE-2024-4949</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/326607001" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>Google--Chrome<br> </td>
<td>Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4950" target="_blank">CVE-2024-4950</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/40065403" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>HP Inc.--Plantronics Hub<br> </td>
<td>A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27460" target="_blank">CVE-2024-27460</a><br><a href="https://support.hp.com/us-en/document/ish_9869257-9869285-16/hpsbpy03895" target="_blank">hp-security-alert@hp.com</a></td>
</tr>
<tr>
<td>Ligowave--UNITY<br> </td>
<td>A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MIMO: through 6.95-1.Rt2880; APC Propeller: through 2-5.95-4.Rt3352.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4999" target="_blank">CVE-2024-4999</a><br><a href="https://onekey.com/blog/security-advisory-remote-code-execution-in-ligowave-devices/" target="_blank">research@onekey.com</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: disable sending io_uring over sockets File reference cycles have caused lots of problems for io_uring in the past, and it still doesn't work exactly right and races with unix_stream_read_generic(). The safest fix would be to completely disallow sending io_uring files via sockets via SCM_RIGHT, so there are no possible cycles invloving registered files and thus rendering SCM accounting on the io_uring side unnecessary.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52654" target="_blank">CVE-2023-52654</a><br><a href="https://git.kernel.org/stable/c/18824f592aad4124d79751bbc1500ea86ac3ff29" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3fe1ea5f921bf5b71cbfdc4469fb96c05936610e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5a33d385eb36991a91e3dddb189d8679e2aac2be" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/705318a99a138c29a512a72c3e0043b3cd7f55f4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bcedd497b3b4a0be56f3adf7c7542720eced0792" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f2f57f51b53be153a522300454ddb3887722fb2c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: aqc111: check packet for fixup for true limit If a device sends a packet that is inbetween 0 and sizeof(u64) the value passed to skb_trim() as length will wrap around ending up as some very large value. The driver will then proceed to parse the header located at that position, which will either oops or process some random value. The fix is to check against sizeof(u64) rather than 0, which the driver currently does. The issue exists since the introduction of the driver.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52655" target="_blank">CVE-2023-52655</a><br><a href="https://git.kernel.org/stable/c/2ebf775f0541ae0d474836fa0cf3220e502f8e3e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/46412b2fb1f9cc895d6d4036bf24f640b5d86dab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/82c386d73689a45d5ee8c1290827bce64056dddd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/84f2e5b3e70f08fce3cb1ff73414631c5e490204" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ccab434e674ca95d483788b1895a70c21b7f016a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d69581c17608d81824dd497d9a54b6a5b6139975" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: io_uring: drop any code related to SCM_RIGHTS This is dead code after we dropped support for passing io_uring fds over SCM_RIGHTS, get rid of it.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52656" target="_blank">CVE-2023-52656</a><br><a href="https://git.kernel.org/stable/c/6e5e6d274956305f1fc0340522b38f5f5be74bdb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/88c49d9c896143cdc0f77197c4dcf24140375e89" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a3812a47a32022ca76bf46ddacdd823dc2aabf8b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a6771f343af90a25f3a14911634562bb5621df02" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cfb24022bb2c31f1f555dc6bc3cc5e2547446fb3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d909d381c3152393421403be4b6435f17a2378b4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Revert "drm/amd/pm: resolve reboot exception for si oland" This reverts commit e490d60a2f76bff636c68ce4fe34c1b6c34bbd86. This causes hangs on SI when DC is enabled and errors on driver reboot and power off cycles.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52657" target="_blank">CVE-2023-52657</a><br><a href="https://git.kernel.org/stable/c/2e443ed55fe3ffb08327b331a9f45e9382413c94" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/955558030954b9637b41c97b730f9b38c92ac488" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/baac292852c0e347626fb5436916947188e5838f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c51468ac328d3922747be55507c117e47da813e6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Revert "net/mlx5: Block entering switchdev mode with ns inconsistency" This reverts commit 662404b24a4c4d839839ed25e3097571f5938b9b. The revert is required due to the suspicion it is not good for anything and cause crash.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52658" target="_blank">CVE-2023-52658</a><br><a href="https://git.kernel.org/stable/c/1bcdd66d33edb446903132456c948f0b764ef2f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3fba8eab2cfc7334e0f132d29dfd2552f2f2a579" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8deeefb24786ea7950b37bde4516b286c877db00" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: x86/mm: Ensure input to pfn_to_kaddr() is treated as a 64-bit type On 64-bit platforms, the pfn_to_kaddr() macro requires that the input value is 64 bits in order to ensure that valid address bits don't get lost when shifting that input by PAGE_SHIFT to calculate the physical address to provide a virtual address for. One such example is in pvalidate_pages() (used by SEV-SNP guests), where the GFN in the struct used for page-state change requests is a 40-bit bit-field, so attempts to pass this GFN field directly into pfn_to_kaddr() ends up causing guest crashes when dealing with addresses above the 1TB range due to the above. Fix this issue with SEV-SNP guests, as well as any similar cases that might cause issues in current/future code, by using an inline function, instead of a macro, so that the input is implicitly cast to the expected 64-bit input type prior to performing the shift operation. While it might be argued that the issue is on the caller side, other archs/macros have taken similar approaches to deal with instances like this, such as ARM explicitly casting the input to phys_addr_t: e48866647b48 ("ARM: 8396/1: use phys_addr_t in pfn_to_kaddr()") A C inline function is even better though. [ mingo: Refined the changelog some more &amp; added __always_inline. ]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52659" target="_blank">CVE-2023-52659</a><br><a href="https://git.kernel.org/stable/c/325956b0173f11e98f90462be4829a8b8b0682ce" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7e1471888a5e6e846e9b4d306e5327db2b58e64e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/814305b5c23cb815ada68d43019f39050472b25f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8e5647a723c49d73b9f108a8bb38e8c29d3948ea" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: media: rkisp1: Fix IRQ handling due to shared interrupts The driver requests the interrupts as IRQF_SHARED, so the interrupt handlers can be called at any time. If such a call happens while the ISP is powered down, the SoC will hang as the driver tries to access the ISP registers. This can be reproduced even without the platform sharing the IRQ line: Enable CONFIG_DEBUG_SHIRQ and unload the driver, and the board will hang. Fix this by adding a new field, 'irqs_enabled', which is used to bail out from the interrupt handler when the ISP is not operational.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52660" target="_blank">CVE-2023-52660</a><br><a href="https://git.kernel.org/stable/c/abd34206f396d3ae50cddbd5aa840b8cd7f68c63" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b39b4d207d4f236a74e20d291f6356f2231fd9ee" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/edcf92bc66d8361c51dff953a55210e5cfd95587" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ffb635bb398fc07cb38f8a7b4a82cbe5f412f08e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/tegra: rgb: Fix missing clk_put() in the error handling paths of tegra_dc_rgb_probe() If clk_get_sys(..., "pll_d2_out0") fails, the clk_get_sys() call must be undone. Add the missing clk_put and a new 'put_pll_d_out0' label in the error handling path, and use it.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52661" target="_blank">CVE-2023-52661</a><br><a href="https://git.kernel.org/stable/c/2388c36e028fff7f8ffd515681a14c6c2c07fea7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/45c8034db47842b25a3ab6139d71e13b4e67b9b3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5c8dc26e31b8b410ad1895e0d314def50c76eed0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/845322a9c06dd1dcf35b6c4e3af89684297c23cc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f3f407ccbe84a34de9be3195d22cdd5969f3fd9f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fa74e4f5d0821829545b9f7034a0e577c205c101" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: fix a memleak in vmw_gmrid_man_get_node When ida_alloc_max fails, resources allocated before should be freed, including *res allocated by kmalloc and ttm_resource_init.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52662" target="_blank">CVE-2023-52662</a><br><a href="https://git.kernel.org/stable/c/03b1072616a8f7d6e8594f643b416a9467c83fbf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/40624af6674745e174c754a20d7c53c250e65e7a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6fc6233f6db1579b69b54b44571f1a7fde8186e6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/83e0f220d1e992fa074157fcf14945bf170ffbc5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/89709105a6091948ffb6ec2427954cbfe45358ce" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d1e546ab91c670e536a274a75481034ab7534876" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: amd: Fix memory leak in amd_sof_acp_probe() Driver uses kasprintf() to initialize fw_{code,data}_bin members of struct acp_dev_data, but kfree() is never called to deallocate the memory, which results in a memory leak. Fix the issue by switching to devm_kasprintf(). Additionally, ensure the allocation was successful by checking the pointer validity.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52663" target="_blank">CVE-2023-52663</a><br><a href="https://git.kernel.org/stable/c/222be59e5eed1554119294edc743ee548c2371d0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7296152e58858f928db448826eb7ba5ae611297b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/88028c45d5871dfc449b2b0a27abf6428453a5ec" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/be4760799c6a7c01184467287f0de41e0dd255f8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: atlantic: eliminate double free in error handling logic Driver has a logic leak in ring data allocation/free, where aq_ring_free could be called multiple times on same ring, if system is under stress and got memory allocation error. Ring pointer was used as an indicator of failure, but this is not correct since only ring data is allocated/deallocated. Ring itself is an array member. Changing ring allocation functions to return error code directly. This simplifies error handling and eliminates aq_ring_free on higher layer.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52664" target="_blank">CVE-2023-52664</a><br><a href="https://git.kernel.org/stable/c/0edb3ae8bfa31cd544b0c195bdec00e036002b5d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b3cb7a830a24527877b0bc900b9bd74a96aea928" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c11a870a73a3bc4cc7df6dd877a45b181795fcbf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d1fde4a7e1dcc4d49cce285107a7a43c3030878d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: powerpc/ps3_defconfig: Disable PPC64_BIG_ENDIAN_ELF_ABI_V2 Commit 8c5fa3b5c4df ("powerpc/64: Make ELFv2 the default for big-endian builds"), merged in Linux-6.5-rc1 changes the calling ABI in a way that is incompatible with the current code for the PS3's LV1 hypervisor calls. This change just adds the line '# CONFIG_PPC64_BIG_ENDIAN_ELF_ABI_V2 is not set' to the ps3_defconfig file so that the PPC64_ELF_ABI_V1 is used. Fixes run time errors like these: BUG: Kernel NULL pointer dereference at 0x00000000 Faulting instruction address: 0xc000000000047cf0 Oops: Kernel access of bad area, sig: 11 [#1] Call Trace: [c0000000023039e0] [c00000000100ebfc] ps3_create_spu+0xc4/0x2b0 (unreliable) [c000000002303ab0] [c00000000100d4c4] create_spu+0xcc/0x3c4 [c000000002303b40] [c00000000100eae4] ps3_enumerate_spus+0xa4/0xf8</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52665" target="_blank">CVE-2023-52665</a><br><a href="https://git.kernel.org/stable/c/482b718a84f08b6fc84879c3e90cc57dba11c115" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d0f0780f03df54d08ced118d27834ee5008724e4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f70557d48215b14a9284ac3a6ae7e4ee1d039f10" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potential circular locking issue in smb2_set_ea() smb2_set_ea() can be called in parent inode lock range. So add get_write argument to smb2_set_ea() not to call nested mnt_want_write().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52666" target="_blank">CVE-2023-52666</a><br><a href="https://git.kernel.org/stable/c/5349fd419e4f685d609c85b781f2b70f0fb14848" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6fc0a265e1b932e5e97a038f99e29400a93baad0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e61fc656ceeaec65f19a92f0ffbeb562b7941e8d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e9ec6665de8f706b4f4133b87b2bd02a159ec57b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ecfd93955994ecc2a1308f5ee4bd90c7fca9a8c6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: fix a potential double-free in fs_any_create_groups When kcalloc() for ft-&gt;g succeeds but kvzalloc() for in fails, fs_any_create_groups() will free ft-&gt;g. However, its caller fs_any_create_table() will free ft-&gt;g again through calling mlx5e_destroy_flow_table(), which will lead to a double-free. Fix this by setting ft-&gt;g to NULL in fs_any_create_groups().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52667" target="_blank">CVE-2023-52667</a><br><a href="https://git.kernel.org/stable/c/2897c981ee63e1be5e530b1042484626a10b26d8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/65a4ade8a6d205979292e88beeb6a626ddbd4779" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/72a729868592752b5a294d27453da264106983b1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/aef855df7e1bbd5aa4484851561211500b22707e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b2fa86b2aceb4bc9ada51cea90f61546d7512cbe" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix lock ordering in btrfs_zone_activate() The btrfs CI reported a lockdep warning as follows by running generic generic/129. WARNING: possible circular locking dependency detected 6.7.0-rc5+ #1 Not tainted ------------------------------------------------------ kworker/u5:5/793427 is trying to acquire lock: ffff88813256d028 (&amp;cache-&gt;lock){+.+.}-{2:2}, at: btrfs_zone_finish_one_bg+0x5e/0x130 but task is already holding lock: ffff88810a23a318 (&amp;fs_info-&gt;zone_active_bgs_lock){+.+.}-{2:2}, at: btrfs_zone_finish_one_bg+0x34/0x130 which lock already depends on the new lock. the existing dependency chain (in reverse order) is: -&gt; #1 (&amp;fs_info-&gt;zone_active_bgs_lock){+.+.}-{2:2}: ... -&gt; #0 (&amp;cache-&gt;lock){+.+.}-{2:2}: ... This is because we take fs_info-&gt;zone_active_bgs_lock after a block_group's lock in btrfs_zone_activate() while doing the opposite in other places. Fix the issue by expanding the fs_info-&gt;zone_active_bgs_lock's critical section and taking it before a block_group's lock.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52668" target="_blank">CVE-2023-52668</a><br><a href="https://git.kernel.org/stable/c/1908e9d01e5395adff68d9d308a0fb15337e6272" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6f74989f5909cdec9b1274641f0fa306b15bb476" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b18f3b60b35a8c01c9a2a0f0d6424c6d73971dc3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: crypto: s390/aes - Fix buffer overread in CTR mode When processing the last block, the s390 ctr code will always read a whole block, even if there isn't a whole block of data left. Fix this by using the actual length left and copy it into a buffer first for processing.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52669" target="_blank">CVE-2023-52669</a><br><a href="https://git.kernel.org/stable/c/a7f580cdb42ec3d53bbb7c4e4335a98423703285" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cd51e26a3b89706beec64f2d8296cfb1c34e0c79" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d07f951903fa9922c375b8ab1ce81b18a0034e3b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d68ac38895e84446848b7647ab9458d54cacba3e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dbc9a791a70ea47be9f2acf251700fe254a2ab23" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e78f1a43e72daf77705ad5b9946de66fc708b874" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: rpmsg: virtio: Free driver_override when rpmsg_remove() Free driver_override when rpmsg_remove(), otherwise the following memory leak will occur: unreferenced object 0xffff0000d55d7080 (size 128): comm "kworker/u8:2", pid 56, jiffies 4294893188 (age 214.272s) hex dump (first 32 bytes): 72 70 6d 73 67 5f 6e 73 00 00 00 00 00 00 00 00 rpmsg_ns........ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [&lt;000000009c94c9c1&gt;] __kmem_cache_alloc_node+0x1f8/0x320 [&lt;000000002300d89b&gt;] __kmalloc_node_track_caller+0x44/0x70 [&lt;00000000228a60c3&gt;] kstrndup+0x4c/0x90 [&lt;0000000077158695&gt;] driver_set_override+0xd0/0x164 [&lt;000000003e9c4ea5&gt;] rpmsg_register_device_override+0x98/0x170 [&lt;000000001c0c89a8&gt;] rpmsg_ns_register_device+0x24/0x30 [&lt;000000008bbf8fa2&gt;] rpmsg_probe+0x2e0/0x3ec [&lt;00000000e65a68df&gt;] virtio_dev_probe+0x1c0/0x280 [&lt;00000000443331cc&gt;] really_probe+0xbc/0x2dc [&lt;00000000391064b1&gt;] __driver_probe_device+0x78/0xe0 [&lt;00000000a41c9a5b&gt;] driver_probe_device+0xd8/0x160 [&lt;000000009c3bd5df&gt;] __device_attach_driver+0xb8/0x140 [&lt;0000000043cd7614&gt;] bus_for_each_drv+0x7c/0xd4 [&lt;000000003b929a36&gt;] __device_attach+0x9c/0x19c [&lt;00000000a94e0ba8&gt;] device_initial_probe+0x14/0x20 [&lt;000000003c999637&gt;] bus_probe_device+0xa0/0xac</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52670" target="_blank">CVE-2023-52670</a><br><a href="https://git.kernel.org/stable/c/229ce47cbfdc7d3a9415eb676abbfb77d676cb08" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2d27a7b19cb354c6d04bcdc9239e261ff29858d6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4e6cef3fae5c164968118a13f3fe293700adc81a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/69ca89d80f2c8a1f5af429b955637beea7eead30" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a416d624e5fb7246ea97c11fbfea7e0e27abf43" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d5362c37e1f8a40096452fc201c30e705750e687" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dd50fe18c234bd5ff22f658f4d414e8fa8cd6a5d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f4bb1d5daf77b1a95a43277268adf0d1430c2346" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix hang/underflow when transitioning to ODM4:1 [Why] Under some circumstances, disabling an OPTC and attempting to reclaim its OPP(s) for a different OPTC could cause a hang/underflow due to OPPs not being properly disconnected from the disabled OPTC. [How] Ensure that all OPPs are unassigned from an OPTC when it gets disabled.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52671" target="_blank">CVE-2023-52671</a><br><a href="https://git.kernel.org/stable/c/4b6b479b2da6badff099b2e3abf0248936eefbf5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ae62f1dde66a6f0eee98defc4c7a346bd5acd239" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e7b2b108cdeab76a7e7324459e50b0c1214c0386" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: pipe: wakeup wr_wait after setting max_usage Commit c73be61cede5 ("pipe: Add general notification queue support") a regression was introduced that would lock up resized pipes under certain conditions. See the reproducer in [1]. The commit resizing the pipe ring size was moved to a different function, doing that moved the wakeup for pipe-&gt;wr_wait before actually raising pipe-&gt;max_usage. If a pipe was full before the resize occured it would result in the wakeup never actually triggering pipe_write. Set @max_usage and @nr_accounted before waking writers if this isn't a watch queue. [Christian Brauner &lt;brauner@kernel.org&gt;: rewrite to account for watch queues]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52672" target="_blank">CVE-2023-52672</a><br><a href="https://git.kernel.org/stable/c/162ae0e78bdabf84ef10c1293c4ed7865cb7d3c8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3efbd114b91525bb095b8ae046382197d92126b9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/68e51bdb1194f11d3452525b99c98aff6f837b24" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6fb70694f8d1ac34e45246b0ac988f025e1e5b55" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b87a1229d8668fbc78ebd9ca0fc797a76001c60f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e95aada4cb93d42e25c30a0ef9eb2923d9711d4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix a debugfs null pointer error [WHY &amp; HOW] Check whether get_subvp_en() callback exists before calling it.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52673" target="_blank">CVE-2023-52673</a><br><a href="https://git.kernel.org/stable/c/43235db21fc23559f50a62f8f273002eeb506f5a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/efb91fea652a42fcc037d2a9ef4ecd1ffc5ff4b7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add clamp() in scarlett2_mixer_ctl_put() Ensure the value passed to scarlett2_mixer_ctl_put() is between 0 and SCARLETT2_MIXER_MAX_VALUE so we don't attempt to access outside scarlett2_mixer_values[].</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52674" target="_blank">CVE-2023-52674</a><br><a href="https://git.kernel.org/stable/c/03035872e17897ba89866940bbc9cefca601e572" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/04f8f053252b86c7583895c962d66747ecdc61b7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ad945ea8d47dd4454c271510bea24850119847c2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d8d8897d65061cbe36bf2909057338303a904810" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e517645ead5ea22c69d2a44694baa23fe1ce7c2b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: powerpc/imc-pmu: Add a null pointer check in update_events_in_group() kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52675" target="_blank">CVE-2023-52675</a><br><a href="https://git.kernel.org/stable/c/024352f7928b28f53609660663329d8c0f4ad032" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0a233867a39078ebb0f575e2948593bbff5826b3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1e80aa25d186a7aa212df5acd8c75f55ac8dae34" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5a669f3511d273c8c1ab1c1d268fbcdf53fc7a05" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/75fc599bcdcb1de093c9ced2e3cccc832f3787f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a2da3f9b1a1019c887ee1d164475a8fcdb0a3fec" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c7d828e12b326ea50fb80c369d7aa87519ed14c6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f105c263009839d80fad6998324a4e1b3511cba0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: bpf: Guard stack limits against 32bit overflow This patch promotes the arithmetic around checking stack bounds to be done in the 64-bit domain, instead of the current 32bit. The arithmetic implies adding together a 64-bit register with a int offset. The register was checked to be below 1&lt;&lt;29 when it was variable, but not when it was fixed. The offset either comes from an instruction (in which case it is 16 bit), from another register (in which case the caller checked it to be below 1&lt;&lt;29 [1]), or from the size of an argument to a kfunc (in which case it can be a u32 [2]). Between the register being inconsistently checked to be below 1&lt;&lt;29, and the offset being up to an u32, it appears that we were open to overflowing the `int`s which were currently used for arithmetic. [1] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L7494-L7498 [2] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L11904</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52676" target="_blank">CVE-2023-52676</a><br><a href="https://git.kernel.org/stable/c/1d38a9ee81570c4bd61f557832dead4d6f816760" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ad140fc856f0b1d5e2215bcb6d0cc247a86805a2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e5ad9ecb84405637df82732ee02ad741a5f782a6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: riscv: Check if the code to patch lies in the exit section Otherwise we fall through to vmalloc_to_page() which panics since the address does not lie in the vmalloc region.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52677" target="_blank">CVE-2023-52677</a><br><a href="https://git.kernel.org/stable/c/1d7a03052846f34d624d0ab41a879adf5e85c85f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/420370f3ae3d3b883813fd3051a38805160b2b9f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/890cfe5337e0aaf03ece1429db04d23c88da72e7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8db56df4a954b774bdc68917046a685a9fa2e4bc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/938f70d14618ec72e10d6fcf8a546134136d7c13" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Confirm list is non-empty before utilizing list_first_entry in kfd_topology.c Before using list_first_entry, make sure to check that list is not empty, if list is empty return -ENODATA. Fixes the below: drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_topology.c:1347 kfd_create_indirect_link_prop() warn: can 'gpu_link' even be NULL? drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_topology.c:1428 kfd_add_peer_prop() warn: can 'iolink1' even be NULL? drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_topology.c:1433 kfd_add_peer_prop() warn: can 'iolink2' even be NULL?</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52678" target="_blank">CVE-2023-52678</a><br><a href="https://git.kernel.org/stable/c/4525525cb7161d08f95d0e47025323dd10214313" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/499839eca34ad62d43025ec0b46b80e77065f6d8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4ac4e023ed7ab1c7c67d2d12b7b6198fcd099e5c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5024cce888e11e5688f77df81db9e14828495d64" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: of: Fix double free in of_parse_phandle_with_args_map In of_parse_phandle_with_args_map() the inner loop that iterates through the map entries calls of_node_put(new) to free the reference acquired by the previous iteration of the inner loop. This assumes that the value of "new" is NULL on the first iteration of the inner loop. Make sure that this is true in all iterations of the outer loop by setting "new" to NULL after its value is assigned to "cur". Extend the unittest to detect the double free and add an additional test case that actually triggers this path.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52679" target="_blank">CVE-2023-52679</a><br><a href="https://git.kernel.org/stable/c/26b4d702c44f9e5cf3c5c001ae619a4a001889db" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4541004084527ce9e95a818ebbc4e6b293ffca21" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4dde83569832f9377362e50f7748463340c5db6b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a0a061151a6200c13149dbcdb6c065203c8425d2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b64d09a4e8596f76d27f4b4a90a1cf6baf6a82f8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b9d760dae5b10e73369b769073525acd7b3be2bd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cafa992134124e785609a406da4ff2b54052aff7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d5f490343c77e6708b6c4aa7dbbfbcbb9546adea" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add missing error checks to *_ctl_get() The *_ctl_get() functions which call scarlett2_update_*() were not checking the return value. Fix to check the return value and pass to the caller.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52680" target="_blank">CVE-2023-52680</a><br><a href="https://git.kernel.org/stable/c/3a09488f4f67f7ade59b8ac62a6c7fb29439cf51" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/50603a67daef161c78c814580d57f7f0be57167e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/773e38f73461ef2134a0d33a08f1668edde9b7c3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/821fbaeaaae23d483d3df799fe91ec8045973ec3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cda7762bea857e6951315a2f7d0632ea1850ed43" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: efivarfs: Free s_fs_info on unmount Now that we allocate a s_fs_info struct on fs context creation, we should ensure that we free it again when the superblock goes away.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52681" target="_blank">CVE-2023-52681</a><br><a href="https://git.kernel.org/stable/c/48be1364dd387e375e1274b76af986cb8747be2c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/547713d502f7b4b8efccd409cff84d731a23853b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/92be3095c6ca1cdc46237839c6087555be9160e3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ea6b597fcaca99562fa56a473bcbbbd79b40af03" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to wait on block writeback for post_read case If inode is compressed, but not encrypted, it missed to call f2fs_wait_on_block_writeback() to wait for GCed page writeback in IPU write path. Thread A GC-Thread - f2fs_gc - do_garbage_collect - gc_data_segment - move_data_block - f2fs_submit_page_write migrate normal cluster's block via meta_inode's page cache - f2fs_write_single_data_page - f2fs_do_write_data_page - f2fs_inplace_write_data - f2fs_submit_page_bio IRQ - f2fs_read_end_io IRQ old data overrides new data due to out-of-order GC and common IO. - f2fs_read_end_io</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52682" target="_blank">CVE-2023-52682</a><br><a href="https://git.kernel.org/stable/c/4535be48780431753505e74e1b1ad4836a189bc2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/55fdc1c24a1d6229fe0ecf31335fb9a2eceaaa00" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9bfd5ea71521d0e522ba581c6ccc5db93759c0c3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f904c156d8011d8291ffd5b6b398f3747e294986" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ACPI: LPIT: Avoid u32 multiplication overflow In lpit_update_residency() there is a possibility of overflow in multiplication, if tsc_khz is large enough (&gt; UINT_MAX/1000). Change multiplication to mul_u32_u32(). Found by Linux Verification Center (linuxtesting.org) with SVACE.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52683" target="_blank">CVE-2023-52683</a><br><a href="https://git.kernel.org/stable/c/56d2eeda87995245300836ee4dbd13b002311782" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/647d1d50c31e60ef9ccb9756a8fdf863329f7aee" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6c38e791bde07d6ca2a0a619ff9b6837e0d5f9ad" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/72222dfd76a79d9666ab3117fcdd44ca8cd0c4de" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b7aab9d906e2e252a7783f872406033ec49b6dae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c1814a4ffd016ce5392c6767d22ef3aa2f0d4bd1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d1ac288b2742aa4af746c5613bac71760fadd1c4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f39c3d578c7d09a18ceaf56750fc7f20b02ada63" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: qseecom: fix memory leaks in error paths Fix instances of returning error codes directly instead of jumping to the relevant labels where memory allocated for the SCM calls would be freed.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52684" target="_blank">CVE-2023-52684</a><br><a href="https://git.kernel.org/stable/c/6c57d7b593c4a4e60db65d5ce0fe1d9f79ccbe9b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/85fdbf6840455be64eac16bdfe0df3368ee3d0f0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: pstore: ram_core: fix possible overflow in persistent_ram_init_ecc() In persistent_ram_init_ecc(), on 64-bit arches DIV_ROUND_UP() will return 64-bit value since persistent_ram_zone::buffer_size has type size_t which is derived from the 64-bit *unsigned long*, while the ecc_blocks variable this value gets assigned to has (always 32-bit) *int* type. Even if that value fits into *int* type, an overflow is still possible when calculating the size_t typed ecc_total variable further below since there's no cast to any 64-bit type before multiplication. Declaring the ecc_blocks variable as *size_t* should fix this mess... Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52685" target="_blank">CVE-2023-52685</a><br><a href="https://git.kernel.org/stable/c/3b333cded94fbe5ce30d699b316c4715151268ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/48dcfc42ce705b652c0619cb99846afc43029de9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/86222a8fc16ec517de8da2604d904c9df3a08e5d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8fb12524c86bdd542a54857d5d076b1b6778c78c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a34946ec3de88a16cc3a87fdab50aad06255a22b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/acd413da3e1f37582207cd6078a41d57c9011918" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d1fe1aede684bd014714dacfdc75586a9ad38657" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f9b891a7e8fcf83901f8507241e23e7420103b61" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv: Add a null pointer check in opal_event_init() kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52686" target="_blank">CVE-2023-52686</a><br><a href="https://git.kernel.org/stable/c/8422d179cf46889c15ceff9ede48c5bfa4e7f0b4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8649829a1dd25199bbf557b2621cedb4bf9b3050" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a523e1da6d88c2034f946adfa4f74b236c95ca9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a14c55eb461d630b836f80591d8caf1f74e62877" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c0b111ea786ddcc8be0682612830796ece9436c7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e08c2e275fa1874de945b87093f925997722ee42" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e6ad05e3ae9c84c5a71d7bb2d44dc845ae7990cf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e93d7cf4c1ddbcd846739e7ad849f955a4f18031" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: crypto: safexcel - Add error handling for dma_map_sg() calls Macro dma_map_sg() may return 0 on error. This patch enables checks in case of the macro failure and ensures unmapping of previously mapped buffers with dma_unmap_sg(). Found by Linux Verification Center (linuxtesting.org) with static analysis tool SVACE.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52687" target="_blank">CVE-2023-52687</a><br><a href="https://git.kernel.org/stable/c/4c0ac81a172a69a7733290915276672787e904ec" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8084b788c2fb1260f7d44c032d5124680b20d2b2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/87e02063d07708cac5bfe9fd3a6a242898758ac8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fc0b785802b856566df3ac943e38a072557001c4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix the error handler of rfkill config When the core rfkill config throws error, it should free the allocated resources. Currently it is not freeing the core pdev create resources. Avoid this issue by calling the core pdev destroy in the error handler of core rfkill config. Found this issue in the code review and it is compile tested only.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52688" target="_blank">CVE-2023-52688</a><br><a href="https://git.kernel.org/stable/c/898d8b3e1414cd900492ee6a0b582f8095ba4a1a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b4e593a7a22fa3c7d0550ef51c90b5c21f790aa8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add missing mutex lock around get meter levels As scarlett2_meter_ctl_get() uses meter_level_map[], the data_mutex should be locked while accessing it.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52689" target="_blank">CVE-2023-52689</a><br><a href="https://git.kernel.org/stable/c/74e3de7cdcc31ce75ab42350ae0946eff62a2da2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/993f7b42fa066b055e3a19b7f76ad8157c0927a0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv: Add a null pointer check to scom_debug_init_one() kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure. Add a null pointer check, and release 'ent' to avoid memory leaks.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52690" target="_blank">CVE-2023-52690</a><br><a href="https://git.kernel.org/stable/c/1eefa93faf69188540b08b024794fa90b1d82e8b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2a82c4439b903639e0a1f21990cd399fb0a49c19" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a260f2dd827bbc82cc60eb4f4d8c22707d80742" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a9c05cbb6644a2103c75b6906e9dafb9981ebd13" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dd8422ff271c22058560832fc3006324ded895a9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ed8d023cfa97b559db58c0e1afdd2eec7a83d8f2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f84c1446daa552e9699da8d1f8375eac0f65edc7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: fix a double-free in si_dpm_init When the allocation of adev-&gt;pm.dpm.dyn_state.vddc_dependency_on_dispclk.entries fails, amdgpu_free_extended_power_table is called to free some fields of adev. However, when the control flow returns to si_dpm_sw_init, it goes to label dpm_failed and calls si_dpm_fini, which calls amdgpu_free_extended_power_table again and free those fields again. Thus a double-free is triggered.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52691" target="_blank">CVE-2023-52691</a><br><a href="https://git.kernel.org/stable/c/06d95c99d5a4f5accdb79464076efe62e668c706" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2bf47c89bbaca2bae16581ef1b28aaec0ade0334" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ac16667237a82e2597e329eb9bc520d1cf9dff30" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/aeed2b4e4a70c7568d4a5eecd6a109713c0dfbf4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/afe9f5b871f86d58ecdc45b217b662227d7890d0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ca8e2e251c65e5a712f6025e27bd9b26d16e6f4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f957a1be647f7fc65926cbf572992ec2747a93f2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fb1936cb587262cd539e84b34541abb06e42b2f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add missing error check to scarlett2_usb_set_config() scarlett2_usb_set_config() calls scarlett2_usb_get() but was not checking the result. Return the error if it fails rather than continuing with an invalid value.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52692" target="_blank">CVE-2023-52692</a><br><a href="https://git.kernel.org/stable/c/145c5aa51486171025ab47f35cff34bff8d0cea3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/51d5697e1c0380d482c3eab002bfc8d0be177e99" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/996fde492ad9b9563ee483b363af40d7696a8467" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/be96acd3eaa790d10a5b33e65267f52d02f6ad88" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ca459dfa7d4ed9098fcf13e410963be6ae9b6bf3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ACPI: video: check for error while searching for backlight device parent If acpi_get_parent() called in acpi_video_dev_register_backlight() fails, for example, because acpi_ut_acquire_mutex() fails inside acpi_get_parent), this can lead to incorrect (uninitialized) acpi_parent handle being passed to acpi_get_pci_dev() for detecting the parent pci device. Check acpi_get_parent() result and set parent device only in case of success. Found by Linux Verification Center (linuxtesting.org) with SVACE.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52693" target="_blank">CVE-2023-52693</a><br><a href="https://git.kernel.org/stable/c/1e3a2b9b4039bb4d136dca59fb31e06465e056f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2124c5bc22948fc4d09a23db4a8acdccc7d21e95" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/39af144b6d01d9b40f52e5d773e653957e6c379c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3a370502a5681986f9828e43be75ce26c6ab24af" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/556f02699d33c1f40b1b31bd25828ce08fa165d8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/72884ce4e10417b1233b614bf134da852df0f15f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c4e1a0ef0b4782854c9b77a333ca912b392bed2f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ccd45faf4973746c4f30ea41eec864e5cf191099" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/bridge: tpd12s015: Drop buggy __exit annotation for remove function With tpd12s015_remove() marked with __exit this function is discarded when the driver is compiled as a built-in. The result is that when the driver unbinds there is no cleanup done which results in resource leakage or worse.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52694" target="_blank">CVE-2023-52694</a><br><a href="https://git.kernel.org/stable/c/08ccff6ece35f08e8107e975903c370d849089e5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/53926e2a39629702f7f809d614b3ca89c2478205" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/81f1bd85960b7a089a91e679ff7cd2524390bbf1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a8657406e12aa10412134622c58977ac657f16d2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ce3e112e7ae854249d8755906acc5f27e1542114" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e00ec5901954d85b39b5f10f94e60ab9af463eb1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check writeback connectors in create_validate_stream_for_sink [WHY &amp; HOW] This is to check connector type to avoid unhandled null pointer for writeback connectors.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52695" target="_blank">CVE-2023-52695</a><br><a href="https://git.kernel.org/stable/c/0fe85301b95077ac4fa4a91909d38b7341e81187" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dbf5d3d02987faa0eec3710dd687cd912362d7b5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv: Add a null pointer check in opal_powercap_init() kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52696" target="_blank">CVE-2023-52696</a><br><a href="https://git.kernel.org/stable/c/69f95c5e9220f77ce7c540686b056c2b49e9a664" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6b58d16037217d0c64a2a09b655f370403ec7219" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9da4a56dd3772570512ca58aa8832b052ae910dc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a67a04ad05acb56640798625e73fa54d6d41cce1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b02ecc35d01a76b4235e008d2dd292895b28ecab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e123015c0ba859cf48aa7f89c5016cc6e98e018d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f152a6bfd187f67afeffc9fd68cbe46f51439be0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw_rt_sdca_jack_common: ctx-&gt;headset_codec_dev = NULL sof_sdw_rt_sdca_jack_exit() are used by different codecs, and some of them use the same dai name. For example, rt712 and rt713 both use "rt712-sdca-aif1" and sof_sdw_rt_sdca_jack_exit(). As a result, sof_sdw_rt_sdca_jack_exit() will be called twice by mc_dailink_exit_loop(). Set ctx-&gt;headset_codec_dev = NULL; after put_device(ctx-&gt;headset_codec_dev); to avoid ctx-&gt;headset_codec_dev being put twice.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52697" target="_blank">CVE-2023-52697</a><br><a href="https://git.kernel.org/stable/c/582231a8c4f73ac153493687ecc1bed853e9c9ef" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a410d58117d6da4b7d41f3c91365f191d006bc3d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e38e252dbceeef7d2f848017132efd68e9ae1416" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: calipso: fix memory leak in netlbl_calipso_add_pass() If IPv6 support is disabled at boot (ipv6.disable=1), the calipso_init() -&gt; netlbl_calipso_ops_register() function isn't called, and the netlbl_calipso_ops_get() function always returns NULL. In this case, the netlbl_calipso_add_pass() function allocates memory for the doi_def variable but doesn't free it with the calipso_doi_free(). BUG: memory leak unreferenced object 0xffff888011d68180 (size 64): comm "syz-executor.1", pid 10746, jiffies 4295410986 (age 17.928s) hex dump (first 32 bytes): 00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [&lt;...&gt;] kmalloc include/linux/slab.h:552 [inline] [&lt;...&gt;] netlbl_calipso_add_pass net/netlabel/netlabel_calipso.c:76 [inline] [&lt;...&gt;] netlbl_calipso_add+0x22e/0x4f0 net/netlabel/netlabel_calipso.c:111 [&lt;...&gt;] genl_family_rcv_msg_doit+0x22f/0x330 net/netlink/genetlink.c:739 [&lt;...&gt;] genl_family_rcv_msg net/netlink/genetlink.c:783 [inline] [&lt;...&gt;] genl_rcv_msg+0x341/0x5a0 net/netlink/genetlink.c:800 [&lt;...&gt;] netlink_rcv_skb+0x14d/0x440 net/netlink/af_netlink.c:2515 [&lt;...&gt;] genl_rcv+0x29/0x40 net/netlink/genetlink.c:811 [&lt;...&gt;] netlink_unicast_kernel net/netlink/af_netlink.c:1313 [inline] [&lt;...&gt;] netlink_unicast+0x54b/0x800 net/netlink/af_netlink.c:1339 [&lt;...&gt;] netlink_sendmsg+0x90a/0xdf0 net/netlink/af_netlink.c:1934 [&lt;...&gt;] sock_sendmsg_nosec net/socket.c:651 [inline] [&lt;...&gt;] sock_sendmsg+0x157/0x190 net/socket.c:671 [&lt;...&gt;] ____sys_sendmsg+0x712/0x870 net/socket.c:2342 [&lt;...&gt;] ___sys_sendmsg+0xf8/0x170 net/socket.c:2396 [&lt;...&gt;] __sys_sendmsg+0xea/0x1b0 net/socket.c:2429 [&lt;...&gt;] do_syscall_64+0x30/0x40 arch/x86/entry/common.c:46 [&lt;...&gt;] entry_SYSCALL_64_after_hwframe+0x61/0xc6 Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with Syzkaller [PM: merged via the LSM tree at Jakub Kicinski request]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52698" target="_blank">CVE-2023-52698</a><br><a href="https://git.kernel.org/stable/c/321b3a5592c8a9d6b654c7c64833ea67dbb33149" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/36e19f84634aaa94f543fedc0a07588949638d53" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/408bbd1e1746fe33e51f4c81c2febd7d3841d031" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/44a88650ba55e6a7f2ec485d2c2413ba7e216f01" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a8f811a146aa2a0230f8edb2e9f4b6609aab8da" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a4529a08d3704c17ea9c7277d180e46b99250ded" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ec4e9d630a64df500641892f4e259e8149594a99" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f14d36e6e97fe935a20e0ceb159c100f90b6627c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: xen-netfront: Add missing skb_mark_for_recycle Notice that skb_mark_for_recycle() is introduced later than fixes tag in commit 6a5bcd84e886 ("page_pool: Allow drivers to hint on SKB recycling"). It is believed that fixes tag were missing a call to page_pool_release_page() between v5.9 to v5.14, after which is should have used skb_mark_for_recycle(). Since v6.6 the call page_pool_release_page() were removed (in commit 535b9c61bdef ("net: page_pool: hide page_pool_release_page()") and remaining callers converted (in commit 6bfef2ec0172 ("Merge branch 'net-page_pool-remove-page_pool_release_page'")). This leak became visible in v6.8 via commit dba1b8a7ab68 ("mm/page_pool: catch page_pool memory leaks").</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27393" target="_blank">CVE-2024-27393</a><br><a href="https://git.kernel.org/stable/c/037965402a010898d34f4e35327d22c0a95cd51f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/27aa3e4b3088426b7e34584274ad45b5afaf7629" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4143b9479caa29bb2380f3620dcbe16ea84eb3b1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7c1250796b6c262b505a46192f4716b8c6a6a8c6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c8b7b2f158d9d4fb89cd2f68244af154f7549bb4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: tcp: Fix Use-After-Free in tcp_ao_connect_init Since call_rcu, which is called in the hlist_for_each_entry_rcu traversal of tcp_ao_connect_init, is not part of the RCU read critical section, it is possible that the RCU grace period will pass during the traversal and the key will be free. To prevent this, it should be changed to hlist_for_each_entry_safe.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27394" target="_blank">CVE-2024-27394</a><br><a href="https://git.kernel.org/stable/c/80e679b352c3ce5158f3f778cfb77eb767e586fb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ca4fb6c6764b3f75b4f5aa81db1536291897ff7f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: Fix Use-After-Free in ovs_ct_exit Since kfree_rcu, which is called in the hlist_for_each_entry_rcu traversal of ovs_ct_limit_exit, is not part of the RCU read critical section, it is possible that the RCU grace period will pass during the traversal and the key will be free. To prevent this, it should be changed to hlist_for_each_entry_safe.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27395" target="_blank">CVE-2024-27395</a><br><a href="https://git.kernel.org/stable/c/2db9a8c0a01fa1c762c1e61a13c212c492752994" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/35880c3fa6f8fe281a19975d2992644588ca33d3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/589523cf0b384164e445dd5db8d5b1bf97982424" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5ea7b72d4fac2fdbc0425cd8f2ea33abe95235b2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9048616553c65e750d43846f225843ed745ec0d4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bca6fa2d9a9f560e6b89fd5190b05cc2f5d422c1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eaa5e164a2110d2fb9e16c8a29e4501882235137" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/edee0758747d7c219e29db9ed1d4eb33e8d32865" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: gtp: Fix Use-After-Free in gtp_dellink Since call_rcu, which is called in the hlist_for_each_entry_rcu traversal of gtp_dellink, is not part of the RCU read critical section, it is possible that the RCU grace period will pass during the traversal and the key will be free. To prevent this, it should be changed to hlist_for_each_entry_safe.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27396" target="_blank">CVE-2024-27396</a><br><a href="https://git.kernel.org/stable/c/07b20d0a3dc13fb1adff10b60021a4924498da58" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0caff3e6390f840666b8dc1ecebf985c2ef3f1dd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/25a1c2d4b1fcf938356a9688a96a6456abd44b29" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2aacd4de45477582993f8a8abb9505a06426bfb6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2e74b3fd6bf542349758f283676dff3660327c07" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/718df1bc226c383dd803397d7f5d95557eb81ac7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cd957d1716ec979d8f5bf38fc659aeb9fdaa2474" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f2a904107ee2b647bb7794a1a82b67740d7c8a64" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use timestamp to check for set element timeout Add a timestamp field at the beginning of the transaction, store it in the nftables per-netns area. Update set backend .insert, .deactivate and sync gc path to use the timestamp, this avoids that an element expires while control plane transaction is still unfinished. .lookup and .update, which are used from packet path, still use the current time to check if the element has expired. And .get path and dump also since this runs lockless under rcu read size lock. Then, there is async gc which also needs to check the current time since it runs asynchronously from a workqueue.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27397" target="_blank">CVE-2024-27397</a><br><a href="https://git.kernel.org/stable/c/383182db8d58c4237772ba0764cded4938a235c3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7395dfacfff65e9938ac0889dafa1ab01e987d15" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout When the sco connection is established and then, the sco socket is releasing, timeout_work will be scheduled to judge whether the sco disconnection is timeout. The sock will be deallocated later, but it is dereferenced again in sco_sock_timeout. As a result, the use-after-free bugs will happen. The root cause is shown below: Cleanup Thread | Worker Thread sco_sock_release | sco_sock_close | __sco_sock_close | sco_sock_set_timer | schedule_delayed_work | sco_sock_kill | (wait a time) sock_put(sk) //FREE | sco_sock_timeout | sock_hold(sk) //USE The KASAN report triggered by POC is shown below: [ 95.890016] ================================================================== [ 95.890496] BUG: KASAN: slab-use-after-free in sco_sock_timeout+0x5e/0x1c0 [ 95.890755] Write of size 4 at addr ffff88800c388080 by task kworker/0:0/7 ... [ 95.890755] Workqueue: events sco_sock_timeout [ 95.890755] Call Trace: [ 95.890755] &lt;TASK&gt; [ 95.890755] dump_stack_lvl+0x45/0x110 [ 95.890755] print_address_description+0x78/0x390 [ 95.890755] print_report+0x11b/0x250 [ 95.890755] ? __virt_addr_valid+0xbe/0xf0 [ 95.890755] ? sco_sock_timeout+0x5e/0x1c0 [ 95.890755] kasan_report+0x139/0x170 [ 95.890755] ? update_load_avg+0xe5/0x9f0 [ 95.890755] ? sco_sock_timeout+0x5e/0x1c0 [ 95.890755] kasan_check_range+0x2c3/0x2e0 [ 95.890755] sco_sock_timeout+0x5e/0x1c0 [ 95.890755] process_one_work+0x561/0xc50 [ 95.890755] worker_thread+0xab2/0x13c0 [ 95.890755] ? pr_cont_work+0x490/0x490 [ 95.890755] kthread+0x279/0x300 [ 95.890755] ? pr_cont_work+0x490/0x490 [ 95.890755] ? kthread_blkcg+0xa0/0xa0 [ 95.890755] ret_from_fork+0x34/0x60 [ 95.890755] ? kthread_blkcg+0xa0/0xa0 [ 95.890755] ret_from_fork_asm+0x11/0x20 [ 95.890755] &lt;/TASK&gt; [ 95.890755] [ 95.890755] Allocated by task 506: [ 95.890755] kasan_save_track+0x3f/0x70 [ 95.890755] __kasan_kmalloc+0x86/0x90 [ 95.890755] __kmalloc+0x17f/0x360 [ 95.890755] sk_prot_alloc+0xe1/0x1a0 [ 95.890755] sk_alloc+0x31/0x4e0 [ 95.890755] bt_sock_alloc+0x2b/0x2a0 [ 95.890755] sco_sock_create+0xad/0x320 [ 95.890755] bt_sock_create+0x145/0x320 [ 95.890755] __sock_create+0x2e1/0x650 [ 95.890755] __sys_socket+0xd0/0x280 [ 95.890755] __x64_sys_socket+0x75/0x80 [ 95.890755] do_syscall_64+0xc4/0x1b0 [ 95.890755] entry_SYSCALL_64_after_hwframe+0x67/0x6f [ 95.890755] [ 95.890755] Freed by task 506: [ 95.890755] kasan_save_track+0x3f/0x70 [ 95.890755] kasan_save_free_info+0x40/0x50 [ 95.890755] poison_slab_object+0x118/0x180 [ 95.890755] __kasan_slab_free+0x12/0x30 [ 95.890755] kfree+0xb2/0x240 [ 95.890755] __sk_destruct+0x317/0x410 [ 95.890755] sco_sock_release+0x232/0x280 [ 95.890755] sock_close+0xb2/0x210 [ 95.890755] __fput+0x37f/0x770 [ 95.890755] task_work_run+0x1ae/0x210 [ 95.890755] get_signal+0xe17/0xf70 [ 95.890755] arch_do_signal_or_restart+0x3f/0x520 [ 95.890755] syscall_exit_to_user_mode+0x55/0x120 [ 95.890755] do_syscall_64+0xd1/0x1b0 [ 95.890755] entry_SYSCALL_64_after_hwframe+0x67/0x6f [ 95.890755] [ 95.890755] The buggy address belongs to the object at ffff88800c388000 [ 95.890755] which belongs to the cache kmalloc-1k of size 1024 [ 95.890755] The buggy address is located 128 bytes inside of [ 95.890755] freed 1024-byte region [ffff88800c388000, ffff88800c388400) [ 95.890755] [ 95.890755] The buggy address belongs to the physical page: [ 95.890755] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff88800c38a800 pfn:0xc388 [ 95.890755] head: order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 95.890755] ano ---truncated---</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27398" target="_blank">CVE-2024-27398</a><br><a href="https://git.kernel.org/stable/c/012363cb1bec5f33a7b94629ab2c1086f30280f2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1b33d55fb7355e27f8c82cd4ecd560f162469249" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3212afd00e3cda790fd0583cb3eaef8f9575a014" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/33a6e92161a78c1073d90e27abe28d746feb0a53" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/483bc08181827fc475643272ffb69c533007e546" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/50c2037fc28df870ef29d9728c770c8955d32178" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6a18eeb1b3bbc67c20d9609c31dca6a69b4bcde5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bfab2c1f7940a232cd519e82fff137e308abfd93" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout There is a race condition between l2cap_chan_timeout() and l2cap_chan_del(). When we use l2cap_chan_del() to delete the channel, the chan-&gt;conn will be set to null. But the conn could be dereferenced again in the mutex_lock() of l2cap_chan_timeout(). As a result the null pointer dereference bug will happen. The KASAN report triggered by POC is shown below: [ 472.074580] ================================================================== [ 472.075284] BUG: KASAN: null-ptr-deref in mutex_lock+0x68/0xc0 [ 472.075308] Write of size 8 at addr 0000000000000158 by task kworker/0:0/7 [ 472.075308] [ 472.075308] CPU: 0 PID: 7 Comm: kworker/0:0 Not tainted 6.9.0-rc5-00356-g78c0094a146b #36 [ 472.075308] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu4 [ 472.075308] Workqueue: events l2cap_chan_timeout [ 472.075308] Call Trace: [ 472.075308] &lt;TASK&gt; [ 472.075308] dump_stack_lvl+0x137/0x1a0 [ 472.075308] print_report+0x101/0x250 [ 472.075308] ? __virt_addr_valid+0x77/0x160 [ 472.075308] ? mutex_lock+0x68/0xc0 [ 472.075308] kasan_report+0x139/0x170 [ 472.075308] ? mutex_lock+0x68/0xc0 [ 472.075308] kasan_check_range+0x2c3/0x2e0 [ 472.075308] mutex_lock+0x68/0xc0 [ 472.075308] l2cap_chan_timeout+0x181/0x300 [ 472.075308] process_one_work+0x5d2/0xe00 [ 472.075308] worker_thread+0xe1d/0x1660 [ 472.075308] ? pr_cont_work+0x5e0/0x5e0 [ 472.075308] kthread+0x2b7/0x350 [ 472.075308] ? pr_cont_work+0x5e0/0x5e0 [ 472.075308] ? kthread_blkcg+0xd0/0xd0 [ 472.075308] ret_from_fork+0x4d/0x80 [ 472.075308] ? kthread_blkcg+0xd0/0xd0 [ 472.075308] ret_from_fork_asm+0x11/0x20 [ 472.075308] &lt;/TASK&gt; [ 472.075308] ================================================================== [ 472.094860] Disabling lock debugging due to kernel taint [ 472.096136] BUG: kernel NULL pointer dereference, address: 0000000000000158 [ 472.096136] #PF: supervisor write access in kernel mode [ 472.096136] #PF: error_code(0x0002) - not-present page [ 472.096136] PGD 0 P4D 0 [ 472.096136] Oops: 0002 [#1] PREEMPT SMP KASAN NOPTI [ 472.096136] CPU: 0 PID: 7 Comm: kworker/0:0 Tainted: G B 6.9.0-rc5-00356-g78c0094a146b #36 [ 472.096136] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu4 [ 472.096136] Workqueue: events l2cap_chan_timeout [ 472.096136] RIP: 0010:mutex_lock+0x88/0xc0 [ 472.096136] Code: be 08 00 00 00 e8 f8 23 1f fd 4c 89 f7 be 08 00 00 00 e8 eb 23 1f fd 42 80 3c 23 00 74 08 48 88 [ 472.096136] RSP: 0018:ffff88800744fc78 EFLAGS: 00000246 [ 472.096136] RAX: 0000000000000000 RBX: 1ffff11000e89f8f RCX: ffffffff8457c865 [ 472.096136] RDX: 0000000000000001 RSI: 0000000000000008 RDI: ffff88800744fc78 [ 472.096136] RBP: 0000000000000158 R08: ffff88800744fc7f R09: 1ffff11000e89f8f [ 472.096136] R10: dffffc0000000000 R11: ffffed1000e89f90 R12: dffffc0000000000 [ 472.096136] R13: 0000000000000158 R14: ffff88800744fc78 R15: ffff888007405a00 [ 472.096136] FS: 0000000000000000(0000) GS:ffff88806d200000(0000) knlGS:0000000000000000 [ 472.096136] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 472.096136] CR2: 0000000000000158 CR3: 000000000da32000 CR4: 00000000000006f0 [ 472.096136] Call Trace: [ 472.096136] &lt;TASK&gt; [ 472.096136] ? __die_body+0x8d/0xe0 [ 472.096136] ? page_fault_oops+0x6b8/0x9a0 [ 472.096136] ? kernelmode_fixup_or_oops+0x20c/0x2a0 [ 472.096136] ? do_user_addr_fault+0x1027/0x1340 [ 472.096136] ? _printk+0x7a/0xa0 [ 472.096136] ? mutex_lock+0x68/0xc0 [ 472.096136] ? add_taint+0x42/0xd0 [ 472.096136] ? exc_page_fault+0x6a/0x1b0 [ 472.096136] ? asm_exc_page_fault+0x26/0x30 [ 472.096136] ? mutex_lock+0x75/0xc0 [ 472.096136] ? mutex_lock+0x88/0xc0 [ 472.096136] ? mutex_lock+0x75/0xc0 [ 472.096136] l2cap_chan_timeo ---truncated---</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27399" target="_blank">CVE-2024-27399</a><br><a href="https://git.kernel.org/stable/c/06acb75e7ed600d0bbf7bff5628aa8f24a97978c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6466ee65e5b27161c846c73ef407f49dfa1bd1d9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8960ff650aec70485b40771cd8e6e8c4cb467d33" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/955b5b6c54d95b5e7444dfc81c95c8e013f27ac0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/adf0398cee86643b8eacde95f17d073d022f782c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e137e2ba96e51902dc2878131823a96bf8e638ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e97e16433eb4533083b096a3824b93a5ca3aee79" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eb86f955488c39526534211f2610e48a5cf8ead4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: once more fix the call oder in amdgpu_ttm_move() v2 This reverts drm/amdgpu: fix ftrace event amdgpu_bo_move always move on same heap. The basic problem here is that after the move the old location is simply not available any more. Some fixes were suggested, but essentially we should call the move notification before actually moving things because only this way we have the correct order for DMA-buf and VM move notifications as well. Also rework the statistic handling so that we don't update the eviction counter before the move. v2: add missing NULL check</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27400" target="_blank">CVE-2024-27400</a><br><a href="https://git.kernel.org/stable/c/0c7ed3ed35eec9138b88d42217b5a6b9a62bda4d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5c25b169f9a0b34ee410891a96bc9d7b9ed6f9be" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a4f6e138720b6e9adf7b82a71d0292f3f276480" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d3a9331a6591e9df64791e076f6591f440af51c3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: firewire: nosy: ensure user_length is taken into account when fetching packet contents Ensure that packet_buffer_get respects the user_length provided. If the length of the head packet exceeds the user_length, packet_buffer_get will now return 0 to signify to the user that no data were read and a larger buffer size is required. Helps prevent user space overflows.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27401" target="_blank">CVE-2024-27401</a><br><a href="https://git.kernel.org/stable/c/1fe60ee709436550f8cfbab01295936b868d5baa" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/38762a0763c10c24a4915feee722d7aa6e73eb98" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4ee0941da10e8fdcdb34756b877efd3282594c1f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/539d51ac48bcfcfa1b3d4a85f8df92fa22c1d41c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/67f34f093c0f7bf33f5b4ae64d3d695a3b978285" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/79f988d3ffc1aa778fc5181bdfab312e57956c6b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7b8c7bd2296e95b38a6ff346242356a2e7190239" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cca330c59c54207567a648357835f59df9a286bb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: phonet/pep: fix racy skb_queue_empty() use The receive queues are protected by their respective spin-lock, not the socket lock. This could lead to skb_peek() unexpectedly returning NULL or a pointer to an already dequeued socket buffer.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27402" target="_blank">CVE-2024-27402</a><br><a href="https://git.kernel.org/stable/c/0a9f558c72c47472c38c05fcb72c70abb9104277" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7d2a894d7f487dcb894df023e9d3014cf5b93fe5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8ef4fcc7014b9f93619851d6b78d6cc2789a4c88" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9d5523e065b568e79dfaa2ea1085a5bcf74baf78" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_flow_offload: reset dst in route object after setting up flow dst is transferred to the flow object, route object does not own it anymore. Reset dst in route object, otherwise if flow_offload_add() fails, error path releases dst twice, leading to a refcount underflow.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27403" target="_blank">CVE-2024-27403</a><br><a href="https://git.kernel.org/stable/c/012df10717da02367aaf92c65f9c89db206c15f4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4c167af9f6b5ae4a5dbc243d5983c295ccc2e43c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/558b00a30e05753a62ecc7e05e939ca8f0241148" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/670548c8db44d76e40e1dfc06812bca36a61e9ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9e0f0430389be7696396c62f037be4bf72cf93e3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mptcp: fix data races on remote_id Similar to the previous patch, address the data race on remote_id, adding the suitable ONCE annotations.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27404" target="_blank">CVE-2024-27404</a><br><a href="https://git.kernel.org/stable/c/2dba5774e8ed326a78ad4339d921a4291281ea6e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/967d3c27127e71a10ff5c083583a038606431b61" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/987c3ed7297e5661bc7f448f06fc366e497ac9b2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e64148635509bf13eea851986f5a0b150e5bd066" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: gadget: ncm: Avoid dropping datagrams of properly parsed NTBs It is observed sometimes when tethering is used over NCM with Windows 11 as host, at some instances, the gadget_giveback has one byte appended at the end of a proper NTB. When the NTB is parsed, unwrap call looks for any leftover bytes in SKB provided by u_ether and if there are any pending bytes, it treats them as a separate NTB and parses it. But in case the second NTB (as per unwrap call) is faulty/corrupt, all the datagrams that were parsed properly in the first NTB and saved in rx_list are dropped. Adding a few custom traces showed the following: [002] d..1 7828.532866: dwc3_gadget_giveback: ep1out: req 000000003868811a length 1025/16384 zsI ==&gt; 0 [002] d..1 7828.532867: ncm_unwrap_ntb: K: ncm_unwrap_ntb toprocess: 1025 [002] d..1 7828.532867: ncm_unwrap_ntb: K: ncm_unwrap_ntb nth: 1751999342 [002] d..1 7828.532868: ncm_unwrap_ntb: K: ncm_unwrap_ntb seq: 0xce67 [002] d..1 7828.532868: ncm_unwrap_ntb: K: ncm_unwrap_ntb blk_len: 0x400 [002] d..1 7828.532868: ncm_unwrap_ntb: K: ncm_unwrap_ntb ndp_len: 0x10 [002] d..1 7828.532869: ncm_unwrap_ntb: K: Parsed NTB with 1 frames In this case, the giveback is of 1025 bytes and block length is 1024. The rest 1 byte (which is 0x00) won't be parsed resulting in drop of all datagrams in rx_list. Same is case with packets of size 2048: [002] d..1 7828.557948: dwc3_gadget_giveback: ep1out: req 0000000011dfd96e length 2049/16384 zsI ==&gt; 0 [002] d..1 7828.557949: ncm_unwrap_ntb: K: ncm_unwrap_ntb nth: 1751999342 [002] d..1 7828.557950: ncm_unwrap_ntb: K: ncm_unwrap_ntb blk_len: 0x800 Lecroy shows one byte coming in extra confirming that the byte is coming in from PC: Transfer 2959 - Bytes Transferred(1025) Timestamp((18.524 843 590) - Transaction 8391 - Data(1025 bytes) Timestamp(18.524 843 590) --- Packet 4063861 Data(1024 bytes) Duration(2.117us) Idle(14.700ns) Timestamp(18.524 843 590) --- Packet 4063863 Data(1 byte) Duration(66.160ns) Time(282.000ns) Timestamp(18.524 845 722) According to Windows driver, no ZLP is needed if wBlockLength is non-zero, because the non-zero wBlockLength has already told the function side the size of transfer to be expected. However, there are in-market NCM devices that rely on ZLP as long as the wBlockLength is multiple of wMaxPacketSize. To deal with such devices, it pads an extra 0 at end so the transfer is no longer multiple of wMaxPacketSize.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27405" target="_blank">CVE-2024-27405</a><br><a href="https://git.kernel.org/stable/c/059285e04ebb273d32323fbad5431c5b94f77e48" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2b7ec68869d50ea998908af43b643bca7e54577e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2cb66b62a5d64ccf09b0591ab86fb085fa491fc5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/35b604a37ec70d68b19dafd10bbacf1db505c9ca" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/57ca0e16f393bb21d69734e536e383a3a4c665fd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/76c51146820c5dac629f21deafab0a7039bc3ccd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a31cf46d108dabce3df80b3e5c07661e24912151" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c7f43900bc723203d7554d299a2ce844054fab8e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: lib/Kconfig.debug: TEST_IOV_ITER depends on MMU Trying to run the iov_iter unit test on a nommu system such as the qemu kc705-nommu emulation results in a crash. KTAP version 1 # Subtest: iov_iter # module: kunit_iov_iter 1..9 BUG: failure at mm/nommu.c:318/vmap()! Kernel panic - not syncing: BUG! The test calls vmap() directly, but vmap() is not supported on nommu systems, causing the crash. TEST_IOV_ITER therefore needs to depend on MMU.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27406" target="_blank">CVE-2024-27406</a><br><a href="https://git.kernel.org/stable/c/1eb1e984379e2da04361763f66eec90dd75cf63e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9e6e541b97762d5b1143070067f7c68f39a408f8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e6316749d603fe9c4c91f6ec3694e06e4de632a3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fixed overflow check in mi_enum_attr()</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27407" target="_blank">CVE-2024-27407</a><br><a href="https://git.kernel.org/stable/c/1c0a95d99b1b2b5d842e5abc7ef7eed1193b60d7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/652cfeb43d6b9aba5c7c4902bed7a7340df131fb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8c77398c72618101d66480b94b34fe9087ee3d08" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: eDMA: Add sync read before starting the DMA transfer in remote setup The Linked list element and pointer are not stored in the same memory as the eDMA controller register. If the doorbell register is toggled before the full write of the linked list a race condition error will occur. In remote setup we can only use a readl to the memory to assure the full write has occurred.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27408" target="_blank">CVE-2024-27408</a><br><a href="https://git.kernel.org/stable/c/bbcc1c83f343e580c3aa1f2a8593343bf7b55bba" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d24fe6d5a1cfdddb7a9ef56736ec501c4d0a5fd3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f396b4df27cfe01a99f4b41f584c49e56477be3a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: HDMA: Add sync read before starting the DMA transfer in remote setup The Linked list element and pointer are not stored in the same memory as the HDMA controller register. If the doorbell register is toggled before the full write of the linked list a race condition error will occur. In remote setup we can only use a readl to the memory to assure the full write has occurred.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27409" target="_blank">CVE-2024-27409</a><br><a href="https://git.kernel.org/stable/c/17be6f5cb223f22e4733ed8fe8b2247cbb677716" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/227ef58a9b0c372efba422e8886a8015a1509eba" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/712a92a48158e02155b4b6b21e03a817f78c9b7e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject iftype change with mesh ID change It's currently possible to change the mesh ID when the interface isn't yet in mesh mode, at the same time as changing it into mesh mode. This leads to an overwrite of data in the wdev-&gt;u union for the interface type it currently has, causing cfg80211_change_iface() to do wrong things when switching. We could probably allow setting an interface to mesh while setting the mesh ID at the same time by doing a different order of operations here, but realistically there's no userspace that's going to do this, so just disallow changes in iftype when setting mesh ID.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27410" target="_blank">CVE-2024-27410</a><br><a href="https://git.kernel.org/stable/c/063715c33b4c37587aeca2c83cf08ead0c542995" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0cfbb26ee5e7b3d6483a73883f9f6157bca22ec9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/177d574be4b58f832354ab1ef5a297aa0c9aa2df" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/930e826962d9f01dcd2220176134427358d112f2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/99eb2159680af8786104dac80528acd5acd45980" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a2add961a5ed25cfd6a74f9ffb9e7ab6d6ded838" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d38d31bbbb9dc0d4d71a45431eafba03d0bc150d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f78c1375339a291cba492a70eaf12ec501d28a8e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: keep DMA buffers required for suspend/resume Nouveau deallocates a few buffers post GPU init which are required for GPU suspend/resume to function correctly. This is likely not as big an issue on systems where the NVGPU is the only GPU, but on multi-GPU set ups it leads to a regression where the kernel module errors and results in a system-wide rendering freeze. This commit addresses that regression by moving the two buffers required for suspend and resume to be deallocated at driver unload instead of post init.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27411" target="_blank">CVE-2024-27411</a><br><a href="https://git.kernel.org/stable/c/be00e15b240ed71fc30c0576af7ab670c8271661" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f6ecfdad359a01c7fd8a3bcfde3ef0acdf107e6e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: power: supply: bq27xxx-i2c: Do not free non existing IRQ The bq27xxx i2c-client may not have an IRQ, in which case client-&gt;irq will be 0. bq27xxx_battery_i2c_probe() already has an if (client-&gt;irq) check wrapping the request_threaded_irq(). But bq27xxx_battery_i2c_remove() unconditionally calls free_irq(client-&gt;irq) leading to: [ 190.310742] ------------[ cut here ]------------ [ 190.310843] Trying to free already-free IRQ 0 [ 190.310861] WARNING: CPU: 2 PID: 1304 at kernel/irq/manage.c:1893 free_irq+0x1b8/0x310 Followed by a backtrace when unbinding the driver. Add an if (client-&gt;irq) to bq27xxx_battery_i2c_remove() mirroring probe() to fix this.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27412" target="_blank">CVE-2024-27412</a><br><a href="https://git.kernel.org/stable/c/083686474e7c97b0f8b66df37fcb64e432e8b771" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2df70149e73e79783bcbc7db4fa51ecef0e2022c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7394abc8926adee6a817bab10797e0adc898af77" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cefe18e9ec84f8fe3e198ccebb815cc996eb9797" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d4d813c0a14d6bf52d810a55db06a2e7e3d98eaa" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d7acc4a569f5f4513120c85ea2b9f04909b7490f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e601ae81910ce6a3797876e190a2d8ef6cf828bc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fbca8bae1ba79d443a58781b45e92a73a24ac8f8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: efi/capsule-loader: fix incorrect allocation size gcc-14 notices that the allocation with sizeof(void) on 32-bit architectures is not enough for a 64-bit phys_addr_t: drivers/firmware/efi/capsule-loader.c: In function 'efi_capsule_open': drivers/firmware/efi/capsule-loader.c:295:24: error: allocation of insufficient size '4' for type 'phys_addr_t' {aka 'long long unsigned int'} with size '8' [-Werror=alloc-size] 295 | cap_info-&gt;phys = kzalloc(sizeof(void *), GFP_KERNEL); | ^ Use the correct type instead here.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27413" target="_blank">CVE-2024-27413</a><br><a href="https://git.kernel.org/stable/c/00cf21ac526011a29fc708f8912da446fac19f7b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/11aabd7487857b8e7d768fefb092f66dfde68492" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4b73473c050a612fb4317831371073eda07c3050" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/537e3f49dbe88881a6f0752beaa596942d9efd64" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/62a5dcd9bd3097e9813de62fa6f22815e84a0172" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/950d4d74d311a18baed6878dbfba8180d7e5dddd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ddc547dd05a46720866c32022300f7376c40119f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fccfa646ef3628097d59f7d9c1a3e84d4b6bb45e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: rtnetlink: fix error logic of IFLA_BRIDGE_FLAGS writing back In the commit d73ef2d69c0d ("rtnetlink: let rtnl_bridge_setlink checks IFLA_BRIDGE_MODE length"), an adjustment was made to the old loop logic in the function `rtnl_bridge_setlink` to enable the loop to also check the length of the IFLA_BRIDGE_MODE attribute. However, this adjustment removed the `break` statement and led to an error logic of the flags writing back at the end of this function. if (have_flags) memcpy(nla_data(attr), &amp;flags, sizeof(flags)); // attr should point to IFLA_BRIDGE_FLAGS NLA !!! Before the mentioned commit, the `attr` is granted to be IFLA_BRIDGE_FLAGS. However, this is not necessarily true fow now as the updated loop will let the attr point to the last NLA, even an invalid NLA which could cause overflow writes. This patch introduces a new variable `br_flag` to save the NLA pointer that points to IFLA_BRIDGE_FLAGS and uses it to resolve the mentioned error logic.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27414" target="_blank">CVE-2024-27414</a><br><a href="https://git.kernel.org/stable/c/167d8642daa6a44b51de17f8ff0f584e1e762db7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/743ad091fb46e622f1b690385bb15e3cd3daf874" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/831bc2728fb48a8957a824cba8c264b30dca1425" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/882a51a10ecf24ce135d573afa0872aef02c5125" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a1227b27fcccc99dc44f912b479e01a17e2d7d31" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b9fbc44159dfc3e9a7073032752d9e03f5194a6f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f2261eb994aa5757c1da046b78e3229a3ece0ad9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: confirm multicast packets before passing them up the stack conntrack nf_confirm logic cannot handle cloned skbs referencing the same nf_conn entry, which will happen for multicast (broadcast) frames on bridges. Example: macvlan0 | br0 / \ ethX ethY ethX (or Y) receives a L2 multicast or broadcast packet containing an IP packet, flow is not yet in conntrack table. 1. skb passes through bridge and fake-ip (br_netfilter)Prerouting. -&gt; skb-&gt;_nfct now references a unconfirmed entry 2. skb is broad/mcast packet. bridge now passes clones out on each bridge interface. 3. skb gets passed up the stack. 4. In macvlan case, macvlan driver retains clone(s) of the mcast skb and schedules a work queue to send them out on the lower devices. The clone skb-&gt;_nfct is not a copy, it is the same entry as the original skb. The macvlan rx handler then returns RX_HANDLER_PASS. 5. Normal conntrack hooks (in NF_INET_LOCAL_IN) confirm the orig skb. The Macvlan broadcast worker and normal confirm path will race. This race will not happen if step 2 already confirmed a clone. In that case later steps perform skb_clone() with skb-&gt;_nfct already confirmed (in hash table). This works fine. But such confirmation won't happen when eb/ip/nftables rules dropped the packets before they reached the nf_confirm step in postrouting. Pablo points out that nf_conntrack_bridge doesn't allow use of stateful nat, so we can safely discard the nf_conn entry and let inet call conntrack again. This doesn't work for bridge netfilter: skb could have a nat transformation. Also bridge nf prevents re-invocation of inet prerouting via 'sabotage_in' hook. Work around this problem by explicit confirmation of the entry at LOCAL_IN time, before upper layer has a chance to clone the unconfirmed entry. The downside is that this disables NAT and conntrack helpers. Alternative fix would be to add locking to all code parts that deal with unconfirmed packets, but even if that could be done in a sane way this opens up other problems, for example: -m physdev --physdev-out eth0 -j SNAT --snat-to 1.2.3.4 -m physdev --physdev-out eth1 -j SNAT --snat-to 1.2.3.5 For multicast case, only one of such conflicting mappings will be created, conntrack only handles 1:1 NAT mappings. Users should set create a setup that explicitly marks such traffic NOTRACK (conntrack bypass) to avoid this, but we cannot auto-bypass them, ruleset might have accept rules for untracked traffic already, so user-visible behaviour would change.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27415" target="_blank">CVE-2024-27415</a><br><a href="https://git.kernel.org/stable/c/2b1414d5e94e477edff1d2c79030f1d742625ea0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/62e7151ae3eb465e0ab52a20c941ff33bb6332e9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7c3f28599652acf431a2211168de4a583f30b6d5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/80cd0487f630b5382734997c3e5e3003a77db315" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cb734975b0ffa688ff6cc0eed463865bf07b6c01" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST If we received HCI_EV_IO_CAPA_REQUEST while HCI_OP_READ_REMOTE_EXT_FEATURES is yet to be responded assume the remote does support SSP since otherwise this event shouldn't be generated.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27416" target="_blank">CVE-2024-27416</a><br><a href="https://git.kernel.org/stable/c/30a5e812f78e3d1cced90e1ed750bf027599205f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/79820a7e1e057120c49be07cbe10643d0706b259" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7e74aa53a68bf60f6019bd5d9a9a1406ec4d4865" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8e2758cc25891d2b76717aaf89b40ed215de188c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/afec8f772296dd8e5a2a6f83bbf99db1b9ca877f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c3df637266df29edee85e94cab5fd7041e5753ba" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/df193568d61234c81de7ed4d540c01975de60277" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fba268ac36ab19f9763ff90d276cde0ce6cd5f31" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ipv6: fix potential "struct net" leak in inet6_rtm_getaddr() It seems that if userspace provides a correct IFA_TARGET_NETNSID value but no IFA_ADDRESS and IFA_LOCAL attributes, inet6_rtm_getaddr() returns -EINVAL with an elevated "struct net" refcount.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27417" target="_blank">CVE-2024-27417</a><br><a href="https://git.kernel.org/stable/c/10bfd453da64a057bcfd1a49fb6b271c48653cdb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1b0998fdd85776775d975d0024bca227597e836a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/33a1b6bfef6def2068c8703403759024ce17053e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/44112bc5c74e64f28f5a9127dc34066c7a09bd0f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/810fa7d5e5202fcfb22720304b755f1bdfd4c174" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8a54834c03c30e549c33d5da0975f3e1454ec906" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9d4ffb5b9d879a75e4f7460e8b10e756b4dfb132" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: mctp: take ownership of skb in mctp_local_output Currently, mctp_local_output only takes ownership of skb on success, and we may leak an skb if mctp_local_output fails in specific states; the skb ownership isn't transferred until the actual output routing occurs. Instead, make mctp_local_output free the skb on all error paths up to the route action, so it always consumes the passed skb.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27418" target="_blank">CVE-2024-27418</a><br><a href="https://git.kernel.org/stable/c/3773d65ae5154ed7df404b050fd7387a36ab5ef3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a3c8fa54e904b0ddb52a08cc2d8ac239054f61fd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a639441c880ac479495e5ab37e3c29f21ae5771b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cbebc55ceacef1fc0651e80e0103cc184552fc68" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix data-races around sysctl_net_busy_read We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27419" target="_blank">CVE-2024-27419</a><br><a href="https://git.kernel.org/stable/c/0866afaff19d8460308b022345ed116a12b1d0e1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/16d71319e29d5825ab53f263b59fdd8dc2d60ad4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/34cab94f7473e7b09f5205d4583fb5096cb63b5b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/43464808669ba9d23996f0b6d875450191687caf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bbf950a6e96a91cf8cf0c71117b94ed3fafc9dd3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d380ce70058a4ccddc3e5f5c2063165dc07672c6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d623fd5298d95b65d27ef5a618ebf39541074856" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f9055fa2b2931261d5f89948ee5bc315b6a22d4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_link_fails_count We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27420" target="_blank">CVE-2024-27420</a><br><a href="https://git.kernel.org/stable/c/07bbccd1adb56b39eef982b8960d59e3c005c6a1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0b8eb369c182814d817b9449bc9e86bfae4310f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/97a4d8b9f67cc7efe9a0c137e12f6d9e40795bf1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bc76645ebdd01be9b9994dac39685a3d0f6f7985" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c558e54f7712b086fbcb611723272a0a4b0d451c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cfe0f73fb38a01bce86fe15ef5f750f850f7d3fe" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cfedde3058bf976f2f292c0a236edd43afcdab57" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/db364859ce68fb3a52d42cd87a54da3dc42dc1c8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_routing_control We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27421" target="_blank">CVE-2024-27421</a><br><a href="https://git.kernel.org/stable/c/4c02b9ccbb11862ee39850b2b285664cd579b039" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/859175d4bc11af829e2fdd261a7effdaba9b5d8f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b5dffcb8f71bdd02a4e5799985b51b12f4eeaf76" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b7d33e083f9d5d39445c0a91e7ad4f3e2c47fcb5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c13fbb5902bce848759385986d4833f5b90782c1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c4309e5f8e80584715c814e1d012dbc3eee5a500" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d732b83251322ecd3b503e03442247745d6052ce" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f9c4d42464173b826190fae2283ed1a4bbae0c8b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_no_activity_timeout We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27422" target="_blank">CVE-2024-27422</a><br><a href="https://git.kernel.org/stable/c/01d4e3afe257768cd2a45f15a0e57bacf932b140" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2309b369fae2d9cdc3c945cd3eaec84eb1958ca3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/498f1d6da11ed6d736d655a2db14ee2d9569eecb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4eacb242e22e31385a50a393681d0fe4b55ed1e9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6f254abae02abd4a0aca062c1b3812d7e2d8ea94" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/73426c32e259c767d40613b956d5b80d0c28a9a9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cbba77abb4a553c1f5afac1ba2a0861aa1f13549" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f99b494b40431f0ca416859f2345746199398e2b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_requested_window_size We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27423" target="_blank">CVE-2024-27423</a><br><a href="https://git.kernel.org/stable/c/0d43a58900e5a2bfcc9de47e16c6c501c0bef853" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/46803b776d869b0c36041828a83c4f7da2dfa03b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/489e05c614dbeb1a1148959f02bdb788891819e6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4f2efa17c3ec5e4be0567b47439b9713c0dc6550" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/652b0b35819610a42b8a90d21acb12f69943b397" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/89aa78a34340e9dbc3248095f44d81d0e1c23193" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a2e706841488f474c06e9b33f71afc947fb3bf56" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/db006d7edbf0b4800390ece3727a82f4ae764043" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_busy_delay We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27424" target="_blank">CVE-2024-27424</a><br><a href="https://git.kernel.org/stable/c/0a30016e892bccabea30af218782c4b6ce0970af" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1f60795dcafc97c45984240d442cdc151f825977" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/43547d8699439a67b78d6bb39015113f7aa360fd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4ccad39009e7bd8a03d60a97c87b0327ae812880" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5ac337138272d26d6d3d4f71bc5b1a87adf8b24d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7782e5e7047cae6b9255ee727c99fc73d77cf773" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/85f34d352f4b79afd63dd13634b23dafe6b570f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f3315a6edaec12b461031eab8c98c78111a41f95" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_acknowledge_delay We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27425" target="_blank">CVE-2024-27425</a><br><a href="https://git.kernel.org/stable/c/33081e0f34899d5325e7c45683dd8dc9cb18b583" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/34c84e0036a60e7e50ae50b42ed194d8daef8cc9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5deaef2bf56456c71b841e0dfde1bee2fd88c4eb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6133a71c75dacea12fcc85838b4455c2055b0f14" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7d56ffc51ebd2777ded8dca50d631ee19d97db5c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/80578681ea274e0a6512bb7515718c206a7b74cf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/806f462ba9029d41aadf8ec93f2f99c5305deada" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a22f9194f61ad4f2b6405c7c86bee85eac1befa5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_maximum_tries We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27426" target="_blank">CVE-2024-27426</a><br><a href="https://git.kernel.org/stable/c/34a164d2448264b62af82bc0af3d2c83d12d38ac" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/42e71408e2c138be9ccce60920bd6cf094ba1e32" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/84b8486e9cedc93875f251ba31abcf73bd586a3a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d28fa5f0e6c1554e2829f73a6a276c9a49689d04" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e799299aafed417cc1f32adccb2a0e5268b3f6d5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f716a68234242f95305dffb5c9426caa64b316b0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f84f7709486d8a578ab4b7d2a556d1b1a59cfc97" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fa3f3ab5c399852d32a0c3cbb8c55882f7e2c61f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_timeout We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27427" target="_blank">CVE-2024-27427</a><br><a href="https://git.kernel.org/stable/c/291d36d772f5ea5c68a263ee440f2c9eade371c9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/500936692ccca8617a955652d1929f079b17a201" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5d5c14efc987900509cec465af26608e39ac607c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/60a7a152abd494ed4f69098cf0f322e6bb140612" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7d1e00fc2af3b7c30835d643a3655b7e9ff7cb20" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b8006cb0a34aaf85cdd8741f4148fd9c76b351d3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eadec8da4451c2c0897199691184602e4ee497d1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fed835d415766a94fc0246dcebc3af4c03fe9941" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix data-races around sysctl_netrom_network_ttl_initialiser We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27428" target="_blank">CVE-2024-27428</a><br><a href="https://git.kernel.org/stable/c/119cae5ea3f9e35cdada8e572cc067f072fa825a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5731369af2de21695fe7c1c91fe134fabe5b33b8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/775ed3549819f814a6ecef5726d2b4c23f249b77" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a47d68d777b41862757b7e3051f2d46d6e25f87b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/acc653e8a3aaab1b7103f98645f2cce7be89e3d3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d1261bde59a3a087ab0c81181821e194278d9264" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dca1d93fe42fb9c42b66f61714fbdc55c87eb002" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eda02a0bed550f07a8283d3e1f25b90a38e151ed" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_obsolescence_count_initialiser We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27429" target="_blank">CVE-2024-27429</a><br><a href="https://git.kernel.org/stable/c/18c95d11c347a12e5c31df1325cef6b995d14ecf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1e84b108f2a71daa8d04032e4d2096522376debb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/591192c3a9fc728a0af7b9dd50bf121220062293" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7e1e25891f090e24a871451c9403abac63cb45dd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b3f0bc3a315cf1af03673a0163c08fe037587acd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cfd9f4a740f772298308b2e6070d2c744fb5cf79" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e3a3718b1723253d4f068e88e81d880d71f1a1e9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e439607291c082332e1e35baf8faf8552e6bcb4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_default_path_quality We need to protect the reader reading sysctl_netrom_default_path_quality because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27430" target="_blank">CVE-2024-27430</a><br><a href="https://git.kernel.org/stable/c/392eb88416dcbc5f1d61b9a88d79d78dc8b27652" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7510b08c5f5ba15983da004b021fc6154eeb4047" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7644df766006d4878a556e427e3ecc78c2d5606b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7f615232556f3c6e3eeecef96ef2b00d0aa905bb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/958d6145a6d9ba9e075c921aead8753fb91c9101" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bbc21f134b89535d1cf110c5f2b33ac54e5839c4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dec82a8fc45c6ce494c2cb31f001a2aadb132b57" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e041df5dc9e68adffcba5499ca28e1252bed6f4b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: cpumap: Zero-initialise xdp_rxq_info struct before running XDP program When running an XDP program that is attached to a cpumap entry, we don't initialise the xdp_rxq_info data structure being used in the xdp_buff that backs the XDP program invocation. Tobias noticed that this leads to random values being returned as the xdp_md-&gt;rx_queue_index value for XDP programs running in a cpumap. This means we're basically returning the contents of the uninitialised memory, which is bad. Fix this by zero-initialising the rxq data structure before running the XDP program.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27431" target="_blank">CVE-2024-27431</a><br><a href="https://git.kernel.org/stable/c/2487007aa3b9fafbd2cb14068f49791ce1d7ede5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3420b3ff1ff489c177ea1cb7bd9fbbc4e9a0be95" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5f4e51abfbe6eb444fa91906a5cd083044278297" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eaa7cb836659ced2d9f814ac32aa3ec193803ed6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f0363af9619c77730764f10360e36c6445c12f7b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f562e4c4aab00986dde3093c4be919c3f2b85a4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: fix PPE hanging issue A patch to resolve an issue was found in MediaTek's GPL-licensed SDK: In the mtk_ppe_stop() function, the PPE scan mode is not disabled before disabling the PPE. This can potentially lead to a hang during the process of disabling the PPE. Without this patch, the PPE may experience a hang during the reboot test.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27432" target="_blank">CVE-2024-27432</a><br><a href="https://git.kernel.org/stable/c/09a1907433865b7c8ee6777e507f5126bdd38c0f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/49202a8256fc50517ef06fd5e2084c4febde6369" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/943c14ece95eb1cf98d477462aebcbfdfd714633" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9fcadd125044007351905d40c405fadc2d3bb6d6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ea80e3ed09ab2c2b75724faf5484721753e92c31" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f78807362828ad01db2a9ed005bf79501b620f27" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: mt7622-apmixedsys: Fix an error handling path in clk_mt8135_apmixed_probe() 'clk_data' is allocated with mtk_devm_alloc_clk_data(). So calling mtk_free_clk_data() explicitly in the remove function would lead to a double-free. Remove the redundant call.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27433" target="_blank">CVE-2024-27433</a><br><a href="https://git.kernel.org/stable/c/a32e88f2b20259f5fe4f8eed598bbc85dc4879ed" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/de3340533bd68a7b3d6be1841b8eb3fa6c762fe6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f3633fed984f1db106ff737a0bb52fadb2d89ac7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fa761ce7a1d15cca1a306b3635f81a22b15fee5b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: don't set the MFP flag for the GTK The firmware doesn't need the MFP flag for the GTK, it can even make the firmware crash. in case the AP is configured with: group cipher TKIP and MFPC. We would send the GTK with cipher = TKIP and MFP which is of course not possible.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27434" target="_blank">CVE-2024-27434</a><br><a href="https://git.kernel.org/stable/c/40405cbb20eb6541c603e7b3d54ade0a7be9d715" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/60f6d5fc84a9fd26528a24d8a267fc6a6698b628" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b4f1b0b3b91762edd19bf9d3b2e4c3a0740501f8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e35f316bce9e5733c9826120c1838f4c447b2c4c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: nvme: fix reconnection fail due to reserved tag allocation We found a issue on production environment while using NVMe over RDMA, admin_q reconnect failed forever while remote target and network is ok. After dig into it, we found it may caused by a ABBA deadlock due to tag allocation. In my case, the tag was hold by a keep alive request waiting inside admin_q, as we quiesced admin_q while reset ctrl, so the request maked as idle and will not process before reset success. As fabric_q shares tagset with admin_q, while reconnect remote target, we need a tag for connect command, but the only one reserved tag was held by keep alive command which waiting inside admin_q. As a result, we failed to reconnect admin_q forever. In order to fix this issue, I think we should keep two reserved tags for admin queue.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27435" target="_blank">CVE-2024-27435</a><br><a href="https://git.kernel.org/stable/c/149afee5c7418ec5db9d7387b9c9a5c1eb7ea2a8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/262da920896e2f2ab0e3947d9dbee0aa09045818" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6851778504cdb49431809b4ba061903d5f592c96" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/de105068fead55ed5c07ade75e9c8e7f86a00d1d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ff2f90f88d78559802466ad1c84ac5bda4416b3a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Stop parsing channels bits when all channels are found. If a usb audio device sets more bits than the amount of channels it could write outside of the map array.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27436" target="_blank">CVE-2024-27436</a><br><a href="https://git.kernel.org/stable/c/22cad1b841a63635a38273b799b4791f202ade72" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5cd466673b34bac369334f66cbe14bb77b7d7827" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/629af0d5fe94a35f498ba2c3f19bd78bfa591be6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6d5dc96b154be371df0d62ecb07efe400701ed8a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6d88b289fb0a8d055cb79d1c46a56aba7809d96d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7e2c1b0f6dd9abde9e60f0f9730026714468770f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9af1658ba293458ca6a13f70637b9654fa4be064" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a39d51ff1f52cd0b6fe7d379ac93bd8b4237d1b7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c8a24fd281dcdf3c926413dafbafcf35cde517a9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock with fiemap and extent locking While working on the patchset to remove extent locking I got a lockdep splat with fiemap and pagefaulting with my new extent lock replacement lock. This deadlock exists with our normal code, we just don't have lockdep annotations with the extent locking so we've never noticed it. Since we're copying the fiemap extent to user space on every iteration we have the chance of pagefaulting. Because we hold the extent lock for the entire range we could mkwrite into a range in the file that we have mmap'ed. This would deadlock with the following stack trace [&lt;0&gt;] lock_extent+0x28d/0x2f0 [&lt;0&gt;] btrfs_page_mkwrite+0x273/0x8a0 [&lt;0&gt;] do_page_mkwrite+0x50/0xb0 [&lt;0&gt;] do_fault+0xc1/0x7b0 [&lt;0&gt;] __handle_mm_fault+0x2fa/0x460 [&lt;0&gt;] handle_mm_fault+0xa4/0x330 [&lt;0&gt;] do_user_addr_fault+0x1f4/0x800 [&lt;0&gt;] exc_page_fault+0x7c/0x1e0 [&lt;0&gt;] asm_exc_page_fault+0x26/0x30 [&lt;0&gt;] rep_movs_alternative+0x33/0x70 [&lt;0&gt;] _copy_to_user+0x49/0x70 [&lt;0&gt;] fiemap_fill_next_extent+0xc8/0x120 [&lt;0&gt;] emit_fiemap_extent+0x4d/0xa0 [&lt;0&gt;] extent_fiemap+0x7f8/0xad0 [&lt;0&gt;] btrfs_fiemap+0x49/0x80 [&lt;0&gt;] __x64_sys_ioctl+0x3e1/0xb50 [&lt;0&gt;] do_syscall_64+0x94/0x1a0 [&lt;0&gt;] entry_SYSCALL_64_after_hwframe+0x6e/0x76 I wrote an fstest to reproduce this deadlock without my replacement lock and verified that the deadlock exists with our existing locking. To fix this simply don't take the extent lock for the entire duration of the fiemap. This is safe in general because we keep track of where we are when we're searching the tree, so if an ordered extent updates in the middle of our fiemap call we'll still emit the correct extents because we know what offset we were on before. The only place we maintain the lock is searching delalloc. Since the delalloc stuff can change during writeback we want to lock the extent range so we have a consistent view of delalloc at the time we're checking to see if we need to set the delalloc flag. With this patch applied we no longer deadlock with my testcase.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35784" target="_blank">CVE-2024-35784</a><br><a href="https://git.kernel.org/stable/c/89bca7fe6382d61e88c67a0b0e7bce315986fb8b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b0ad381fa7690244802aed119b478b4bdafc31dd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ded566b4637f1b6b4c9ba74e7d0b8493e93f19cf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix kernel panic caused by incorrect error handling The error path while failing to register devices on the TEE bus has a bug leading to kernel panic as follows: [ 15.398930] Unable to handle kernel paging request at virtual address ffff07ed00626d7c [ 15.406913] Mem abort info: [ 15.409722] ESR = 0x0000000096000005 [ 15.413490] EC = 0x25: DABT (current EL), IL = 32 bits [ 15.418814] SET = 0, FnV = 0 [ 15.421878] EA = 0, S1PTW = 0 [ 15.425031] FSC = 0x05: level 1 translation fault [ 15.429922] Data abort info: [ 15.432813] ISV = 0, ISS = 0x00000005, ISS2 = 0x00000000 [ 15.438310] CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [ 15.443372] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [ 15.448697] swapper pgtable: 4k pages, 48-bit VAs, pgdp=00000000d9e3e000 [ 15.455413] [ffff07ed00626d7c] pgd=1800000bffdf9003, p4d=1800000bffdf9003, pud=0000000000000000 [ 15.464146] Internal error: Oops: 0000000096000005 [#1] PREEMPT SMP Commit 7269cba53d90 ("tee: optee: Fix supplicant based device enumeration") lead to the introduction of this bug. So fix it appropriately.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35785" target="_blank">CVE-2024-35785</a><br><a href="https://git.kernel.org/stable/c/4b12ff5edd141926d49c9ace4791adf3a4902fe7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/520f79c110ff712b391b3d87fcacf03c74bc56ee" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/95915ba4b987cf2b222b0f251280228a1ff977ac" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bc40ded92af55760d12bec8222d4108de725dbe4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bfa344afbe472a9be08f78551fa2190c1a07d7d3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e5b5948c769aa1ebf962dddfb972f87d8f166f95" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix stale locked mutex in nouveau_gem_ioctl_pushbuf If VM_BIND is enabled on the client the legacy submission ioctl can't be used, however if a client tries to do so regardless it will return an error. In this case the clients mutex remained unlocked leading to a deadlock inside nouveau_drm_postclose or any other nouveau ioctl call.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35786" target="_blank">CVE-2024-35786</a><br><a href="https://git.kernel.org/stable/c/b466416bdd6ecbde15ce987226ea633a0268fbb1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c288a61a48ddb77ec097e11ab81b81027cd4e197" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/daf8739c3322a762ce84f240f50e0c39181a41ab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: md/md-bitmap: fix incorrect usage for sb_index Commit d7038f951828 ("md-bitmap: don't use -&gt;index for pages backing the bitmap file") removed page-&gt;index from bitmap code, but left wrong code logic for clustered-md. current code never set slot offset for cluster nodes, will sometimes cause crash in clustered env. Call trace (partly): md_bitmap_file_set_bit+0x110/0x1d8 [md_mod] md_bitmap_startwrite+0x13c/0x240 [md_mod] raid1_make_request+0x6b0/0x1c08 [raid1] md_handle_request+0x1dc/0x368 [md_mod] md_submit_bio+0x80/0xf8 [md_mod] __submit_bio+0x178/0x300 submit_bio_noacct_nocheck+0x11c/0x338 submit_bio_noacct+0x134/0x614 submit_bio+0x28/0xdc submit_bh_wbc+0x130/0x1cc submit_bh+0x1c/0x28</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35787" target="_blank">CVE-2024-35787</a><br><a href="https://git.kernel.org/stable/c/55e55eb65fd5e09faf5a0e49ffcdd37905aaf4da" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5a95815b17428ce2f56ec18da5e0d1b2a1a15240" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/736ad6c577a367834118f57417038d45bb5e0a31" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ecbd8ebb51bf7e4939d83b9e6022a55cac44ef06" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix bounds check for dcn35 DcfClocks [Why] NumFclkLevelsEnabled is used for DcfClocks bounds check instead of designated NumDcfClkLevelsEnabled. That can cause array index out-of-bounds access. [How] Use designated variable for dcn35 DcfClocks bounds check.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35788" target="_blank">CVE-2024-35788</a><br><a href="https://git.kernel.org/stable/c/2f10d4a51bbcd938f1f02f16c304ad1d54717b96" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c373f233dab44a13752daec13788e2ad3bf86410" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f6e163e9c3d50cd167ab9d411ed01b7718177387" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes When moving a station out of a VLAN and deleting the VLAN afterwards, the fast_rx entry still holds a pointer to the VLAN's netdev, which can cause use-after-free bugs. Fix this by immediately calling ieee80211_check_fast_rx after the VLAN change.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35789" target="_blank">CVE-2024-35789</a><br><a href="https://git.kernel.org/stable/c/2884a50f52313a7a911de3afcad065ddbb3d78fc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4f2bdb3c5e3189297e156b3ff84b140423d64685" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6b948b54c8bd620725e0c906e44b10c0b13087a7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7eeabcea79b67cc29563e6a9a5c81f9e2c664d5b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/be1dd9254fc115321d6fbee042026d42afc8d931" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c8bddbd91bc8e42c961a5e2cec20ab879f21100f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e8678551c0243f799b4859448781cbec1bd6f1cb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e8b067c4058c0121ac8ca71559df8e2e08ff1a7e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ea9a0cfc07a7d3601cc680718d9cff0d6927a921" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: create sysfs nodes as driver's default device attribute group The DisplayPort driver's sysfs nodes may be present to the userspace before typec_altmode_set_drvdata() completes in dp_altmode_probe. This means that a sysfs read can trigger a NULL pointer error by deferencing dp-&gt;hpd in hpd_show or dp-&gt;lock in pin_assignment_show, as dev_get_drvdata() returns NULL in those cases. Remove manual sysfs node creation in favor of adding attribute group as default for devices bound to the driver. The ATTRIBUTE_GROUPS() macro is not used here otherwise the path to the sysfs nodes is no longer compliant with the ABI.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35790" target="_blank">CVE-2024-35790</a><br><a href="https://git.kernel.org/stable/c/0ad011776c057ce881b7fd6d8c79ecd459c087e9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/165376f6b23e9a779850e750fb2eb06622e5a531" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4a22aeac24d0d5f26ba741408e8b5a4be6dc5dc0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Flush pages under kvm-&gt;lock to fix UAF in svm_register_enc_region() Do the cache flush of converted pages in svm_register_enc_region() before dropping kvm-&gt;lock to fix use-after-free issues where region and/or its array of pages could be freed by a different task, e.g. if userspace has __unregister_enc_region_locked() already queued up for the region. Note, the "obvious" alternative of using local variables doesn't fully resolve the bug, as region-&gt;pages is also dynamically allocated. I.e. the region structure itself would be fine, but region-&gt;pages could be freed. Flushing multiple pages under kvm-&gt;lock is unfortunate, but the entire flow is a rare slow path, and the manual flush is only needed on CPUs that lack coherency for encrypted memory.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35791" target="_blank">CVE-2024-35791</a><br><a href="https://git.kernel.org/stable/c/12f8e32a5a389a5d58afc67728c76e61beee1ad4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2d13b79640b147bd77c34a5998533b2021a4122d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4868c0ecdb6cfde7c70cf478c46e06bb9c7e5865" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5ef1d8c1ddbf696e47b226e11888eaf8d9e8e807" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e126b508ed2e616d679d85fca2fbe77bb48bbdd7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f6d53d8a2617dd58c89171a6b9610c470ebda38a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: crypto: rk3288 - Fix use after free in unprepare The unprepare call must be carried out before the finalize call as the latter can free the request.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35792" target="_blank">CVE-2024-35792</a><br><a href="https://git.kernel.org/stable/c/48dd260fdb728eda4a246f635d1325e82f0d3555" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c0afb6b88fbbc177fa322a835f874be217bffe45" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eb2a41a8ae8c8c4f68aef3bd94665c0cf23e04be" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: debugfs: fix wait/cancellation handling during remove Ben Greear further reports deadlocks during concurrent debugfs remove while files are being accessed, even though the code in question now uses debugfs cancellations. Turns out that despite all the review on the locking, we missed completely that the logic is wrong: if the refcount hits zero we can finish (and need not wait for the completion), but if it doesn't we have to trigger all the cancellations. As written, we can _never_ get into the loop triggering the cancellations. Fix this, and explain it better while at it.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35793" target="_blank">CVE-2024-35793</a><br><a href="https://git.kernel.org/stable/c/3d08cca5fd0aabb62b7015067ab40913b33da906" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/952c3fce297f12c7ff59380adb66b564e2bc9b64" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e88b5ae01901c4a655a53158397746334778a57b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dm-raid: really frozen sync_thread during suspend 1) commit f52f5c71f3d4 ("md: fix stopping sync thread") remove MD_RECOVERY_FROZEN from __md_stop_writes() and doesn't realize that dm-raid relies on __md_stop_writes() to frozen sync_thread indirectly. Fix this problem by adding MD_RECOVERY_FROZEN in md_stop_writes(), and since stop_sync_thread() is only used for dm-raid in this case, also move stop_sync_thread() to md_stop_writes(). 2) The flag MD_RECOVERY_FROZEN doesn't mean that sync thread is frozen, it only prevent new sync_thread to start, and it can't stop the running sync thread; In order to frozen sync_thread, after seting the flag, stop_sync_thread() should be used. 3) The flag MD_RECOVERY_FROZEN doesn't mean that writes are stopped, use it as condition for md_stop_writes() in raid_postsuspend() doesn't look correct. Consider that reentrant stop_sync_thread() do nothing, always call md_stop_writes() in raid_postsuspend(). 4) raid_message can set/clear the flag MD_RECOVERY_FROZEN at anytime, and if MD_RECOVERY_FROZEN is cleared while the array is suspended, new sync_thread can start unexpected. Fix this by disallow raid_message() to change sync_thread status during suspend. Note that after commit f52f5c71f3d4 ("md: fix stopping sync thread"), the test shell/lvconvert-raid-reshape.sh start to hang in stop_sync_thread(), and with previous fixes, the test won't hang there anymore, however, the test will still fail and complain that ext4 is corrupted. And with this patch, the test won't hang due to stop_sync_thread() or fail due to ext4 is corrupted anymore. However, there is still a deadlock related to dm-raid456 that will be fixed in following patches.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35794" target="_blank">CVE-2024-35794</a><br><a href="https://git.kernel.org/stable/c/16c4770c75b1223998adbeb7286f9a15c65fba73" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/af916cb66a80597f3523bc85812e790bcdcfd62b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eaa8fc9b092837cf2c754bde1a15d784ce9a85ab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix deadlock while reading mqd from debugfs An errant disk backup on my desktop got into debugfs and triggered the following deadlock scenario in the amdgpu debugfs files. The machine also hard-resets immediately after those lines are printed (although I wasn't able to reproduce that part when reading by hand): [ 1318.016074][ T1082] ====================================================== [ 1318.016607][ T1082] WARNING: possible circular locking dependency detected [ 1318.017107][ T1082] 6.8.0-rc7-00015-ge0c8221b72c0 #17 Not tainted [ 1318.017598][ T1082] ------------------------------------------------------ [ 1318.018096][ T1082] tar/1082 is trying to acquire lock: [ 1318.018585][ T1082] ffff98c44175d6a0 (&amp;mm-&gt;mmap_lock){++++}-{3:3}, at: __might_fault+0x40/0x80 [ 1318.019084][ T1082] [ 1318.019084][ T1082] but task is already holding lock: [ 1318.020052][ T1082] ffff98c4c13f55f8 (reservation_ww_class_mutex){+.+.}-{3:3}, at: amdgpu_debugfs_mqd_read+0x6a/0x250 [amdgpu] [ 1318.020607][ T1082] [ 1318.020607][ T1082] which lock already depends on the new lock. [ 1318.020607][ T1082] [ 1318.022081][ T1082] [ 1318.022081][ T1082] the existing dependency chain (in reverse order) is: [ 1318.023083][ T1082] [ 1318.023083][ T1082] -&gt; #2 (reservation_ww_class_mutex){+.+.}-{3:3}: [ 1318.024114][ T1082] __ww_mutex_lock.constprop.0+0xe0/0x12f0 [ 1318.024639][ T1082] ww_mutex_lock+0x32/0x90 [ 1318.025161][ T1082] dma_resv_lockdep+0x18a/0x330 [ 1318.025683][ T1082] do_one_initcall+0x6a/0x350 [ 1318.026210][ T1082] kernel_init_freeable+0x1a3/0x310 [ 1318.026728][ T1082] kernel_init+0x15/0x1a0 [ 1318.027242][ T1082] ret_from_fork+0x2c/0x40 [ 1318.027759][ T1082] ret_from_fork_asm+0x11/0x20 [ 1318.028281][ T1082] [ 1318.028281][ T1082] -&gt; #1 (reservation_ww_class_acquire){+.+.}-{0:0}: [ 1318.029297][ T1082] dma_resv_lockdep+0x16c/0x330 [ 1318.029790][ T1082] do_one_initcall+0x6a/0x350 [ 1318.030263][ T1082] kernel_init_freeable+0x1a3/0x310 [ 1318.030722][ T1082] kernel_init+0x15/0x1a0 [ 1318.031168][ T1082] ret_from_fork+0x2c/0x40 [ 1318.031598][ T1082] ret_from_fork_asm+0x11/0x20 [ 1318.032011][ T1082] [ 1318.032011][ T1082] -&gt; #0 (&amp;mm-&gt;mmap_lock){++++}-{3:3}: [ 1318.032778][ T1082] __lock_acquire+0x14bf/0x2680 [ 1318.033141][ T1082] lock_acquire+0xcd/0x2c0 [ 1318.033487][ T1082] __might_fault+0x58/0x80 [ 1318.033814][ T1082] amdgpu_debugfs_mqd_read+0x103/0x250 [amdgpu] [ 1318.034181][ T1082] full_proxy_read+0x55/0x80 [ 1318.034487][ T1082] vfs_read+0xa7/0x360 [ 1318.034788][ T1082] ksys_read+0x70/0xf0 [ 1318.035085][ T1082] do_syscall_64+0x94/0x180 [ 1318.035375][ T1082] entry_SYSCALL_64_after_hwframe+0x46/0x4e [ 1318.035664][ T1082] [ 1318.035664][ T1082] other info that might help us debug this: [ 1318.035664][ T1082] [ 1318.036487][ T1082] Chain exists of: [ 1318.036487][ T1082] &amp;mm-&gt;mmap_lock --&gt; reservation_ww_class_acquire --&gt; reservation_ww_class_mutex [ 1318.036487][ T1082] [ 1318.037310][ T1082] Possible unsafe locking scenario: [ 1318.037310][ T1082] [ 1318.037838][ T1082] CPU0 CPU1 [ 1318.038101][ T1082] ---- ---- [ 1318.038350][ T1082] lock(reservation_ww_class_mutex); [ 1318.038590][ T1082] lock(reservation_ww_class_acquire); [ 1318.038839][ T1082] lock(reservation_ww_class_mutex); [ 1318.039083][ T1082] rlock(&amp;mm-&gt;mmap_lock); [ 1318.039328][ T1082] [ 1318.039328][ T1082] *** DEADLOCK *** [ 1318.039328][ T1082] [ 1318.040029][ T1082] 1 lock held by tar/1082: [ 1318.040259][ T1082] #0: ffff98c4c13f55f8 (reservation_ww_class_mutex){+.+.}-{3:3}, at: amdgpu_debugfs_mqd_read+0x6a/0x250 [amdgpu] [ 1318.040560][ T1082] [ 1318.040560][ T1082] stack backtrace: [ ---truncated---</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35795" target="_blank">CVE-2024-35795</a><br><a href="https://git.kernel.org/stable/c/197f6d6987c55860f6eea1c93e4f800c59078874" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4687e3c6ee877ee25e57b984eca00be53b9a8db5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8678b1060ae2b75feb60b87e5b75e17374e3c1c5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8b03556da6e576c62664b6cd01809e4a09d53b5b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: ll_temac: platform_get_resource replaced by wrong function The function platform_get_resource was replaced with devm_platform_ioremap_resource_byname and is called using 0 as name. This eventually ends up in platform_get_resource_byname in the call stack, where it causes a null pointer in strcmp. if (type == resource_type(r) &amp;&amp; !strcmp(r-&gt;name, name)) It should have been replaced with devm_platform_ioremap_resource.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35796" target="_blank">CVE-2024-35796</a><br><a href="https://git.kernel.org/stable/c/3a38a829c8bc27d78552c28e582eb1d885d07d11" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/46efbdbc95a30951c2579caf97b6df2ee2b3bef3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/476eed5f1c22034774902a980aa48dc4662cb39a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/553d294db94b5f139378022df480a9fb6c3ae39e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6d9395ba7f85bdb7af0b93272e537484ecbeff48" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7e9edb569fd9f688d887e36db8170f6e22bafbc8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/92c0c29f667870f17c0b764544bdf22ce0e886a1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix two shmem bugs When cachestat on shmem races with swapping and invalidation, there are two possible bugs: 1) A swapin error can have resulted in a poisoned swap entry in the shmem inode's xarray. Calling get_shadow_from_swap_cache() on it will result in an out-of-bounds access to swapper_spaces[]. Validate the entry with non_swap_entry() before going further. 2) When we find a valid swap entry in the shmem's inode, the shadow entry in the swapcache might not exist yet: swap IO is still in progress and we're before __remove_mapping; swapin, invalidation, or swapoff have removed the shadow from swapcache after we saw the shmem swap entry. This will send a NULL to workingset_test_recent(). The latter purely operates on pointer bits, so it won't crash - node 0, memcg ID 0, eviction timestamp 0, etc. are all valid inputs - but it's a bogus test. In theory that could result in a false "recently evicted" count. Such a false positive wouldn't be the end of the world. But for code clarity and (future) robustness, be explicit about this case. Bail on get_shadow_from_swap_cache() returning NULL.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35797" target="_blank">CVE-2024-35797</a><br><a href="https://git.kernel.org/stable/c/24a0e73d544439bb9329fbbafac44299e548a677" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b79f9e1ff27c994a4c452235ba09e672ec698e23" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d5d39c707a4cf0bcc84680178677b97aa2cb2627" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d962f6c583458037dc7e529659b2b02b9dd3d94b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: btrfs: fix race in read_extent_buffer_pages() There are reports from tree-checker that detects corrupted nodes, without any obvious pattern so possibly an overwrite in memory. After some debugging it turns out there's a race when reading an extent buffer the uptodate status can be missed. To prevent concurrent reads for the same extent buffer, read_extent_buffer_pages() performs these checks: /* (1) */ if (test_bit(EXTENT_BUFFER_UPTODATE, &amp;eb-&gt;bflags)) return 0; /* (2) */ if (test_and_set_bit(EXTENT_BUFFER_READING, &amp;eb-&gt;bflags)) goto done; At this point, it seems safe to start the actual read operation. Once that completes, end_bbio_meta_read() does /* (3) */ set_extent_buffer_uptodate(eb); /* (4) */ clear_bit(EXTENT_BUFFER_READING, &amp;eb-&gt;bflags); Normally, this is enough to ensure only one read happens, and all other callers wait for it to finish before returning. Unfortunately, there is a racey interleaving: Thread A | Thread B | Thread C ---------+----------+--------- (1) | | | (1) | (2) | | (3) | | (4) | | | (2) | | | (1) When this happens, thread B kicks of an unnecessary read. Worse, thread C will see UPTODATE set and return immediately, while the read from thread B is still in progress. This race could result in tree-checker errors like this as the extent buffer is concurrently modified: BTRFS critical (device dm-0): corrupted node, root=256 block=8550954455682405139 owner mismatch, have 11858205567642294356 expect [256, 18446744073709551360] Fix it by testing UPTODATE again after setting the READING bit, and if it's been set, skip the unnecessary read. [ minor update of changelog ]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35798" target="_blank">CVE-2024-35798</a><br><a href="https://git.kernel.org/stable/c/0427c8ef8bbb7f304de42ef51d69c960e165e052" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2885d54af2c2e1d910e20d5c8045bae40e02fbc1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3a25878a3378adce5d846300c9570f15aa7f7a80" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ef1e68236b9153c27cb7cf29ead0c532870d4215" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Prevent crash when disable stream [Why] Disabling stream encoder invokes a function that no longer exists. [How] Check if the function declaration is NULL in disable stream encoder.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35799" target="_blank">CVE-2024-35799</a><br><a href="https://git.kernel.org/stable/c/2b17133a0a2e0e111803124dad09e803718d4a48" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4356a2c3f296503c8b420ae8adece053960a9f06" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/59772327d439874095516673b4b30c48bd83ca38" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/72d72e8fddbcd6c98e1b02d32cf6f2b04e10bd1c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: efi: fix panic in kdump kernel Check if get_next_variable() is actually valid pointer before calling it. In kdump kernel this method is set to NULL that causes panic during the kexec-ed kernel boot. Tested with QEMU and OVMF firmware.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35800" target="_blank">CVE-2024-35800</a><br><a href="https://git.kernel.org/stable/c/090d2b4515ade379cd592fbc8931344945978210" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/62b71cd73d41ddac6b1760402bbe8c4932e23531" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7784135f134c13af17d9ffb39a57db8500bc60ff" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9114ba9987506bcfbb454f6e68558d68cb1abbde" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b9d103aca85f082a343b222493f3cab1219aaaf4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Keep xfd_state in sync with MSR_IA32_XFD Commit 672365477ae8 ("x86/fpu: Update XFD state where required") and commit 8bf26758ca96 ("x86/fpu: Add XFD state to fpstate") introduced a per CPU variable xfd_state to keep the MSR_IA32_XFD value cached, in order to avoid unnecessary writes to the MSR. On CPU hotplug MSR_IA32_XFD is reset to the init_fpstate.xfd, which wipes out any stale state. But the per CPU cached xfd value is not reset, which brings them out of sync. As a consequence a subsequent xfd_update_state() might fail to update the MSR which in turn can result in XRSTOR raising a #NM in kernel space, which crashes the kernel. To fix this, introduce xfd_set_state() to write xfd_state together with MSR_IA32_XFD, and use it in all places that set MSR_IA32_XFD.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35801" target="_blank">CVE-2024-35801</a><br><a href="https://git.kernel.org/stable/c/10e4b5166df9ff7a2d5316138ca668b42d004422" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1acbca933313aa866e39996904c9aca4d435c4cd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/21c7c00dae55cb0e3810d5f9506b58f68475d41d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/92b0f04e937665bde5768f3fcc622dcce44413d8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b61e3b7055ac6edee4be071c52f48c26472d2624" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: x86/sev: Fix position dependent variable references in startup code The early startup code executes from a 1:1 mapping of memory, which differs from the mapping that the code was linked and/or relocated to run at. The latter mapping is not active yet at this point, and so symbol references that rely on it will fault. Given that the core kernel is built without -fPIC, symbol references are typically emitted as absolute, and so any such references occuring in the early startup code will therefore crash the kernel. While an attempt was made to work around this for the early SEV/SME startup code, by forcing RIP-relative addressing for certain global SEV/SME variables via inline assembly (see snp_cpuid_get_table() for example), RIP-relative addressing must be pervasively enforced for SEV/SME global variables when accessed prior to page table fixups. __startup_64() already handles this issue for select non-SEV/SME global variables using fixup_pointer(), which adjusts the pointer relative to a `physaddr` argument. To avoid having to pass around this `physaddr` argument across all functions needing to apply pointer fixups, introduce a macro RIP_RELATIVE_REF() which generates a RIP-relative reference to a given global variable. It is used where necessary to force RIP-relative accesses to global variables. For backporting purposes, this patch makes no attempt at cleaning up other occurrences of this pattern, involving either inline asm or fixup_pointer(). Those will be addressed later. [ bp: Call it "rip_rel_ref" everywhere like other code shortens "rIP-relative reference" and make the asm wrapper __always_inline. ]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35802" target="_blank">CVE-2024-35802</a><br><a href="https://git.kernel.org/stable/c/0982fd6bf0b822876f2e93ec782c4c28a3f85535" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1c811d403afd73f04bde82b83b24c754011bd0e8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/66fa3fcb474b2b892fe42d455a6f7ec5aaa98fb9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/954a4a87814465ad61cc97c1cd3de1525baaaf07" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fe272b61506bb1534922ef07aa165fd3c37a6a90" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: x86/efistub: Call mixed mode boot services on the firmware's stack Normally, the EFI stub calls into the EFI boot services using the stack that was live when the stub was entered. According to the UEFI spec, this stack needs to be at least 128k in size - this might seem large but all asynchronous processing and event handling in EFI runs from the same stack and so quite a lot of space may be used in practice. In mixed mode, the situation is a bit different: the bootloader calls the 32-bit EFI stub entry point, which calls the decompressor's 32-bit entry point, where the boot stack is set up, using a fixed allocation of 16k. This stack is still in use when the EFI stub is started in 64-bit mode, and so all calls back into the EFI firmware will be using the decompressor's limited boot stack. Due to the placement of the boot stack right after the boot heap, any stack overruns have gone unnoticed. However, commit 5c4feadb0011983b ("x86/decompressor: Move global symbol references to C code") moved the definition of the boot heap into C code, and now the boot stack is placed right at the base of BSS, where any overruns will corrupt the end of the .data section. While it would be possible to work around this by increasing the size of the boot stack, doing so would affect all x86 systems, and mixed mode systems are a tiny (and shrinking) fraction of the x86 installed base. So instead, record the firmware stack pointer value when entering from the 32-bit firmware, and switch to this stack every time a EFI boot service call is made.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35803" target="_blank">CVE-2024-35803</a><br><a href="https://git.kernel.org/stable/c/2149f8a56e2ed345c7a4d022a79f6b8fc53ae926" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/725351c036452b7db5771a7bed783564bc4b99cc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/930775060ca348b8665f60eef14b204172d14f31" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cefcd4fe2e3aaf792c14c9e56dab89e3d7a65d02" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fba7ee7187581b5bc222003e73e2592b398bb06d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Mark target gfn of emulated atomic instruction as dirty When emulating an atomic access on behalf of the guest, mark the target gfn dirty if the CMPXCHG by KVM is attempted and doesn't fault. This fixes a bug where KVM effectively corrupts guest memory during live migration by writing to guest memory without informing userspace that the page is dirty. Marking the page dirty got unintentionally dropped when KVM's emulated CMPXCHG was converted to do a user access. Before that, KVM explicitly mapped the guest page into kernel memory, and marked the page dirty during the unmap phase. Mark the page dirty even if the CMPXCHG fails, as the old data is written back on failure, i.e. the page is still written. The value written is guaranteed to be the same because the operation is atomic, but KVM's ABI is that all writes are dirty logged regardless of the value written. And more importantly, that's what KVM did before the buggy commit. Huge kudos to the folks on the Cc list (and many others), who did all the actual work of triaging and debugging. base-commit: 6769ea8da8a93ed4630f1ce64df6aafcaabfce64</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35804" target="_blank">CVE-2024-35804</a><br><a href="https://git.kernel.org/stable/c/225d587a073584946c05c9b7651d637bd45c0c71" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/726374dde5d608b15b9756bd52b6fc283fda7a06" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/910c57dfa4d113aae6571c2a8b9ae8c430975902" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9d1b22e573a3789ed1f32033ee709106993ba551" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a9bd6bb6f02bf7132c1ab192ba62bbfa52df7d66" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dm snapshot: fix lockup in dm_exception_table_exit There was reported lockup when we exit a snapshot with many exceptions. Fix this by adding "cond_resched" to the loop that frees the exceptions.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35805" target="_blank">CVE-2024-35805</a><br><a href="https://git.kernel.org/stable/c/116562e804ffc9dc600adab6326dde31d72262c7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3d47eb405781cc5127deca9a14e24b27696087a1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5f4ad4d0b0943296287313db60b3f84df4aad683" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6e7132ed3c07bd8a6ce3db4bb307ef2852b322dc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9759ff196e7d248bcf8386a7451d6ff8537a7d9c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e50f83061ac250f90710757a3e51b70a200835e2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e7d4cff57c3c43fdd72342c78d4138f509c7416e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fa5c055800a7fd49a36bbb52593aca4ea986a366" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: soc: fsl: qbman: Always disable interrupts when taking cgr_lock smp_call_function_single disables IRQs when executing the callback. To prevent deadlocks, we must disable IRQs when taking cgr_lock elsewhere. This is already done by qman_update_cgr and qman_delete_cgr; fix the other lockers.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35806" target="_blank">CVE-2024-35806</a><br><a href="https://git.kernel.org/stable/c/0e6521b0f93ff350434ed4ae61a250907e65d397" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/276af8efb05c8e47acf2738a5609dd72acfc703f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/584c2a9184a33a40fceee838f856de3cffa19be3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/62c3ecd2833cff0eff4a82af4082c44ca8d2518a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a62168653774c36398d65846a98034436ee66d03" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/af25c5180b2b1796342798f6c56fcfd12f5035bd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b56a793f267679945d1fdb9a280013bd2d0ed7f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dd199e5b759ffe349622a4b8fbcafc51fc51b1ec" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e6378314bb920acb39013051fa65d8f9f8030430" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ext4: fix corruption during on-line resize We observed a corruption during on-line resize of a file system that is larger than 16 TiB with 4k block size. With having more then 2^32 blocks resize_inode is turned off by default by mke2fs. The issue can be reproduced on a smaller file system for convenience by explicitly turning off resize_inode. An on-line resize across an 8 GiB boundary (the size of a meta block group in this setup) then leads to a corruption: dev=/dev/&lt;some_dev&gt; # should be &gt;= 16 GiB mkdir -p /corruption /sbin/mke2fs -t ext4 -b 4096 -O ^resize_inode $dev $((2 * 2**21 - 2**15)) mount -t ext4 $dev /corruption dd if=/dev/zero bs=4096 of=/corruption/test count=$((2*2**21 - 4*2**15)) sha1sum /corruption/test # 79d2658b39dcfd77274e435b0934028adafaab11 /corruption/test /sbin/resize2fs $dev $((2*2**21)) # drop page cache to force reload the block from disk echo 1 &gt; /proc/sys/vm/drop_caches sha1sum /corruption/test # 3c2abc63cbf1a94c9e6977e0fbd72cd832c4d5c3 /corruption/test 2^21 = 2^15*2^6 equals 8 GiB whereof 2^15 is the number of blocks per block group and 2^6 are the number of block groups that make a meta block group. The last checksum might be different depending on how the file is laid out across the physical blocks. The actual corruption occurs at physical block 63*2^15 = 2064384 which would be the location of the backup of the meta block group's block descriptor. During the on-line resize the file system will be converted to meta_bg starting at s_first_meta_bg which is 2 in the example - meaning all block groups after 16 GiB. However, in ext4_flex_group_add we might add block groups that are not part of the first meta block group yet. In the reproducer we achieved this by substracting the size of a whole block group from the point where the meta block group would start. This must be considered when updating the backup block group descriptors to follow the non-meta_bg layout. The fix is to add a test whether the group to add is already part of the meta block group or not.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35807" target="_blank">CVE-2024-35807</a><br><a href="https://git.kernel.org/stable/c/239c669edb2bffa1aa2612519b1d438ab35d6be6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/37b6a3ba793bbbae057f5b991970ebcc52cb3db5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/722d2c01b8b108f8283d1b7222209d5b2a5aa7bd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/75cc31c2e7193b69f5d25650bda5bb42ed92f8a1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a6b3bfe176e8a5b05ec4447404e412c2a3fc92cc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b461910af8ba3bed80f48c2bf852686d05c6fc5c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e8e8b197317228b5089ed9e7802dadf3ccaa027a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ee4e9c1976147a850f6085a13fca95bcaa00d84c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fb1088d51bbaa0faec5a55d4f5818a9ab79e24df" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: md/dm-raid: don't call md_reap_sync_thread() directly Currently md_reap_sync_thread() is called from raid_message() directly without holding 'reconfig_mutex', this is definitely unsafe because md_reap_sync_thread() can change many fields that is protected by 'reconfig_mutex'. However, hold 'reconfig_mutex' here is still problematic because this will cause deadlock, for example, commit 130443d60b1b ("md: refactor idle/frozen_sync_thread() to fix deadlock"). Fix this problem by using stop_sync_thread() to unregister sync_thread, like md/raid did.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35808" target="_blank">CVE-2024-35808</a><br><a href="https://git.kernel.org/stable/c/347dcdc15a1706f61aa545ae498ededdf31aeebc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9e59b8d76ff511505eb0dd1478329f09e0f04669" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cd32b27a66db8776d8b8e82ec7d7dde97a8693b0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: PCI/PM: Drain runtime-idle callbacks before driver removal A race condition between the .runtime_idle() callback and the .remove() callback in the rtsx_pcr PCI driver leads to a kernel crash due to an unhandled page fault [1]. The problem is that rtsx_pci_runtime_idle() is not expected to be running after pm_runtime_get_sync() has been called, but the latter doesn't really guarantee that. It only guarantees that the suspend and resume callbacks will not be running when it returns. However, if a .runtime_idle() callback is already running when pm_runtime_get_sync() is called, the latter will notice that the runtime PM status of the device is RPM_ACTIVE and it will return right away without waiting for the former to complete. In fact, it cannot wait for .runtime_idle() to complete because it may be called from that callback (it arguably does not make much sense to do that, but it is not strictly prohibited). Thus in general, whoever is providing a .runtime_idle() callback needs to protect it from running in parallel with whatever code runs after pm_runtime_get_sync(). [Note that .runtime_idle() will not start after pm_runtime_get_sync() has returned, but it may continue running then if it has started earlier.] One way to address that race condition is to call pm_runtime_barrier() after pm_runtime_get_sync() (not before it, because a nonzero value of the runtime PM usage counter is necessary to prevent runtime PM callbacks from being invoked) to wait for the .runtime_idle() callback to complete should it be running at that point. A suitable place for doing that is in pci_device_remove() which calls pm_runtime_get_sync() before removing the driver, so it may as well call pm_runtime_barrier() subsequently, which will prevent the race in question from occurring, not just in the rtsx_pcr driver, but in any PCI drivers providing .runtime_idle() callbacks.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35809" target="_blank">CVE-2024-35809</a><br><a href="https://git.kernel.org/stable/c/47d8aafcfe313511a98f165a54d0adceb34e54b1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6347348c6aba52dda0b33296684cbb627bdc6970" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7cc94dd36e48879e76ae7a8daea4ff322b7d9674" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/900b81caf00c89417172afe0e7e49ac4eb110f4b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a87375bb586515c0af63d5dcdcd58ec4acf20a6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9d5286d4e7f68beab450deddbb6a32edd5ecf4bf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bbe068b24409ef740657215605284fc7cdddd491" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d534198311c345e4b062c4b88bb609efb8bd91d5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d86ad8c3e152349454b82f37007ff6ba45f26989" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix the lifetime of the bo cursor memory The cleanup can be dispatched while the atomic update is still active, which means that the memory acquired in the atomic update needs to not be invalidated by the cleanup. The buffer objects in vmw_plane_state instead of using the builtin map_and_cache were trying to handle the lifetime of the mapped memory themselves, leading to crashes. Use the map_and_cache instead of trying to manage the lifetime of the buffer objects held by the vmw_plane_state. Fixes kernel oops'es in IGT's kms_cursor_legacy forked-bo.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35810" target="_blank">CVE-2024-35810</a><br><a href="https://git.kernel.org/stable/c/104a5b2772bc7c0715ae7355ccf9d294a472765c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/86cb706a40b7e6b2221ee49a298a65ad9b46c02d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a9e8a7159ca09af9b1a300a6c8e8b6ff7501c76" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ed381800ea6d9a4c7f199235a471c0c48100f0ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix use-after-free bug in brcmf_cfg80211_detach This is the candidate patch of CVE-2023-47233 : https://nvd.nist.gov/vuln/detail/CVE-2023-47233 In brcm80211 driver,it starts with the following invoking chain to start init a timeout worker: -&gt;brcmf_usb_probe -&gt;brcmf_usb_probe_cb -&gt;brcmf_attach -&gt;brcmf_bus_started -&gt;brcmf_cfg80211_attach -&gt;wl_init_priv -&gt;brcmf_init_escan -&gt;INIT_WORK(&amp;cfg-&gt;escan_timeout_work, brcmf_cfg80211_escan_timeout_worker); If we disconnect the USB by hotplug, it will call brcmf_usb_disconnect to make cleanup. The invoking chain is : brcmf_usb_disconnect -&gt;brcmf_usb_disconnect_cb -&gt;brcmf_detach -&gt;brcmf_cfg80211_detach -&gt;kfree(cfg); While the timeout woker may still be running. This will cause a use-after-free bug on cfg in brcmf_cfg80211_escan_timeout_worker. Fix it by deleting the timer and canceling the worker in brcmf_cfg80211_detach. [arend.vanspriel@broadcom.com: keep timer delete as is and cancel work just before free]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35811" target="_blank">CVE-2024-35811</a><br><a href="https://git.kernel.org/stable/c/0a7591e14a8da794d0b93b5d1c6254ccb23adacb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0b812f706fd7090be74812101114a0e165b36744" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0f7352557a35ab7888bc7831411ec8a3cbe20d78" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/190794848e2b9d15de92d502b6ac652806904f5a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/202c503935042272e2f9e1bb549d5f69a8681169" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6678a1e7d896c00030b31491690e8ddc9a90767a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8c36205123dc57349b59b4f1a2301eb278cbc731" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8e3f03f4ef7c36091f46e7349096efb5a2cdb3a1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bacb8c3ab86dcd760c15903fcee58169bc3026aa" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: cdc-wdm: close race between read and workqueue wdm_read() cannot race with itself. However, in service_outstanding_interrupt() it can race with the workqueue, which can be triggered by error handling. Hence we need to make sure that the WDM_RESPONDING flag is not just only set but tested.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35812" target="_blank">CVE-2024-35812</a><br><a href="https://git.kernel.org/stable/c/164be0a824387301312689bb29b2be92ab2cd39d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/19f955ad9437a6859a529af34e2eafd903d5e7c1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2ff436b6399859e06539a2b9c667897d3cc85ad5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/339f83612f3a569b194680768b22bf113c26a29d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/347cca11bb78b9f3c29b45a9c52e70258bd008bf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3afdcc4e1a00facad210f5c5891bb2fbc026067f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5904411219601127ffdbd2d622bb5d67f9d8d16c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7182175f565ffffa2ba1911726c5656bfc7a1bae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8672ad663a22d0e4a325bb7d817b36ec412b967c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/916cd2fcbc1e344bcabf4b2a834cdf5a0417d30c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9723602387217caa71d623ffcce314dc39e84a09" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9b319f4a88094b2e020e6db6e819c808d890098d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a86e54a345139f1a7668c9f83bdc7ac6f91b6f78" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ab92e11b73b48b79f144421430891f3aa6242656" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/da3b75931bb737be74d6b4341e0080f233ed1409" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e4e47e406d74cab601b2ab21ba5e3add811e05ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mmc: core: Avoid negative index with array access Commit 4d0c8d0aef63 ("mmc: core: Use mrq.sbc in close-ended ffu") assigns prev_idata = idatas[i - 1], but doesn't check that the iterator i is greater than zero. Let's fix this by adding a check.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35813" target="_blank">CVE-2024-35813</a><br><a href="https://git.kernel.org/stable/c/064db53f9023a2d5877a2d12de6bc27995f6ca56" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2b539c88940e22494da80a93ee1c5a28bbad10f6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4466677dcabe2d70de6aa3d4bd4a4fafa94a71f2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7d0e8a6147550aa058fa6ade8583ad252aa61304" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/81b8645feca08a54c7c4bf36e7b176f4983b2f28" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ad9cc5e9e53ab94aa0c7ac65d43be7eb208dcb55" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b9a7339ae403035ffe7fc37cb034b36947910f68" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cf55a7acd1ed38afe43bba1c8a0935b51d1dc014" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: swiotlb: Fix double-allocation of slots due to broken alignment handling Commit bbb73a103fbb ("swiotlb: fix a braino in the alignment check fix"), which was a fix for commit 0eee5ae10256 ("swiotlb: fix slot alignment checks"), causes a functional regression with vsock in a virtual machine using bouncing via a restricted DMA SWIOTLB pool. When virtio allocates the virtqueues for the vsock device using dma_alloc_coherent(), the SWIOTLB search can return page-unaligned allocations if 'area-&gt;index' was left unaligned by a previous allocation from the buffer: # Final address in brackets is the SWIOTLB address returned to the caller | virtio-pci 0000:00:07.0: orig_addr 0x0 alloc_size 0x2000, iotlb_align_mask 0x800 stride 0x2: got slot 1645-1649/7168 (0x98326800) | virtio-pci 0000:00:07.0: orig_addr 0x0 alloc_size 0x2000, iotlb_align_mask 0x800 stride 0x2: got slot 1649-1653/7168 (0x98328800) | virtio-pci 0000:00:07.0: orig_addr 0x0 alloc_size 0x2000, iotlb_align_mask 0x800 stride 0x2: got slot 1653-1657/7168 (0x9832a800) This ends badly (typically buffer corruption and/or a hang) because swiotlb_alloc() is expecting a page-aligned allocation and so blindly returns a pointer to the 'struct page' corresponding to the allocation, therefore double-allocating the first half (2KiB slot) of the 4KiB page. Fix the problem by treating the allocation alignment separately to any additional alignment requirements from the device, using the maximum of the two as the stride to search the buffer slots and taking care to ensure a minimum of page-alignment for buffers larger than a page. This also resolves swiotlb allocation failures occuring due to the inclusion of ~PAGE_MASK in 'iotlb_align_mask' for large allocations and resulting in alignment requirements exceeding swiotlb_max_mapping_size().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35814" target="_blank">CVE-2024-35814</a><br><a href="https://git.kernel.org/stable/c/04867a7a33324c9c562ee7949dbcaab7aaad1fb4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3e7acd6e25ba77dde48c3b721c54c89cd6a10534" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/777391743771040e12cc40d3d0d178f70c616491" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c88668aa6c1da240ea3eb4d128b7906e740d3cb8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: fs/aio: Check IOCB_AIO_RW before the struct aio_kiocb conversion The first kiocb_set_cancel_fn() argument may point at a struct kiocb that is not embedded inside struct aio_kiocb. With the current code, depending on the compiler, the req-&gt;ki_ctx read happens either before the IOCB_AIO_RW test or after that test. Move the req-&gt;ki_ctx read such that it is guaranteed that the IOCB_AIO_RW test happens first.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35815" target="_blank">CVE-2024-35815</a><br><a href="https://git.kernel.org/stable/c/10ca82aff58434e122c7c757cf0497c335f993f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/18d5fc3c16cc317bd0e5f5dabe0660df415cadb7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/396dbbc18963648e9d1a4edbb55cfe08fa374d50" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5c43d0041e3a05c6c41c318b759fff16d2384596" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/94eb0293703ced580f05dfbe5a57da5931e9aee2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/961ebd120565cb60cebe21cb634fbc456022db4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a71cba07783abc76b547568b6452cd1dd9981410" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c01ed748847fe8b810d86efc229b9e6c7fafa01e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: firewire: ohci: prevent leak of left-over IRQ on unbind Commit 5a95f1ded28691e6 ("firewire: ohci: use devres for requested IRQ") also removed the call to free_irq() in pci_remove(), leading to a leftover irq of devm_request_irq() at pci_disable_msi() in pci_remove() when unbinding the driver from the device remove_proc_entry: removing non-empty directory 'irq/136', leaking at least 'firewire_ohci' Call Trace: ? remove_proc_entry+0x19c/0x1c0 ? __warn+0x81/0x130 ? remove_proc_entry+0x19c/0x1c0 ? report_bug+0x171/0x1a0 ? console_unlock+0x78/0x120 ? handle_bug+0x3c/0x80 ? exc_invalid_op+0x17/0x70 ? asm_exc_invalid_op+0x1a/0x20 ? remove_proc_entry+0x19c/0x1c0 unregister_irq_proc+0xf4/0x120 free_desc+0x3d/0xe0 ? kfree+0x29f/0x2f0 irq_free_descs+0x47/0x70 msi_domain_free_locked.part.0+0x19d/0x1d0 msi_domain_free_irqs_all_locked+0x81/0xc0 pci_free_msi_irqs+0x12/0x40 pci_disable_msi+0x4c/0x60 pci_remove+0x9d/0xc0 [firewire_ohci 01b483699bebf9cb07a3d69df0aa2bee71db1b26] pci_device_remove+0x37/0xa0 device_release_driver_internal+0x19f/0x200 unbind_store+0xa1/0xb0 remove irq with devm_free_irq() before pci_disable_msi() also remove it in fail_msi: of pci_probe() as this would lead to an identical leak</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35816" target="_blank">CVE-2024-35816</a><br><a href="https://git.kernel.org/stable/c/318f6d53dd425c400e35f1a9b7af682c2c6a66d6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/43c70cbc2502cf2557105c662eeed6a15d082b88" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/575801663c7dc38f826212b39e3b91a4a8661c33" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: amdgpu_ttm_gart_bind set gtt bound flag Otherwise after the GTT bo is released, the GTT and gart space is freed but amdgpu_ttm_backend_unbind will not clear the gart page table entry and leave valid mapping entry pointing to the stale system page. Then if GPU access the gart address mistakely, it will read undefined value instead page fault, harder to debug and reproduce the real issue.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35817" target="_blank">CVE-2024-35817</a><br><a href="https://git.kernel.org/stable/c/589c414138a1bed98e652c905937d8f790804efe" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5cdce3dda3b3dacde902f63a8ee72c2b7f91912d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5d5f1a7f3b1039925f79c7894f153c2a905201fb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6c6064cbe58b43533e3451ad6a8ba9736c109ac3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6fcd12cb90888ef2d8af8d4c04e913252eee4ef3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e8d27caef2c829a306e1f762fb95f06e8ec676f6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: LoongArch: Define the __io_aw() hook as mmiowb() Commit fb24ea52f78e0d595852e ("drivers: Remove explicit invocations of mmiowb()") remove all mmiowb() in drivers, but it says: "NOTE: mmiowb() has only ever guaranteed ordering in conjunction with spin_unlock(). However, pairing each mmiowb() removal in this patch with the corresponding call to spin_unlock() is not at all trivial, so there is a small chance that this change may regress any drivers incorrectly relying on mmiowb() to order MMIO writes between CPUs using lock-free synchronisation." The mmio in radeon_ring_commit() is protected by a mutex rather than a spinlock, but in the mutex fastpath it behaves similar to spinlock. We can add mmiowb() calls in the radeon driver but the maintainer says he doesn't like such a workaround, and radeon is not the only example of mutex protected mmio. So we should extend the mmiowb tracking system from spinlock to mutex, and maybe other locking primitives. This is not easy and error prone, so we solve it in the architectural code, by simply defining the __io_aw() hook as mmiowb(). And we no longer need to override queued_spin_unlock() so use the generic definition. Without this, we get such an error when run 'glxgears' on weak ordering architectures such as LoongArch: radeon 0000:04:00.0: ring 0 stalled for more than 10324msec radeon 0000:04:00.0: ring 3 stalled for more than 10240msec radeon 0000:04:00.0: GPU lockup (current fence id 0x000000000001f412 last fence id 0x000000000001f414 on ring 3) radeon 0000:04:00.0: GPU lockup (current fence id 0x000000000000f940 last fence id 0x000000000000f941 on ring 0) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35)</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35818" target="_blank">CVE-2024-35818</a><br><a href="https://git.kernel.org/stable/c/0b61a7dc6712b78799b3949997e8a5e94db5c4b0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/97cd43ba824aec764f5ea2790d0c0a318f885167" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9adec248bba33b1503252caf8e59d81febfc5ceb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9c68ece8b2a5c5ff9b2fcaea923dd73efeb174cd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d7d7c6cdea875be3b241d7d39873bb431db7154d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: soc: fsl: qbman: Use raw spinlock for cgr_lock smp_call_function always runs its callback in hard IRQ context, even on PREEMPT_RT, where spinlocks can sleep. So we need to use a raw spinlock for cgr_lock to ensure we aren't waiting on a sleeping task. Although this bug has existed for a while, it was not apparent until commit ef2a8d5478b9 ("net: dpaa: Adjust queue depth on rate change") which invokes smp_call_function_single via qman_update_cgr_safe every time a link goes up or down.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35819" target="_blank">CVE-2024-35819</a><br><a href="https://git.kernel.org/stable/c/2b3fede8225133671ce837c0d284804aa3bc7a02" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/32edca2f03a6cc42c650ddc3ad83d086e3f365d1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/54d26adf64c04f186098b39dba86b86037084baa" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a3ca8292ce9fdcce122706c28c3f07bc857fe5e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cd53a8ae5aacb4ecd25088486dea1cd02e74b506" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d6b5aac451c9cc12e43ab7308e0e2ddc52c62c14" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f39d36b7540cf0088ed7ce2de2794f2aa237f6df" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fbec4e7fed89b579f2483041fabf9650fb0dd6bc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ff50716b7d5b7985979a5b21163cd79fb3d21d59" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_queue_proc modifying req-&gt;flags With multiple poll entries __io_queue_proc() might be running in parallel with poll handlers and possibly task_work, we should not be carelessly modifying req-&gt;flags there. io_poll_double_prepare() handles a similar case with locking but it's much easier to move it into __io_arm_poll_handler().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35820" target="_blank">CVE-2024-35820</a><br><a href="https://git.kernel.org/stable/c/0ecb8919469e6d5c74eea24086b34ce1bda5aef7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1a8ec63b2b6c91caec87d4e132b1f71b5df342be" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/51a490a7f63cae0754120e7c04f4f47920bd48db" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ubifs: Set page uptodate in the correct place Page cache reads are lockless, so setting the freshly allocated page uptodate before we've overwritten it with the data it's supposed to have in it will allow a simultaneous reader to see old data. Move the call to SetPageUptodate into ubifs_write_end(), which is after we copied the new data into the page.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35821" target="_blank">CVE-2024-35821</a><br><a href="https://git.kernel.org/stable/c/142d87c958d9454c3cffa625fab56f3016e8f9f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/17772bbe9cfa972ea1ff827319f6e1340de76566" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4aa554832b9dc9e66249df75b8f447d87853e12e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4b7c4fc60d6a46350fbe54f5dc937aeaa02e675e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/723012cab779eee8228376754e22c6594229bf8f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/778c6ad40256f1c03244fc06d7cdf71f6b5e7310" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8f599ab6fabbca4c741107eade70722a98adfd9f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f19b1023a3758f40791ec166038d6411c8894ae3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fc99f4e2d2f1ce766c14e98463c2839194ae964f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: udc: remove warning when queue disabled ep It is possible trigger below warning message from mass storage function, WARNING: CPU: 6 PID: 3839 at drivers/usb/gadget/udc/core.c:294 usb_ep_queue+0x7c/0x104 pc : usb_ep_queue+0x7c/0x104 lr : fsg_main_thread+0x494/0x1b3c Root cause is mass storage function try to queue request from main thread, but other thread may already disable ep when function disable. As there is no function failure in the driver, in order to avoid effort to fix warning, change WARN_ON_ONCE() in usb_ep_queue() to pr_debug().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35822" target="_blank">CVE-2024-35822</a><br><a href="https://git.kernel.org/stable/c/2a587a035214fa1b5ef598aea0b81848c5b72e5e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2b002c308e184feeaeb72987bca3f1b11e5f70b8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/30511676eb54d480d014352bf784f02577a10252" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/36177c2595df12225b95ce74eb1ac77b43d5a58c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3e944ddc17c042945d983e006df7860687a8849a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/68d951880d0c52c7f13dcefb5501b69b8605ce8c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/99731076722eb7ed26b0c87c879da7bb71d24290" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/df5cbb908f1687e8ab97e222a16b7890d5501acf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f74c5e0b54b02706d9a862ac6cddade30ac86bcf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: vt: fix unicode buffer corruption when deleting characters This is the same issue that was fixed for the VGA text buffer in commit 39cdb68c64d8 ("vt: fix memory overlapping when deleting chars in the buffer"). The cure is also the same i.e. replace memcpy() with memmove() due to the overlaping buffers.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35823" target="_blank">CVE-2024-35823</a><br><a href="https://git.kernel.org/stable/c/0190d19d7651c08abc187dac3819c61b726e7e3f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1581dafaf0d34bc9c428a794a22110d7046d186d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1ce408f75ccf1e25b3fddef75cca878b55f2ac90" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2933b1e4757a0a5c689cf48d80b1a2a85f237ff1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7529cbd8b5f6697b369803fe1533612c039cabda" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/994a1e583c0c206c8ca7d03334a65b79f4d8bc51" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fc7dfe3d123f00e720be80b920da287810a1f37d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ff7342090c1e8c5a37015c89822a68b275b46f8a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: misc: lis3lv02d_i2c: Fix regulators getting en-/dis-abled twice on suspend/resume When not configured for wakeup lis3lv02d_i2c_suspend() will call lis3lv02d_poweroff() even if the device has already been turned off by the runtime-suspend handler and if configured for wakeup and the device is runtime-suspended at this point then it is not turned back on to serve as a wakeup source. Before commit b1b9f7a49440 ("misc: lis3lv02d_i2c: Add missing setting of the reg_ctrl callback"), lis3lv02d_poweroff() failed to disable the regulators which as a side effect made calling poweroff() twice ok. Now that poweroff() correctly disables the regulators, doing this twice triggers a WARN() in the regulator core: unbalanced disables for regulator-dummy WARNING: CPU: 1 PID: 92 at drivers/regulator/core.c:2999 _regulator_disable ... Fix lis3lv02d_i2c_suspend() to not call poweroff() a second time if already runtime-suspended and add a poweron() call when necessary to make wakeup work. lis3lv02d_i2c_resume() has similar issues, with an added weirness that it always powers on the device if it is runtime suspended, after which the first runtime-resume will call poweron() again, causing the enabled count for the regulator to increase by 1 every suspend/resume. These unbalanced regulator_enable() calls cause the regulator to never be turned off and trigger the following WARN() on driver unbind: WARNING: CPU: 1 PID: 1724 at drivers/regulator/core.c:2396 _regulator_put Fix this by making lis3lv02d_i2c_resume() mirror the new suspend().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35824" target="_blank">CVE-2024-35824</a><br><a href="https://git.kernel.org/stable/c/4154e767354140db7804207117e7238fb337b0e7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/997ca415384612c8df76d99d9a768e0b3f42b325" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ac3e0384073b2408d6cb0d972fee9fcc3776053d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f6df761182fc953907b18aba5049fc2a044ecb45" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: gadget: ncm: Fix handling of zero block length packets While connecting to a Linux host with CDC_NCM_NTB_DEF_SIZE_TX set to 65536, it has been observed that we receive short packets, which come at interval of 5-10 seconds sometimes and have block length zero but still contain 1-2 valid datagrams present. According to the NCM spec: "If wBlockLength = 0x0000, the block is terminated by a short packet. In this case, the USB transfer must still be shorter than dwNtbInMaxSize or dwNtbOutMaxSize. If exactly dwNtbInMaxSize or dwNtbOutMaxSize bytes are sent, and the size is a multiple of wMaxPacketSize for the given pipe, then no ZLP shall be sent. wBlockLength= 0x0000 must be used with extreme care, because of the possibility that the host and device may get out of sync, and because of test issues. wBlockLength = 0x0000 allows the sender to reduce latency by starting to send a very large NTB, and then shortening it when the sender discovers that there's not sufficient data to justify sending a large NTB" However, there is a potential issue with the current implementation, as it checks for the occurrence of multiple NTBs in a single giveback by verifying if the leftover bytes to be processed is zero or not. If the block length reads zero, we would process the same NTB infintely because the leftover bytes is never zero and it leads to a crash. Fix this by bailing out if block length reads zero.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35825" target="_blank">CVE-2024-35825</a><br><a href="https://git.kernel.org/stable/c/6b2c73111a252263807b7598682663dc33aa4b4c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7664ee8bd80309b90d53488b619764f0a057f2b7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/92b051b87658df7649ffcdef522593f21a2b296b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a0f77b5d6067285b8eca0ee3bd1e448a6258026f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a766761d206e7c36d7526e0ae749949d17ca582c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e2dbfea520e60d58e0c498ba41bde10452257779" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ef846cdbd100f7f9dc045e8bcd7fe4b3a3713c03" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f90ce1e04cbcc76639d6cba0fdbd820cd80b3c70" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: block: Fix page refcounts for unaligned buffers in __bio_release_pages() Fix an incorrect number of pages being released for buffers that do not start at the beginning of a page.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35826" target="_blank">CVE-2024-35826</a><br><a href="https://git.kernel.org/stable/c/242006996d15f5ca62e22f8c7de077d9c4a8f367" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/38b43539d64b2fa020b3b9a752a986769f87f7a6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7d3765550374f71248c55e6206ea1d6fd4537e65" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c9d3d2fbde9b8197bce88abcbe8ee8e713ffe7c2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ecbd9ced84dd655a8f4cd49d2aad0e80dbf6bf35" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: io_uring/net: fix overflow check in io_recvmsg_mshot_prep() The "controllen" variable is type size_t (unsigned long). Casting it to int could lead to an integer underflow. The check_add_overflow() function considers the type of the destination which is type int. If we add two positive values and the result cannot fit in an integer then that's counted as an overflow. However, if we cast "controllen" to an int and it turns negative, then negative values *can* fit into an int type so there is no overflow. Good: 100 + (unsigned long)-4 = 96 &lt;-- overflow Bad: 100 + (int)-4 = 96 &lt;-- no overflow I deleted the cast of the sizeof() as well. That's not a bug but the cast is unnecessary.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35827" target="_blank">CVE-2024-35827</a><br><a href="https://git.kernel.org/stable/c/0c8c74bb59e7d77554016efc34c2d10376985e5e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/59a534690ecc3af72c6ab121aeac1237a4adae66" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/868ec868616438df487b9e2baa5a99f8662cc47c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8ede3db5061bb1fe28e2c9683329aafa89d2b1b4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b6563ad0d599110bd5cf8f56c47d279c3ed796fe" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: fix some memleaks in lbs_allocate_cmd_buffer() In the for statement of lbs_allocate_cmd_buffer(), if the allocation of cmdarray[i].cmdbuf fails, both cmdarray and cmdarray[i].cmdbuf needs to be freed. Otherwise, there will be memleaks in lbs_allocate_cmd_buffer().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35828" target="_blank">CVE-2024-35828</a><br><a href="https://git.kernel.org/stable/c/4d99d267da3415db2124029cb5a6d2d955ca43f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5f0e4aede01cb01fa633171f0533affd25328c3a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8e243ac649c10922a6b4855170eaefe4c5b3faab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/96481624fb5a6319079fb5059e46dbce43a90186" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bea9573c795acec5614d4ac2dcc7b3b684cea5bf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d219724d4b0ddb8ec7dfeaed5989f23edabaf591" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/da10f6b7918abd5b4bc5c9cb66f0fc6763ac48f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e888c4461e109f7b93c3522afcbbaa5a8fdf29d2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f0dd27314c7afe34794c2aa19dd6f2d30eb23bc7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/lima: fix a memleak in lima_heap_alloc When lima_vm_map_bo fails, the resources need to be deallocated, or there will be memleaks.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35829" target="_blank">CVE-2024-35829</a><br><a href="https://git.kernel.org/stable/c/04ae3eb470e52a3c41babe85ff8cee195e4dcbea" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4ab14eccf5578af1dd5668a5f2d771df27683cab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/746606d37d662c70ae1379fc658ee9c65f06880f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8e25c0ee5665e8a768b8e21445db1f86e9156eb7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ec6bb037e4a35fcbb5cd7bc78242d034ed893fcd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f2e80ac9344aebbff576453d5c0290b332e187ed" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f6d51a91b41704704e395de6839c667b0f810bbf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: media: tc358743: register v4l2 async device only after successful setup Ensure the device has been setup correctly before registering the v4l2 async device, thus allowing userspace to access.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35830" target="_blank">CVE-2024-35830</a><br><a href="https://git.kernel.org/stable/c/17c2650de14842c25c569cbb2126c421489a3a24" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4f1490a5d7a0472ee5d9f36547bc4ba46be755c7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/610f20e5cf35ca9c0992693cae0dd8643ce932e7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/87399f1ff92203d65f1febf5919429f4bb613a02" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8ba8db9786b55047df5ad3db3e01dd886687a77d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b8505a1aee8f1edc9d16d72ae09c93de086e2a1a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c915c46a25c3efb084c4f5e69a053d7f7a635496" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/daf21394f9898fb9f0698c3e50de08132d2164e6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/edbb3226c985469a2f8eb69885055c9f5550f468" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: io_uring: Fix release of pinned pages when __io_uaddr_map fails Looking at the error path of __io_uaddr_map, if we fail after pinning the pages for any reasons, ret will be set to -EINVAL and the error handler won't properly release the pinned pages. I didn't manage to trigger it without forcing a failure, but it can happen in real life when memory is heavily fragmented.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35831" target="_blank">CVE-2024-35831</a><br><a href="https://git.kernel.org/stable/c/0b6f39c175ba5f0ef72bdb3b9d2a06ad78621d62" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4d376d7ad62b6a8e8dfff56b559d9d275e5b9b3a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/67d1189d1095d471ed7fa426c7e384a7140a5dd7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/712e2c8415f55a4a4ddaa98a430b87f624109f69" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: bcachefs: kvfree bch_fs::snapshots in bch2_fs_snapshots_exit bch_fs::snapshots is allocated by kvzalloc in __snapshot_t_mut. It should be freed by kvfree not kfree. Or umount will triger: [ 406.829178 ] BUG: unable to handle page fault for address: ffffe7b487148008 [ 406.830676 ] #PF: supervisor read access in kernel mode [ 406.831643 ] #PF: error_code(0x0000) - not-present page [ 406.832487 ] PGD 0 P4D 0 [ 406.832898 ] Oops: 0000 [#1] PREEMPT SMP PTI [ 406.833512 ] CPU: 2 PID: 1754 Comm: umount Kdump: loaded Tainted: G OE 6.7.0-rc7-custom+ #90 [ 406.834746 ] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014 [ 406.835796 ] RIP: 0010:kfree+0x62/0x140 [ 406.836197 ] Code: 80 48 01 d8 0f 82 e9 00 00 00 48 c7 c2 00 00 00 80 48 2b 15 78 9f 1f 01 48 01 d0 48 c1 e8 0c 48 c1 e0 06 48 03 05 56 9f 1f 01 &lt;48&gt; 8b 50 08 48 89 c7 f6 c2 01 0f 85 b0 00 00 00 66 90 48 8b 07 f6 [ 406.837810 ] RSP: 0018:ffffb9d641607e48 EFLAGS: 00010286 [ 406.838213 ] RAX: ffffe7b487148000 RBX: ffffb9d645200000 RCX: ffffb9d641607dc4 [ 406.838738 ] RDX: 000065bb00000000 RSI: ffffffffc0d88b84 RDI: ffffb9d645200000 [ 406.839217 ] RBP: ffff9a4625d00068 R08: 0000000000000001 R09: 0000000000000001 [ 406.839650 ] R10: 0000000000000001 R11: 000000000000001f R12: ffff9a4625d4da80 [ 406.840055 ] R13: ffff9a4625d00000 R14: ffffffffc0e2eb20 R15: 0000000000000000 [ 406.840451 ] FS: 00007f0a264ffb80(0000) GS:ffff9a4e2d500000(0000) knlGS:0000000000000000 [ 406.840851 ] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 406.841125 ] CR2: ffffe7b487148008 CR3: 000000018c4d2000 CR4: 00000000000006f0 [ 406.841464 ] Call Trace: [ 406.841583 ] &lt;TASK&gt; [ 406.841682 ] ? __die+0x1f/0x70 [ 406.841828 ] ? page_fault_oops+0x159/0x470 [ 406.842014 ] ? fixup_exception+0x22/0x310 [ 406.842198 ] ? exc_page_fault+0x1ed/0x200 [ 406.842382 ] ? asm_exc_page_fault+0x22/0x30 [ 406.842574 ] ? bch2_fs_release+0x54/0x280 [bcachefs] [ 406.842842 ] ? kfree+0x62/0x140 [ 406.842988 ] ? kfree+0x104/0x140 [ 406.843138 ] bch2_fs_release+0x54/0x280 [bcachefs] [ 406.843390 ] kobject_put+0xb7/0x170 [ 406.843552 ] deactivate_locked_super+0x2f/0xa0 [ 406.843756 ] cleanup_mnt+0xba/0x150 [ 406.843917 ] task_work_run+0x59/0xa0 [ 406.844083 ] exit_to_user_mode_prepare+0x197/0x1a0 [ 406.844302 ] syscall_exit_to_user_mode+0x16/0x40 [ 406.844510 ] do_syscall_64+0x4e/0xf0 [ 406.844675 ] entry_SYSCALL_64_after_hwframe+0x6e/0x76 [ 406.844907 ] RIP: 0033:0x7f0a2664e4fb</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35832" target="_blank">CVE-2024-35832</a><br><a href="https://git.kernel.org/stable/c/369acf97d6fd5da620d053d0f1878ffe32eff555" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/56590678791119b9a655202e49898edfb9307271" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-qdma: Fix a memory leak related to the queue command DMA This dma_alloc_coherent() is undone neither in the remove function, nor in the error handling path of fsl_qdma_probe(). Switch to the managed version to fix both issues.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35833" target="_blank">CVE-2024-35833</a><br><a href="https://git.kernel.org/stable/c/15eb996d7d13cb72a16389231945ada8f0fef2c3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/198270de9d8eb3b5d5f030825ea303ef95285d24" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1c75fe450b5200c78f4a102a0eb8e15d8f1ccda8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/25ab4d72eb7cbfa0f3d97a139a9b2bfcaa72dd59" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3aa58cb51318e329d203857f7a191678e60bb714" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5cd8a51517ce15edbdcea4fc74c4c127ddaa1bd6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ae6769ba51417c1c86fb645812d5bff455eee802" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: xsk: recycle buffer in case Rx queue was full Add missing xsk_buff_free() call when __xsk_rcv_zc() failed to produce descriptor to XSK Rx queue.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35834" target="_blank">CVE-2024-35834</a><br><a href="https://git.kernel.org/stable/c/269009893146c495f41e9572dd9319e787c2eba9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7b4d93d31aade99210d41cd9d4cbd2957c98bc8c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cce713664548284daf977739e7ff1cd59e84189c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: fix a double-free in arfs_create_groups When `in` allocated by kvzalloc fails, arfs_create_groups will free ft-&gt;g and return an error. However, arfs_create_table, the only caller of arfs_create_groups, will hold this error and call to mlx5e_destroy_flow_table, in which the ft-&gt;g will be freed again.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35835" target="_blank">CVE-2024-35835</a><br><a href="https://git.kernel.org/stable/c/2501afe6c4c9829d03abe9a368b83d9ea1b611b7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3c6d5189246f590e4e1f167991558bdb72a4738b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/42876db001bbea7558e8676d1019f08f9390addb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/66cc521a739ccd5da057a1cb3d6346c6d0e7619b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b21db3f1ab7967a81d6bbd328d28fe5a4c07a8a7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c57ca114eb00e03274dd38108d07a3750fa3c056" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cf116d9c3c2aebd653c2dfab5b10c278e9ec3ee5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e3d3ed8c152971dbe64c92c9ecb98fdb52abb629" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dpll: fix pin dump crash for rebound module When a kernel module is unbound but the pin resources were not entirely freed (other kernel module instance of the same PCI device have had kept the reference to that pin), and kernel module is again bound, the pin properties would not be updated (the properties are only assigned when memory for the pin is allocated), prop pointer still points to the kernel module memory of the kernel module which was deallocated on the unbind. If the pin dump is invoked in this state, the result is a kernel crash. Prevent the crash by storing persistent pin properties in dpll subsystem, copy the content from the kernel module when pin is allocated, instead of using memory of the kernel module.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35836" target="_blank">CVE-2024-35836</a><br><a href="https://git.kernel.org/stable/c/5050a5b9d8b4d3c6f7e376e07670e437db7ccf9c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/830ead5fb0c5855ce4d70ba2ed4a673b5f1e7d9b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: clear BM pool before initialization Register value persist after booting the kernel using kexec which results in kernel panic. Thus clear the BM pool registers before initialisation to fix the issue.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35837" target="_blank">CVE-2024-35837</a><br><a href="https://git.kernel.org/stable/c/83f99138bf3b396f761600ab488054396fb5768f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/938729484cfa535e9987ed0f86f29a2ae3a8188b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9f538b415db862e74b8c5d3abbccfc1b2b6caa38" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/af47faa6d3328406038b731794e7cf508c71affa" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cec65f09c47d8c2d67f2bcad6cf05c490628d1ec" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dc77f6ab5c3759df60ff87ed24f4d45df0f3b4c4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix potential sta-link leak When a station is allocated, links are added but not set to valid yet (e.g. during connection to an AP MLD), we might remove the station without ever marking links valid, and leak them. Fix that.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35838" target="_blank">CVE-2024-35838</a><br><a href="https://git.kernel.org/stable/c/49aaeb8c539b1633b3bd7c2df131ec578aa1eae1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/587c5892976108674bbe61a8ff659de279318034" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b01a74b3ca6fd51b62c67733ba7c3280fa6c5d26" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e04bf59bdba0fa45d52160be676114e16be855a9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: replace physindev with physinif in nf_bridge_info An skb can be added to a neigh-&gt;arp_queue while waiting for an arp reply. Where original skb's skb-&gt;dev can be different to neigh's neigh-&gt;dev. For instance in case of bridging dnated skb from one veth to another, the skb would be added to a neigh-&gt;arp_queue of the bridge. As skb-&gt;dev can be reset back to nf_bridge-&gt;physindev and used, and as there is no explicit mechanism that prevents this physindev from been freed under us (for instance neigh_flush_dev doesn't cleanup skbs from different device's neigh queue) we can crash on e.g. this stack: arp_process neigh_update skb = __skb_dequeue(&amp;neigh-&gt;arp_queue) neigh_resolve_output(..., skb) ... br_nf_dev_xmit br_nf_pre_routing_finish_bridge_slow skb-&gt;dev = nf_bridge-&gt;physindev br_handle_frame_finish Let's use plain ifindex instead of net_device link. To peek into the original net_device we will use dev_get_by_index_rcu(). Thus either we get device and are safe to use it or we don't get it and drop skb.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35839" target="_blank">CVE-2024-35839</a><br><a href="https://git.kernel.org/stable/c/544add1f1cfb78c3dfa3e6edcf4668f6be5e730c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7ae19ee81ca56b13c50a78de6c47d5b8fdc9d97b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9325e3188a9cf3f69fc6f32af59844bbc5b90547" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9874808878d9eed407e3977fd11fee49de1e1d86" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mptcp: use OPTION_MPTCP_MPJ_SYNACK in subflow_finish_connect() subflow_finish_connect() uses four fields (backup, join_id, thmac, none) that may contain garbage unless OPTION_MPTCP_MPJ_SYNACK has been set in mptcp_parse_option()</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35840" target="_blank">CVE-2024-35840</a><br><a href="https://git.kernel.org/stable/c/413b913507326972135d2977975dbff8b7f2c453" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/51e4cb032d49ce094605f27e45eabebc0408893c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/76e8de7273a22a00d27e9b8b7d4d043d6433416a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ad3e8f5c3d5c53841046ef7a947c04ad45a20721" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/be1d9d9d38da922bd4beeec5b6dd821ff5a1dfeb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: tls, fix WARNIING in __sk_msg_free A splice with MSG_SPLICE_PAGES will cause tls code to use the tls_sw_sendmsg_splice path in the TLS sendmsg code to move the user provided pages from the msg into the msg_pl. This will loop over the msg until msg_pl is full, checked by sk_msg_full(msg_pl). The user can also set the MORE flag to hint stack to delay sending until receiving more pages and ideally a full buffer. If the user adds more pages to the msg than can fit in the msg_pl scatterlist (MAX_MSG_FRAGS) we should ignore the MORE flag and send the buffer anyways. What actually happens though is we abort the msg to msg_pl scatterlist setup and then because we forget to set 'full record' indicating we can no longer consume data without a send we fallthrough to the 'continue' path which will check if msg_data_left(msg) has more bytes to send and then attempts to fit them in the already full msg_pl. Then next iteration of sender doing send will encounter a full msg_pl and throw the warning in the syzbot report. To fix simply check if we have a full_record in splice code path and if not send the msg regardless of MORE flag.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35841" target="_blank">CVE-2024-35841</a><br><a href="https://git.kernel.org/stable/c/02e368eb1444a4af649b73cbe2edd51780511d86" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/294e7ea85f34748f04e5f3f9dba6f6b911d31aa8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dc9dfc8dc629e42f2234e3327b75324ffc752bc9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: sof-common: Add NULL check for normal_link string It's not granted that all entries of struct sof_conn_stream declare a `normal_link` (a non-SOF, direct link) string, and this is the case for SoCs that support only SOF paths (hence do not support both direct and SOF usecases). For example, in the case of MT8188 there is no normal_link string in any of the sof_conn_stream entries and there will be more drivers doing that in the future. To avoid possible NULL pointer KPs, add a NULL check for `normal_link`.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35842" target="_blank">CVE-2024-35842</a><br><a href="https://git.kernel.org/stable/c/b1d3db6740d0997ffc6e5a0d96ef7cbd62b35fdd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cad471227a37c0c7c080bfc9ed01b53750e82afe" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cde6ca5872bf67744dffa875a7cb521ab007b7ef" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e3b3ec967a7d93b9010a5af9a2394c8b5c8f31ed" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Use device rbtree in iopf reporting path The existing I/O page fault handler currently locates the PCI device by calling pci_get_domain_bus_and_slot(). This function searches the list of all PCI devices until the desired device is found. To improve lookup efficiency, replace it with device_rbtree_find() to search the device within the probed device rbtree. The I/O page fault is initiated by the device, which does not have any synchronization mechanism with the software to ensure that the device stays in the probed device tree. Theoretically, a device could be released by the IOMMU subsystem after device_rbtree_find() and before iopf_get_dev_fault_param(), which would cause a use-after-free problem. Add a mutex to synchronize the I/O page fault reporting path and the IOMMU release device path. This lock doesn't introduce any performance overhead, as the conflict between I/O page fault reporting and device releasing is very rare.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35843" target="_blank">CVE-2024-35843</a><br><a href="https://git.kernel.org/stable/c/3d39238991e745c5df85785604f037f35d9d1b15" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/def054b01a867822254e1dda13d587f5c7a99e2a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix reserve_cblocks counting error when out of space When a file only needs one direct_node, performing the following operations will cause the file to be unrepairable: unisoc # ./f2fs_io compress test.apk unisoc #df -h | grep dm-48 /dev/block/dm-48 112G 112G 1.2M 100% /data unisoc # ./f2fs_io release_cblocks test.apk 924 unisoc # df -h | grep dm-48 /dev/block/dm-48 112G 112G 4.8M 100% /data unisoc # dd if=/dev/random of=file4 bs=1M count=3 3145728 bytes (3.0 M) copied, 0.025 s, 120 M/s unisoc # df -h | grep dm-48 /dev/block/dm-48 112G 112G 1.8M 100% /data unisoc # ./f2fs_io reserve_cblocks test.apk F2FS_IOC_RESERVE_COMPRESS_BLOCKS failed: No space left on device adb reboot unisoc # df -h | grep dm-48 /dev/block/dm-48 112G 112G 11M 100% /data unisoc # ./f2fs_io reserve_cblocks test.apk 0 This is because the file has only one direct_node. After returning to -ENOSPC, reserved_blocks += ret will not be executed. As a result, the reserved_blocks at this time is still 0, which is not the real number of reserved blocks. Therefore, fsck cannot be set to repair the file. After this patch, the fsck flag will be set to fix this problem. unisoc # df -h | grep dm-48 /dev/block/dm-48 112G 112G 1.8M 100% /data unisoc # ./f2fs_io reserve_cblocks test.apk F2FS_IOC_RESERVE_COMPRESS_BLOCKS failed: No space left on device adb reboot then fsck will be executed unisoc # df -h | grep dm-48 /dev/block/dm-48 112G 112G 11M 100% /data unisoc # ./f2fs_io reserve_cblocks test.apk 924</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35844" target="_blank">CVE-2024-35844</a><br><a href="https://git.kernel.org/stable/c/2f6d721e14b69d6e1251f69fa238b48e8374e25f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/569c198c9e2093fd29cc071856a4e548fda506bc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/889846dfc8ee2cf31148a44bfd2faeb2faadc685" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f0bf89e84c3afb79d7a3a9e4bc853ad6a3245c0a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fa3ac8b1a227d9b470b87972494293348b5839ee" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fc0aed88afbf6f606205129a7466eebdf528e3f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dbg-tlv: ensure NUL termination The iwl_fw_ini_debug_info_tlv is used as a string, so we must ensure the string is terminated correctly before using it.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35845" target="_blank">CVE-2024-35845</a><br><a href="https://git.kernel.org/stable/c/71d4186d470e9cda7cd1a0921b4afda737c6f641" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/783d413f332a3ebec916664b366c28f58147f82c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/96aa40761673da045a7774f874487cdb50c6a2f7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c855a1a5b7e3de57e6b1b29563113d5e3bfdb89a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ea1d166fae14e05d49ffb0ea9fcd4658f8d3dcea" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fabe2db7de32a881e437ee69db32e0de785a6209" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fec14d1cdd92f340b9ba2bd220abf96f9609f2a9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mm: zswap: fix shrinker NULL crash with cgroup_disable=memory Christian reports a NULL deref in zswap that he bisected down to the zswap shrinker. The issue also cropped up in the bug trackers of libguestfs [1] and the Red Hat bugzilla [2]. The problem is that when memcg is disabled with the boot time flag, the zswap shrinker might get called with sc-&gt;memcg == NULL. This is okay in many places, like the lruvec operations. But it crashes in memcg_page_state() - which is only used due to the non-node accounting of cgroup's the zswap memory to begin with. Nhat spotted that the memcg can be NULL in the memcg-disabled case, and I was then able to reproduce the crash locally as well. [1] https://github.com/libguestfs/libguestfs/issues/139 [2] https://bugzilla.redhat.com/show_bug.cgi?id=2275252</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35846" target="_blank">CVE-2024-35846</a><br><a href="https://git.kernel.org/stable/c/682886ec69d22363819a83ddddd5d66cb5c791e1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b0fdabc908a7f81d12382c87ca9e46a9c2e14042" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Prevent double free on error The error handling path in its_vpe_irq_domain_alloc() causes a double free when its_vpe_init() fails after successfully allocating at least one interrupt. This happens because its_vpe_irq_domain_free() frees the interrupts along with the area bitmap and the vprop_page and its_vpe_irq_domain_alloc() subsequently frees the area bitmap and the vprop_page again. Fix this by unconditionally invoking its_vpe_irq_domain_free() which handles all cases correctly and by removing the bitmap/vprop_page freeing from its_vpe_irq_domain_alloc(). [ tglx: Massaged change log ]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35847" target="_blank">CVE-2024-35847</a><br><a href="https://git.kernel.org/stable/c/03170e657f62c26834172742492a8cb8077ef792" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5b012f77abde89bf0be8a0547636184fea618137" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5dbdbe1133911ca7d8466bb86885adec32ad9438" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/aa44d21574751a7d6bca892eb8e0e9ac68372e52" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b72d2b1448b682844f995e660b77f2a1fabc1662" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c26591afd33adce296c022e3480dea4282b7ef91" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dd681710ab77c8beafe2e263064cb1bd0e2d6ca9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f5417ff561b8ac9a7e53c747b8627a7ab58378ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: eeprom: at24: fix memory corruption race condition If the eeprom is not accessible, an nvmem device will be registered, the read will fail, and the device will be torn down. If another driver accesses the nvmem device after the teardown, it will reference invalid memory. Move the failure point before registering the nvmem device.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35848" target="_blank">CVE-2024-35848</a><br><a href="https://git.kernel.org/stable/c/26d32bec4c6d255a03762f33c637bfa3718be15a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2af84c46b9b8f2d6c0f88d09ee5c849ae1734676" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6d8b56ec0c8f30d5657382f47344a32569f7a9bc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c43e5028f5a35331eb25017f5ff6cc21735005c6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c850f71fca09ea41800ed55905980063d17e01da" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f42c97027fb75776e2e9358d16bf4a99aeb04cf2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: btrfs: fix information leak in btrfs_ioctl_logical_to_ino() Syzbot reported the following information leak for in btrfs_ioctl_logical_to_ino(): BUG: KMSAN: kernel-infoleak in instrument_copy_to_user include/linux/instrumented.h:114 [inline] BUG: KMSAN: kernel-infoleak in _copy_to_user+0xbc/0x110 lib/usercopy.c:40 instrument_copy_to_user include/linux/instrumented.h:114 [inline] _copy_to_user+0xbc/0x110 lib/usercopy.c:40 copy_to_user include/linux/uaccess.h:191 [inline] btrfs_ioctl_logical_to_ino+0x440/0x750 fs/btrfs/ioctl.c:3499 btrfs_ioctl+0x714/0x1260 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:904 [inline] __se_sys_ioctl+0x261/0x450 fs/ioctl.c:890 __x64_sys_ioctl+0x96/0xe0 fs/ioctl.c:890 x64_sys_call+0x1883/0x3b50 arch/x86/include/generated/asm/syscalls_64.h:17 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f Uninit was created at: __kmalloc_large_node+0x231/0x370 mm/slub.c:3921 __do_kmalloc_node mm/slub.c:3954 [inline] __kmalloc_node+0xb07/0x1060 mm/slub.c:3973 kmalloc_node include/linux/slab.h:648 [inline] kvmalloc_node+0xc0/0x2d0 mm/util.c:634 kvmalloc include/linux/slab.h:766 [inline] init_data_container+0x49/0x1e0 fs/btrfs/backref.c:2779 btrfs_ioctl_logical_to_ino+0x17c/0x750 fs/btrfs/ioctl.c:3480 btrfs_ioctl+0x714/0x1260 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:904 [inline] __se_sys_ioctl+0x261/0x450 fs/ioctl.c:890 __x64_sys_ioctl+0x96/0xe0 fs/ioctl.c:890 x64_sys_call+0x1883/0x3b50 arch/x86/include/generated/asm/syscalls_64.h:17 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f Bytes 40-65535 of 65536 are uninitialized Memory access of size 65536 starts at ffff888045a40000 This happens, because we're copying a 'struct btrfs_data_container' back to user-space. This btrfs_data_container is allocated in 'init_data_container()' via kvmalloc(), which does not zero-fill the memory. Fix this by using kvzalloc() which zeroes out the memory on allocation.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35849" target="_blank">CVE-2024-35849</a><br><a href="https://git.kernel.org/stable/c/2f7ef5bb4a2f3e481ef05fab946edb97c84f67cf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/30189e54ba80e3209d34cfeea87b848f6ae025e6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3a63cee1a5e14a3e52c19142c61dd5fcb524f6dc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/689efe22e9b5b7d9d523119a9a5c3c17107a0772" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/73db209dcd4ae026021234d40cfcb2fb5b564b86" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8bdbcfaf3eac42f98e5486b3d7e130fa287811f6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e58047553a4e859dafc8d1d901e1de77c9dd922d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fddc19631c51d9c17d43e9f822a7bc403af88d54" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix NULL-deref on non-serdev setup Qualcomm ROME controllers can be registered from the Bluetooth line discipline and in this case the HCI UART serdev pointer is NULL. Add the missing sanity check to prevent a NULL-pointer dereference when setup() is called for a non-serdev controller.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35850" target="_blank">CVE-2024-35850</a><br><a href="https://git.kernel.org/stable/c/67459f1a707aae6d590454de07956c2752e21ea4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7ddb9de6af0f1c71147785b12fd7c8ec3f06cc86" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bec4d4c6fa5c6526409f582e4f31144e20c86c21" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix NULL-deref on non-serdev suspend Qualcomm ROME controllers can be registered from the Bluetooth line discipline and in this case the HCI UART serdev pointer is NULL. Add the missing sanity check to prevent a NULL-pointer dereference when wakeup() is called for a non-serdev controller during suspend. Just return true for now to restore the original behaviour and address the crash with pre-6.2 kernels, which do not have commit e9b3e5b8c657 ("Bluetooth: hci_qca: only assign wakeup with serial port support") that causes the crash to happen already at setup() time.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35851" target="_blank">CVE-2024-35851</a><br><a href="https://git.kernel.org/stable/c/52f9041deaca3fc5c40ef3b9cb943993ec7d2489" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6b47cdeb786c38e4174319218db3fa6d7b4bba88" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/73e87c0a49fda31d7b589edccf4c72e924411371" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b64092d2f108f0cd1d7fd7e176f5fb2a67a2f189" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e60502b907be350c518819297b565007a94c706d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix memory leak when canceling rehash work The rehash delayed work is rescheduled with a delay if the number of credits at end of the work is not negative as supposedly it means that the migration ended. Otherwise, it is rescheduled immediately. After "mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash" the above is no longer accurate as a non-negative number of credits is no longer indicative of the migration being done. It can also happen if the work encountered an error in which case the migration will resume the next time the work is scheduled. The significance of the above is that it is possible for the work to be pending and associated with hints that were allocated when the migration started. This leads to the hints being leaked [1] when the work is canceled while pending as part of ACL region dismantle. Fix by freeing the hints if hints are associated with a work that was canceled while pending. Blame the original commit since the reliance on not having a pending work associated with hints is fragile. [1] unreferenced object 0xffff88810e7c3000 (size 256): comm "kworker/0:16", pid 176, jiffies 4295460353 hex dump (first 32 bytes): 00 30 95 11 81 88 ff ff 61 00 00 00 00 00 00 80 .0......a....... 00 00 61 00 40 00 00 00 00 00 00 00 04 00 00 00 ..a.@........... backtrace (crc 2544ddb9): [&lt;00000000cf8cfab3&gt;] kmalloc_trace+0x23f/0x2a0 [&lt;000000004d9a1ad9&gt;] objagg_hints_get+0x42/0x390 [&lt;000000000b143cf3&gt;] mlxsw_sp_acl_erp_rehash_hints_get+0xca/0x400 [&lt;0000000059bdb60a&gt;] mlxsw_sp_acl_tcam_vregion_rehash_work+0x868/0x1160 [&lt;00000000e81fd734&gt;] process_one_work+0x59c/0xf20 [&lt;00000000ceee9e81&gt;] worker_thread+0x799/0x12c0 [&lt;00000000bda6fe39&gt;] kthread+0x246/0x300 [&lt;0000000070056d23&gt;] ret_from_fork+0x34/0x70 [&lt;00000000dea2b93e&gt;] ret_from_fork_asm+0x1a/0x30</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35852" target="_blank">CVE-2024-35852</a><br><a href="https://git.kernel.org/stable/c/51cefc9da400b953fee749c9e5d26cd4a2b5d758" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5bfe7bf9656ed2633718388f12b7c38b86414a04" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/63d814d93c5cce4c18284adc810028f28dca493f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/857ed800133ffcfcee28582090b63b0cbb8ba59d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d72dd6fcd7886d0523afbab8b4a4b22d17addd7d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/de1aaefa75be9d0ec19c9a3e0e2f9696de20c6ab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fb4e2b70a7194b209fc7320bbf33b375f7114bd5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix memory leak during rehash The rehash delayed work migrates filters from one region to another. This is done by iterating over all chunks (all the filters with the same priority) in the region and in each chunk iterating over all the filters. If the migration fails, the code tries to migrate the filters back to the old region. However, the rollback itself can also fail in which case another migration will be erroneously performed. Besides the fact that this ping pong is not a very good idea, it also creates a problem. Each virtual chunk references two chunks: The currently used one ('vchunk-&gt;chunk') and a backup ('vchunk-&gt;chunk2'). During migration the first holds the chunk we want to migrate filters to and the second holds the chunk we are migrating filters from. The code currently assumes - but does not verify - that the backup chunk does not exist (NULL) if the currently used chunk does not reference the target region. This assumption breaks when we are trying to rollback a rollback, resulting in the backup chunk being overwritten and leaked [1]. Fix by not rolling back a failed rollback and add a warning to avoid future cases. [1] WARNING: CPU: 5 PID: 1063 at lib/parman.c:291 parman_destroy+0x17/0x20 Modules linked in: CPU: 5 PID: 1063 Comm: kworker/5:11 Tainted: G W 6.9.0-rc2-custom-00784-gc6a05c468a0b #14 Hardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019 Workqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work RIP: 0010:parman_destroy+0x17/0x20 [...] Call Trace: &lt;TASK&gt; mlxsw_sp_acl_atcam_region_fini+0x19/0x60 mlxsw_sp_acl_tcam_region_destroy+0x49/0xf0 mlxsw_sp_acl_tcam_vregion_rehash_work+0x1f1/0x470 process_one_work+0x151/0x370 worker_thread+0x2cb/0x3e0 kthread+0xd0/0x100 ret_from_fork+0x34/0x50 ret_from_fork_asm+0x1a/0x30 &lt;/TASK&gt;</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35853" target="_blank">CVE-2024-35853</a><br><a href="https://git.kernel.org/stable/c/0ae8ff7b6d42e33943af462910bdcfa2ec0cb8cf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/413a01886c3958d4b8aac23a3bff3d430b92093e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/617e98ba4c50f4547c9eb0946b1cfc26937d70d1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8ca3f7a7b61393804c46f170743c3b839df13977" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b3fd51f684a0711504f82de510da109ae639722d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b822644fd90992ee362c5e0c8d2556efc8856c76" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c6f3fa7f5a748bf6e5c4eb742686d6952f854e76" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash The rehash delayed work migrates filters from one region to another according to the number of available credits. The migrated from region is destroyed at the end of the work if the number of credits is non-negative as the assumption is that this is indicative of migration being complete. This assumption is incorrect as a non-negative number of credits can also be the result of a failed migration. The destruction of a region that still has filters referencing it can result in a use-after-free [1]. Fix by not destroying the region if migration failed. [1] BUG: KASAN: slab-use-after-free in mlxsw_sp_acl_ctcam_region_entry_remove+0x21d/0x230 Read of size 8 at addr ffff8881735319e8 by task kworker/0:31/3858 CPU: 0 PID: 3858 Comm: kworker/0:31 Tainted: G W 6.9.0-rc2-custom-00782-gf2275c2157d8 #5 Hardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019 Workqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work Call Trace: &lt;TASK&gt; dump_stack_lvl+0xc6/0x120 print_report+0xce/0x670 kasan_report+0xd7/0x110 mlxsw_sp_acl_ctcam_region_entry_remove+0x21d/0x230 mlxsw_sp_acl_ctcam_entry_del+0x2e/0x70 mlxsw_sp_acl_atcam_entry_del+0x81/0x210 mlxsw_sp_acl_tcam_vchunk_migrate_all+0x3cd/0xb50 mlxsw_sp_acl_tcam_vregion_rehash_work+0x157/0x1300 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30 &lt;/TASK&gt; Allocated by task 174: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 __kasan_kmalloc+0x8f/0xa0 __kmalloc+0x19c/0x360 mlxsw_sp_acl_tcam_region_create+0xdf/0x9c0 mlxsw_sp_acl_tcam_vregion_rehash_work+0x954/0x1300 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30 Freed by task 7: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 kasan_save_free_info+0x3b/0x60 poison_slab_object+0x102/0x170 __kasan_slab_free+0x14/0x30 kfree+0xc1/0x290 mlxsw_sp_acl_tcam_region_destroy+0x272/0x310 mlxsw_sp_acl_tcam_vregion_rehash_work+0x731/0x1300 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35854" target="_blank">CVE-2024-35854</a><br><a href="https://git.kernel.org/stable/c/311eeaa7b9e26aba5b3d57b09859f07d8e9fc049" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4c89642ca47fb620914780c7c51d8d1248201121" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/54225988889931467a9b55fdbef534079b665519" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/813e2ab753a8f8c243a39ede20c2e0adc15f3887" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a02687044e124f8ccb427cd3632124a4e1a7d7c1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a429a912d6c779807f4d72a6cc0a1efaaa3613e1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e118e7ea24d1392878ef85926627c6bc640c4388" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix possible use-after-free during activity update The rule activity update delayed work periodically traverses the list of configured rules and queries their activity from the device. As part of this task it accesses the entry pointed by 'ventry-&gt;entry', but this entry can be changed concurrently by the rehash delayed work, leading to a use-after-free [1]. Fix by closing the race and perform the activity query under the 'vregion-&gt;lock' mutex. [1] BUG: KASAN: slab-use-after-free in mlxsw_sp_acl_tcam_flower_rule_activity_get+0x121/0x140 Read of size 8 at addr ffff8881054ed808 by task kworker/0:18/181 CPU: 0 PID: 181 Comm: kworker/0:18 Not tainted 6.9.0-rc2-custom-00781-gd5ab772d32f7 #2 Hardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019 Workqueue: mlxsw_core mlxsw_sp_acl_rule_activity_update_work Call Trace: &lt;TASK&gt; dump_stack_lvl+0xc6/0x120 print_report+0xce/0x670 kasan_report+0xd7/0x110 mlxsw_sp_acl_tcam_flower_rule_activity_get+0x121/0x140 mlxsw_sp_acl_rule_activity_update_work+0x219/0x400 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30 &lt;/TASK&gt; Allocated by task 1039: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 __kasan_kmalloc+0x8f/0xa0 __kmalloc+0x19c/0x360 mlxsw_sp_acl_tcam_entry_create+0x7b/0x1f0 mlxsw_sp_acl_tcam_vchunk_migrate_all+0x30d/0xb50 mlxsw_sp_acl_tcam_vregion_rehash_work+0x157/0x1300 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30 Freed by task 1039: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 kasan_save_free_info+0x3b/0x60 poison_slab_object+0x102/0x170 __kasan_slab_free+0x14/0x30 kfree+0xc1/0x290 mlxsw_sp_acl_tcam_vchunk_migrate_all+0x3d7/0xb50 mlxsw_sp_acl_tcam_vregion_rehash_work+0x157/0x1300 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35855" target="_blank">CVE-2024-35855</a><br><a href="https://git.kernel.org/stable/c/1b73f6e4ea770410a937a8db98f77e52594d23a0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/79b5b4b18bc85b19d3a518483f9abbbe6d7b3ba4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b183b915beef818a25e3154d719ca015a1ae0770" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b996e8699da810e4c915841d6aaef761007f933a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c17976b42d546ee118ca300db559630ee96fb758" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e24d2487424779c02760ff50cd9021b8676e19ef" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/feabdac2057e863d0e140a2adf3d232eb4882db4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: Fix double free of skb in coredump hci_devcd_append() would free the skb on error so the caller don't have to free it again otherwise it would cause the double free of skb. Reported-by : Dan Carpenter &lt;dan.carpenter@linaro.org&gt;</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35856" target="_blank">CVE-2024-35856</a><br><a href="https://git.kernel.org/stable/c/18bdb386a1a30e7a3d7732a98e45e69cf6b5710d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/80dfef128cb9f1b1ef67c0fe8c8deb4ea7ad30c1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e20093c741d8da9f6390dd45d75b779861547035" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: icmp: prevent possible NULL dereferences from icmp_build_probe() First problem is a double call to __in_dev_get_rcu(), because the second one could return NULL. if (__in_dev_get_rcu(dev) &amp;&amp; __in_dev_get_rcu(dev)-&gt;ifa_list) Second problem is a read from dev-&gt;ip6_ptr with no NULL check: if (!list_empty(&amp;rcu_dereference(dev-&gt;ip6_ptr)-&gt;addr_list)) Use the correct RCU API to fix these. v2: add missing include &lt;net/addrconf.h&gt;</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35857" target="_blank">CVE-2024-35857</a><br><a href="https://git.kernel.org/stable/c/23b7ee4a8d559bf38eac7ce5bb2f6ebf76f9c401" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3e2979bf080c40da4f7c93aff8575ab8bc62b767" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/599c9ad5e1d43f5c12d869f5fd406ba5d8c55270" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c58e88d49097bd12dfcfef4f075b43f5d5830941" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d68dc711d84fdcf698e5d45308c3ddeede586350" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix memory leak when bringing down interface When bringing down the TX rings we flush the rings but forget to reclaimed the flushed packets. This leads to a memory leak since we do not free the dma mapped buffers. This also leads to tx control block corruption when bringing down the interface for power management.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35858" target="_blank">CVE-2024-35858</a><br><a href="https://git.kernel.org/stable/c/09040baf8779ad880e0e0d0ea10e57aa929ef3ab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2389ad1990163d29cba5480d693b4c2e31cc545c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9f898fc2c31fbf0ac5ecd289f528a716464cb005" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: block: fix module reference leakage from bdev_open_by_dev error path At the time bdev_may_open() is called, module reference is grabbed already, hence module reference should be released if bdev_may_open() failed. This problem is found by code review.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35859" target="_blank">CVE-2024-35859</a><br><a href="https://git.kernel.org/stable/c/0e9327c67410b129bf85e5c3a5aaea518328636f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9617cd6f24b294552a817f80f5225431ef67b540" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4367" target="_blank">CVE-2024-4367</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1893645" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4764" target="_blank">CVE-2024-4764</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1879093" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4765" target="_blank">CVE-2024-4765</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1871109" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have lead to potential user confusion and spoofing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4766" target="_blank">CVE-2024-4766</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1871214" target="_blank">security@mozilla.org</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1871217" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4767" target="_blank">CVE-2024-4767</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1878577" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4768" target="_blank">CVE-2024-4768</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1886082" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4769" target="_blank">CVE-2024-4769</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1886108" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4770" target="_blank">CVE-2024-4770</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1893270" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4771" target="_blank">CVE-2024-4771</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1893891" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4772" target="_blank">CVE-2024-4772</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1870579" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfuscate a spoofed web site. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4773" target="_blank">CVE-2024-4773</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1875248" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4774" target="_blank">CVE-2024-4774</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1886598" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4775" target="_blank">CVE-2024-4775</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1887332" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4776" target="_blank">CVE-2024-4776</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1887343" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4777" target="_blank">CVE-2024-4777</a><br><a href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=1878199%2C1893340" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4778" target="_blank">CVE-2024-4778</a><br><a href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=1838834%2C1889291%2C1889595%2C1890204%2C1891545" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Focus for iOS<br> </td>
<td>The file scheme of URLs would be hidden, resulting in potential spoofing of a website's address in the location bar This vulnerability affects Focus for iOS &lt; 126.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5022" target="_blank">CVE-2024-5022</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1874560" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-24/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>NEC Platforms, Ltd--ITK-6DGS-1(BK) TEL<br> </td>
<td>NEC Platforms DT900 and DT900S Series 5.0.0.0 - v5.3.4.4, v5.4.0.0 - v5.6.0.20 allows an attacker to access a non-documented the system settings to change settings via local network with unauthenticated user.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3016" target="_blank">CVE-2024-3016</a><br><a href="https://jpn.nec.com/security-info/secinfo/nv24-002_en.html" target="_blank">psirt-info@cyber.jp.nec.com</a></td>
</tr>
<tr>
<td>Netflix--ConsoleMe<br> </td>
<td>Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Netflix ConsoleMe allows Command Injection.This issue affects ConsoleMe: before 1.4.0.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5023" target="_blank">CVE-2024-5023</a><br><a href="https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2024-002.md" target="_blank">security-report@netflix.com</a></td>
</tr>
<tr>
<td>OpenSSL--OpenSSL<br> </td>
<td>Issue summary: Checking excessively long DSA keys or parameters may be very slow. Impact summary: Applications that use the functions EVP_PKEY_param_check() or EVP_PKEY_public_check() to check a DSA public key or DSA parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service. The functions EVP_PKEY_param_check() or EVP_PKEY_public_check() perform various checks on DSA parameters. Some of those computations take a long time if the modulus (`p` parameter) is too large. Trying to use a very large modulus is slow and OpenSSL will not allow using public keys with a modulus which is over 10,000 bits in length for signature verification. However the key and parameter check functions do not limit the modulus size when performing the checks. An application that calls EVP_PKEY_param_check() or EVP_PKEY_public_check() and supplies a key or parameters obtained from an untrusted source could be vulnerable to a Denial of Service attack. These functions are not called by OpenSSL itself on untrusted DSA keys so only applications that directly call these functions may be vulnerable. Also vulnerable are the OpenSSL pkey and pkeyparam command line applications when using the `-check` option. The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are affected by this issue.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4603" target="_blank">CVE-2024-4603</a><br><a href="https://github.com/openssl/openssl/commit/3559e868e58005d15c6013a0c1fd832e51c73397" target="_blank">openssl-security@openssl.org</a><br><a href="https://github.com/openssl/openssl/commit/53ea06486d296b890d565fb971b2764fcd826e7e" target="_blank">openssl-security@openssl.org</a><br><a href="https://github.com/openssl/openssl/commit/9c39b3858091c152f52513c066ff2c5a47969f0d" target="_blank">openssl-security@openssl.org</a><br><a href="https://github.com/openssl/openssl/commit/da343d0605c826ef197aceedc67e8e04f065f740" target="_blank">openssl-security@openssl.org</a><br><a href="https://www.openssl.org/news/secadv/20240516.txt" target="_blank">openssl-security@openssl.org</a></td>
</tr>
<tr>
<td>Puneeth Reddy--Online Shopping System Advanced<br> </td>
<td>Open-source project Online Shopping System Advanced is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. </td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3579" target="_blank">CVE-2024-3579</a><br><a href="https://cert.pl/en/posts/2024/05/CVE-2024-3579" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/05/CVE-2024-3579" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Rockwell Automation--FactoryTalk Remote Access<br> </td>
<td>An unquoted executable path exists in the Rockwell Automation FactoryTalkÂ® Remote Accessâ„¢ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a System user. A threat actor needs admin privileges to exploit this vulnerability.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3640" target="_blank">CVE-2024-3640</a><br><a href="https://www.rockwellautomation.com/en-us/support/advisory.SD1671.html" target="_blank">PSIRT@rockwellautomation.com</a></td>
</tr>
<tr>
<td>Rockwell Automation--FactoryTalk View SE<br> </td>
<td>A vulnerability exists in the Rockwell Automation FactoryTalkÂ® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. If exploited, the attack could result in information exposure, revealing sensitive information. Additionally, a threat actor could potentially modify and delete the data in a remote database. An attack would only affect the HMI design time, not runtime.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4609" target="_blank">CVE-2024-4609</a><br><a href="https://www.rockwellautomation.com/en-us/support/advisory.SD1670.html" target="_blank">PSIRT@rockwellautomation.com</a></td>
</tr>
<tr>
<td>The Document Foundation--LibreOffice<br> </td>
<td>Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3044" target="_blank">CVE-2024-3044</a><br><a href="https://www.libreoffice.org/about-us/security/advisories/CVE-2024-3044" target="_blank">security@documentfoundation.org</a></td>
</tr>
<tr>
<td>Unknown--Add Custom CSS and JS<br> </td>
<td>The Add Custom CSS and JS WordPress plugin through 1.20 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in as author and above add Stored XSS payloads via a CSRF attack</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3903" target="_blank">CVE-2024-3903</a><br><a href="https://wpscan.com/vulnerability/0a0e7bd4-948d-47c9-9219-380bda9f3034/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Base64 Encoder/Decoder<br> </td>
<td>The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3822" target="_blank">CVE-2024-3822</a><br><a href="https://wpscan.com/vulnerability/ff5411b1-9e04-4e72-a502-e431d774642a/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Base64 Encoder/Decoder<br> </td>
<td>The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3823" target="_blank">CVE-2024-3823</a><br><a href="https://wpscan.com/vulnerability/a138215c-4b8c-4182-978f-d21ce25070d3/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Base64 Encoder/Decoder<br> </td>
<td>The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3824" target="_blank">CVE-2024-3824</a><br><a href="https://wpscan.com/vulnerability/749ae334-b1d1-421e-a04c-35464c961a4a/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--HL Twitter<br> </td>
<td>The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3629" target="_blank">CVE-2024-3629</a><br><a href="https://wpscan.com/vulnerability/c1f6ed2c-0f84-4b13-b39e-5cb91443c2b1/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--HL Twitter<br> </td>
<td>The HL Twitter WordPress plugin through 2014.1.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3630" target="_blank">CVE-2024-3630</a><br><a href="https://wpscan.com/vulnerability/cbab7639-fdb2-4ee5-b5ca-9e30701a63b7/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--HL Twitter<br> </td>
<td>The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check when unlinking twitter accounts, which could allow attackers to make logged in admins perform such actions via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3631" target="_blank">CVE-2024-3631</a><br><a href="https://wpscan.com/vulnerability/c59a8b49-6f3e-452b-ba9b-50b80c522ee9/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--LetterPress <br> </td>
<td>The LetterPress WordPress plugin through 1.2.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks, such as delete arbitrary subscribers</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3590" target="_blank">CVE-2024-3590</a><br><a href="https://wpscan.com/vulnerability/829f4d40-e5b0-4009-b753-85ca2a5b3d25/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Newsletter Popup<br> </td>
<td>The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3641" target="_blank">CVE-2024-3641</a><br><a href="https://wpscan.com/vulnerability/f4047f1e-d5ea-425f-8def-76dd5e6a497e/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Newsletter Popup<br> </td>
<td>The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow attackers to make logged in admins perform such action via a CSRF attack</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3642" target="_blank">CVE-2024-3642</a><br><a href="https://wpscan.com/vulnerability/dc44d85f-afe8-4824-95b0-11b9abfb04d8/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Newsletter Popup<br> </td>
<td>The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3643" target="_blank">CVE-2024-3643</a><br><a href="https://wpscan.com/vulnerability/698277e6-56f9-4688-9a84-c2fa3ea9f7dc/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Newsletter Popup<br> </td>
<td>The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3644" target="_blank">CVE-2024-3644</a><br><a href="https://wpscan.com/vulnerability/10eb712a-d9c3-46c9-be6a-02811396fae8/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--NextGEN Gallery <br> </td>
<td>The NextGEN Gallery WordPress plugin before 3.59.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2744" target="_blank">CVE-2024-2744</a><br><a href="https://wpscan.com/vulnerability/a5579c15-50ba-4618-95e4-04b2033d721f/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Popup4Phone<br> </td>
<td>The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3231" target="_blank">CVE-2024-3231</a><br><a href="https://wpscan.com/vulnerability/81dbb5c0-ccdd-4af1-b2f2-71cb1b37fe93/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Popup4Phone<br> </td>
<td>The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3580" target="_blank">CVE-2024-3580</a><br><a href="https://wpscan.com/vulnerability/31f401c4-735a-4efb-b81f-ab98c00c526b/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Post Grid Gutenberg Blocks and WordPress Blog Plugin <br> </td>
<td>The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.0.2 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3239" target="_blank">CVE-2024-3239</a><br><a href="https://wpscan.com/vulnerability/dfa1421b-41b0-4b25-95ef-0843103e1f5e/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--SP Project &amp; Document Manager<br> </td>
<td>The SP Project &amp; Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3748" target="_blank">CVE-2024-3748</a><br><a href="https://wpscan.com/vulnerability/01427cfb-5c51-4524-9b9d-e09a603bc34c/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--SP Project &amp; Document Manager<br> </td>
<td>The SP Project &amp; Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3749" target="_blank">CVE-2024-3749</a><br><a href="https://wpscan.com/vulnerability/d14bb16e-ce1d-4c31-8791-bc63174897c0/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Save as PDF Plugin by Pdfcrowd<br> </td>
<td>The Save as PDF Plugin by Pdfcrowd WordPress plugin before 3.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5971" target="_blank">CVE-2023-5971</a><br><a href="https://wpscan.com/vulnerability/03a201d2-535e-4574-afac-791dcf23e6e1/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Ultimate Blocks <br> </td>
<td>The Ultimate Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3241" target="_blank">CVE-2024-3241</a><br><a href="https://wpscan.com/vulnerability/a645daee-42ea-43f8-9480-ef3be69606e0/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--UnGallery<br> </td>
<td>The UnGallery WordPress plugin through 2.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3582" target="_blank">CVE-2024-3582</a><br><a href="https://wpscan.com/vulnerability/5a348b5d-13aa-40c3-9d21-0554683f8019/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--VikBooking Hotel Booking Engine &amp; PMS<br> </td>
<td>The VikBooking Hotel Booking Engine &amp; PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine &amp; PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2441" target="_blank">CVE-2024-2441</a><br><a href="https://wpscan.com/vulnerability/9647e273-5724-4a02-868d-9b79f4bb2b79/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--VikBooking Hotel Booking Engine &amp; PMS<br> </td>
<td>The VikBooking Hotel Booking Engine &amp; PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users that can access a menu to manipulate requests and perform unauthorized actions such as editing, renaming or deleting (categories for example) despite initial settings prohibiting such access. This vulnerability resembles broken access control, enabling unauthorized users to modify critical VikBooking Hotel Booking Engine &amp; PMS WordPress plugin before 1.6.8 configurations.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2749" target="_blank">CVE-2024-2749</a><br><a href="https://wpscan.com/vulnerability/c0640d3a-80b3-4cad-a3cf-fb5d86558e91/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--WP Prayer<br> </td>
<td>The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3405" target="_blank">CVE-2024-3405</a><br><a href="https://wpscan.com/vulnerability/6968d43c-16ff-43a9-8451-71aabbe69014/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--WP Prayer<br> </td>
<td>The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3406" target="_blank">CVE-2024-3406</a><br><a href="https://wpscan.com/vulnerability/1bfab060-64d2-4c38-8bc8-a8f81c5a6e0d/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--WP Prayer<br> </td>
<td>The WP Prayer WordPress plugin through 2.0.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3407" target="_blank">CVE-2024-3407</a><br><a href="https://wpscan.com/vulnerability/262348ab-a335-4acf-8e4d-229fc0b4972f/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--WP Shortcodes Plugin Shortcodes Ultimate<br> </td>
<td>The WP Shortcodes Plugin - Shortcodes Ultimate WordPress plugin before 7.1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3548" target="_blank">CVE-2024-3548</a><br><a href="https://wpscan.com/vulnerability/9eef8b29-2c62-4daa-ae90-467ff9be18d8/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--month name translation benaceur<br> </td>
<td>The month name translation benaceur WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3634" target="_blank">CVE-2024-3634</a><br><a href="https://wpscan.com/vulnerability/76e000e0-314f-4e39-8871-68bf8cc95b22/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--reCAPTCHA Jetpack<br> </td>
<td>The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3940" target="_blank">CVE-2024-3940</a><br><a href="https://wpscan.com/vulnerability/bb0245e5-8e94-4f11-9003-d6208945056c/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--reCAPTCHA Jetpack<br> </td>
<td>The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3941" target="_blank">CVE-2024-3941</a><br><a href="https://wpscan.com/vulnerability/6e09e922-983c-4406-8053-747d839995d1/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--socialdriver-framework<br> </td>
<td>The socialdriver-framework WordPress plugin before 2024.0.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2697" target="_blank">CVE-2024-2697</a><br><a href="https://wpscan.com/vulnerability/c430b30d-61db-45f5-8499-91b491503b9c/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Veeam--Service Provider Console<br> </td>
<td>Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29212" target="_blank">CVE-2024-29212</a><br><a href="https://www.veeam.com/kb4575" target="_blank">support@hackerone.com</a></td>
</tr>
<tr>
<td>Xen--Xen<br> </td>
<td>Unlike 32-bit PV guests, HVM guests may switch freely between 64-bit and other modes. This in particular means that they may set registers used to pass 32-bit-mode hypercall arguments to values outside of the range 32-bit code would be able to set them to. When processing of hypercalls takes a considerable amount of time, the hypervisor may choose to invoke a hypercall continuation. Doing so involves putting (perhaps updated) hypercall arguments in respective registers. For guests not running in 64-bit mode this further involves a certain amount of translation of the values. Unfortunately internal sanity checking of these translated values assumes high halves of registers to always be clear when invoking a hypercall. When this is found not to be the case, it triggers a consistency check in the hypervisor and causes a crash.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46842" target="_blank">CVE-2023-46842</a><br><a href="https://xenbits.xenproject.org/xsa/advisory-454.html" target="_blank">security@xen.org</a></td>
</tr>
<tr>
<td>Xen--Xen<br> </td>
<td>Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equally impacted. For more details, see: https://xenbits.xen.org/xsa/advisory-407.html https://xenbits.xen.org/xsa/advisory-434.html</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31142" target="_blank">CVE-2024-31142</a><br><a href="https://xenbits.xenproject.org/xsa/advisory-455.html" target="_blank">security@xen.org</a></td>
</tr>
<tr>
<td>Xpdf--Xpdf<br> </td>
<td>Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4976" target="_blank">CVE-2024-4976</a><br><a href="https://www.xpdfreader.com/security-bug/CVE-2024-4976.html" target="_blank">xpdf@xpdfreader.com</a></td>
</tr>
<tr>
<td>alpitronic--Hypercharger EV Charger<br> </td>
<td>If misconfigured, alpitronic Hypercharger EV charging devices can expose a web interface protected by authentication. If the default credentials are not changed, an attacker can use public knowledge to access the device as an administrator.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4622" target="_blank">CVE-2024-4622</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-130-02" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>berriai--berriai/litellm<br> </td>
<td>A remote code execution (RCE) vulnerability exists in the berriai/litellm project due to improper control of the generation of code when using the `eval` function unsafely in the `litellm.get_secret()` method. Specifically, when the server utilizes Google KMS, untrusted data is passed to the `eval` function without any sanitization. Attackers can exploit this vulnerability by injecting malicious values into environment variables through the `/config/update` endpoint, which allows for the update of settings in `proxy_server_config.yaml`.</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4264" target="_blank">CVE-2024-4264</a><br><a href="https://huntr.com/bounties/a3221b0c-6e25-4295-ab0f-042997e8fc61" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>gaizhenbiao--gaizhenbiao/chuanhuchatgpt<br> </td>
<td>A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the functionality for uploading chat history. The vulnerability arises due to improper input validation when handling file paths during the chat history upload process. An attacker can exploit this vulnerability by intercepting requests and manipulating the 'name' parameter to specify arbitrary file paths. This allows the attacker to read sensitive files on the server, leading to information leakage, including API keys and private information. The issue affects version 20240310 of the application.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4321" target="_blank">CVE-2024-4321</a><br><a href="https://huntr.com/bounties/19a16f8e-3d92-498f-abc9-8686005f067e" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>imartinez--imartinez/privategpt<br> </td>
<td>imartinez/privategpt version 0.2.0 is vulnerable to a local file inclusion vulnerability that allows attackers to read arbitrary files from the filesystem. By manipulating file upload functionality to ingest arbitrary local files, attackers can exploit the 'Search in Docs' feature or query the AI to retrieve or disclose the contents of any file on the system. This vulnerability could lead to various impacts, including but not limited to remote code execution by obtaining private SSH keys, unauthorized access to private files, source code disclosure facilitating further attacks, and exposure of configuration files.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3403" target="_blank">CVE-2024-3403</a><br><a href="https://huntr.com/bounties/7431d1dd-f014-4d4f-acb6-f97369ef3688" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>imartinez--imartinez/privategpt<br> </td>
<td>A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper validation of file uploads. Attackers can exploit this vulnerability by uploading malicious HTML files, such as those containing JavaScript payloads, which are then executed in the context of the victim's session when accessed. This could lead to the execution of arbitrary JavaScript code in the context of the user's browser session, potentially resulting in phishing attacks or other malicious actions. The vulnerability affects the latest version of the repository.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3851" target="_blank">CVE-2024-3851</a><br><a href="https://huntr.com/bounties/cae1a492-4e09-4d56-8e11-17703bdfe653" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>mlflow--mlflow/mlflow<br> </td>
<td>A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnerability arises from the application's handling of artifact URLs, where a '#' character can be used to insert a path into the fragment, effectively skipping validation. This allows an attacker to construct a URL that, when processed, ignores the protocol scheme and uses the provided path for filesystem access. As a result, an attacker can read arbitrary files, including sensitive information such as SSH and cloud keys, by exploiting the way the application converts the URL into a filesystem path. The issue stems from insufficient validation of the fragment portion of the URL, leading to arbitrary file read through path traversal.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3848" target="_blank">CVE-2024-3848</a><br><a href="https://github.com/mlflow/mlflow/commit/f8d51e21523238280ebcfdb378612afd7844eca8" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/8d5aadaa-522f-4839-b41b-d7da362dd610" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>mlflow--mlflow/mlflow<br> </td>
<td>A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with only EDIT permissions on an experiment can delete any artifacts. This issue arises due to the lack of proper validation for DELETE requests by users with EDIT permissions, allowing them to perform unauthorized deletions of artifacts. The vulnerability specifically affects the handling of artifact deletions within the application, as demonstrated by the ability of a low privilege user to delete a directory inside an artifact using a DELETE request, despite the official documentation stating that users with EDIT permission can only read and update artifacts, not delete them.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4263" target="_blank">CVE-2024-4263</a><br><a href="https://github.com/mlflow/mlflow/commit/b43e0e3de5b500554e13dc032ba2083b2d6c94b8" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/bfa116d3-2af8-4c4a-ac34-ccde7491ae11" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing attackers to access sensitive information or escalate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2020-18305" target="_blank">CVE-2020-18305</a><br><a href="https://gist.github.com/yasinyilmaz/1fe3fe58dd275edb77dcbe890fce2f2c" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers to access and manipulate the database through crafted requests. By exploiting this flaw, attackers can bypass authentication mechanisms, view sensitive information stored in the database, and potentially exfiltrate data.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-28132" target="_blank">CVE-2022-28132</a><br><a href="https://www.exploit-db.com/exploits/50939" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. There is a buffer overflow over the encrypted token parsing logic in the HTTP service that allows remote code execution. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32502" target="_blank">CVE-2022-32502</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may be able to connect to the device and bypass both hardware and software security protections. This affects Nuki Keypad before 1.9.2 and Nuki Fob before 1.8.1.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32503" target="_blank">CVE-2022-32503</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. The code used to parse the JSON objects received from the WebSocket service provided by the device leads to a stack buffer overflow. An attacker would be able to exploit this to gain arbitrary code execution on a KeyTurner device. This affects Nuki Smart Lock 3.0 before 3.3.5 and 2.0 before 2.12.4, as well as Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32504" target="_blank">CVE-2022-32504</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. It is possible to send multiple BLE malformed packets to block some of the functionality and reboot the device. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32505" target="_blank">CVE-2022-32505</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to the circuit board could use the SWD debug features to control the execution of code on the processor and debug the firmware, as well as read or alter the content of the internal and external flash memory. This affects Nuki Smart Lock 3.0 before 3.3.5, Nuki Smart Lock 2.0 before 2.12.4, as well as Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32506" target="_blank">CVE-2022-32506</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged accounts, could also be called from unprivileged accounts. This demonstrates that no access controls were implemented for the different BLE commands across the different accounts. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32507" target="_blank">CVE-2022-32507</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. By sending a malformed HTTP verb, it is possible to force a reboot of the device. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32508" target="_blank">CVE-2022-32508</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. Lack of certificate validation on HTTP communications allows attackers to intercept and tamper data. This affects Nuki Smart Lock 3.0 before 3.3.5, Nuki Bridge v1 before 1.22.0 and Nuki Bridge v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32509" target="_blank">CVE-2022-32509</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be easily eavesdropped by a malicious actor to impersonate a legitimate user and gain access to the full set of API endpoints. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32510" target="_blank">CVE-2022-32510</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-24203" target="_blank">CVE-2023-24203</a><br><a href="https://github.com/momo1239/CVE-2023-24203-and-CVE-2023-24204" target="_blank">cve@mitre.org</a><br><a href="https://momonguyen.com/2023/cve-2023-24203/" target="_blank">cve@mitre.org</a><br><a href="https://www.sourcecodester.com/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-24204" target="_blank">CVE-2023-24204</a><br><a href="https://github.com/momo1239/CVE-2023-24203-and-CVE-2023-24204" target="_blank">cve@mitre.org</a><br><a href="https://momonguyen.com/2023/cve-2023-24203/" target="_blank">cve@mitre.org</a><br><a href="https://www.sourcecodester.com/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which allows remote attackers to reconfigure Asterisk and make external and internal calls via HTTP and WebSocket requests sent to the API.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-26566" target="_blank">CVE-2023-26566</a><br><a href="https://qsecure.com.cy/resources/advisories/sangoma-freepbx-linux-hardcoded-credentials" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>phpok 6.4.003 is vulnerable to SQL injection in the function index_f() in phpok64/framework/api/call_control.php.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-29881" target="_blank">CVE-2023-29881</a><br><a href="https://gist.github.com/Northind/97522a49ae4bb0c8e6e2a49e75fd637a" target="_blank">cve@mitre.org</a><br><a href="https://github.com/qinggan/phpok/issues/15" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Stakater Forecastle 1.0.139 and before allows %5C../ directory traversal in the website component.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40297" target="_blank">CVE-2023-40297</a><br><a href="https://github.com/sahar042/CVE-2023-40297" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0, 3.1.0, 4.0.0, 4.1.0, and 4.1.1 have set incorrect file permission, which allows attackers to do code execution via modified bash and python scripts.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46870" target="_blank">CVE-2023-46870</a><br><a href="https://github.com/Chapoly1305/CVE-2023-46870" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Shrubbery tac_plus 2.x, 3.x. and 4.x through F4.0.4.28 allows unauthenticated Remote Command Execution. The product allows users to configure authorization checks as shell commands through the tac_plus.cfg configuration file. These are executed when a client sends an authorization request with a username that has pre-authorization directives configured. However, it is possible to inject additional commands into these checks because strings from TACACS+ packets are used as command-line arguments. If the installation lacks a a pre-shared secret (there is no pre-shared secret by default), then the injection can be triggered without authentication. (The attacker needs to know a username configured to use a pre-authorization command.) NOTE: this is related to CVE-2023-45239 but the issue is in the original Shrubbery product, not Meta's fork.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-48643" target="_blank">CVE-2023-48643</a><br><a href="https://github.com/takeshixx/tac_plus-pre-auth-rce" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an "SSID Confusion" issue. This occurs because the SSID is not always used to derive the pairwise master key or session keys, and because there is not a protected exchange of an SSID during a 4-way handshake.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52424" target="_blank">CVE-2023-52424</a><br><a href="https://mentor.ieee.org/802.11/dcn/24/11-24-0938-03-000m-protect-ssid-in-4-way-handshake.docx" target="_blank">cve@mitre.org</a><br><a href="https://www.top10vpn.com/assets/2024/05/Top10VPN-x-Vanhoef-SSID-Confusion.pdf" target="_blank">cve@mitre.org</a><br><a href="https://www.top10vpn.com/research/wifi-vulnerability-ssid/" target="_blank">cve@mitre.org</a><br><a href="https://www.wi-fi.org/news-events/press-releases" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in Panoramic Corporation Digital Imaging Software v.9.1.2.7600 allows a local attacker to escalate privileges via the ccsservice.exe component.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22774" target="_blank">CVE-2024-22774</a><br><a href="https://blueteamalpha.com/blog/new-vulnerability-discovered-in-panoramic-x-ray-software/" target="_blank">cve@mitre.org</a><br><a href="https://github.com/Gray-0men/CVE-2024-22774" target="_blank">cve@mitre.org</a><br><a href="https://pancorp.com/index.html" target="_blank">cve@mitre.org</a><br><a href="https://pancorp.com/pdf/Panoramic-Dental-Imaging-%28GLAN%29-Windows-10x64-Setup-Rev3.pdf" target="_blank">cve@mitre.org</a><br><a href="https://pancorp.com/software/files/PANCORP_DENTAL_IMAGING_9.1.2.7600.exe" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payload.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22910" target="_blank">CVE-2024-22910</a><br><a href="https://gist.github.com/cgnl/672ace3cbad1116fcd9ae633e54ea9f8" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24157" target="_blank">CVE-2024-24157</a><br><a href="https://github.com/gnuboard/g6/issues/314" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.29.07, kernel 5.3: IB19130163 in 05.38.07, kernel 5.4: IB19130163 in 05.46.07, kernel 5.5: IB19130163 in 05.54.07, and kernel 5.6: IB19130163 in 05.61.07 could lead to escalating privileges in SMM.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25078" target="_blank">CVE-2024-25078</a><br><a href="https://www.insyde.com/security-pledge" target="_blank">cve@mitre.org</a><br><a href="https://www.insyde.com/security-pledge/SA-2024001" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A memory corruption vulnerability in HddPassword in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38.09, kernel 5.4 before 05.46.09, kernel 5.5 before 05.54.09, and kernel 5.6 before 05.61.09 could lead to escalating privileges in SMM.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25079" target="_blank">CVE-2024-25079</a><br><a href="https://www.insyde.com/security-pledge" target="_blank">cve@mitre.org</a><br><a href="https://www.insyde.com/security-pledge/SA-2024001" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Oxygen XML Web Author v26.0.0 and older and Oxygen Content Fusion v6.1 and older are vulnerable to Cross-Site Scripting (XSS) for malicious URLs.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25662" target="_blank">CVE-2024-25662</a><br><a href="https://www.oxygenxml.com/security/advisory/SYNC-2024-020601.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In the Linux kernel before 6.9, an untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and can trigger its handler. This affects AMD SEV-SNP and AMD SEV-ES.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25742" target="_blank">CVE-2024-25742</a><br><a href="https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.9" target="_blank">cve@mitre.org</a><br><a href="https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e3ef461af35a8c74f2f4ce6616491ddb355a208f" target="_blank">cve@mitre.org</a><br><a href="https://github.com/torvalds/linux/commit/e3ef461af35a8c74f2f4ce6616491ddb355a208f" target="_blank">cve@mitre.org</a><br><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3008.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signal handler in userspace applications. This affects AMD SEV-SNP and AMD SEV-ES.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25743" target="_blank">CVE-2024-25743</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2270836" target="_blank">cve@mitre.org</a><br><a href="https://bugzilla.suse.com/show_bug.cgi?id=1223307" target="_blank">cve@mitre.org</a><br><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3008.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-26306" target="_blank">CVE-2024-26306</a><br><a href="https://downloads.es.net/pub/iperf/esnet-secadv-2024-0001.txt.asc" target="_blank">cve@mitre.org</a><br><a href="https://github.com/esnet/iperf/releases/tag/3.17" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting vulnerability in Evertz microsystems MViP-II Firmware 8.6.5, XPS-EDGE-* Build 1467, evEDGE-EO-* Build 0029, MMA10G-* Build 0498, 570IPG-X19-10G Build 0691 allows a remote attacker to execute arbitrary code via a crafted payload to the login parameters.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-26367" target="_blank">CVE-2024-26367</a><br><a href="http://cc.com/" target="_blank">cve@mitre.org</a><br><a href="http://evertz.com/" target="_blank">cve@mitre.org</a><br><a href="https://wiki.notveg.ninja/blog/CVE-2024-26367/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the delete-task.php component.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-26517" target="_blank">CVE-2024-26517</a><br><a href="https://github.com/unrealjbr/CVE-2024-26517" target="_blank">cve@mitre.org</a><br><a href="https://www.sourcecodester.com/php/16877/school-task-manager-using-php-source-code.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. 3.0.3 is the main fixed version; however, for Ruby 3.0 users, a fixed version is stringio 3.0.1.1, and for Ruby 3.1 users, a fixed version is stringio 3.0.1.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27280" target="_blank">CVE-2024-27280</a><br><a href="https://hackerone.com/reports/1399856" target="_blank">cve@mitre.org</a><br><a href="https://www.ruby-lang.org/en/news/2024/03/21/buffer-overread-cve-2024-27280/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27281" target="_blank">CVE-2024-27281</a><br><a href="https://hackerone.com/reports/1187477" target="_blank">cve@mitre.org</a><br><a href="https://www.ruby-lang.org/en/news/2024/03/21/rce-rdoc-cve-2024-27281/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27282" target="_blank">CVE-2024-27282</a><br><a href="https://hackerone.com/reports/2122624" target="_blank">cve@mitre.org</a><br><a href="https://www.ruby-lang.org/en/news/2024/04/23/arbitrary-memory-address-read-regexp-cve-2024-27282/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A memory corruption vulnerability in SdHost and SdMmcDevice in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38.09, kernel 5.4 before 05.46.09, kernel 5.5 before 05.54.09, and kernel 5.6 before 05.61.09 could lead to escalating privileges in SMM.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27353" target="_blank">CVE-2024-27353</a><br><a href="https://www.insyde.com/security-pledge" target="_blank">cve@mitre.org</a><br><a href="https://www.insyde.com/security-pledge/SA-2024001" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the filter name field. This vulnerability has been fixed in version 3.23.0.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27593" target="_blank">CVE-2024-27593</a><br><a href="https://blog.smarttecs.com/posts/2024-002-cve-2024-27593/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28063" target="_blank">CVE-2024-28063</a><br><a href="https://www.objectif-securite.ch/advisories/totemomail-reflected-xss.txt" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Kiteworks Totemomail 7.x and 8.x before 8.3.0 allows /responsiveUI/EnvelopeOpenServlet messageId directory traversal for unauthenticated file read and delete operations (with displayLoginChunkedImages) and write operations (with storeLoginChunkedImages).</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28064" target="_blank">CVE-2024-28064</a><br><a href="https://www.objectif-securite.ch/advisories/totemomail-path-traversal.txt" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions existed only in Subscription edition and have now been restored in Community edition, where they are not custmizable.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28087" target="_blank">CVE-2024-28087</a><br><a href="https://documentation.bonitasoft.com/bonita/latest/release-notes#_fixes_in_bonita_2024_1_2024_04_11" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scripting (XSS) via add-task.php?task_name=.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28276" target="_blank">CVE-2024-28276</a><br><a href="https://github.com/unrealjbr/CVE-2024-28276" target="_blank">cve@mitre.org</a><br><a href="https://www.sourcecodester.com/download-code?nid=16877&amp;title=School+Task+Manager+Using+PHP+with+Source+Code" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In Sourcecodester School Task Manager v1.0, a vulnerability was identified within the subject_name= parameter, enabling Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows attackers to manipulate the subject's name, potentially leading to the execution of malicious JavaScript payloads.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28277" target="_blank">CVE-2024-28277</a><br><a href="https://github.com/unrealjbr/CVE-2024-28277" target="_blank">cve@mitre.org</a><br><a href="https://www.sourcecodester.com/download-code?nid=16877&amp;title=School+Task+Manager+Using+PHP+with+Source+Code" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28279" target="_blank">CVE-2024-28279</a><br><a href="https://code-projects.org/computer-book-store-in-php-with-source-code/" target="_blank">cve@mitre.org</a><br><a href="https://github.com/unrealjbr/CVE-2024-28279" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose information and escalate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28285" target="_blank">CVE-2024-28285</a><br><a href="https://gist.github.com/liang-junkai/3e91f58070812ea76c1b8c126c3e28c7" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29157" target="_blank">CVE-2024-29157</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29158" target="_blank">CVE-2024-29158</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29159" target="_blank">CVE-2024-29159</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29160" target="_blank">CVE-2024-29160</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29161" target="_blank">CVE-2024-29161</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read, resulting in denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29162" target="_blank">CVE-2024-29162</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29163" target="_blank">CVE-2024-29163</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29164" target="_blank">CVE-2024-29164</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29165" target="_blank">CVE-2024-29165</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29166" target="_blank">CVE-2024-29166</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in briscKernelDriver.sys in BlueRiSC WindowsSCOPE Cyber Forensics before 3.3 allows a local attacker to execute arbitrary code within the driver and create a local denial-of-service condition due to an improper DACL being applied to the device the driver creates.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29513" target="_blank">CVE-2024-29513</a><br><a href="https://github.com/dru1d-foofus/briscKernelDriver" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29857" target="_blank">CVE-2024-29857</a><br><a href="https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9029857" target="_blank">cve@mitre.org</a><br><a href="https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9029857" target="_blank">cve@mitre.org</a><br><a href="https://www.bouncycastle.org/latest_releases.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30171" target="_blank">CVE-2024-30171</a><br><a href="https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9030171" target="_blank">cve@mitre.org</a><br><a href="https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9030171" target="_blank">cve@mitre.org</a><br><a href="https://www.bouncycastle.org/latest_releases.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30172" target="_blank">CVE-2024-30172</a><br><a href="https://www.bouncycastle.org/latest_releases.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SQL Injection vulnerability in Cloud based customer service management platform v.1.0.0 allows a local attacker to execute arbitrary code via a crafted payload to Login.asp component.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30801" target="_blank">CVE-2024-30801</a><br><a href="http://cloud.com/" target="_blank">cve@mitre.org</a><br><a href="http://www.minipacs.com/ylqxrj" target="_blank">cve@mitre.org</a><br><a href="https://github.com/WarmBrew/web_vul/blob/main/Cloud%20based%20customer%20service/SQLi.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in Vehicle Management System 7.31.0.3_20230412 allows an attacker to escalate privileges via the login.html component.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30802" target="_blank">CVE-2024-30802</a><br><a href="https://github.com/WarmBrew/web_vul/blob/main/TTX.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in Reportico Web before v.8.1.0 allows a local attacker to execute arbitrary code and obtain sensitive information via the sessionid function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31556" target="_blank">CVE-2024-31556</a><br><a href="https://github.com/reportico-web/reportico/issues/53" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Insecure Permission vulnerability in TotalAV v.6.0.740 allows a local attacker to escalate privileges via a crafted file</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31771" target="_blank">CVE-2024-31771</a><br><a href="https://github.com/restdone/CVE-2024-31771" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Buffer Overflow vulnerability in emp-ot v.0.2.4 allows a remote attacker to execute arbitrary code via the FerretCOT&lt;T&gt;::read_pre_data128_from_file function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31803" target="_blank">CVE-2024-31803</a><br><a href="https://github.com/FudanMPL/Vulnerabilities-in-MPC-Framework/tree/main/emp-ot/stack-buffer-overflow-ferret_cot" target="_blank">cve@mitre.org</a><br><a href="https://github.com/emp-toolkit/emp-ot/issues/89" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31810" target="_blank">CVE-2024-31810</a><br><a href="https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/HardCode/HardCode.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>The com.solarized.firedown (aka Solarized FireDown Browser &amp; Downloader) application 1.0.76 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. com.solarized.firedown.IntentActivity uses a WebView component to display web content and doesn't adequately sanitize the URI or any extra data passed in the intent by any installed application (with no permissions).</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31974" target="_blank">CVE-2024-31974</a><br><a href="https://github.com/actuator/com.solarized.firedown/blob/main/CVE-2024-31974" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32349" target="_blank">CVE-2024-32349</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecPsk" parameter in the "cstecgi.cgi" binary.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32350" target="_blank">CVE-2024-32350</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mru" parameter in the "cstecgi.cgi" binary.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32351" target="_blank">CVE-2024-32351</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecL2tpEnable" parameter in the "cstecgi.cgi" binary.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32352" target="_blank">CVE-2024-32352</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32353" target="_blank">CVE-2024-32353</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32354" target="_blank">CVE-2024-32354</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32355" target="_blank">CVE-2024-32355</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32605" target="_blank">CVE-2024-32605</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32606" target="_blank">CVE-2024-32606</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a SEGV in H5A__close in H5Aint.c, resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32607" target="_blank">CVE-2024-32607</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32609" target="_blank">CVE-2024-32609</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32610" target="_blank">CVE-2024-32610</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32611" target="_blank">CVE-2024-32611</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLcache.c, resulting in the corruption of the instruction pointer, a different vulnerability than CVE-2024-32613.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32612" target="_blank">CVE-2024-32612</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c, a different vulnerability than CVE-2024-32612.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32613" target="_blank">CVE-2024-32613</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32614" target="_blank">CVE-2024-32614</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused by the earlier use of an initialized pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32615" target="_blank">CVE-2024-32615</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32616" target="_blank">CVE-2024-32616</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32617" target="_blank">CVE-2024-32617</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c, resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32618" target="_blank">CVE-2024-32618</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32619" target="_blank">CVE-2024-32619</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32620" target="_blank">CVE-2024-32620</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32621" target="_blank">CVE-2024-32621</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_extent_simple in H5S.c).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32622" target="_blank">CVE-2024-32622</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5VM_array_fill in H5VM.c (called from H5S_select_elements in H5Spoint.c).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32623" target="_blank">CVE-2024-32623</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__ref_mem_setnull in H5Tref.c (called from H5T__conv_ref in H5Tconv.c), resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32624" target="_blank">CVE-2024-32624</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in Open-Source Technology Committee SRS real-time video server RS/4.0.268(Leo) and SRS/4.0.195(Leo) allows a remote attacker to execute arbitrary code via a crafted request.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33250" target="_blank">CVE-2024-33250</a><br><a href="https://github.com/hacker2004/cccccckkkkkk/blob/main/CVE-2024-33250.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>QuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33263" target="_blank">CVE-2024-33263</a><br><a href="https://github.com/bellard/quickjs/issues/277" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the Wireless Page.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33433" target="_blank">CVE-2024-33433</a><br><a href="https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/X2000R/XSS_2_Guest_Access_Control/README.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stack component.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33454" target="_blank">CVE-2024-33454</a><br><a href="https://gist.github.com/Zakary-D/30f565c4266c02c62aa9089c363e78e9" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the login.php component</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33485" target="_blank">CVE-2024-33485</a><br><a href="https://github.com/CveSecLook/cve/issues/17" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via goform/formWPS, allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33771" target="_blank">CVE-2024-33771</a><br><a href="https://github.com/YuboZhaoo/IoT/blob/main/D-Link/DIR-619L/20240424.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formTcpipSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter "curTime."</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33772" target="_blank">CVE-2024-33772</a><br><a href="https://github.com/YuboZhaoo/IoT/blob/main/D-Link/DIR-619L/20240424.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanGuestSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33773" target="_blank">CVE-2024-33773</a><br><a href="https://github.com/YuboZhaoo/IoT/blob/main/D-Link/DIR-619L/20240424.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanSetup_Wizard allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33774" target="_blank">CVE-2024-33774</a><br><a href="https://github.com/YuboZhaoo/IoT/blob/main/D-Link/DIR-619L/20240424.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33818" target="_blank">CVE-2024-33818</a><br><a href="https://medium.com/%40rajput.thakur/insecure-direct-object-references-cve-2024-33818-86785aa8c969" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Globitel KSA SpeechLog v8.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Save Query function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33819" target="_blank">CVE-2024-33819</a><br><a href="https://medium.com/%40rajput.thakur/speechlog-v-8-1-stored-cross-site-scripting-cve-2024-33819-1b1164fb0ecd" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33863" target="_blank">CVE-2024-33863</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creation, file inclusion, and PDF document generation via malicious JavaScript.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33864" target="_blank">CVE-2024-33864</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is an NTLM hash leak via the /api/Cdn/GetFile and /api/DocumentTemplate/{GUID] endpoints.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33865" target="_blank">CVE-2024-33865</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33866" target="_blank">CVE-2024-33866</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33867" target="_blank">CVE-2024-33867</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33868" target="_blank">CVE-2024-33868</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33873" target="_blank">CVE-2024-33873</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33874" target="_blank">CVE-2024-33874</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33875" target="_blank">CVE-2024-33875</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_deserialize in H5Spoint.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33876" target="_blank">CVE-2024-33876</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33877" target="_blank">CVE-2024-33877</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>The WebTop package for NethServer 7 and 8 allows stored XSS (for example, via the Subject field if an e-mail message).</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34058" target="_blank">CVE-2024-34058</a><br><a href="https://www.openwall.com/lists/oss-security/2024/05/16/3" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php. This vulnerability allows attackers to delete arbitrary files via a crafted request.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34191" target="_blank">CVE-2024-34191</a><br><a href="https://chmod744.super.site/htmly-cve" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Totolink AC1200 Wireless Dual Band Gigabit Router A3002RU_V3 Firmware V3.0.0-B20230809.1615 is vulnerable to Buffer Overflow. The "boa" program allows attackers to modify the value of the "vwlan_idx" field via "formMultiAP". This can lead to a stack overflow through the "formWlEncrypt" CGI function by constructing malicious HTTP requests and passing a WLAN SSID value exceeding the expected length, potentially resulting in command execution or denial of service attacks.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34196" target="_blank">CVE-2024-34196</a><br><a href="https://gist.github.com/Swind1er/1ec2fde42254598a72f1d716f9cfe2a1" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34199" target="_blank">CVE-2024-34199</a><br><a href="https://github.com/DMCERTCE/PoC_Tiny_Overflow" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQosRules function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34200" target="_blank">CVE-2024-34200</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setIpQosRules" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the getSaveConfig function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34201" target="_blank">CVE-2024-34201</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/getSaveConfig" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setMacFilterRules function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34202" target="_blank">CVE-2024-34202</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setMacFilterRules" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setLanguageCfg function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34203" target="_blank">CVE-2024-34203</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setLanguageCfg" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34204" target="_blank">CVE-2024-34204</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setUpgradeFW" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the download_firmware function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34205" target="_blank">CVE-2024-34205</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/download_firmware" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34206" target="_blank">CVE-2024-34206</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setWebWlanIdx" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setStaticDhcpConfig function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34207" target="_blank">CVE-2024-34207</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setStaticDhcpConfig" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFilterRules function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34209" target="_blank">CVE-2024-34209</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setIpPortFilterRules" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the CloudACMunualUpdate function via the FileName parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34210" target="_blank">CVE-2024-34210</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/CloudACMunualUpdate_injection" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34211" target="_blank">CVE-2024-34211</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/HardCodeRoot" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunualUpdate function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34212" target="_blank">CVE-2024-34212</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/CloudACMunualUpdate_overflow" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForwardRules function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34213" target="_blank">CVE-2024-34213</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/SetPortForwardRules" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setUrlFilterRules function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34215" target="_blank">CVE-2024-34215</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/SetUrlFilterRules" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfileClientMode function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34217" target="_blank">CVE-2024-34217</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/addWlProfileClientMode" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34218" target="_blank">CVE-2024-34218</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/NTPSyncWithHost" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34219" target="_blank">CVE-2024-34219</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/SetTelnetCfg" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34220" target="_blank">CVE-2024-34220</a><br><a href="https://github.com/dovankha/CVE-2024-34220" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34221" target="_blank">CVE-2024-34221</a><br><a href="https://github.com/dovankha/CVE-2024-34221" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34222" target="_blank">CVE-2024-34222</a><br><a href="https://github.com/dovankha/CVE-2024-34222" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34223" target="_blank">CVE-2024-34223</a><br><a href="https://github.com/dovankha/CVE-2024-34223" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34224" target="_blank">CVE-2024-34224</a><br><a href="https://github.com/dovankha/CVE-2024-34224" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34225" target="_blank">CVE-2024-34225</a><br><a href="https://github.com/dovankha/CVE-2024-34225" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&amp;id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34226" target="_blank">CVE-2024-34226</a><br><a href="https://github.com/dovankha/CVE-2024-34226" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Information parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34230" target="_blank">CVE-2024-34230</a><br><a href="https://github.com/Amrita2000/CVES/blob/main/CVE-2024-34230.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Short Name parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34231" target="_blank">CVE-2024-34231</a><br><a href="https://github.com/Amrita2000/CVES/blob/main/CVE-2024-34231.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript payload using the admin web interface when creating new courses and new course notifications.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34241" target="_blank">CVE-2024-34241</a><br><a href="https://grumpz.net/cve-2024-34241-a-step-by-step-discovery-guide" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34243" target="_blank">CVE-2024-34243</a><br><a href="https://github.com/JByteL/CVE/tree/main/CVE-2024-34243" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in makehtml_js_action.php.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34245" target="_blank">CVE-2024-34245</a><br><a href="https://github.com/Stoocea/Vulnerability-analysis-Notes/blob/main/cms/DedeCMS-V5.7.114%20%20Arbitrary%20file%20read%20vulnerability.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34256" target="_blank">CVE-2024-34256</a><br><a href="https://github.com/ZackSecurity/VulnerReport/blob/cve/ofcms/1.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>njwt up to v0.4.0 was discovered to contain a prototype pollution in the Parser.prototype.parse method.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34273" target="_blank">CVE-2024-34273</a><br><a href="https://github.com/chrisandoryan/vuln-advisory/blob/main/nJwt/CVE-2024-34273.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the function urldecode.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34308" target="_blank">CVE-2024-34308</a><br><a href="https://github.com/s4ndw1ch136/IOT-vuln-reports/blob/main/totolink%20LR350/README.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34310" target="_blank">CVE-2024-34310</a><br><a href="https://github.com/3309899621/CVE-2024-34310" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A Blind command injection vulnerability in Tenda O3V2 V1.0.0.12 and earlier allows remote attackers to execute operating system commands via dest parameter in /goform/getTraceroute</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34338" target="_blank">CVE-2024-34338</a><br><a href="http://exzettabyte.me/blind-command-injection-in-tenda-o3v2" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34459" target="_blank">CVE-2024-34459</a><br><a href="https://gitlab.gnome.org/GNOME/libxml2/-/issues/720" target="_blank">cve@mitre.org</a><br><a href="https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.11.8" target="_blank">cve@mitre.org</a><br><a href="https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.12.7" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sunhillo SureLine through 8.10.0 on RICI 5000 devices allows cgi/usrPasswd.cgi userid_change XSS within the Forgot Password feature.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34582" target="_blank">CVE-2024-34582</a><br><a href="https://github.com/silent6trinity/CVE-2024-34582" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34899" target="_blank">CVE-2024-34899</a><br><a href="https://hackerdna.com/courses/cve/cve-2024-34899" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>FlyFish v3.0.0 was discovered to contain a buffer overflow via the password parameter on the login page. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34905" target="_blank">CVE-2024-34905</a><br><a href="https://github.com/CloudWise-OpenSource/FlyFish/issues/191" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file upload vulnerability in dootask v0.30.13 allows attackers to execute arbitrary code via uploading a crafted PDF file.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34906" target="_blank">CVE-2024-34906</a><br><a href="https://github.com/kuaifan/dootask/issues/210" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file upload vulnerability in KYKMS v1.0.1 and below allows attackers to execute arbitrary code via uploading a crafted PDF file.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34909" target="_blank">CVE-2024-34909</a><br><a href="https://github.com/Joying-C/Cross-site-scripting-vulnerability/tree/main/KYKMS_Cross_site%20_scripting%20_vulnerability" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file upload vulnerability in r-pan-scaffolding v5.0 and below allows attackers to execute arbitrary code via uploading a crafted PDF file.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34913" target="_blank">CVE-2024-34913</a><br><a href="https://github.com/Joying-C/Cross-site-scripting-vulnerability/tree/main/r-pan-scaffolding_Cross_site%20_scripting%20_vulnerability" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>php-censor v2.1.4 and fixed in v.2.1.5 was discovered to utilize a weak hashing algorithm for its remember_key value. This allows attackers to bruteforce to bruteforce the remember_key value to gain access to accounts that have checked "remember me" when logging in.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34914" target="_blank">CVE-2024-34914</a><br><a href="https://chmod744.super.site/redacted-vulnerability" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file upload vulnerability in the component \modstudent\controller.php of Pisay Online E-Learning System using PHP/MySQL v1.0 allows attackers to execute arbitrary code via uploading a crafted file.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34919" target="_blank">CVE-2024-34919</a><br><a href="https://github.com/CveSecLook/cve/issues/20" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34921" target="_blank">CVE-2024-34921</a><br><a href="https://github.com/cainiao159357/x5000r_poc/blob/main/README.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at ip/goform/exeCommand.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34942" target="_blank">CVE-2024-34942</a><br><a href="https://palm-vertebra-fe9.notion.site/formexeCommand-200db77a90d34c708b903c935c7c65c0" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34943" target="_blank">CVE-2024-34943</a><br><a href="https://palm-vertebra-fe9.notion.site/fromNatStaticSetting-fae26e1bfbe64b49a46230a629b6d198" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34944" target="_blank">CVE-2024-34944</a><br><a href="https://www.tendacn.com/hk/download/detail-2344.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPW parameter at ip/goform/WizardHandle.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34945" target="_blank">CVE-2024-34945</a><br><a href="https://palm-vertebra-fe9.notion.site/fromWizardHandle-98e188c072984620a907ea5df0d80ad5" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34946" target="_blank">CVE-2024-34946</a><br><a href="https://palm-vertebra-fe9.notion.site/fromDhcpListClient_page-c9ee71f670534555a5ef2d99320da48e" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>D-Link DIR-822+ v1.0.5 was discovered to contain a stack-based buffer overflow vulnerability in the SetNetworkTomographySettings module.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34950" target="_blank">CVE-2024-34950</a><br><a href="https://dear-sunshine-ba5.notion.site/D-Link-DIR-822-v1-0-5-Stack-Overflow-e77ff3d9c31f4a98bfa0fa71eca54000" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Code-projects Budget Management 1.0 is vulnerable to Cross Site Scripting (XSS) via the budget parameter.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34954" target="_blank">CVE-2024-34954</a><br><a href="https://github.com/ethicalhackerNL/CVEs/blob/main/Budget%20Management/XSS/XSS.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34955" target="_blank">CVE-2024-34955</a><br><a href="https://github.com/ethicalhackerNL/CVEs/blob/main/Budget%20Management/SQLi.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/sysImages_deal.php?mudi=infoSet.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34957" target="_blank">CVE-2024-34957</a><br><a href="https://github.com/Gr-1m/cms/blob/main/1.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/banner_deal.php?mudi=add</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34958" target="_blank">CVE-2024-34958</a><br><a href="https://github.com/Gr-1m/cms/blob/main/2.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>DedeCMS V5.7.113 is vulnerable to Cross Site Scripting (XSS) via sys_data_replace.php.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34959" target="_blank">CVE-2024-34959</a><br><a href="https://gitee.com/upgogo/s123/issues/I9MARO" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34974" target="_blank">CVE-2024-34974</a><br><a href="https://github.com/hunzi0/Vullnfo/tree/main/Tenda/AC18/formSetPPTPServer" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via uploading a crafted file.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34982" target="_blank">CVE-2024-34982</a><br><a href="https://github.com/n2ryx/CVE/blob/main/Lylme_pagev1.9.5.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34997" target="_blank">CVE-2024-34997</a><br><a href="https://github.com/joblib/joblib/issues/1582" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&amp;dataType=&amp;fieldName=state&amp;fieldName2=state&amp;tabName=banner&amp;dataID=6.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35009" target="_blank">CVE-2024-35009</a><br><a href="https://github.com/Thirtypenny77/cms/blob/main/5.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/banner_deal.php?mudi=del&amp;dataType=&amp;dataTypeCN=%E5%9B%BE%E7%89%87%E5%B9%BF%E5%91%8A&amp;theme=cs&amp;dataID=6.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35010" target="_blank">CVE-2024-35010</a><br><a href="https://github.com/Thirtypenny77/cms/blob/main/6.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=rev&amp;nohrefStr=close.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35011" target="_blank">CVE-2024-35011</a><br><a href="https://github.com/Thirtypenny77/cms/blob/main/8.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=add&amp;nohrefStr=close.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35012" target="_blank">CVE-2024-35012</a><br><a href="https://github.com/Thirtypenny77/cms/blob/main/7.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/tplSys_deal.php?mudi=area.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35039" target="_blank">CVE-2024-35039</a><br><a href="https://github.com/ywf7678/cms/blob/main/1.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35048" target="_blank">CVE-2024-35048</a><br><a href="https://github.com/javahuang/SurveyKing/issues/56" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35049" target="_blank">CVE-2024-35049</a><br><a href="https://github.com/javahuang/SurveyKing/issues/55" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35050" target="_blank">CVE-2024-35050</a><br><a href="https://github.com/javahuang/SurveyKing/issues/57" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35099" target="_blank">CVE-2024-35099</a><br><a href="https://github.com/s4ndw1ch136/IOT-vuln-reports/blob/main/V9.3.5u.6698_B20230810/README.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Insecure Permissions vulnerability in VITEC AvediaServer (Model avsrv-m8105) 8.6.2-1 allows a remote attacker to escalate privileges via a crafted script.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35102" target="_blank">CVE-2024-35102</a><br><a href="https://vuln2you.blogspot.com/2024/05/avediaserver-unauthorised-api-access.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/homePro_deal.php?mudi=del&amp;dataType=&amp;dataTypeCN.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35108" target="_blank">CVE-2024-35108</a><br><a href="https://github.com/FirstLIF/cms/blob/main/1.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /homePro_deal.php?mudi=add&amp;nohrefStr=close.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35109" target="_blank">CVE-2024-35109</a><br><a href="https://github.com/FirstLIF/cms/blob/main/2.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users access a malicious link, their cookies can be captured by an attacker.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35110" target="_blank">CVE-2024-35110</a><br><a href="https://github.com/yzmcms/yzmcms/issues/68" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Veritas System Recovery before 23.2_Hotfix has incorrect permissions for the Veritas System Recovery folder, and thus low-privileged users can conduct attacks.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35204" target="_blank">CVE-2024-35204</a><br><a href="https://www.veritas.com/content/support/en_US/article.100065391" target="_blank">cve@mitre.org</a><br><a href="https://www.veritas.com/support/en_US/security/VTS24-005" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names before processing them through external application interactions, leading to a form of path traversal. This potentially enables any application to dispatch a crafted library file, aiming to overwrite an existing native library utilized by WPS Office. Successful exploitation could result in the execution of arbitrary commands under the guise of WPS Office's application ID.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35205" target="_blank">CVE-2024-35205</a><br><a href="https://www.microsoft.com/en-us/security/blog/2024/05/01/dirty-stream-attack-discovering-and-mitigating-a-common-vulnerability-pattern-in-android-apps/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In Tor Arti before 1.2.3, STUB circuits incorrectly have a length of 2 (with lite vanguards), aka TROVE-2024-003.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35312" target="_blank">CVE-2024-35312</a><br><a href="https://gitlab.torproject.org/tpo/core/arti/-/issues/1409" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In Tor Arti before 1.2.3, circuits sometimes incorrectly have a length of 3 (with full vanguards), aka TROVE-2024-004.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35313" target="_blank">CVE-2024-35313</a><br><a href="https://gitlab.torproject.org/tpo/core/arti/-/issues/1400" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>question_image.ts in SurveyJS Form Library before 1.10.4 allows contentMode=youtube XSS via the imageLink property.</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-36043" target="_blank">CVE-2024-36043</a><br><a href="https://github.com/surveyjs/survey-library/commit/b25fbf0efd4486dc55f836240bebc2305803b96d" target="_blank">cve@mitre.org</a><br><a href="https://github.com/surveyjs/survey-library/issues/8286" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-36048" target="_blank">CVE-2024-36048</a><br><a href="https://codereview.qt-project.org/c/qt/qtnetworkauth/+/560317" target="_blank">cve@mitre.org</a><br><a href="https://codereview.qt-project.org/c/qt/qtnetworkauth/+/560368" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-36050" target="_blank">CVE-2024-36050</a><br><a href="https://github.com/NixOS/nix/issues/969" target="_blank">cve@mitre.org</a><br><a href="https://github.com/NixOS/ofborg/issues/68#issuecomment-2082789441" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A stored Cross-Site Scripting (XSS) vulnerability exists in the parisneo/lollms-webui application due to improper validation of uploaded files in the profile picture upload functionality. Attackers can exploit this vulnerability by uploading malicious HTML files containing JavaScript code, which is executed when the file is accessed. This vulnerability is remotely exploitable via Cross-Site Request Forgery (CSRF), allowing attackers to perform actions on behalf of authenticated users and potentially leading to unauthorized access to sensitive information within the Lollms-webui application.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2299" target="_blank">CVE-2024-2299</a><br><a href="https://huntr.com/bounties/f1adaac0-b9ed-4093-a0f3-2d0a4ecba398" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute arbitrary code. The vulnerability arises due to insufficient sanitization of user-supplied input in the configuration settings, specifically within the 'extensions' parameter. Attackers can exploit this by crafting a payload that includes relative path traversal sequences ('../../../'), enabling them to navigate to arbitrary directories. This flaw subsequently allows the server to load and execute a malicious '__init__.py' file, leading to remote code execution. The issue affects the latest version of parisneo/lollms-webui.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2358" target="_blank">CVE-2024-2358</a><br><a href="https://huntr.com/bounties/b2771df3-be50-45bd-93c4-0974ce38bc22" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A vulnerability in the parisneo/lollms-webui allows for arbitrary file upload and read due to insufficient sanitization of user-supplied input. Specifically, the issue resides in the `install_model()` function within `lollms_core/lollms/binding.py`, where the application fails to properly sanitize the `file://` protocol and other inputs, leading to arbitrary read and upload capabilities. Attackers can exploit this vulnerability by manipulating the `path` and `variant_name` parameters to achieve path traversal, allowing for the reading of arbitrary files and uploading files to arbitrary locations on the server. This vulnerability affects the latest version of parisneo/lollms-webui.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2361" target="_blank">CVE-2024-2361</a><br><a href="https://huntr.com/bounties/cd383817-924a-445a-838e-d0c867c6a176" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall_binding functionality in lollms_core/lollms/server/endpoints/lollms_binding_infos.py of the latest version. The vulnerability arises due to insufficient path sanitization, allowing an attacker to exploit path traversal to navigate to arbitrary directories. By manipulating the binding_path to point to a controlled directory and uploading a malicious __init__.py file, an attacker can execute arbitrary code on the server.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2366" target="_blank">CVE-2024-2366</a><br><a href="https://huntr.com/bounties/63266c77-408b-45ff-962c-8163db50a864" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A command injection vulnerability exists in the 'run_xtts_api_server' function of the parisneo/lollms-webui application, specifically within the 'lollms_xtts.py' script. The vulnerability arises due to the improper neutralization of special elements used in an OS command. The affected function utilizes 'subprocess.Popen' to execute a command constructed with a Python f-string, without adequately sanitizing the 'xtts_base_url' input. This flaw allows attackers to execute arbitrary commands remotely by manipulating the 'xtts_base_url' parameter. The vulnerability affects versions up to and including the latest version before 9.5. Successful exploitation could lead to arbitrary remote code execution (RCE) on the system where the application is deployed.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3126" target="_blank">CVE-2024-3126</a><br><a href="https://github.com/parisneo/lollms-webui/commit/41dbb1b3f2e78ea276e5269544e50514252c0c25" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/0e2bec70-826e-4c24-8015-31921e23fd12" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affecting versions up to the latest release before 9.5. The vulnerability arises due to insufficient sanitization of the 'config' parameter in the 'apply_settings' function, allowing an attacker to manipulate the application's configuration by sending specially crafted JSON payloads. This could lead to remote code execution (RCE) by bypassing existing patches designed to mitigate such vulnerabilities.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3435" target="_blank">CVE-2024-3435</a><br><a href="https://github.com/parisneo/lollms-webui/commit/bb99b59e710d00c4f2598faa5e183fa30fbd3bc2" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/494f349a-8650-4d30-a0bd-4742fda44ce5" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `/list_personalities` endpoint. By manipulating the `category` parameter, an attacker can traverse the directory structure and list any directory on the system. This issue affects the latest version of the application. The vulnerability is due to improper handling of user-supplied input in the `list_personalities` function, where the `category` parameter can be controlled to specify arbitrary directories for listing. Successful exploitation of this vulnerability could allow an attacker to list all folders in the drive on the system, potentially leading to information disclosure.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4322" target="_blank">CVE-2024-4322</a><br><a href="https://huntr.com/bounties/5116d858-ce00-418c-a5a5-851c5608c209" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the `/apply_settings` and `/execute_code` endpoints. Attackers can bypass protections by setting the host to localhost, enabling code execution, and disabling code validation through the `/apply_settings` endpoint. Subsequently, arbitrary commands can be executed remotely via the `/execute_code` endpoint, exploiting the delay in settings enforcement. This issue was addressed in version 9.5.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4326" target="_blank">CVE-2024-4326</a><br><a href="https://github.com/parisneo/lollms-webui/commit/abb4c6d495a95a3ef5b114ffc57f85cd650b905e" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/2ab9f03d-0538-4317-be21-0748a079cbdd" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms<br> </td>
<td>A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code execution due to insufficient sanitization of user input. The issue arises from the lack of path sanitization when handling the `name` parameter in the `unInstall_binding` function, allowing an attacker to traverse directories and execute arbitrary code by loading a malicious `__init__.py` file. This vulnerability affects the latest version of the software. The exploitation of this vulnerability could lead to remote code execution on the system where parisneo/lollms is deployed.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4078" target="_blank">CVE-2024-4078</a><br><a href="https://github.com/parisneo/lollms/commit/7ebe08da7e0026b155af4f7be1d6417bc64cf02f" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/a55a8c04-df44-49b2-bcfa-2a2b728a299d" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>run-llama--run-llama/llama_index<br> </td>
<td>A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI to connect to Language Learning Models (LLMs). The vulnerability arises from the improper use of the eval function, allowing a malicious or compromised LLM hosting provider to execute arbitrary commands on the client's machine. This issue was fixed in version 0.10.13. The exploitation of this vulnerability could lead to a hosting provider gaining full control over client machines.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4181" target="_blank">CVE-2024-4181</a><br><a href="https://github.com/run-llama/llama_index/commit/d73715eaf0642705583e7897c78b9c8dd2d3a7ba" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/1a204520-598a-434e-b13d-0d34f2a5ddc1" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>wandb--wandb/wandb<br> </td>
<td>A Server-Side Request Forgery (SSRF) vulnerability exists in the wandb/wandb repository due to improper handling of HTTP 302 redirects. This issue allows team members with access to the 'User settings -&gt; Webhooks' function to exploit this vulnerability to access internal HTTP(s) servers. In severe cases, such as on AWS instances, this could potentially be abused to achieve remote code execution on the victim's machine. The vulnerability is present in the latest version of the repository.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4642" target="_blank">CVE-2024-4642</a><br><a href="https://huntr.com/bounties/055eb540-57f8-46d6-b858-3a9e22d347d9" target="_blank">security@huntr.dev</a></td>
</tr>
</tbody>
</table>
<p><a href="https://www.cisa.gov/#top">Back to top</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Is Elon Musk a Security Expert? - ThreatWire]]></title>
<description><![CDATA[Author: Hak5 - Bewertung: 961x - Views:14256 ⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️





@endingwithali →
Twitch: https://twitch.tv/endingwithali
Twitter: https://twitter.com/endingwithali
YouTube: https://youtube.com/@endingwithali
Everywhere else: https://links.ali.dev
Want to work with...]]></description>
<link>https://tsecurity.de/de/2136934/it-security-video/is-elon-musk-a-security-expert-threatwire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2136934/it-security-video/is-elon-musk-a-security-expert-threatwire/</guid>
<pubDate>Mon, 06 May 2024 16:11:35 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/-sfqJx5FWqg/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Hak5 - Bewertung: 961x - Views:14256 <br/></p><p><iframe id="ytplayer" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/-sfqJx5FWqg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️





@endingwithali →
Twitch: https://twitch.tv/endingwithali
Twitter: https://twitter.com/endingwithali
YouTube: https://youtube.com/@endingwithali
Everywhere else: https://links.ali.dev
Want to work with Ali? endingwithalicollabs@gmail.com




[❗] Join the Patreon→ https://patreon.com/threatwire
0:00  Intro
00:10 1 - NextJS Vulnerabilities Discovered
02:06 2 - New Technique Allows VPN Bypass
04:31 3 - FIDO2 Flaw Exposes MITM Attack
05:51 4 - Signal Vs Telegram
08:24 5 - Outro 


LINKS
🔗 Story 1: NextJS Vulnerabilities Discovered
https://portswigger.net/web-security/request-smuggling/advanced/response-queue-poisoning
https://github.com/advisories/GHSA-77r5-gw3j-2mpf
https://github.com/advisories/GHSA-fr5h-rqp8-mj6g
https://cybersecuritynews.com/next-js-server-compromise/


🔗 Story 2: New Technique Allows VPN Bypass
https://www.leviathansecurity.com/blog/tunnelvision
https://cybersecuritynews.com/tunnelvision/


🔗 Story 3: FIDO2 Flaw Exposes MITM Attack
https://www.silverfort.com/blog/using-mitm-to-bypass-fido2/
https://gbhackers.com/fid02-mitm-vulnerability/


🔗 Story 4:  Signal Vs Telegram
https://www.city-journal.org/article/signals-katherine-maher-problem
https://www.ccn.com/news/technology/telegram-vs-signal-elon-musk-claims-vulnerabilities/
https://www.businessinsider.com/elon-musk-encrypted-messenger-app-wars-telegram-signal-2024-5
https://twitter.com/elonmusk/status/1787589564917490059
https://news.ycombinator.com/item?id=40341716
https://nitter.poast.org/matthew_d_green/status/1789687898863792453


____________________________________________


Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[My solution to the GNU/Linux controversy: Call it Lunix]]></title>
<description><![CDATA[We all know that an OS consists of the kernel and the core userland environment. But the controversy is usually with regard to which of those components must be named out separately, and if they even should be. History Going back to history to figure out the origins of these systems, we find that...]]></description>
<link>https://tsecurity.de/de/2131909/linux-tipps/my-solution-to-the-gnulinux-controversy-call-it-lunix/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2131909/linux-tipps/my-solution-to-the-gnulinux-controversy-call-it-lunix/</guid>
<pubDate>Thu, 02 May 2024 19:50:08 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>We all know that an OS consists of the kernel and the core userland environment. But the controversy is usually with regard to which of those components must be named out separately, and if they even should be.</p> <h1>History</h1> <p>Going back to history to figure out the origins of these systems, we find that it all started with AT&amp;T Bell Labs UNIX. Bell Labs licensed UNIX to universities so they could research and extend it. One such version of UNIX from University of California, Berkeley (UCB) was interesting to other universities, so they decided to release their extension of UNIX as 1BSD.</p> <h2>1. BSD from its origins to USL vs BSDi Lawsuit</h2> <p>At one point, a VAX system was stationed at UCB, but the port of UNIX to VAX, UNIX/32V did not take advantage of VAX's virtual memory capabilities. Students at UCB rewrote the 32V kernel to take advantage of virtual memory along with ports of software from 2BSD to VAX and utilities from UNIX/32V, creating a new operating system named 3BSD. For this reason, DARPA funded the Computer Science Research Group (CSRG) at UCB.</p> <p>By the time of 4.3BSD (4.3BSD-Tahoe), software licenses were getting expensive, so the developers decided to rewrite the TCP/IP stack and release the distribution as 4.3BSD Networking Release 1 (4.3BSD Net/1). The kernel source code was also rewritten during move from VAX to Tahoe systems with 4.3BSD-Tahoe, with a separation of machine-dependent and machine-independent code.</p> <p>After 4.3BSD/Net 1, 4.3BSD-Reno was released as an interim release for 4.4BSD. At the time, DARPA ended the funding of CSRG, so the students wanted to port more of the AT&amp;T UNIX software to be released freely before CSRG disbands, and they rewrote many of the UNIX utilities. This rewrite was released as 4.3BSD Networking Release 2 (4.3BSD Net/2).</p> <p>Meanwhile, a programmer named William Jolitz was working on porting 4.3BSD-Reno to Intel 80386, and later he rebased to 4.3BSD Net/2. His project was named 386BSD. Another company, named Berkeley Software Design Inc. (BSDi) was developing BSD/386, a proprietary commercial version of BSD for Intel 80386, based on 4.3BSD Net/2. As BSDi was released, AT&amp;T UNIX System Laboratories (USL), the then division of AT&amp;T responsible for UNIX filed a lawsuit against BSDi claiming illegal use of AT&amp;T licensed code, preventing the release of 386BSD and 4.3BSD Net/2 to non UNIX-licensees. This lawsuit was started in 1992.</p> <h2>2. Linux</h2> <p>At that time, Linus wanted some free kernel that works on the 80386, so he decided to write one on his own. He said himself that if BSD386 was available at the time, he wouldn't have developed Linux. So even though BSD was an operating system of its own, its association with UNIX cost its popularity against Linux systems. By the time the lawsuit was settled in 1994, the Linux community had ported over the GNU project to create working distributions of GNU/Linux.</p> <h2>3. GNU's Not UNIX</h2> <p>Now coming to GNU. In 1983, Stallman decided that there should be some free operating system, and he chose to base his system on the principles of UNIX. Cleverly, he chose the name GNU's Not UNIX, because that was one of the reasons that eventually ended up in them not hitting the lawsuit like BSDi did. Unlike BSD, the GNU Project was clean from the beginning, so AT&amp;T would have nothing on them. He also started the FSF 2 years later to support the development of GNU.</p> <h2>4. Association of GNU with Linux</h2> <p>By 1992, two things happened. GNU was developed as a general purpose OS, so they developed the userspace first, while the kernel space remained incomplete, largely because their choice of microkernel design would need careful design choices. At the same time, Linux was developed for 80386, so it ended up delivering a working kernel, without no usable environment. So the Linux community ended up porting the work of the GNU Project by adding patches to GNU software for compatibility, and GNU gladly welcomed their changes. But when a working OS distribution was created, the Linux community said that they are only interested in the development of Linux, and GNU is a separate project. This is how GNU's contribution was neglected for the first time, before people started adding in X and other packages with SLS and Yggdrasil Linux/GNU/X.</p> <p>Linux also greatly benefitted from the GNU GPL v2 license, which was a product of the GNU Project and FSF. It was GPLv2 that allowed Linux to demand back contributions legally from corporations.</p> <p>Additionally, Linux refused utilizing GPL v3, because Linus was not concerned about ethical issues as much as developing his own system. For this reason, omitting GNU while choosing to highlight Linux is like taking the spotlight away from the party fought more for our freedoms, while giving it to the neutral party, that plays pretty well with capitalism. Not that Linux itself is evil (evil defined as taking a stance with a harmful idea) for that choice, just like how Linus doesn't even care about mentioning the name Linux. But the people who use the term and are against any mention of GNU could be said to be doing just that. At least some of them. That is, those who do it alongside claiming that copyleft is a disgusting form of license compared to permissive licenses, because it "forces" you to not close-source your derivative works. In this instance, I'll have to take the side of GPL, but I digress.</p> <h1>What is an OS? - Resolving the controversy</h1> <p>People can't agree on whether it's the kernel, or whether it's the kernel + everything in the userspace, excluding application software. This makes people either stick with using the term Linux, or claim that it is Linux/GNU/Freedesktop/systemd/Plasma/Kvantum, which is too complicated, and thus Linux is the only rational short form.</p> <p>But I think when someone uses terms like Linux/GNU/Freedesktop, they're already missing the point. The use of the word GNU serves several purposes. One is to remember GNU as an important contributor, and secondly, it is to differentiate the system. When we say Linux distribution, people in the Linux community understand that they mean PC OS distributions based on Linux, with the exclusion of ChromeOS, Android-x86 and other JEOS systems. That's because we understand Linux distributions to be "something", and this "something" is what we are trying to specify here.</p> <p>In my opinion, one main factor is that the desktop distributions we use are POSIX-compliant systems. Now, we have BSD and GNU as the two main POSIX-projects (keeping aside 3rd party NT subsystems like MSYS2, Cygwin, etc.). Microsoft also had a native POSIX subsystem for NT, which lived alongside its OS/2 subsystem, Win32 subsystem and security subsystem. Drawing a parallel with Windows here, I could say that Windows is a Win32/NT system. If we instead used the POSIX subsystem, alone, that would make it a POSIX/NT system, which would be UNIX-like.</p> <p>So, similarly, our desktop Linux distributions are POSIX systems. There are two kinds of POSIX systems, one of which is BSD, where the kernel and userland are part of the same project. That makes them BSD UNIX, or just BSD POSIX if they want to avoid copyright infringement. The other option is where a POSIX environment is implemented atop the ubiquitous Linux kernel. Such a system would be called POSIX/Linux or UNIX/Linux. But since it is not exactly UNIX, and to avoid copyright infringement, we'll call it by something that claims to be not UNIX, which is the original GNU's Not UNIX!</p> <p>So we can either call it POSIX/Linux or GNU/Linux, but UNIX/Linux can be problematic. At this point, GNU is a well fitting name, so we might as well use it. But this won't satisfy those who dislike GNU due to years of hatred which I won't be able to fix with any amount of words. So I have a solution for them.</p> <h1>Lunix</h1> <p>The word Lunix is a combination of Linux and UNIX. By using this, we've separated the UNIX-like systems from non-UNIX-like systems such as Android, ChromeOS, etc. We have also solved the problem of concentrating the value of the entire distribution on to one of the many components that makes it a unique OS, which is Linux. Additionally, there is no trace of the word GNU, satisfying all those who hated GNU. Also, there is no issue of copyright infringement, because we did not use the word UNIX explicitly.</p> <p>But this will further prompt users to ask, but why is it called Lunix when it is Linux? At that point, you can educate the newbies on how Linux is the kernel, and an operating system consists of a kernel and an userland, and the userland in these distributions implement a POSIX system, which is why we call them Lunix, meaning Linux+UNIX. Further, the people who support GNU can educate them on how most of the distributions implement a POSIX system thanks to the GNU Project, and add in how they campaigned for software freedom and were highly influential in bringing about the popularity of open source projects as we see today.</p> <hr> <p>This is all beside the point that I chose the word Lunix because it sounded funny AF. But I hope my ideas were at least useful in changing the mindset about GNU/Linux, and could resolve the conflict in some manner.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/blacklightpy"> /u/blacklightpy </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1cr4c9k/my_solution_to_the_gnulinux_controversy_call_it/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1cr4c9k/my_solution_to_the_gnulinux_controversy_call_it/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-29901 | workos authkit-nextjs up to 0.4.1 x-workos-session authentication replay]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in workos authkit-nextjs up to 0.4.1. This affects an unknown part. The manipulation of the argument x-workos-session leads to authentication bypass by capture-replay.

This vulnerability is uniquely identified as CVE-2024-29901. It is possibl...]]></description>
<link>https://tsecurity.de/de/2124485/sicherheitsluecken/cve-2024-29901-workos-authkit-nextjs-up-to-041-x-workos-session-authentication-replay/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2124485/sicherheitsluecken/cve-2024-29901-workos-authkit-nextjs-up-to-041-x-workos-session-authentication-replay/</guid>
<pubDate>Fri, 26 Apr 2024 16:13:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> has been found in <a href="https://vuldb.com/?product.workos:authkit-nextjs">workos authkit-nextjs up to 0.4.1</a>. This affects an unknown part. The manipulation of the argument <em>x-workos-session</em> leads to authentication bypass by capture-replay.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.258705">CVE-2024-29901</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud Server Host Vultr Rips User Data Ownership Clause From ToS After Web Outage]]></title>
<description><![CDATA[Tobias Mann reports via The Register: Cloud server provider Vultr has rapidly revised its terms-of-service after netizens raised the alarm over broad clauses that demanded the "perpetual, irrevocable, royalty-free" rights to customer "content." The red tape was updated in January, as captured by ...]]></description>
<link>https://tsecurity.de/de/2072897/it-security-nachrichten/cloud-server-host-vultr-rips-user-data-ownership-clause-from-tos-after-web-outage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2072897/it-security-nachrichten/cloud-server-host-vultr-rips-user-data-ownership-clause-from-tos-after-web-outage/</guid>
<pubDate>Thu, 14 Mar 2024 06:50:35 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Tobias Mann reports via The Register: Cloud server provider Vultr has rapidly revised its terms-of-service after netizens raised the alarm over broad clauses that demanded the "perpetual, irrevocable, royalty-free" rights to customer "content." The red tape was updated in January, as captured by the Internet Archive, and this month users were asked to agree to the changes by a pop-up that appeared when using their web-based Vultr control panel. That prompted folks to look through the terms, and there they found clauses granting the US outfit a "worldwide license ... to use, reproduce, process, adapt ... modify, prepare derivative works, publish, transmit, and distribute" user content.
 
It turned out these demands have been in place since before the January update; customers have only just noticed them now. Given Vultr hosts servers and storage in the cloud for its subscribers, some feared the biz was giving itself way too much ownership over their stuff, all in this age of AI training data being put up for sale by platforms. In response to online outcry, largely stemming from Reddit, Vultr in the past few hours rewrote its ToS to delete those asserted content rights. CEO J.J. Kardwell told The Register earlier today it's a case of standard legal boilerplate being taken out of context. The clauses were supposed to apply to customer forum posts, rather than private server content, and while, yes, the terms make more sense with that in mind, one might argue the legalese was overly broad in any case.
 
"We do not use user data," Kardwell stressed to us. "We never have, and we never will. We take privacy and security very seriously. It's at the core of what we do globally." [...] According to Kardwell, the content clauses are entirely separate to user data deployed in its cloud, and are more aimed at one's use of the Vultr website, emphasizing the last line of the relevant fine print: "... for purposes of providing the services to you." He also pointed out that the wording has been that way for some time, and added the prompt asking users to agree to an updated ToS was actually spurred by unrelated Microsoft licensing changes. In light of the controversy, Vultr vowed to remove the above section to "simplify and further clarify" its ToS, and has indeed done so. In a separate statement, the biz told The Register the removal will be followed by a full review and update to its terms of service. "It's clearly causing confusion for some portion of users. We recognize that the average user doesn't have a law degree," Kardwell added. "We're very focused on being responsive to the community and the concerns people have and we believe the strongest thing we can do to demonstrate that there is no bad intent here is to remove it."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Cloud+Server+Host+Vultr+Rips+User+Data+Ownership+Clause+From+ToS+After+Web+Outage%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F24%2F03%2F28%2F2319230%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F24%2F03%2F28%2F2319230%2Fcloud-server-host-vultr-rips-user-data-ownership-clause-from-tos-after-web-outage%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/24/03/28/2319230/cloud-server-host-vultr-rips-user-data-ownership-clause-from-tos-after-web-outage?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-23841 | apollographql apollo-client-nextjs 0.7.0 Link cross site scripting (GHSA-rv8p-rr2h-fgpg)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in apollographql apollo-client-nextjs 0.7.0. This vulnerability affects unknown code of the component Link Handler. The manipulation leads to basic cross site scripting.

This vulnerability was named CVE-2024-23841. The attack can be initiated r...]]></description>
<link>https://tsecurity.de/de/2041984/sicherheitsluecken/cve-2024-23841-apollographql-apollo-client-nextjs-070-link-cross-site-scripting-ghsa-rv8p-rr2h-fgpg/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2041984/sicherheitsluecken/cve-2024-23841-apollographql-apollo-client-nextjs-070-link-cross-site-scripting-ghsa-rv8p-rr2h-fgpg/</guid>
<pubDate>Thu, 22 Feb 2024 09:42:02 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">problematic</a> was found in <a href="https://vuldb.com/?product.apollographql:apollo-client-nextjs">apollographql apollo-client-nextjs 0.7.0</a>. This vulnerability affects unknown code of the component <em>Link Handler</em>. The manipulation leads to basic cross site scripting.

This vulnerability was named <a href="https://vuldb.com/?source_cve.252424">CVE-2024-23841</a>. The attack can be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Does anyone remember `sysfetch`?]]></title>
<description><![CDATA[3 years ago this community helped me write my first script at the time called just fetch.sh. The fetch thing hadn't gone completely off the rails yet and I just got into coding. I decided to whip up my own Neofetch because to me it was bloated lol. First commit was 3 years and about 2 months ago;...]]></description>
<link>https://tsecurity.de/de/2004031/linux-tipps/does-anyone-remember-sysfetch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2004031/linux-tipps/does-anyone-remember-sysfetch/</guid>
<pubDate>Wed, 24 Jan 2024 17:16:35 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>3 years ago this community helped me write my first script at the time called just fetch.sh. The fetch thing hadn't gone completely off the rails yet and I just got into coding. I decided to whip up my own Neofetch because to me it was bloated lol. <a href="https://github.com/wick3dr0se/sysfetch/commit/4190caeb6fb1f14eedffc9ec34b4dc0cf637b160#diff-f01f6bfbafc00864c45147f9a21a3726ba1dff14aadc19542bca3d897ea24cae">First commit</a> was 3 years and about 2 months ago; I hardcoded color codes and made sure to invoke command substition on every line!! I made everything a one-liner using tools like <code>awk</code> and <code>sed</code> where possible where now I do the opposite (using pure Bash where possible)</p> <p>It's been awhile since I shared <code>sysfetch</code> and I'm curious what people would think of it now but mostly curious how when I shared it back then it sort of blew up with contributors and such. I think because I wrote it so bad originally it had more room for improvement. But I've improved and continued to maintain it as I've learned more and more Bash. I rewrote the script entirely more than a few times since back then. If you remember this project, let me know what you think now! I would appreciate any testers, contributors, feedback or anything that helps regardless!</p> <p><a href="https://github.com/wick3dr0se/sysfetch">https://github.com/wick3dr0se/sysfetch</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/wick3dr0se"> /u/wick3dr0se </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/19ekl09/does_anyone_remember_sysfetch/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/19ekl09/does_anyone_remember_sysfetch/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Leverage SvelteKit, Skeleton, and Chart.js for Rapid Prototyping and Efficient Execution]]></title>
<description><![CDATA[a boilerplate for advanced charting and data visualizationContinue reading on Towards Data Science »]]></description>
<link>https://tsecurity.de/de/2001104/ai-nachrichten/how-to-leverage-sveltekit-skeleton-and-chartjs-for-rapid-prototyping-and-efficient-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2001104/ai-nachrichten/how-to-leverage-sveltekit-skeleton-and-chartjs-for-rapid-prototyping-and-efficient-execution/</guid>
<pubDate>Mon, 22 Jan 2024 21:08:09 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="medium-feed-item"><p class="medium-feed-image"><a href="https://towardsdatascience.com/how-to-leverage-sveltekit-skeleton-and-chart-js-for-rapid-prototyping-and-efficient-execution-8173f7356ce1"><img src="https://cdn-images-1.medium.com/max/1280/1*LVLGkpISrxBGx8LUWoSwYg.jpeg" width="1280"></a></p><p class="medium-feed-snippet">a boilerplate for advanced charting and data visualization</p><p class="medium-feed-link"><a href="https://towardsdatascience.com/how-to-leverage-sveltekit-skeleton-and-chart-js-for-rapid-prototyping-and-efficient-execution-8173f7356ce1">Continue reading on Towards Data Science »</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[MiraclePtr: protecting users from use-after-free vulnerabilities on more platforms]]></title>
<description><![CDATA[Posted by Keishi Hattori, Sergei Glazunov, Bartek Nowierski on behalf of the MiraclePtr team
Welcome back to our latest update on MiraclePtr, our project to protect against use-after-free vulnerabilities in Google Chrome. If you need a refresher, you can read our previous blog post detailing Mira...]]></description>
<link>https://tsecurity.de/de/1998723/it-security-nachrichten/miracleptr-protecting-users-from-use-after-free-vulnerabilities-on-more-platforms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1998723/it-security-nachrichten/miracleptr-protecting-users-from-use-after-free-vulnerabilities-on-more-platforms/</guid>
<pubDate>Sat, 20 Jan 2024 12:38:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="byline-author">Posted by Keishi Hattori, Sergei Glazunov, Bartek Nowierski on behalf of the MiraclePtr team</span><p>
Welcome back to our latest update on MiraclePtr, our project to protect against use-after-free vulnerabilities in Google Chrome. If you need a refresher, you can read our <a href="https://security.googleblog.com/2022/09/use-after-freedom-miracleptr.html">previous blog post</a> detailing MiraclePtr and its objectives.
</p>
<h1>More platforms</h1>


<p>
We are thrilled to announce that since our last update, we have successfully enabled MiraclePtr for more platforms and processes: 
</p>
<ul>

<li>In June 2022, we enabled MiraclePtr for the browser process on Windows and Android. 

</li><li>In September 2022, we expanded its coverage to include all processes except renderer processes. 

</li><li>In June 2023, we enabled MiraclePtr for ChromeOS, macOS, and Linux. 
</li>
</ul>
<p>
Furthermore, we have changed <a href="https://chromium.googlesource.com/chromium/src/+/main/docs/security/severity-guidelines.md#TOC-MiraclePtr">security guidelines</a> to downgrade MiraclePtr-protected issues by one severity level!
</p>
<h1>Evaluating Security Impact</h1>


<p>
First let’s focus on its security impact. Our analysis is based on two primary information sources: incoming vulnerability reports and crash reports from user devices. Let's take a closer look at each of these sources and how they inform our understanding of MiraclePtr's effectiveness.
</p>
<h3>Bug reports</h3>


<p>
Chrome vulnerability reports come from various sources, such as:
</p>
<ul>

<li><a href="https://bughunters.google.com/about/rules/5745167867576320/chrome-vulnerability-reward-program-rules">Chrome Vulnerability Reward Program</a> participants,

</li><li>our fuzzing infrastructure,

</li><li>internal and external teams investigating security incidents.
</li>
</ul>
<p>
For the purposes of this analysis, we focus on vulnerabilities that affect platforms where MiraclePtr was enabled at the time the issues were reported. We also exclude bugs that occur inside a sandboxed renderer process. Since the initial launch of MiraclePtr in 2022, we have received 168 use-after-free reports matching our criteria.
</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQTJTVefnA6pPD_rGBgiSUGK0uGcMjowzdIHw89xIa-cdaRybspLntIMcGQCBAJvhbxmS7sZCE9UThhQ-2SRgtKJ100BKklVX8WIaj-ovJ5PBau1TGypbxSIYyMfxcu0F7gf-8f6qoUQSfbw2E2kYp5ErGsDww53EbNi99mfeD_vqWu9xPFJAB0cRiBgMC/s679/Screenshot%202024-01-10%2011.40.12%20AM.png"><img border="0" data-original-height="396" data-original-width="679" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQTJTVefnA6pPD_rGBgiSUGK0uGcMjowzdIHw89xIa-cdaRybspLntIMcGQCBAJvhbxmS7sZCE9UThhQ-2SRgtKJ100BKklVX8WIaj-ovJ5PBau1TGypbxSIYyMfxcu0F7gf-8f6qoUQSfbw2E2kYp5ErGsDww53EbNi99mfeD_vqWu9xPFJAB0cRiBgMC/s16000/Screenshot%202024-01-10%2011.40.12%20AM.png"></a></div>
<p>
What does the data tell us? MiraclePtr effectively <strong>mitigated 57% of these use-after-free vulnerabilities in privileged processes</strong>, exceeding our initial estimate of 50%. Reaching this level of effectiveness, however, required additional work. For instance, we not only rewrote class fields to use MiraclePtr, as discussed in the previous post, but also added MiraclePtr support for bound function arguments, such as <code>Unretained</code> pointers. These pointers have been a significant source of use-after-frees in Chrome, and the additional protection allowed us to mitigate 39 more issues.
</p>
<p>
Moreover, these vulnerability reports enable us to pinpoint areas needing improvement. We're actively working on adding support for select third-party libraries that have been a source of use-after-free bugs, as well as developing a more advanced rewriter tool that can handle transformations like converting <code>std::vector&lt;T*&gt;</code> into <code>std::vector&lt;raw_ptr&lt;T&gt;&gt;</code>. We've also made several smaller fixes, such as extending the lifetime of the task state object to cover several issues in the “<code>this</code> pointer” category.
</p>
<h3>Crash reports</h3>


<p>
Crash reports offer a different perspective on MiraclePtr's effectiveness. As explained in the previous blog post, when an allocation is quarantined, its contents are overwritten with a special bit pattern. If the allocation is used later, the pattern will often be interpreted as an invalid memory address, causing a crash when the process attempts to access memory at that address. Since the dereferenced address remains within a small, predictable memory range, we can distinguish MiraclePtr crashes from other crashes.
</p>
<p>
Although this approach has its limitations — such as not being able to obtain stack traces from allocation and deallocation times like <a href="https://github.com/google/sanitizers/wiki/AddressSanitizer">AddressSanitizer</a> does — it has enabled us to detect and fix vulnerabilities. Last year, <a href="https://bugs.chromium.org/p/chromium/issues/list?q=opened%3E2021-12-31%20opened%3C2023-01-01%20Security_Impact%3DExtended%2CStable%20Security_Severity%3DCritical%20status%3Afixed&amp;can=1">six</a> critical severity vulnerabilities were identified in the default setup of Chrome Stable, the version most people use. Impressively, five of the six were discovered while investigating MiraclePtr crash reports! One particularly interesting example is <a href="https://bugs.chromium.org/p/chromium/issues/detail?id=1340253">CVE-2022-3038</a>. The issue was discovered through MiraclePtr crash reports and fixed in Chrome 105. Several months later, Google's Threat Analysis Group <a href="https://blog.google/threat-analysis-group/spyware-vendors-use-0-days-and-n-days-against-popular-platforms/">discovered</a> an exploit for that vulnerability used in the wild against clients of a different Chromium-based browser that hadn’t shipped the fix yet.
</p>
<p>
To further enhance our crash analysis capabilities, we've recently launched <a href="https://docs.google.com/document/d/1xfGa_IMtFZiQ3beOmkncEafODwn4U90ZyL4NfPaAtDY/edit?pli=1&amp;resourcekey=0-89BZl1SVILB6ylOHula0IA#heading=h.ug7k4kk8zc84">an experimental feature</a> that allows us to collect additional information for MiraclePtr crashes, including stack traces. This effectively shortens the average crash report investigation time.
</p>
<h1>Performance</h1>


<p>
MiraclePtr enables us to have robust protection against use-after-free bug exploits, but there is a performance cost associated with it. Therefore, we have conducted experiments on each platform where we have shipped MiraclePtr, which we used in our decision-making process.
</p>
<p>
The main cost of MiraclePtr is memory. Specifically, the memory usage of the browser process increased by 5.5-8% on desktop platforms and approximately 2% on Android. Yet, when examining the holistic memory usage across all processes, the impact remains within a moderate 1-3% range to lower percentiles only.
</p>
<p>
The main cause of the additional memory usage is the extra size to allocate the reference count. One might think that adding 4 bytes to each allocation wouldn’t be a big deal. However, there are many small allocations in Chrome, so even the 4B overhead is not negligible. Moreover, PartitionAlloc also uses pre-defined allocation bucket sizes, so this extra 4B pushes certain allocations (particularly power-of-2 sized) into a larger bucket, e.g. 4096B → 5120B.
</p>
<p>
We also considered the performance cost. We verified that there were no regressions to the majority of our top-level performance metrics, including all of the page load metrics, like Largest Contentful Paint, First Contentful Paint and Cumulative Layout Shift. We did find a few regressions, such as a 10% increase in the 99th percentile of the browser process <a href="https://docs.google.com/document/d/1vDSGFvJblh7yJ3U3RVB_7qZLubyfTbQdQjuN1GoUNkc/edit">main thread contention metric</a>, a 1.5% regression in First Input Delay on ChromeOS, and a 1.5% regression in tab startup time on Android. The main thread contention metric tries to estimate how often a user input can be delayed and so for example on Windows this was a change from 1.6% to 1.7% at the 99th percentile only. These are all minor regressions. There has been zero change in daily active usage, and we do not anticipate these regressions to have any noticeable impact on users.
</p>
<h1>Conclusion</h1>


<p>
In summary, MiraclePtr has proven to be effective in mitigating use-after-free vulnerabilities and enhancing the overall security of the Chrome browser. While there are performance costs associated with the implementation of MiraclePtr, our analysis suggests that the benefits in terms of security improvements far outweigh these. We are committed to continually refining and expanding the feature to cover more areas. For example we are working to add coverage to third-party libraries used by the GPU process, and we plan to enable BRP on the renderer process. By sharing our findings and experiences, we hope to contribute to the broader conversation surrounding browser security and inspire further innovation in this crucial area.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 JavaScript changes you missed in 2023]]></title>
<description><![CDATA[Author: Fireship - Bewertung: 35897x - Views:661188 How has JavaScript and web development changed in 2023? Learn about the top 10 updates to Next.js, React, Angular, Vue, and Node.js. 

#webdevelopment #programming #top10 

💬 Chat with Me on Discord

https://discord.gg/fireship

🔗 Resources

JS ...]]></description>
<link>https://tsecurity.de/de/1989281/it-security-video/10-javascript-changes-you-missed-in-2023/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1989281/it-security-video/10-javascript-changes-you-missed-in-2023/</guid>
<pubDate>Sat, 13 Jan 2024 17:21:43 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/ANCm3oG7htM/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Fireship - Bewertung: 35897x - Views:661188 <br/></p><p><iframe id="ytplayer" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/ANCm3oG7htM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>How has JavaScript and web development changed in 2023? Learn about the top 10 updates to Next.js, React, Angular, Vue, and Node.js. 

#webdevelopment #programming #top10 

💬 Chat with Me on Discord

https://discord.gg/fireship

🔗 Resources

JS groupBy method https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Object/groupBy
Next.js Criticism https://pilcrow.vercel.app/blog/nextjs-why?s
HTMX in 100 Seconds https://youtu.be/r-GSGH2RxJs?si=jQR6TVNzaJ8dEobC

🔥 Get More Content - Upgrade to PRO

Upgrade at https://fireship.io/pro
Use code YT25 for 25% off PRO access 

🎨 My Editor Settings

- Atom One Dark 
- vscode-icons
- Fira Code Font

🔖 Topics Covered

- JavaScript framework of the year award
- New features in JS language
- HTML dialog element
- Next.js App Directory
- What is UnJS?
- Major changes to Angular 17
- Bun JavaScript Runtime vs Node.js<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[6 warning signs CIOs should look out for in 2024]]></title>
<description><![CDATA[CIOs had to navigate a labyrinth of challenges in 2023: generative AI rewrote the rulebook of technological possibility, governments started to draft new regulatory frameworks for the tech sector, and global conflicts disrupted business operations. Through it all, CIOs had to adapt swiftly.



Th...]]></description>
<link>https://tsecurity.de/de/1977209/it-security-nachrichten/6-warning-signs-cios-should-look-out-for-in-2024/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1977209/it-security-nachrichten/6-warning-signs-cios-should-look-out-for-in-2024/</guid>
<pubDate>Thu, 04 Jan 2024 11:05:53 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>CIOs had to navigate a labyrinth of challenges in 2023: generative AI rewrote the rulebook of technological possibility, governments started to draft new regulatory frameworks for the tech sector, and global conflicts disrupted business operations. Through it all, CIOs had to adapt swiftly.</p>



<p>The lessons learned will prove useful in the year to come, as CIOs steer their organizations through digital transformations against the backdrop of an unpredictable world.</p>



<p>“One of the biggest lessons from 2023 was the need for adaptability,” says Peter Bilyk, chief innovation officer at Ukrainian law firm Juscutum. “Companies that were able to pivot quickly in response to new technologies, market demands, or global events fared better.”</p>



<p>Remaining adaptable will be key as we step into 2024. “CIOs need to remain agile, proactive, and adaptive to navigate these challenges successfully,” says Michal Lewy-Harush, global CIO at cloud native security company Aqua Security.</p>



<p>This year, digital transformation will continue to be on everyone’s agenda, now coupled with a heightened focus on ethical considerations in light of evolving regulatory frameworks. And as organizations integrate more advanced technologies into their operations, cybersecurity should continue to be a top priority.</p>



<p>In the face of the challenges that lie ahead, recognizing warning signs or red flags early on could yield massive advantages for CIOs. Being visionary and agile won’t simply be a way of outsmarting competitors, it could be a survival skill.</p>



<h2 class="wp-block-heading">AI is a double-edged sword</h2>



<p>Over the past year, organizations and tech professionals have been experimenting heavily with AI. Now it’s time to take that to a new level.</p>



<p>“Readiness is determined by the ability to experiment, and the ability to scale what works — building this capacity is critical to be future-ready,” says Siim Sikkut, former government CIO of Estonia, who’s now managing partner at IT consultancy Digital Nation. “For tech, it means dedicated time, talent, and budget to consciously and constantly try out new things. And then mainstreaming into your business the stuff that proves valuable.”</p>



<p>Dong-Hwan Cho, CIO of SK Telecom in South Korea, agrees. “The introduction of GenAI across all areas of business is essential to stay ahead of the competition,” he says. However, not everything that glitters is gold. “Achieving the level of effectiveness that can fully recover the investment cost is a different dimension from seeing a great demonstration,” he adds.</p>



<p>Next year, organizations should refine their strategies and consider the ethical implications of artificial intelligence more seriously. “While AI is at the forefront of technological advancement, its potential for misuse and the ethical dilemmas it poses have become more apparent,” Bilyk says.</p>



<p>Lesia Kasian, chief delivery officer at Ukrainian software developer JEVERA, shares this viewpoint. “The business shouldn’t forget about people and social responsibility, so AI to business transformation should be planned carefully,” she says.</p>



<p>She also adds that organizations should be highly adaptable. “New technologies might spread with unprecedented speed and, as a result, impact business plans in unplanned manners,” Kasian says. “So businesses must be ready to adapt in a smart way. It requires effort, yet the winner catches everything.”</p>



<h2 class="wp-block-heading">Swift changes in AI regulation</h2>



<p>2023 saw a massive boom in AI, and governments are starting to catch up. In the US, President Biden rolled out an <a href="https://www.csoonline.com/article/657637/what-the-white-house-executive-order-on-ai-means-for-cybersecurity-leaders.html">executive order</a> on the safe and secure uses of AI, while in the European Union, lawmakers in December agreed on the details of the <a href="https://www.consilium.europa.eu/en/press/press-releases/2023/12/09/artificial-intelligence-act-council-and-parliament-strike-a-deal-on-the-first-worldwide-rules-for-ai/" rel="nofollow">AI Act</a> — one of the first bills in the world to establish comprehensive rules for AI.</p>



<p>So CIOs will have to follow the debate closely as the year progresses. “Staying updated with new regulations, especially regarding AI ethics, data usage, and copyright concerns, is crucial,” says Bilyk. “Ignoring these changes can lead to legal complications and a loss of public trust.”</p>



<p>Companies should make sure they have enough compliance experts, while startups need to hire them early on because they have to understand if and how regulations apply to them. Also, it helps if CIOs know exactly which AI-powered tools their company uses and how their in-house tools are developed. Not knowing this is a serious red flag.</p>



<p>“A lot of times, leadership, or the legal side, doesn’t even know what developers are building,” Joseph Thacker, security researcher at AppOmni, told <a href="https://www.csoonline.com/article/1258597/how-the-eu-ai-act-regulates-artificial-intelligence-and-what-it-means-for-cybersecurity.html">CSO</a>. “I think for small and medium enterprises, it’s going to be pretty tough.”</p>



<h2 class="wp-block-heading">Geopolitical tensions might disrupt operations</h2>



<p>As the world grapples with increasing geopolitical tensions, businesses are encountering a spectrum of challenges. It’s vital for CIOs to stay informed by keeping up with international news while also being mindful of external influences.</p>



<p>“The escalation of tensions between the US and China could disrupt supply chains for many companies, so it’s crucial to diversify risks to reduce dependence on these two countries,” says Bilyk. This approach is essential to maintain business continuity.</p>



<p>For companies with teams operating in geopolitically sensitive areas like Ukraine or Israel, it becomes even more important to have robust contingency plans in place.</p>



<p>“In Ukraine, the focus has shifted from adopting new technologies to preserving and enhancing the existing infrastructure due to the war’s impact,” says Sergi Milman, CEO and founder of online company verification service, YouControl.</p>



<h2 class="wp-block-heading">Company culture and talent shortage</h2>



<p>In addition, CIOs should be aware of staff turnover rates and the reasons behind them, although this isn’t necessarily part of the job description. Gaining this insight can help them identify potential problems in team dynamics or organizational culture early on. Addressing these issues can also lead to effective strategies to retain talent, thereby fostering a more consistent and efficient workforce.</p>



<p>In certain industries, talent shortages and skills gaps are significant challenges that organizations must navigate. “The rapid evolution of technology is widening the gap in skills, particularly in emerging technologies,” says Bilyk.</p>



<p>To attract and retain talent, organizations must ensure they offer a work environment that meets the needs of the workforce. Bilyk recommends adopting flexible remote work policies if possible and providing support to employees when they need it.</p>



<p>“Mundane tasks and ineffective processes can transform any organization into a swarm,” Kasian says. “Revision and improvement of workflows and business processes are always iterative tasks.”</p>



<p>She also suggests that efficiency should be a priority for companies. “New software implementation and the adoption of AI don’t make the organization operate better by itself,” she adds. “The reality pushes the business to transform itself faster. And, at the same time, the old five-year plans might not work anymore.”</p>



<h2 class="wp-block-heading">Companies can’t afford to overlook security</h2>



<p>As technology advances, the complexity and sophistication of cyber attacks increase. It’s not enough to defend against known threats. It’s also important to anticipate new trends that emerge with AI advancement.</p>



<p>“The risks of intrusions, corporate data theft, and attacks on infrastructure are increasing,” Kasian says. “To operate safely, organizations must preventively think about security. If the company doesn’t have a security officer and dedicated security team yet, it’s time to start urgently changing this.”</p>



<p>In fact, in light of rising security threats, the role of the CIO has seen a convergence with cybersecurity, says Grant McCormick, CIO of California-based cybersecurity company Exabeam. “Regardless of whether security reports to the CIO or another leader within the company, it’s in everyone’s best interest to be conscious of the organization’s security posture, and to enable IT and cybersecurity to work in a highly synchronized manner,” he says.</p>



<p>Sikkut urges companies to be more proactive and recommends that CIOs adopt a ‘trust-by-design’ approach from the start, integrating security and privacy protection into their business processes.</p>



<p>Yet, in spite of their best efforts, organizations often find it challenging to keep pace with the evolving landscape of threats. In such situations, seeking external assistance can help. Independent ethical hackers who work with platforms like HackerOne can be an option, as they’re getting better at finding and fixing risks associated with generative AI.</p>



<p>“<a href="https://www.hackerone.com/reports/7th-annual-hacker-powered-security-report" rel="nofollow">More than half of the hackers within our community</a> plan for gen AI to be a main target, and to specialize in hacking the OWASP Top 10 for LLMs,” says Chris Evans, CISO and chief hacking officer at HackerOne. “The lower barrier to entry for individuals interested in this field builds an inclusive path toward the security experts of tomorrow and a safer internet for everyone.”</p>



<p>Once again, the keyword is adapt. “Be aware of the unknowns around new attack vectors and new emerging risks and, by that, leave enough flexibility to change your security strategy without blocking the organization,” says Aqua Security’s Lewy-Harush.</p>



<h2 class="wp-block-heading">Strategic investment in data management</h2>



<p>Lastly, organizations need to think about how they manage their data. This means investing money and resources into reliable systems that can organize, store, and protect the information they use every day. Doing this helps them make better decisions, improves efficiency, and keeps important data safe.</p>



<p>“As the volume of data increases and the need for robust data management becomes critical, a red flag would be the lack of a scalable data management strategy that can keep up with the demand for instant access and insight from AI systems,” says Carl D’Halluin, chief technology officer at data storage software developer Datadobi. </p>



<p>Reluctance to adopt new technologies, including API-centric architectures and meshed applications, can also be an issue, he adds, because these are crucial to ensure interconnectivity and efficiency in data management.</p>
</div></div></div><category>Artificial Intelligence, CIO, Data and Information Security, Data Management, Generative AI, IT Leadership, Regulation, Security Practices</category>]]></content:encoded>
</item>
<item>
<title><![CDATA[1.5 Years of Spark Knowledge in 8 Tips]]></title>
<description><![CDATA[My learnings from Databricks customer engagementsFigure 1: a technical diagram of how to write apache spark. Image by author.After working with ~15 of the largest retail organizations for the past 18 months, here are the Spark tips I commonly repeat. Throughout this post, we assume a general work...]]></description>
<link>https://tsecurity.de/de/1968105/ai-nachrichten/15-years-of-spark-knowledge-in-8-tips/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1968105/ai-nachrichten/15-years-of-spark-knowledge-in-8-tips/</guid>
<pubDate>Sun, 24 Dec 2023 18:07:03 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>My learnings from Databricks customer engagements</h4><figure><img alt="spark partition data skew optimize optimization pyspark sql python UI partition" src="https://cdn-images-1.medium.com/max/1024/0*mSSB_TnPb9Xid3jB"><figcaption>Figure 1: a technical diagram of how to write apache spark. Image by author.</figcaption></figure><p>After working with ~15 of the largest retail organizations for the past 18 months, here are the Spark tips I commonly repeat. Throughout this post, we assume a general working knowledge of spark and it’s structure, but this post should be accessible to all levels of spark.</p><p>Let’s dive in!</p><h3>0 — Quick Review</h3><p>Quickly, let’s review what spark does…</p><p>Spark is a big data processing engine. It takes python/java/scala/R/SQL and converts that code into a highly optimized set of transformations.</p><figure><img alt="spark partition data skew optimize optimization pyspark sql python UI partition" src="https://cdn-images-1.medium.com/max/1024/1*sKzAtxRKU4aQ61Q5iDshUQ.png"><figcaption>Figure 2: spark driver and worker configuration. Image by author.</figcaption></figure><p>At it’s lowest level, spark creates tasks, which are <strong>parallelizable transformations on data partitions</strong>. These tasks are then distributed across from a driver node to worker nodes, which are responsible for leveraging their CPU cores to complete the transformations. By distributing tasks to potentially many workers, spark allows us to horizontally scale and thereby support complex data pipelines that would be impossible on a single machine.</p><p>Ok, hopefully not all of that was new information. Either way, in the following sections we’ll slow down a bit. These tips should help both novices and intermediates at spark.</p><h3>1 — Spark is a Grocery Store</h3><p>Spark is complex. To help both you and potentially others understand its structure, let’s leverage an impressively good analogy borrowed from <a href="https://en.wikipedia.org/wiki/Queueing_theory">queueing theory</a>: <strong>spark is a grocery store.</strong></p><p>When thinking about the distributed computing component of spark, there are three main components….</p><ul><li><strong>Data partitions: </strong>subsets of rows of our data. In our grocery store, they are <strong>groceries.</strong></li><li><strong>Spark tasks: </strong>low-level transformations performed on a data partition. In our grocery store, they are <strong>customers</strong>.</li><li><strong>Cores: </strong>the part of your processor(s) that do work in parallel. In our grocery store, they are <strong>cashiers</strong>.</li></ul><p>That’s it!</p><p>Now, let’s leverage these concepts to talk through some fundamentals of spark.</p><figure><img alt="spark partition data skew optimize optimization pyspark sql python UI partition" src="https://cdn-images-1.medium.com/max/1024/1*BX8-dGgSsPHBk0_4x41qfg.gif"><figcaption>Figure 3: illustration of the cashier analog, specifically for data skew. Image by author.</figcaption></figure><p>As show in figure 3, our cashiers (cores) can only process one customer (task) at a time. Furthermore, some customers have a lot of groceries (partition row count), as shown by the first customer at cashier 2. From these simple observations…</p><ul><li>The more cashiers (cores), the more customers (tasks) you can process in parallel. This is <a href="https://www.geeksforgeeks.org/horizontal-and-vertical-scaling-in-databases/#">horizontal/vertical scaling</a>.</li><li>If you don’t have enough customers (tasks) to saturate your cashiers (cores), you’ll be paying for the cashier to sit there. This relates to <a href="https://www.databricks.com/blog/2018/05/02/introducing-databricks-optimized-auto-scaling.html">autoscaling</a>, cluster sizing, and partition sizing.</li><li>If customers (tasks) have very different amounts of groceries (partition row counts), you’ll see uneven utilization of your cashiers. This is <a href="https://towardsdatascience.com/data-skew-in-pyspark-783d529a9dd7"><strong>data skew</strong></a>.</li><li>The better your cashiers (cores), the faster they can process a single customer (task). This relates to upgrading your processor.</li><li>etc.</li></ul><p>Given the analogy comes from queueing theory, a field directly related to distributed computing, it’s quite powerful!</p><blockquote>Use this analogy to debug, communicate, and develop spark.</blockquote><h3>2— Collect Data to Memory Once</h3><p>The most common mistake for spark novices is misunderstanding lazy evaluation.</p><p><a href="https://medium.com/@think-data/mastering-lazy-evaluation-a-must-know-for-pyspark-pros-ac855202495e">Lazy evaluation</a> means that no data transformations will be performed until you invoke a collection to memory. Examples of methods that invoke a collection include but are not limited to…</p><ul><li><a href="https://spark.apache.org/docs/latest/api/python/reference/pyspark.sql/api/pyspark.sql.DataFrame.collect.html">.collect()</a>: bring the DataFrame into memory as a python list.</li><li><a href="https://spark.apache.org/docs/latest/api/python/reference/pyspark.sql/api/pyspark.sql.DataFrame.show.html">.show()</a>: print the first n rows of your DataFrame.</li><li><a href="https://spark.apache.org/docs/latest/api/python/reference/pyspark.sql/api/pyspark.sql.DataFrame.count.html">.count()</a>: get the number of rows of your DataFrame.</li><li><a href="https://spark.apache.org/docs/3.1.1/api/python/reference/api/pyspark.sql.functions.first.html">.first()</a>: get the first row of your DataFrame.</li></ul><p>The single most common incorrect collection method is leveraging .count() throughout a program. Every time you invoke a collection, all upstream transformations will be recomputed from scratch, so if you have 5 invocations of .count(), your program will asymptotically run 5x as long.</p><blockquote>Spark is lazily evaluated! Pipelines should have a single flow from source(s) to target(s).</blockquote><h3>3— Meet the SLA then Stop</h3><p>A surprisingly common issue that’s come up when working with large organizations is they lose sight of the big picture and thereby optimize pipelines in an inefficient manner.</p><p>Here’s how pipelines should be optimized for the majority of use cases…</p><ol><li><strong>Ask if we need to do the project. </strong>Put simply, think about what you’re actually getting from optimizing a pipeline. If you expect to improve runtime by 20% and the pipeline costs $100 to run, should you invest your extremely expensive data engineer’s salary to save $20 per run? Maybe. Maybe not.</li><li><strong>Look for low hanging fruit in the code. </strong>After agreeing to do the project, check if the code has obvious flaws. Examples are misuse of lazy evaluation, unnecessary transformations, and incorrect ordering of transformations.</li><li><strong>Get the job running under the SLA by leveraging compute. </strong>After checking that the code is relatively efficient, just throw compute at the problem so you can 1) meet the SLA and, 2) gather statistics from the spark UI.</li><li><strong>Stop.</strong> If you’re properly saturating your compute and cost isn’t egregious, do some last minute compute improvements then stop. Your time is valuable. Don’t waste it saving dollars when you could be creating thousands of dollars elsewhere.</li><li><strong>Deep dive. </strong>Finally, if you really need to deep dive because cost is unacceptable, then roll up your sleeves and optimize data, code, and compute.</li></ol><p>The beauty of this framework is that 1–4 only require cursory knowledge of spark and are very quick to execute; sometimes you can collect information on steps 1–4 during a 30 minute call. The framework also ensures that we’ll stop as soon as we are <em>good enough</em>. Finally, if step 5 is needed, we can delegate that to those on the team who are strongest at spark.</p><blockquote>By finding all the ways to avoid over-optimizing a pipeline, you’re saving precious developer hours.</blockquote><h3>4 — Disk Spill</h3><p>Disk spill is the single most common reason that spark jobs run slow.</p><p>It’s a very simple concept. Spark is designed to leverage in-memory processing. If you don’t have enough memory, spark will try to write the extra data to disk to prevent your process from crashing. This is called disk spill.</p><figure><img alt="spark partition data skew optimize optimization pyspark sql python UI partition" src="https://cdn-images-1.medium.com/max/1024/1*g_GsUFBBrOEfMNPHhKicuQ.png"><figcaption>Figure 4: screen shot of the spark UI highlighting disk spill. Image by author.</figcaption></figure><p>Writing to and reading from disk is slow, so it should be avoided. If you want to learn how to identify and mitigate spill, follow <a href="https://selectfrom.dev/spark-performance-tuning-spill-7318363e18cb">this tutorial</a>. However, some very common and simple methods to mitigate spill are…</p><ol><li>Process less data per task, which can be achieved by changing the partition count via <a href="https://spark.apache.org/docs/latest/sql-performance-tuning.html#other-configuration-options">spark.shuffle.partitions</a> or <a href="https://spark.apache.org/docs/3.1.3/api/python/reference/api/pyspark.sql.DataFrame.repartition.html">repartition</a>.</li><li>Increase the RAM to core ratio in your compute.</li></ol><blockquote>If you want your job to run optimally, prevent spill.</blockquote><h3>5— Use SQL Syntax</h3><p>Whether you’re using scala, java, python, SQL, or R, spark will always leverage the same transformations under the hood. So, use the the right language for your task.</p><p>SQL is the least verbose “language” out of all supported spark languages for many operations! More tangibly:</p><ul><li>If you’re adding or modifying a column, use <a href="https://spark.apache.org/docs/3.1.3/api/python/reference/api/pyspark.sql.DataFrame.selectExpr.html">selectExpr</a> or <a href="https://spark.apache.org/docs/latest/api/python/reference/pyspark.sql/api/pyspark.sql.functions.expr.html">expr</a>, especially paired with Python’s <a href="https://realpython.com/python-f-strings/">f-strings</a>.</li><li>If you need complex SQL, create temp views then use <a href="https://spark.apache.org/docs/latest/api/sql/index.html">spark.sql()</a>.</li></ul><p>Here are two quick examples…</p><pre># Column rename and cast with SQL<br>df = df.selectExpr([f"{c}::int as {c}_abc" for c in df.columns])<br><br># Column rename and cast with native spark<br>for c in df.columns:<br>    df = df.withColumn(f"{c}_abc", F.col(c).cast("int")).drop(c)</pre><pre># Window functions with SQL<br>df.withColumn("running_total", expr(<br>  "sum(value) over (order by id rows between unbounded preceding and current row)"<br>))<br><br># Window functions with native spark<br>windowSpec = Window.orderBy("id").rowsBetween(Window.unboundedPreceding, Window.currentRow)<br>df_with_running_total_native = df.withColumn("running_total", F.sum("value").over(windowSpec))</pre><blockquote>Use SQL.</blockquote><h3>6— Glob Filters</h3><p>Do you need to read a bunch of data files stored in a complex directory? If so, use spark’s extremely powerful <a href="https://spark.apache.org/docs/latest/sql-data-sources-generic-options.html#generic-file-source-options">read options</a>.</p><p>The first time I encountered this problem, I rewrote <a href="https://www.tutorialspoint.com/python/os_walk.htm">os.walk</a> to work with my cloud provider where data was stored. I very proudly showed this method to my project partner who simply said, “let me share my screen,” and proceeded to introduce me to glob filters.</p><pre># Read all parquet files in the directory (and subdirectories)<br>df = spark.read.load(<br>  "examples/src/main/resources/dir1",<br>  format="parquet", <br>  pathGlobFilter="*.parquet"<br>)</pre><p>When I applied the glob filter shown above instead of my custom os.walk, the ingestion operation was over 10x faster.</p><blockquote>Spark has powerful parameters. Check if your desired functionality exists before building bespoke implementations.</blockquote><h3>7 — Use Reduce with DataFrame.Union</h3><p>Loops are almost always detrimental to spark performance. Here’s why…</p><p>Spark has two core phases — planning and execution. In the planning phase, spark creates a directed acyclical graph (DAG) which indicates how your specified transformations will be carried out. The planning phase is relatively expensive and can sometimes take several seconds, so you want to invoke it as infrequently as possible.</p><p>Let’s discuss a use case where you must iterate through many DataFrames, perform expensive transformations, then append them to a table.</p><p>First, there is native support for nearly all iterative use cases, specifically <a href="https://stackoverflow.com/questions/58170261/how-to-use-pandas-udf-in-class">pandas UDFs</a>, window functions, and joins. But, if you truly do need a loop, here’s how you invoke a single planning phase and thereby get all transformations in a single DAG.</p><pre>import functools<br>from pyspark.sql import DataFrame<br><br>paths = get_file_paths()<br><br># BAD: For loop<br>for path in paths:<br>  df = spark.read.load(path)<br>  df = fancy_transformations(df)<br>  df.write.mode("append").saveAsTable("xyz")<br><br># GOOD: functools.reduce<br>lazily_evaluated_reads = [spark.read.load(path) for path in paths]<br>lazily_evaluted_transforms = [fancy_transformations(df) for df in lazily_evaluated_reads]<br>unioned_df = functools.reduce(DataFrame.union, lazily_evaluted_transforms)<br>unioned_df.write.mode("append").saveAsTable("xyz")</pre><p>The first solution uses a for loop to iterate over paths, do fancy transformations, then append to our delta table of interest. In the second, we store a list of lazily evaluated DataFrames, apply transformations over them, then reduce them via a union, performing a single spark plan and write.</p><p>We can actually see the difference in architecture on the backend via the Spark UI…</p><figure><img alt="spark partition data skew optimize optimization pyspark sql python UI partition" src="https://cdn-images-1.medium.com/max/1024/1*LZ6Ytq85mTgGcZs-dqWxqQ.png"><figcaption>Figure 5: spark DAG for for loop vs. functools.reduce. Image by author.</figcaption></figure><p>In figure 5, the DAG on the left corresponding to the for loop will have 10 stages. However, the DAG on the right corresponding to functools.reduce will have a single stage and thereby can be processed more easily in parallel.</p><p>For a simple use case of reading 400 unique delta tables then appending to a delta table, this method was 6x faster than a for loop.</p><blockquote>Get creative to create a single spark DAG.</blockquote><h3>8 — Use ChatGPT</h3><p>This is not about hype.</p><p>Spark is a well-establish and thereby well-documented piece of software. LLMs, specifically GPT-4, are really good at distilling complex information into digestible and concise explanations. Since the release of GPT-4, I have not done a complex spark project where I didn’t heavily rely on GPT-4.</p><figure><img alt="spark partition data skew optimize optimization pyspark sql python UI partition" src="https://cdn-images-1.medium.com/max/1024/1*eCSwc1slXJ_mpS0PxUU7Tg.png"><figcaption>Figure 6: example of GPT-4 output on impacting data partition size in spark. Image by author.</figcaption></figure><p>However, stating the (hopefully) obvious, be careful with LLMs. Anything you send to a closed source model can become training data for the parent organization — make sure you don’t send anything sensitive. Also, please validate that the output from GPT is legit.</p><blockquote>When used properly, LLMs are game-changing for spark learning and development. It’s worth $20/month.</blockquote><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=f003c4743083" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/1-5-years-of-spark-knowledge-in-8-tips-f003c4743083">1.5 Years of Spark Knowledge in 8 Tips</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[foobar2000 2.6 - Advanced audio player.]]></title>
<description><![CDATA[foobar2000 is an advanced audio player.

Main features

Supported audio formats: MP3, MP4, AAC, CD Audio, WMA, Vorbis, Opus, FLAC, WavPack, WAV, AIFF, Musepack, Speex, AU, SND... and more with additional components.
Gapless playback.
Easily customizable user interface layout.
Advanced tagg...]]></description>
<link>https://tsecurity.de/de/1962880/ios-mac-os/foobar2000-26-advanced-audio-player/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1962880/ios-mac-os/foobar2000-26-advanced-audio-player/</guid>
<pubDate>Tue, 19 Dec 2023 13:16:15 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><strong>foobar2000</strong> is an advanced audio player.</p>

<h5>Main features</h5>
<ul>
<li>Supported audio formats: MP3, MP4, AAC, CD Audio, WMA, Vorbis, Opus, FLAC, WavPack, WAV, AIFF, Musepack, Speex, AU, SND... and more with additional components.</li>
<li>Gapless playback.</li>
<li>Easily customizable user interface layout.</li>
<li>Advanced tagging capabilities.</li>
<li>Support for ripping Audio CDs as well as transcoding all supported audio formats using the Converter component.</li>
<li>Full ReplayGain support.</li>
<li>Customizable keyboard shortcuts.</li>
<li>Open component architecture allowing third-party developers to extend functionality of the player.</li>
</ul><br><br><h5>Support for add-on components:</h5>
<ul>
<li>.fb2k-component format has been extended to include Mac architecture.</li>
<li>Added Components preferences page.</li>
<li>Module decoder is no longer included, available as add-on component.</li>
</ul>

<h5>Playback:</h5>
<ul>
<li>Added an option to toggle additional decoding (DTS, HDCD, etc) during playback, so you can play DTS-WAV without decoding DTS.</li>
<li>Changed how DSP settings are applied when playing through a high-latency output such as UPnP.</li>
<li>Fixed a bug that caused current track restart in certain scenarios, such as rapidly changing playback settings.</li>
<li>Rewritten full file buffer feature, no longer blocks until whole file has been read. Large FLAC files for an example should now open with no delay.</li>
<li>Greatly improved Audio Unit support.</li>
<li>Added Audio-Stretch DSP.</li>
</ul>

<h5>User interface:</h5>
<ul>
<li>ReFacets sorting changed to match playlist &amp; album list sorting.</li>
<li>Rewrote external album art lookup code, wildcard lookup now works where it didn't before.</li>
</ul>

<h5>Internet radio &amp; networking:</h5>
<ul>
<li>Added Internet Radio Search feature, using radio-browser.</li>
<li>Rewritten HLS radio playback.</li>
<li>Improved FTP/HTTP playback &amp; browsing, fewer connections used.</li>
<li>Lots of FTP issues fixed. Encrypted FTP now works properly.</li>
<li>Fixed specific cases of HTTP redirects being incorrectly handled.</li>
</ul>

<h5>Archive reading:</h5>
<ul>
<li>Fixed non-working extraction of .RSN (renamed .RAR).</li>
<li>Updated RAR unpacker code to the latest RAR library version.</li>
<li>Updated zlib to v1.3.</li>
<li>Fixed stack overflow with specific archive files in indexed music folders.</li>
</ul>

<h5>Codec updates:</h5>
<ul>
<li>Fixed incorrect handling of certain rare Monkey's Audio configurations.</li>
<li>Fixed missing decode postprocessor (DTS/HDCD etc) for TAK.</li>
<li>Fixed wrong reported length of certain RF64 WAV files.</li>
<li>Made possible to play Vorbis muxed into MP4.</li>
<li>Added support for tagging Wave64 &amp; RF64 formats.</li>
<li>Report LC-AAC codec long name as just "AAC".</li>
<li>Fixed missing HE-AAC delay compensation, breaking gapless playback of HE-AAC encoded with modern encoders.</li>
<li>Made possible to read &amp; write itunesalbumid &amp; itunesartistid tags in M4A/MP4.</li>
<li>Implemented reading of multiplexed Ogg files.</li>
<li>Fixed bad handling of undefined-length chunks in WAV files.</li>
<li>Made MP3 VBRI delay reported and skipped correctly. Note that VBRI files are still not gapless.</li>
<li>Fixed missing "encoding" info field for AC3.</li>
<li>Fixed DTS codec info for DTS in Matroska.</li>
<li>Made TAK MD5 checksums read without TAK decoder component, allowing audio integrity verification.</li>
<li>Made FLAC seektable tool also rewrite oversized seektables.</li>
<li>FLAC decoder: log premature EOF, mark partially encoded files as bad even if they don't appear corrupted otherwise.</li>
<li>Added standard %codec_long% field to properly display detailed names of all codecs.</li>
<li>Improved reporting of AAC &amp; DTS codec/profile info.</li>
<li>Fix for "DTS 96/24", made bit depth reported as 24-bit.</li>
<li>Made possible to decode float16 &amp; float24 WAVs again.</li>
<li>Made possible to read ReplayGain info from Musepack APE tags (normally it's supposed to be in Musepack headers).</li>
<li>Updated libopus to v1.4</li>
<li>Updated Monkey's Audio to 10.30.</li>
</ul>

<h5>Other:</h5>
<ul>
<li>Fixed bug in Media Library preventing previously-unplayable files from being reindexed after installation of new decoders (2.0 regression).</li>
<li>Improved recovery from corrupted configuration files.</li>
<li>Suppressed unnecessary playlist rewrite on autoplaylist startup.</li>
<li>Made search query GREATER/LESS/EQUAL treat numbers as floating-point rather than integer.</li>
</ul><br><br><a href="https://www.macupdate.com/app/mac/64315/foobar2000">Download Now</a><img src="https://desktop.macupdate.com/api/620/discover/ttra" height="1" width="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Using Polars Plugins for a 14x Speed Boost with Rust]]></title>
<description><![CDATA[Achieving high speed outside the native Polars libraryGenerated by DALL-E 3IntroductionPolars is taking the world by storm thanks to it’s speed, memory efficiency, and beautiful API. If you want to know how powerful it is, look no further than the DuckDB Benchmarks. And these aren’t even using th...]]></description>
<link>https://tsecurity.de/de/1922875/ai-nachrichten/using-polars-plugins-for-a-14x-speed-boost-with-rust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1922875/ai-nachrichten/using-polars-plugins-for-a-14x-speed-boost-with-rust/</guid>
<pubDate>Thu, 09 Nov 2023 20:04:39 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Achieving high speed outside the native Polars library</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*d80QiiyjjYXmFyY9NfD0VQ.png"><figcaption>Generated by DALL-E 3</figcaption></figure><h3>Introduction</h3><p><a href="https://www.pola.rs/">Polars</a> is taking the world by storm thanks to it’s speed, memory efficiency, and beautiful API. If you want to know how powerful it is, look no further than the <a href="https://duckdb.org/2023/04/14/h2oai.html#results">DuckDB Benchmarks</a>. And these aren’t even using the most recent version of Polars.</p><p>For all the amazing things Polars can do though, it has not traditionally been a better solution than Pandas to do ALL the calculations you might want to do. There are a few exceptions where Polars has not outperformed. With the recent release of the Polars plugin system for Rust though, that may no longer be the case.</p><h3>Polars Plugins</h3><p>What exactly is a polars plugin? It is simply a way to create your own Polars Expressions using native Rust and exposing those to expressions using a custom namespace. It allows you to take the speed of Rust, and apply it to your Polars DataFrame to perform calculations in a way that takes advantage of the speed and built-in tooling Polars provides.</p><p>Let’s take a look at some concrete examples.</p><h4>Sequential Calculations</h4><p>One area that Polars seems to lack some functionality is operations that require a knowledge of the previous value of a DataFrame. Calculations that are sequential in nature are not always super easy or efficient to write in native Polars expressions. Let’s take a look at one specific example.</p><p>We have the following algorithm to calculate the cumulative value of an array of numbers for a given run, defined as a set of numbers that have the same sign. For example:</p><pre>┌───────┬───────────┐<br>│ value ┆ run_value │<br>│ ---   ┆ ---       │<br>│ i64   ┆ i64       │<br>╞═══════╪═══════════╡<br>│ 1     ┆ 1         │   # First run starts here<br>│ 2     ┆ 3         │<br>│ 3     ┆ 6         │<br>│ -1    ┆ -1        │   # Run resets here<br>│ -2    ┆ -3        │<br>│ 1     ┆ 1         │   # Run resets here<br>└───────┴───────────┘</pre><p>So we want to have a cumulative sum of a column which resets every time the sign of the value switches from either positive to negative or negative to positive.</p><p>Lets start with a baseline version written in pandas.</p><pre>def calculate_runs_pd(s: pd.Series) -&gt; pd.Series:<br>    out = []<br>    is_positive = True<br>    current_value = 0.0<br>    for value in s:<br>        if value &gt; 0:<br>            if is_positive:<br>                current_value += value<br>            else:<br>                current_value = value<br>                is_positive = True<br>        else:<br>            if is_positive:<br>                current_value = value<br>                is_positive = False<br>            else:<br>                current_value += value<br>        out.append(current_value)<br>    return pd.Series(out)</pre><p>We iterate over a series, calculating the current value of the run at each position, and returning a new Pandas Series.</p><h4>Benchmarking</h4><p>Before moving on, we are going to set up a few benchmarks. We are going to measure both execution speed and memory consumption using <a href="https://pypi.org/project/pytest-benchmark/">pytest-benchmark</a> and <a href="https://pytest-memray.readthedocs.io/en/latest/">pytest-memray</a>. We will set up the problem such that we have an entity column, a time column, and a feature column. The goal is to calculate the run values for each entity in the data across time. We will set the number of entities and time stamps each to 1,000, giving us a DataFrame with 1,000,000 rows.</p><p>When we run our Pandas implementation against our benchmark using Pandas’ groupby apply functionality we get the following results:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*l6H3UXHDoDJaeQV0oJ1xMA.png"><figcaption>Pandas Apply Pytest-Benchmark (Image by Author)</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/680/1*wMwjHHWM-DzJ-DhPPGhnSA.png"><figcaption>Memray Output for Pandas Apply (Image by Author)</figcaption></figure><h4>Polars Naive Implementation</h4><p>Okay, so now we have our benchmark. Let’s look at implementing this same functionality in Polars now. We will start with a very similar looking version that will be applied by mapping the function across a Polars GroupBy object.</p><pre>def calculate_runs_pl_apply(s: pl.Series) -&gt; pl.DataFrame:<br>    out = []<br>    is_positive = True<br>    current_value = 0.0<br>    for value in s:<br>        if value is None:<br>            pass<br>        elif value &gt; 0:<br>            if is_positive:<br>                current_value += value<br>            else:<br>                current_value = value<br>                is_positive = True<br>        else:<br>            if is_positive:<br>                current_value = value<br>                is_positive = False<br>            else:<br>                current_value += value<br>        out.append(current_value)<br>    return pl.DataFrame(pl.Series("run", out))</pre><p>Now let’s see how this compares to our original Pandas benchmark.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*JCyRMEpYqKb1p16ALKAWSQ.png"><figcaption>Pandas Apply vs Polars Apply Pytest-Benchmark (Image by Author)</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/688/1*mjyzKCTkKBWi2umPUCyalA.png"><figcaption>Memray Output for Polars Apply (Image by Author)</figcaption></figure><p>Well, that didn’t work very well. That shouldn’t come as a surprise though. The writers of Polars have made it very clear that the very common groupby apply approach in Pandas is not an efficient way to do computations in Polars. Here it shows. Both the speed and memory consumption are worse than our original Pandas implementation.</p><h4>Polars Expression Implementation</h4><p>Let’s write this same function as native Polars expressions now. This is the preferred and optimized way to work with Polars. The algorithm will look a little different. But here is what I came up with to calculate the same output.</p><pre>def calculate_runs_pl_native(df: pl.LazyFrame, col: str, by: str) -&gt; pl.LazyFrame:<br>    return (<br>        df.with_columns((pl.col(col) &gt; 0).alias("__is_positive"))<br>        .with_columns(<br>            (pl.col("__is_positive") != pl.col("__is_positive").shift(1))<br>            .over(by)<br>            .fill_null(False)<br>            .alias("__change_sides")<br>        )<br>        .with_columns(pl.col("__change_sides").cumsum().over(by).alias("__run_groups"))<br>        .with_columns(pl.col(col).cumsum().over(by, "__run_groups").alias("runs"))<br>        .select(~cs.starts_with("__"))<br>    )</pre><p>A quick explanation for what we are doing here:</p><ul><li>Find all the rows where the feature is positive</li><li>Find all the rows where the __is_positive column is different from the previous row.</li><li>Take a cumulative sum of __change_sides to mark each distinct run</li><li>Take a cumulative sum of the value over each distinct run</li></ul><p>So now we have our native Polars function. Let’s do our benchmark again.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vTB6iAkwwOcOej6ZHlaA_Q.png"><figcaption>Pandas Apply vs Polars Apply vs Polars Native Pytest-Benchmark (Image by Author)</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/676/1*yWyaVXJmpFRPkawdh99x-Q.png"><figcaption>Memray Output for Polars Native (Image by Author)</figcaption></figure><p>We unfortunately did not see an improvement in the execution speed of our function. This is likely due to the number of over statements we have to do in order to calculate the run values. We did however, see an expected memory reduction. There may be an even better way to implement this with Polars expressions, but I am not going to worry about it right now.</p><h4>Polars Plugins</h4><p>So now let’s take a look at the new Polars plugins. If you want a tutorial on setting these up, take a look at <a href="https://pola-rs.github.io/polars/user-guide/expressions/plugins/">the documentation here.</a> Here I am mostly going to show a specific implementation of a plugin. First we are going to write our algorithm in Rust.</p><pre>use polars::prelude::*;<br>use pyo3_polars::derive::polars_expr;<br><br>#[polars_expr(output_type=Float64)]<br>fn calculate_runs(inputs: &amp;[Series]) -&gt; PolarsResult&lt;Series&gt; {<br>    let values = inputs[0].f64()?;<br>    let mut run_values: Vec&lt;f64&gt; = Vec::with_capacity(values.len());<br>    let mut current_run_value = 0.0;<br>    let mut run_is_positive = true;<br>    for value in values {<br>        match value {<br>            None =&gt; {<br>                run_values.push(current_run_value);<br>            }<br>            Some(value) =&gt; {<br>                if value &gt; 0.0 {<br>                    if run_is_positive {<br>                        current_run_value += value;<br>                    } else {<br>                        current_run_value = value;<br>                        run_is_positive = true;<br>                    }<br>                } else if run_is_positive {<br>                    current_run_value = value;<br>                    run_is_positive = false;<br>                } else {<br>                    current_run_value += value;<br>                }<br>                run_values.push(current_run_value);<br>            }<br>        }<br>    }<br><br>    Ok(Series::from_vec("runs", run_values))<br>}</pre><p>You will notice this looks pretty similar to the algorithm we wrote in Python. We aren’t doing any fancy Rust magic here! We denote the output type using a macro that polars provides and that is it. We can then register our new function as an expression.</p><pre>from polars import selectors as cs<br>from polars.utils.udfs import _get_shared_lib_location<br><br>lib = _get_shared_lib_location(__file__)<br><br><br>@pl.api.register_expr_namespace("runs")<br>class RunNamespace:<br>    def __init__(self, expr: pl.Expr):<br>        self._expr = expr<br><br>    def calculate_runs(<br>        self,<br>    ) -&gt; pl.Expr:<br>        return self._expr.register_plugin(<br>            lib=lib,<br>            symbol="calculate_runs",<br>            is_elementwise=False,<br>            cast_to_supertypes=True,<br>        )</pre><p>And then we can run it like this:</p><pre>from polars_extentsion import RunNamespace<br><br>df.select(<br>  pl.col(feat_col).runs.calculate_runs().over(entity_col).alias("run_value")<br>).collect()</pre><p>Okay now lets check out the results!</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mXkum5gcJxfzHR2WzTs4-w.png"><figcaption>All Implementations Pytest-Benchmark (Image by Author)</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/682/1*atgKUXpFfO8tuxb7Rna3bg.png"><figcaption>Memory Output for Polars Plugin (Image by Author)</figcaption></figure><p>Now that is more like it! We got a 14x speed improvement and dropped from ~57MiB to ~8MiB of memory allocated.</p><h3>When to Use Polars Plugins</h3><p>Now that I have shown the power of using plugins, let’s talk about when you shouldn’t use them. A few reasons I might not use plugins (each with it’s own caveats):</p><ul><li><strong>If you can easily write a really fast version of your calculation using native Polars expressions. </strong>The Polars developers are really smart. I would not bet money on myself writing a function significantly faster than they can. The tools for Polars are there. Take advantage of what they are good at!</li><li><strong>If there is no natural parallelization for your calculation</strong>. For example, if we were not running the above problem over multiple entities, our speedup would likely have been significantly less. We benefitted both from the speed of Rust, and the natural ability of Polars to apply our Rust function over multiple groups at once.</li><li><strong>If you don’t need top notch speed or memory performance. </strong>Many people will agree that writing Rust is much more difficult and time consuming than writing Python. So if you don’t care if your function takes 2 seconds to run instead of 200 ms, you may not need to use plugins.</li></ul><p>Keeping the things above in mind, here are now a few requirements that I feel pull me towards using plugins sometimes:</p><ul><li><strong>Speed and memory matter a lot. </strong>I recently rewrote a lot of a data pipeline’s functionality in a Polars plugin because we were switching back and forth between Polars and other tools and the memory allocations were getting too big. It was getting hard to run the pipeline on the infrastructure we wanted to with the amount of data we wanted to. The plugins made it easy to run the same pipeline in much less time and on a much smaller machine.</li><li><strong>You have a unique use case. </strong>Polars provides so many built in functions. But it is a generic toolset that is broadly applicable to a lot of problems. Sometimes that toolset is not specifically applicable to the problem you are trying to solve. In this case, a plugin might be exactly what you want. Two of the most common examples of this that I have run into are more intense mathematical calculations, such as applying a cross-sectional linear regression, or sequential (row-based) calculations as we showed here.</li></ul><p>The new plugin system is the perfect compliment to all of the columnar-based calculations that Polars already supports out of the box. With this addition, Polars is allowing for a beautiful extensibility to its capabilities. On top of writing your own plugins, watch out for some cool Polars plugin packages being developed that you can use to extend your capabilities without having to write plugins yourself!</p><p>Polars is moving fast and making waves. Check out the project, start using it, watch out for what other awesome features they will be releasing, and maybe start learning a little Rust while you are at it!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=ce80bcc13d94" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/using-polars-plugins-for-a-14x-speed-boost-with-rust-ce80bcc13d94">Using Polars Plugins for a 14x Speed Boost with Rust</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[#TheAndroidShow: Faster and easier to build excellent apps, across devices.]]></title>
<description><![CDATA[Posted by Anirudh Dewani, Director of Android Developer Relations



We just wrapped another episode of #TheAndroidShow; in the show, we covered the latest in Android development, including a look at the new Pixel watch and the world of wearables, gathered the team to demo tools and libraries to ...]]></description>
<link>https://tsecurity.de/de/1909813/android-tipps/theandroidshow-faster-and-easier-to-build-excellent-apps-across-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1909813/android-tipps/theandroidshow-faster-and-easier-to-build-excellent-apps-across-devices/</guid>
<pubDate>Sun, 29 Oct 2023 06:01:44 +0100</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhdHA7ADz5u58NXcPIdFiK5Z68VL5w1P1cYsdp1UnhMDs6nfoczLiRUzIYRxO1_RZ3mfmenuVhmfdgRMhViHyT__VfiaiOwAIdowUZHFL4sEySVreIh6HqpMcvAWqhKLUj_Bou6ocSexz1wpuwRIdb3R-TrQVLrBe1u1QiJC59EGdFR8zdZpuEPoGMO3rg/s1600/TAS_AdBlog_%23TheAndroidShow_Social.png">

<em>Posted by Anirudh Dewani, Director of Android Developer Relations</em>

<a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqdR_p45WjfmrbTqvjkyUo-xNz73qUrbiLxuT8DhjTHQNwjjA0u2Rk5lRoJWYEJq2HHap5AauXFdk1PuhFyamnnM5EeKAj-IStBsNC4YdNFrWQQZBFidjI3qp4_KCwTaFi9w2RXM36JIVW2wvghOtmhuDgVCFB2n2mw4biXgcx-ej0EeNMc4anLAoeMPs/s1600/TAS_AdBlog_%23TheAndroidShow_Header.png" imageanchor="1"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqdR_p45WjfmrbTqvjkyUo-xNz73qUrbiLxuT8DhjTHQNwjjA0u2Rk5lRoJWYEJq2HHap5AauXFdk1PuhFyamnnM5EeKAj-IStBsNC4YdNFrWQQZBFidjI3qp4_KCwTaFi9w2RXM36JIVW2wvghOtmhuDgVCFB2n2mw4biXgcx-ej0EeNMc4anLAoeMPs/s1600/TAS_AdBlog_%23TheAndroidShow_Header.png" data-original-width="100%" data-original-height="800"></a>

<p>We just wrapped <a href="http://android-developers.googleblog.com/2023/10/developer.android.com/events/show" target="_blank">another episode of #TheAndroidShow</a>; in the show, we covered the latest in Android development, including a look at the new Pixel watch and the world of wearables, gathered the team to demo tools and libraries to build for foldables, large screen devices, with Compose, Android 14, Studio Bot, and more. <a href="http://d.android.com/events/show" target="_blank">Take a look</a>, and here’s a recap of some of the ways we’re helping make it <b>faster and easier to build excellent apps, across devices:</b> </p>



<h3>Studio Bot: improving your productivity, through Generative AI</h3>

<p>At <a href="https://www.youtube.com/live/r8T0SnwHRNI?si=UcjRJkm3cwykwe0u&amp;t=687" target="_blank">Google I/O</a> we gave you a preview of <a href="https://www.youtube.com/live/r8T0SnwHRNI?si=UcjRJkm3cwykwe0u&amp;t=687" target="_blank">Studio Bot</a>, an AI powered coding assistant that is tightly integrated into Android Studio, designed to make Android development faster and easier. Last month, <a href="https://android-developers.googleblog.com/2023/09/studio-bot-expands-to-international-markets.html" target="_blank">Studio Bot expanded into over 170 countries</a>, and today we’re adding even more functionality in <a href="https://developer.android.com/studio/preview" target="_blank">the latest canary release</a> to help you be more productive. <a href="https://developer.android.com/studio/preview/studio-bot/ai-code-completion" target="_blank">AI code completion</a> enables you to receive suggestions for more complex code completions, such as multiline code or even entire functions. You can also now add comments to your code, and document code with just a click using Studio Bot. We caught up with Jamal Eason to learn about the investments the team is working on, including our improvements in quality.</p>



<h3>Faster and easier to build, with Jetpack Compose</h3>

<p>Jetpack Compose gives you powerful and intuitive APIs, which make it faster and easier to build UIs. Since Google I/O, we’ve been working on <a href="https://android-developers.googleblog.com/2023/08/whats-new-in-jetpack-compose-august-23-release.html" target="_blank">improving performance</a> across Compose to make it even more helpful. Developers around the world are taking advantage of Compose to help them rewrite screens, build new screens, or create new apps. For example, The Reddit team adopted Compose for their design system, which improved their code flexibility and reduced code duplication. They rewrote several features in Compose and their new tech stack, one of them being <a href="https://medium.com/androiddevelopers/building-reddit-recap-with-jetpack-compose-on-android-dbe34ae4c957" target="_blank">Reddit Recap</a>, with beautiful animations. They were able to achieve feature parity with 44% less code when they rewrote it using Compose, saving engineering resources and time. </p>



<h3>Build across devices, with large screens</h3>

<p>Foldables and tablets are an important space - and the market for large screens is growing with Samsung announcing that half of their users are thinking of making a foldable their next phone. We’re continuing to build tools and libraries to make it easier to build for different device types, including <a href="https://developer.android.com/studio/preview/android-device-streaming" target="_blank">device streaming</a> and new drag and drop APIs in Compose. See how <a href="https://android-developers.googleblog.com/2023/10/zoom-optimized-for-large-screens-on-android.html" target="_blank">Zoom saw 2x higher user engagement and optimized their app for large screens</a>, and get started with making your app work better across screen sizes and form factors.</p>



<h3>The latest in wearables, with Wear OS 4 and Pixel Watch 2</h3>

<p>Earlier this month, we saw the launch of Google Pixel Watch 2 - the first Google watch with all the capabilities of Wear OS 4! The latest version of Wear OS offers several capabilities that make it easier to develop exceptional wearable experiences, from <a href="https://developer.android.com/training/wearables/wff" target="_blank">Watch Face Format</a> to enhanced tiles and more. <a href="https://android-developers.googleblog.com/2023/10/wear-os-4-is-now-stable-and-available-on-google-pixel-watch-2.html" target="_blank">Read more</a> to discover the latest updates to Wear OS and how you can get started!</p>



<h3>Making excellent, premium apps</h3>

<p>Earlier this month, <a href="https://android-developers.googleblog.com/2023/10/android-14-is-live-in-aosp.html" target="_blank">Android 14 started rolling out to users</a> around the world. So there’s no better time to start optimizing your apps for the release and taking advantage of new features in <a href="https://developer.android.com/about/versions/14" target="_blank">Android 14</a> to help you build excellent experiences for your users using the best of Android, such as improved camera functionality with <a href="https://developer.android.com/guide/topics/media/platform/hdr-image-format" target="_blank">UltraHDR</a>, seamless authentication with Credential Manager and enhanced widget development with Jetpack Glance. In the show, we saw how Snapchat used <a href="https://developer.android.com/training/sign-in/passkeys" target="_blank">Camera2 Extension API</a> to build camera features such as night mode, zoom, and tap-to-focus, enhancing their user’s experience capturing high-quality Snaps on Android devices, and also had a conversation with Dave Burke about Android 14 and more. Take a look! </p>



<h3>Connecting with you at events around the world</h3>

<p>This year, we're excited to bring the Android team and our Android Google Developer Expert friends to events around the world, <a href="https://android-developers.googleblog.com/2023/10/events-tas.html" target="_blank">you can learn more about it here</a>. Later this month, the Android team will be at Droidcon London (October 26-27), bringing talks and hosting office hours around many exciting topics, and a panel of subject matter experts. Android GDEs will be speaking at 100+ DevFest events around the world, with special appearances from the Android team at DevFests in New York, the Bay Area, London, and Singapore among others. We look forward to connecting with thousands of you in person!</p><br>

<p>Missed the show? You can watch it <a href="https://developer.android.com/events/show" target="_blank">here</a>, or check out the full playlist <a href="https://www.youtube.com/playlist?list=PLWz5rJ2EKKc9ECua7vzYbowdn-0L8WwHL" target="_blank">here</a>. This is your conversation with the broader Android community, and if you’ve got an idea for the next show, we’d love to hear it - send us a Tweet, or share a message in the comments. We can’t wait to hear from you! </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Economic Times quest for fixing INP]]></title>
<description><![CDATA[Interaction to Next Paint (INP) is a metric that assesses a website's responsiveness to user input. Good responsiveness means that a page is quick to respond to user interactions. The lower a page's INP is, the better it is able to respond to user interactions.

  .inp-mobile {
    display: inlin...]]></description>
<link>https://tsecurity.de/de/1886629/web-tipps/economic-times-quest-for-fixing-inp/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1886629/web-tipps/economic-times-quest-for-fixing-inp/</guid>
<pubDate>Wed, 24 May 2023 09:44:46 +0200</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://web.dev/inp/">Interaction to Next Paint (INP)</a> is a metric that assesses a website's responsiveness to user input. Good responsiveness means that a page is quick to respond to user interactions. The lower a page's INP is, the better it is able to respond to user interactions.</p>
<style>
  .inp-mobile {
    display: inline;
  }

  .inp-desktop {
    display: none;
  }

  @media screen and (min-width: 640px) {
    .inp-mobile {
      display: none;
    }

    .inp-desktop {
      display: inline;
    }
  }
</style>
<figure>
  <svg title="A diagram of the INP thresholds. An INP at or below 200 milliseconds is considered good. Between 200 and 500 milliseconds suggests a page's responsiveness needs improvement. Anything over 500 milliseconds means that a page's responsiveness is poor." class="inp-mobile" version="1.1" id="Layer_1" xmlns="http://www.w3.org/2000/svg" x="0" y="0" viewBox="0 0 296.6 220.2" style="enable-background:new 0 0 296.6 220.2" xml:space="preserve"><style>.st0{fill:#2979FF} .st1{fill-rule:evenodd;clip-rule:evenodd;fill:#0CCE6B} .st2{fill:#191919} .st3{fill-rule:evenodd;clip-rule:evenodd;fill:#FFA400} .st4{fill-rule:evenodd;clip-rule:evenodd;fill:#FF4E42} @media screen and (prefers-color-scheme: light){.st2{fill:#191919}} [data-user-theme=light] .st2 {fill:#191919} @media screen and (prefers-color-scheme: dark){.st2{fill:#fff}} [data-user-theme=dark] .st2{fill:#fff}</style><path class="st0" d="M83.3 63V0h11.9v63H83.3zm26.3 0V0h13.8l25.3 42.2h.7l-.7-12.1V0h11.8v63H148l-26.8-44.6h-.7l.7 12.1V63h-11.6zm65.4 0V0h22.2c4.1 0 7.7.8 10.9 2.5s5.8 4 7.7 7 2.9 6.4 2.9 10.4c0 3.9-1 7.4-2.9 10.4s-4.5 5.4-7.7 7c-3.2 1.7-6.9 2.5-10.9 2.5h-15.6V28.6h15.9c2.1 0 3.8-.4 5.2-1.2s2.5-1.9 3.2-3.2c.7-1.3 1.1-2.8 1.1-4.3s-.4-2.9-1.1-4.2c-.7-1.3-1.8-2.3-3.2-3.2s-3.1-1.2-5.2-1.2h-10.7V63H175z"></path><path class="st1" d="M0 137.1h96v38.4H0v-38.4z"></path><path class="st2" d="M34 161c-.6 0-1.2-.1-1.8-.3-.5-.2-1-.5-1.4-.9-.4-.4-.7-.9-1-1.4-.2-.6-.3-1.1-.3-1.8 0-.6.1-1.2.3-1.8.2-.6.6-1 1-1.4.4-.4.9-.7 1.4-.9.5-.2 1.1-.3 1.8-.3s1.3.1 1.8.3c.6.2 1 .6 1.4 1l-.9.9c-.2-.2-.4-.4-.6-.5-.2-.1-.5-.3-.8-.3-.3-.1-.6-.1-.9-.1-.4 0-.8.1-1.2.2-.4.1-.7.4-1 .6-.3.3-.5.6-.7 1-.2.4-.2.8-.2 1.3s.1.9.2 1.3c.2.4.4.7.7 1 .3.3.6.5 1 .7.4.1.8.2 1.2.2.4 0 .8-.1 1.1-.2.3-.1.6-.3.9-.5.3-.2.5-.5.6-.8.2-.3.3-.6.3-1H34v-1.2h4.2v.7c0 .6-.1 1.2-.3 1.7-.2.5-.5.9-.9 1.3s-.8.6-1.3.8c-.5.3-1.1.4-1.7.4zm9.5 0c-.6 0-1.2-.1-1.8-.3-.5-.2-1-.5-1.4-1-.4-.4-.7-.9-.9-1.4-.2-.5-.3-1.1-.3-1.8 0-.6.1-1.2.3-1.8.2-.5.5-1 .9-1.4.4-.4.9-.7 1.4-1 .5-.2 1.1-.3 1.8-.3.6 0 1.2.1 1.8.3.5.2 1 .6 1.4 1 .4.4.7.9.9 1.4.2.5.3 1.1.3 1.8 0 .6-.1 1.2-.3 1.8-.2.5-.5 1-.9 1.4-.4.4-.9.7-1.4 1-.5.2-1.1.3-1.8.3zm0-1.2c.6 0 1.1-.1 1.6-.4.5-.3.8-.7 1.1-1.1.3-.5.4-1.1.4-1.7 0-.6-.1-1.2-.4-1.7-.3-.5-.7-.9-1.1-1.1-.5-.3-1-.4-1.6-.4-.6 0-1.1.1-1.6.4-.5.3-.8.7-1.1 1.1-.3.5-.4 1-.4 1.7 0 .6.1 1.2.4 1.7.3.5.7.9 1.1 1.1.5.3 1 .4 1.6.4zm9.9 1.2c-.6 0-1.2-.1-1.8-.3-.5-.2-1-.5-1.4-1-.4-.4-.7-.9-.9-1.4-.2-.5-.3-1.1-.3-1.8 0-.6.1-1.2.3-1.8.2-.5.5-1 .9-1.4.4-.4.9-.7 1.4-1 .5-.2 1.1-.3 1.8-.3.6 0 1.2.1 1.8.3.5.2 1 .6 1.4 1 .4.4.7.9.9 1.4.2.5.3 1.1.3 1.8 0 .6-.1 1.2-.3 1.8-.2.5-.5 1-.9 1.4-.4.4-.9.7-1.4 1-.6.2-1.2.3-1.8.3zm0-1.2c.6 0 1.1-.1 1.6-.4.5-.3.8-.7 1.1-1.1.3-.5.4-1.1.4-1.7 0-.6-.1-1.2-.4-1.7-.3-.5-.7-.9-1.1-1.1-.5-.3-1-.4-1.6-.4-.6 0-1.1.1-1.6.4-.5.3-.8.7-1.1 1.1-.3.5-.4 1-.4 1.7 0 .6.1 1.2.4 1.7.3.5.7.9 1.1 1.1.5.3 1 .4 1.6.4zm6 1.1v-8.6h2.8c.9 0 1.7.2 2.3.5.7.4 1.2.9 1.5 1.5.4.6.5 1.4.5 2.2 0 .8-.2 1.6-.5 2.2-.4.6-.9 1.2-1.5 1.5-.6.4-1.4.5-2.3.5h-2.8zm1.3-1.3h1.4c.6 0 1.2-.1 1.7-.4.5-.3.8-.6 1.1-1 .2-.5.4-1 .4-1.6 0-.6-.1-1.2-.4-1.6-.2-.5-.6-.8-1.1-1-.5-.3-1-.4-1.7-.4h-1.4v6z"></path><path class="st3" d="M96 137.1h105.6v38.4H96v-38.4z"></path><path class="st2" d="M130.8 153.9v-8.6h1.6l3.9 6.3h.1l-.1-1.7v-4.7h1.3v8.6h-1.4l-4.1-6.6h-.1l.1 1.7v5h-1.3zm8.7 0v-8.6h5.2v1.2h-3.9v6.1h3.9v1.2h-5.2zm.7-3.7V149h4.1v1.2h-4.1zm6.2 3.7v-8.6h5.2v1.2h-3.9v6.1h3.9v1.2h-5.2zm.7-3.7V149h4.1v1.2h-4.1zm6.1 3.7v-8.6h2.8c.9 0 1.7.2 2.3.5.7.4 1.2.9 1.5 1.5.4.6.5 1.4.5 2.2s-.2 1.6-.5 2.2c-.4.6-.9 1.2-1.5 1.5-.6.4-1.4.5-2.3.5h-2.8zm1.3-1.3h1.4c.6 0 1.2-.1 1.7-.4.5-.2.8-.6 1.1-1 .2-.5.4-1 .4-1.6 0-.6-.1-1.2-.4-1.6-.2-.5-.6-.8-1.1-1-.5-.2-1-.4-1.7-.4h-1.4v6zm9.9 1.4c-.5 0-.9-.1-1.3-.3-.4-.2-.8-.4-1.1-.8-.3-.4-.5-.8-.7-1.3l1.2-.5c.1.5.3.9.7 1.2.3.3.7.5 1.2.5.3 0 .5 0 .8-.1.2-.1.4-.2.6-.4s.2-.4.2-.7c0-.3-.1-.5-.2-.7-.1-.2-.3-.3-.6-.5s-.6-.3-1-.5l-.5-.2c-.2-.1-.5-.2-.7-.3-.2-.1-.5-.3-.7-.5-.2-.2-.4-.4-.5-.7-.1-.3-.2-.6-.2-.9 0-.4.1-.8.3-1.2.2-.4.5-.6.9-.8.4-.2.9-.3 1.4-.3.6 0 1 .1 1.4.3.4.2.7.4.9.7.2.3.4.5.4.8l-1.2.5c0-.2-.1-.3-.2-.5s-.3-.3-.5-.4c-.2-.1-.4-.2-.8-.2-.2 0-.5.1-.7.2-.2.1-.4.2-.5.4-.1.2-.2.3-.2.6s.1.6.4.8c.3.2.6.4 1.1.5l.6.2c.3.1.6.2.8.3.3.1.5.3.7.5.2.2.4.4.5.7.1.3.2.6.2 1s-.1.8-.3 1.2c-.2.3-.4.6-.7.8-.3.2-.6.3-.9.4s-.5.2-.8.2zM107 167.9v-8.6h1.3v8.6H107zm3.2 0v-8.6h1.8l2.5 6.5h.1l2.5-6.5h1.8v8.6h-1.3V163l.1-1.5h-.1l-2.5 6.4h-1l-2.5-6.4h-.1l.1 1.5v4.9h-1.4zm10.6 0v-8.6h3c.5 0 1 .1 1.4.3.4.2.8.5 1 .9.3.4.4.9.4 1.4 0 .5-.1 1-.4 1.4-.2.4-.6.7-1 .9-.4.2-.9.3-1.4.3h-2.2v-1.2h2.3c.3 0 .6-.1.8-.2.2-.1.4-.3.5-.5.1-.2.2-.4.2-.7 0-.2-.1-.4-.2-.7-.1-.2-.3-.4-.5-.5-.2-.1-.5-.2-.8-.2h-1.7v7.3h-1.4zm7.2 0v-8.6h3c.5 0 1 .1 1.4.3.4.2.7.5 1 .9.2.4.4.8.4 1.4 0 .3-.1.7-.2 1s-.3.6-.6.8c-.3.2-.6.4-1 .6-.4.1-.8.2-1.2.2h-2.1v-1.2h2.3c.3 0 .5-.1.7-.2.2-.1.4-.3.5-.5.1-.2.2-.5.2-.7 0-.2-.1-.5-.2-.7-.1-.2-.3-.4-.5-.5-.2-.1-.5-.2-.8-.2h-1.7v7.4H128zm2-4h1.5l2.7 3.9v.1h-1.5l-2.7-4zm9.3 4.1c-.6 0-1.2-.1-1.8-.3-.5-.2-1-.5-1.4-1-.4-.4-.7-.9-.9-1.4-.2-.5-.3-1.1-.3-1.8s.1-1.2.3-1.8c.2-.5.5-1 .9-1.4.4-.4.9-.7 1.4-1 .5-.2 1.1-.3 1.8-.3.6 0 1.2.1 1.8.3.5.2 1 .6 1.4 1 .4.4.7.9.9 1.4.2.5.3 1.1.3 1.8s-.1 1.2-.3 1.8c-.2.5-.5 1-.9 1.4-.4.4-.9.7-1.4 1-.6.2-1.2.3-1.8.3zm0-1.2c.6 0 1.1-.1 1.6-.4.5-.3.8-.7 1.1-1.1.3-.5.4-1.1.4-1.7 0-.6-.1-1.2-.4-1.7-.3-.5-.7-.9-1.1-1.1-.5-.3-1-.4-1.6-.4-.6 0-1.1.1-1.6.4-.5.3-.8.7-1.1 1.1-.3.5-.4 1-.4 1.7 0 .6.1 1.2.4 1.7.3.5.7.9 1.1 1.1.5.3 1 .4 1.6.4zm7.9 1.1-3-8.6h1.4l1.9 5.7.3 1h.1l.3-1 2-5.7h1.4l-3.1 8.6h-1.3zm5.6 0v-8.6h5.2v1.2h-3.9v6.1h3.9v1.2h-5.2zm.7-3.7V163h4.1v1.2h-4.1zm6.2 3.7v-8.6h1.8l2.5 6.5h.1l2.5-6.5h1.8v8.6H167V163l.1-1.5h-.1l-2.5 6.4h-1l-2.5-6.4h-.1l.1 1.5v4.9h-1.3zm10.6 0v-8.6h5.2v1.2h-3.9v6.1h3.9v1.2h-5.2zm.7-3.7V163h4.1v1.2H171zm6.1 3.7v-8.6h1.6l3.9 6.3h.1l-.1-1.7v-4.7h1.3v8.6h-1.4l-4.1-6.6h-.1l.1 1.7v5h-1.3zm10.5 0V160h1.3v7.9h-1.3zm-2.4-7.4v-1.2h6.1v1.2h-6.1z"></path><path class="st4" d="M200.6 137.1h96v38.4h-96v-38.4z"></path><path class="st2" d="M232.5 160.9v-8.6h3c.5 0 1 .1 1.4.3.4.2.8.5 1 .9.3.4.4.9.4 1.4 0 .5-.1 1-.4 1.4-.2.4-.6.7-1 .9-.4.2-.9.3-1.4.3h-2.2v-1.2h2.3c.3 0 .6-.1.8-.2.2-.1.4-.3.5-.5.1-.2.2-.4.2-.7 0-.2-.1-.4-.2-.7-.1-.2-.3-.4-.5-.5-.2-.1-.5-.2-.8-.2h-1.7v7.3h-1.4zm11 .1c-.6 0-1.2-.1-1.8-.3-.5-.2-1-.5-1.4-1-.4-.4-.7-.9-.9-1.4-.2-.5-.3-1.1-.3-1.8s.1-1.2.3-1.8c.2-.5.5-1 .9-1.4.4-.4.9-.7 1.4-1 .5-.2 1.1-.3 1.8-.3.6 0 1.2.1 1.8.3.5.2 1 .6 1.4 1 .4.4.7.9.9 1.4.2.5.3 1.1.3 1.8s-.1 1.2-.3 1.8c-.2.5-.5 1-.9 1.4-.4.4-.9.7-1.4 1-.5.2-1.1.3-1.8.3zm0-1.2c.6 0 1.1-.1 1.6-.4.5-.3.8-.7 1.1-1.1.3-.5.4-1.1.4-1.7 0-.6-.1-1.2-.4-1.7-.3-.5-.7-.9-1.1-1.1-.5-.3-1-.4-1.6-.4-.6 0-1.1.1-1.6.4-.5.3-.8.7-1.1 1.1-.3.5-.4 1-.4 1.7 0 .6.1 1.2.4 1.7.3.5.7.9 1.1 1.1.6.3 1.1.4 1.6.4zm9.9 1.2c-.6 0-1.2-.1-1.8-.3-.5-.2-1-.5-1.4-1-.4-.4-.7-.9-.9-1.4-.2-.5-.3-1.1-.3-1.8s.1-1.2.3-1.8c.2-.5.5-1 .9-1.4.4-.4.9-.7 1.4-1 .5-.2 1.1-.3 1.8-.3.6 0 1.2.1 1.8.3.5.2 1 .6 1.4 1 .4.4.7.9.9 1.4.2.5.3 1.1.3 1.8s-.1 1.2-.3 1.8c-.2.5-.5 1-.9 1.4-.4.4-.9.7-1.4 1-.6.2-1.1.3-1.8.3zm0-1.2c.6 0 1.1-.1 1.6-.4.5-.3.8-.7 1.1-1.1.3-.5.4-1.1.4-1.7 0-.6-.1-1.2-.4-1.7-.3-.5-.7-.9-1.1-1.1-.5-.3-1-.4-1.6-.4-.6 0-1.1.1-1.6.4-.5.3-.8.7-1.1 1.1-.3.5-.4 1-.4 1.7 0 .6.1 1.2.4 1.7.3.5.7.9 1.1 1.1.5.3 1 .4 1.6.4zm6 1.1v-8.6h3c.5 0 1 .1 1.4.3.4.2.7.5 1 .9.2.4.4.8.4 1.4 0 .3-.1.7-.2 1s-.3.6-.6.8c-.3.2-.6.4-1 .6-.4.1-.8.2-1.2.2h-2.1v-1.2h2.3c.3 0 .5-.1.7-.2.2-.1.4-.3.5-.5.1-.2.2-.5.2-.7 0-.2-.1-.5-.2-.7-.1-.2-.3-.4-.5-.5-.2-.1-.5-.2-.8-.2h-1.7v7.4h-1.2zm2-4h1.5l2.7 3.9v.1H264l-2.6-4zM178.1 219.9c-.5 0-1-.1-1.5-.3-.5-.2-1-.5-1.4-1-.4-.4-.7-1-.8-1.7l1.5-.6c.1.6.4 1 .8 1.4.4.4.9.5 1.4.5.6 0 1.1-.2 1.5-.6.4-.4.6-.9.6-1.5s-.2-1.1-.6-1.5c-.4-.4-.9-.6-1.5-.6-.4 0-.7.1-1 .2-.3.1-.5.4-.7.6l-1.7-.8.7-5.5h5.9v1.6h-4.5l-.4 2.9h.1c.2-.2.5-.3.8-.5.3-.1.7-.2 1.2-.2.6 0 1.2.2 1.7.5s1 .7 1.3 1.3c.3.5.5 1.2.5 1.9s-.2 1.3-.5 1.9c-.3.6-.8 1-1.3 1.3-.7.5-1.4.7-2.1.7zm9.9 0c-.7 0-1.3-.1-1.9-.4-.5-.3-1-.7-1.4-1.2-.4-.5-.7-1.1-.9-1.8-.2-.7-.3-1.4-.3-2.2 0-.8.1-1.6.3-2.2.2-.7.5-1.3.9-1.8s.9-.9 1.4-1.2c.6-.3 1.2-.5 1.9-.5s1.3.2 1.9.5c.6.3 1 .7 1.4 1.2.4.5.7 1.1.9 1.8.2.7.3 1.4.3 2.2 0 .8-.1 1.6-.3 2.2-.2.7-.5 1.3-.9 1.8s-.9.9-1.4 1.2c-.6.2-1.2.4-1.9.4zm.1-1.7c.6 0 1-.2 1.5-.5.4-.4.7-.9 1-1.5.2-.6.3-1.3.3-2.1s-.1-1.5-.3-2.1c-.2-.6-.5-1.1-1-1.5-.4-.4-.9-.5-1.5-.5s-1.1.2-1.5.5c-.4.4-.7.8-.9 1.5-.2.6-.3 1.3-.3 2.1s.1 1.5.3 2.1c.2.6.5 1.1.9 1.5.4.3.9.5 1.5.5zm10.5 1.7c-.7 0-1.3-.1-1.9-.4-.5-.3-1-.7-1.4-1.2-.4-.5-.7-1.1-.9-1.8-.2-.7-.3-1.4-.3-2.2 0-.8.1-1.6.3-2.2.2-.7.5-1.3.9-1.8s.9-.9 1.4-1.2c.6-.3 1.2-.5 1.9-.5s1.3.2 1.9.5c.6.3 1 .7 1.4 1.2.4.5.7 1.1.9 1.8.2.7.3 1.4.3 2.2 0 .8-.1 1.6-.3 2.2-.2.7-.5 1.3-.9 1.8s-.9.9-1.4 1.2c-.6.2-1.2.4-1.9.4zm0-1.7c.6 0 1-.2 1.5-.5.4-.4.7-.9 1-1.5.2-.6.3-1.3.3-2.1s-.1-1.5-.3-2.1c-.2-.6-.5-1.1-1-1.5-.4-.4-.9-.5-1.5-.5s-1.1.2-1.5.5c-.4.4-.7.8-.9 1.5-.2.6-.3 1.3-.3 2.1s.1 1.5.3 2.1c.2.6.5 1.1.9 1.5.4.3.9.5 1.5.5zm10 1.4v-8.2h1.6v1.1h.1c.2-.3.4-.5.6-.7.3-.2.6-.4.9-.5.3-.1.7-.2 1-.2.6 0 1.1.1 1.5.4.4.3.7.7.9 1.1.3-.4.6-.8 1.1-1.1.5-.3 1-.5 1.7-.5 1 0 1.7.3 2.1.9.5.6.7 1.4.7 2.3v5.2h-1.7v-4.9c0-.7-.1-1.1-.4-1.4-.3-.3-.7-.5-1.2-.5-.4 0-.7.1-1 .3-.3.2-.5.5-.7.9-.2.4-.2.8-.2 1.2v4.4h-1.7v-4.9c0-.7-.1-1.1-.4-1.4-.3-.3-.7-.5-1.2-.5-.4 0-.7.1-1 .3-.3.2-.5.5-.7.9-.2.4-.2.8-.2 1.2v4.4h-1.8zm17.2.3c-.6 0-1.2-.1-1.7-.3-.5-.2-.9-.5-1.2-.8-.3-.3-.5-.7-.7-1.1l1.5-.7c.2.4.5.8.8 1 .4.2.8.3 1.2.3.4 0 .8-.1 1.1-.2.3-.2.5-.4.5-.8 0-.2-.1-.4-.2-.6-.1-.1-.3-.3-.6-.4-.2-.1-.5-.2-.8-.2l-1-.2c-.4-.1-.8-.3-1.1-.5-.3-.2-.6-.5-.8-.8-.2-.3-.3-.7-.3-1.1 0-.5.1-.9.4-1.3.3-.4.7-.6 1.1-.8.5-.2 1-.3 1.6-.3.5 0 1 .1 1.4.2.4.1.8.3 1.1.6.3.3.6.6.8 1l-1.5.7c-.2-.4-.4-.6-.7-.8-.3-.1-.6-.2-1-.2s-.7.1-1 .2c-.3.2-.4.4-.4.6 0 .3.1.5.4.7.2.2.5.3.9.4l1.2.3c.8.2 1.4.5 1.8.9.4.4.6.9.6 1.5 0 .5-.2 1-.5 1.4-.3.4-.7.7-1.2.9-.6.2-1.1.4-1.7.4zM69 220v-1.6s.2-.1.4-.4c.2-.2.5-.5.8-.9l1.1-1.1 1-1c.3-.3.5-.6.7-.8.3-.3.5-.6.7-.8.2-.2.3-.5.4-.7.1-.2.1-.5.1-.8 0-.3-.1-.5-.2-.8-.1-.3-.3-.4-.6-.6-.3-.1-.6-.2-1-.2s-.7.1-1 .2c-.3.1-.5.3-.6.6-.1.2-.3.4-.3.7l-1.5-.6c.1-.3.2-.5.4-.8.2-.3.4-.5.7-.8.3-.3.6-.5 1-.6.4-.2.9-.3 1.4-.2.7 0 1.3.2 1.9.5.5.3.9.7 1.2 1.2.3.5.4 1 .4 1.6 0 .5-.1.9-.2 1.3-.2.4-.4.8-.7 1.2-.3.4-.5.7-.8 1l-.5.5c-.2.2-.4.5-.7.7l-.7.7-.6.6-.4.4h4.8v1.6H69zm13.2.2c-.7 0-1.3-.1-1.9-.4-.5-.3-1-.7-1.4-1.2-.4-.5-.7-1.1-.9-1.8-.2-.7-.3-1.4-.3-2.2 0-.8.1-1.6.3-2.2.2-.7.5-1.3.9-1.8s.9-.9 1.4-1.2c.6-.3 1.2-.5 1.9-.5s1.3.2 1.9.5c.6.3 1 .7 1.4 1.2.4.5.7 1.1.9 1.8.2.7.3 1.4.3 2.2 0 .8-.1 1.6-.3 2.2-.2.7-.5 1.3-.9 1.8s-.9.9-1.4 1.2c-.6.3-1.2.4-1.9.4zm0-1.6c.6 0 1-.2 1.5-.5.4-.4.7-.9 1-1.5.2-.6.3-1.3.3-2.1s-.1-1.5-.3-2.1c-.2-.6-.5-1.1-1-1.5-.4-.4-.9-.5-1.5-.5s-1.1.2-1.5.5c-.4.4-.7.8-.9 1.5-.2.6-.3 1.3-.3 2.1s.1 1.5.3 2.1c.2.6.5 1.1.9 1.5.4.3.9.5 1.5.5zm10.5 1.6c-.7 0-1.3-.1-1.9-.4-.5-.3-1-.7-1.4-1.2-.4-.5-.7-1.1-.9-1.8-.2-.7-.3-1.4-.3-2.2 0-.8.1-1.6.3-2.2.2-.7.5-1.3.9-1.8s.9-.9 1.4-1.2c.6-.3 1.2-.5 1.9-.5s1.3.2 1.9.5c.6.3 1 .7 1.4 1.2.4.5.7 1.1.9 1.8.2.7.3 1.4.3 2.2 0 .8-.1 1.6-.3 2.2-.2.7-.5 1.3-.9 1.8s-.9.9-1.4 1.2c-.6.3-1.2.4-1.9.4zm0-1.6c.6 0 1-.2 1.5-.5.4-.4.7-.9 1-1.5.2-.6.3-1.3.3-2.1s-.1-1.5-.3-2.1c-.2-.6-.5-1.1-1-1.5-.4-.4-.9-.5-1.5-.5s-1.1.2-1.5.5c-.4.4-.7.8-.9 1.5-.2.6-.3 1.3-.3 2.1s.1 1.5.3 2.1c.2.6.5 1.1.9 1.5.5.3 1 .5 1.5.5zm10 1.4v-8.2h1.6v1.1h.1c.2-.3.4-.5.6-.7.3-.2.6-.4.9-.5.3-.1.7-.2 1-.2.6 0 1.1.1 1.5.4.4.3.7.7.9 1.1.3-.4.6-.8 1.1-1.1.5-.3 1-.5 1.7-.5 1 0 1.7.3 2.1.9.5.6.7 1.4.7 2.3v5.2h-1.7v-4.9c0-.7-.1-1.1-.4-1.4-.3-.3-.7-.5-1.2-.5-.4 0-.7.1-1 .3-.3.2-.5.5-.7.9-.2.4-.2.8-.2 1.2v4.4H108v-4.9c0-.7-.1-1.1-.4-1.4-.3-.3-.7-.5-1.2-.5-.4 0-.7.1-1 .3-.3.2-.5.5-.7.9-.2.4-.2.8-.2 1.2v4.4h-1.8zm17.2.2c-.6 0-1.2-.1-1.7-.3-.5-.2-.9-.5-1.2-.8-.3-.3-.5-.7-.7-1.1l1.5-.7c.2.4.5.8.8 1 .4.2.8.3 1.2.3.4 0 .8-.1 1.1-.2.3-.2.5-.4.5-.8 0-.2-.1-.4-.2-.6-.1-.1-.3-.3-.6-.4-.2-.1-.5-.2-.8-.2l-1-.2c-.4-.1-.8-.3-1.1-.5-.3-.2-.6-.5-.8-.8-.2-.3-.3-.7-.3-1.1 0-.5.1-.9.4-1.3.3-.4.7-.6 1.1-.8.5-.2 1-.3 1.6-.3.5 0 1 .1 1.4.2.4.1.8.3 1.1.6.3.3.6.6.8 1l-1.5.7c-.2-.4-.4-.6-.7-.8-.3-.1-.6-.2-1-.2s-.7.1-1 .2c-.3.2-.4.4-.4.6 0 .3.1.5.4.7.2.2.5.3.9.4l1.2.3c.8.2 1.4.5 1.8.9.4.4.6.9.6 1.5 0 .5-.2 1-.5 1.4-.3.4-.7.7-1.2.9-.5.3-1.1.4-1.7.4zM42.4 96.3V82h1.7v14.3h-1.7zm4.6 0V86.1h1.6v1.5h.1c.3-.5.7-.9 1.3-1.3.6-.4 1.3-.5 2-.5 1.2 0 2.2.4 2.8 1.1.6.7 1 1.7 1 2.9v6.5h-1.7V90c0-1-.2-1.7-.7-2.1-.5-.4-1.1-.6-1.8-.6-.6 0-1.1.2-1.5.5-.4.3-.8.7-1 1.2-.2.5-.4 1-.4 1.6v5.7H47zm10-10.2h6v1.5h-6v-1.5zm1.8 7.5V83.3h1.7v10c0 .5.1.9.3 1.2s.6.4 1.1.4c.2 0 .4 0 .6-.1.2-.1.4-.2.5-.2v1.7c-.2.1-.4.1-.6.2-.2.1-.5.1-.8.1-.9 0-1.5-.2-2.1-.8-.5-.6-.7-1.3-.7-2.2zm10.3 3c-1 0-1.9-.2-2.6-.7-.8-.5-1.4-1.1-1.8-1.9-.4-.8-.6-1.7-.6-2.8 0-1 .2-1.9.6-2.7s1-1.5 1.7-2 1.6-.8 2.6-.8 1.9.2 2.6.7c.7.4 1.3 1.1 1.7 1.8.4.8.6 1.7.6 2.7v.5H65V90h7c0-.3-.1-.6-.2-.9-.1-.3-.3-.6-.5-.9-.2-.3-.6-.5-.9-.7-.4-.2-.8-.3-1.4-.3-.7 0-1.2.2-1.7.5s-.8.8-1.1 1.4c-.3.6-.4 1.2-.4 2 0 .9.2 1.6.5 2.2.3.6.8 1 1.3 1.3.5.3 1.1.4 1.7.4.8 0 1.4-.2 1.8-.5.5-.4.9-.8 1.2-1.3l1.4.7c-.4.8-1 1.4-1.7 1.9-.9.6-1.8.8-2.9.8zm6.7-.3V86.1h1.6v1.6h.1c.1-.4.4-.7.7-1 .3-.3.7-.5 1.1-.7s.8-.2 1.2-.2h.7c.2 0 .3.1.5.2v1.8c-.2-.1-.5-.2-.7-.2-.2-.1-.5-.1-.7-.1-.5 0-1 .1-1.4.4-.4.3-.7.7-1 1.1-.2.5-.4 1-.4 1.5v5.7h-1.7zm10.4.3c-.8 0-1.4-.1-2-.4s-1-.7-1.3-1.2c-.3-.5-.5-1.1-.5-1.8 0-.8.2-1.4.6-1.9.4-.5.9-.9 1.5-1.2.7-.3 1.4-.4 2.2-.4.4 0 .9 0 1.2.1s.7.2 1 .3c.3.1.5.2.7.3v-.6c0-.8-.3-1.4-.8-1.8-.5-.5-1.2-.7-2-.7-.6 0-1.1.1-1.6.4-.5.2-.9.6-1.1 1l-1.3-1c.3-.4.6-.7 1-1 .4-.3.9-.5 1.4-.7.5-.2 1.1-.2 1.6-.2 1.4 0 2.5.4 3.2 1.1.8.7 1.2 1.7 1.2 3v6.5h-1.6v-1.5h-.1c-.2.3-.4.6-.7.8s-.7.5-1.1.7c-.5.2-1 .2-1.5.2zm.1-1.5c.6 0 1.1-.1 1.6-.4.5-.3.9-.7 1.2-1.2.3-.5.5-1 .5-1.6-.3-.2-.7-.4-1.2-.5s-1-.2-1.5-.2c-1 0-1.7.2-2.1.6-.4.4-.7.9-.7 1.5s.2 1 .6 1.4 1 .4 1.6.4zm11.8 1.5c-1 0-1.9-.2-2.7-.7-.8-.5-1.4-1.1-1.8-1.9-.4-.8-.7-1.7-.7-2.8 0-1 .2-2 .7-2.8.4-.8 1.1-1.5 1.8-1.9.8-.5 1.7-.7 2.7-.7 1.1 0 2.1.3 2.8.8.7.5 1.3 1.2 1.6 2l-1.5.6c-.2-.6-.6-1.1-1.1-1.4-.5-.3-1.1-.5-1.8-.5-.6 0-1.2.2-1.7.5s-.9.8-1.2 1.4c-.3.6-.5 1.3-.5 2 0 .8.2 1.4.5 2 .3.6.7 1 1.2 1.4.5.3 1.1.5 1.7.5.7 0 1.3-.2 1.9-.5s.9-.8 1.2-1.4l1.5.6c-.3.8-.9 1.5-1.6 2s-1.9.8-3 .8zm5.5-10.5h6v1.5h-6v-1.5zm1.7 7.5V83.3h1.7v10c0 .5.1.9.3 1.2s.6.4 1.1.4c.2 0 .4 0 .6-.1.2-.1.4-.2.5-.2v1.7c-.2.1-.4.1-.6.2-.2.1-.5.1-.8.1-.9 0-1.5-.2-2.1-.8s-.7-1.3-.7-2.2zm6.5 2.7V86.1h1.7v10.2h-1.7zm.9-12c-.3 0-.6-.1-.9-.4s-.4-.5-.4-.9c0-.3.1-.6.4-.9.2-.2.5-.4.9-.4.3 0 .6.1.9.4.2.2.4.5.4.9 0 .3-.1.6-.4.9-.3.2-.6.4-.9.4zm8.1 12.3c-1 0-1.9-.2-2.7-.7-.8-.5-1.4-1.1-1.8-1.9-.4-.8-.7-1.7-.7-2.8 0-1 .2-1.9.7-2.8.4-.8 1.1-1.5 1.8-2 .8-.5 1.7-.7 2.7-.7 1 0 1.9.2 2.7.7.8.5 1.4 1.1 1.9 2s.7 1.7.7 2.7c0 1-.2 1.9-.7 2.8-.4.8-1.1 1.5-1.9 1.9-.8.6-1.7.8-2.7.8zm0-1.5c.6 0 1.2-.2 1.7-.5s1-.8 1.3-1.3c.3-.6.5-1.3.5-2.1s-.2-1.5-.5-2.1-.8-1-1.3-1.3c-.5-.3-1.1-.5-1.7-.5-.6 0-1.2.2-1.7.5s-1 .7-1.3 1.3-.5 1.3-.5 2.1.2 1.5.5 2.1c.3.6.8 1 1.3 1.3.5.4 1.1.5 1.7.5zm7 1.2V86.1h1.6v1.5h.1c.3-.5.7-.9 1.3-1.3.6-.4 1.3-.5 2-.5 1.2 0 2.2.4 2.8 1.1.6.7 1 1.7 1 2.9v6.5h-1.7V90c0-1-.2-1.7-.7-2.1-.5-.4-1.1-.6-1.8-.6-.6 0-1.1.2-1.5.5-.4.3-.8.7-1 1.2-.2.5-.4 1-.4 1.6v5.7h-1.7zM143 86.1h6v1.5h-6v-1.5zm1.7 7.5V83.3h1.7v10c0 .5.1.9.3 1.2s.6.4 1.1.4c.2 0 .4 0 .6-.1.2-.1.4-.2.5-.2v1.7c-.2.1-.4.1-.6.2-.2.1-.5.1-.8.1-.9 0-1.5-.2-2.1-.8-.4-.6-.7-1.3-.7-2.2zm10.5 3c-1 0-1.9-.2-2.7-.7-.8-.5-1.4-1.1-1.8-1.9-.4-.8-.7-1.7-.7-2.8 0-1 .2-1.9.7-2.8.4-.8 1.1-1.5 1.8-2 .8-.5 1.7-.7 2.7-.7 1 0 1.9.2 2.7.7.8.5 1.4 1.1 1.9 2 .4.8.7 1.7.7 2.7 0 1-.2 1.9-.7 2.8-.4.8-1.1 1.5-1.9 1.9-.8.6-1.7.8-2.7.8zm0-1.5c.6 0 1.2-.2 1.7-.5s1-.8 1.3-1.3c.3-.6.5-1.3.5-2.1s-.2-1.5-.5-2.1c-.3-.6-.8-1-1.3-1.3-.5-.3-1.1-.5-1.7-.5-.6 0-1.2.2-1.7.5s-1 .7-1.3 1.3c-.3.6-.5 1.3-.5 2.1s.2 1.5.5 2.1c.3.6.8 1 1.3 1.3.5.4 1.1.5 1.7.5zm12.2 1.2V82h2.1l7.2 11.4h.1l-.1-2.8V82h1.7v14.3h-1.8l-7.5-11.9h-.1l.1 2.8v9.2h-1.7zm18.2.3c-1 0-1.9-.2-2.6-.7-.8-.5-1.4-1.1-1.8-1.9-.4-.8-.6-1.7-.6-2.8 0-1 .2-1.9.6-2.7.4-.8 1-1.5 1.7-2s1.6-.8 2.6-.8 1.9.2 2.6.7c.7.4 1.3 1.1 1.7 1.8.4.8.6 1.7.6 2.7v.5h-8.8V90h7c0-.3-.1-.6-.2-.9-.1-.3-.3-.6-.5-.9-.2-.3-.6-.5-.9-.7-.4-.2-.8-.3-1.4-.3-.7 0-1.2.2-1.7.5s-.8.8-1.1 1.4c-.3.6-.4 1.2-.4 2 0 .9.2 1.6.5 2.2.3.6.8 1 1.3 1.3.5.3 1.1.4 1.7.4.8 0 1.4-.2 1.8-.5.5-.4.9-.8 1.2-1.3l1.4.7c-.4.8-1 1.4-1.7 1.9-1 .6-1.9.8-3 .8zm5.5-.3 4.1-5.9h.2l2.9-4.3h2l-4 5.6h-.1l-3.1 4.6h-2zm.1-10.2h1.9l3.2 4.5h.1l4 5.7h-2l-3-4.5h-.1l-4.1-5.7zm9.9 0h6v1.5h-6v-1.5zm1.8 7.5V83.3h1.7v10c0 .5.1.9.3 1.2.2.3.6.4 1.1.4.2 0 .4 0 .6-.1.2-.1.4-.2.5-.2v1.7c-.2.1-.4.1-.6.2-.2.1-.5.1-.8.1-.9 0-1.5-.2-2.1-.8-.4-.6-.7-1.3-.7-2.2zm11.2 2.7V82h4.8c.8 0 1.5.2 2.2.5.7.4 1.2.8 1.6 1.5.4.6.6 1.4.6 2.2 0 .8-.2 1.6-.6 2.2-.4.6-.9 1.1-1.6 1.5-.7.4-1.4.5-2.2.5H215v-1.6h4c.6 0 1-.1 1.4-.4.4-.3.7-.6.9-1 .2-.4.3-.8.3-1.2s-.1-.8-.3-1.2c-.2-.4-.5-.7-.9-1-.4-.3-.9-.4-1.4-.4h-3.2v12.7h-1.7zm14.1.3c-.8 0-1.4-.1-2-.4s-1-.7-1.3-1.2-.5-1.1-.5-1.8c0-.8.2-1.4.6-1.9s.9-.9 1.5-1.2c.7-.3 1.4-.4 2.2-.4.4 0 .9 0 1.2.1s.7.2 1 .3c.3.1.5.2.7.3v-.6c0-.8-.3-1.4-.8-1.8-.5-.5-1.2-.7-2-.7-.6 0-1.1.1-1.6.4-.5.2-.9.6-1.1 1l-1.3-1c.3-.4.6-.7 1-1 .4-.3.9-.5 1.4-.7s1.1-.2 1.6-.2c1.4 0 2.5.4 3.2 1.1.8.7 1.2 1.7 1.2 3v6.5h-1.6v-1.5h-.1c-.2.3-.4.6-.7.8s-.7.5-1.1.7c-.6.2-1 .2-1.5.2zm.1-1.5c.6 0 1.1-.1 1.6-.4.5-.3.9-.7 1.2-1.2.3-.5.5-1 .5-1.6-.3-.2-.7-.4-1.2-.5s-1-.2-1.5-.2c-1 0-1.7.2-2.1.6-.4.4-.7.9-.7 1.5s.2 1 .6 1.4 1 .4 1.6.4zm7.4 1.2V86.1h1.7v10.2h-1.7zm.8-12c-.3 0-.6-.1-.9-.4s-.4-.5-.4-.9c0-.3.1-.6.4-.9.2-.2.5-.4.9-.4.3 0 .6.1.9.4.2.2.4.5.4.9 0 .3-.1.6-.4.9-.2.2-.5.4-.9.4zm3.5 12V86.1h1.6v1.5h.1c.3-.5.7-.9 1.3-1.3.6-.4 1.3-.5 2-.5 1.2 0 2.2.4 2.8 1.1.6.7 1 1.7 1 2.9v6.5h-1.7V90c0-1-.2-1.7-.7-2.1-.5-.4-1.1-.6-1.8-.6-.6 0-1.1.2-1.5.5-.4.3-.8.7-1 1.2-.2.5-.4 1-.4 1.6v5.7H240zm10.1-10.2h6v1.5h-6v-1.5zm1.7 7.5V83.3h1.7v10c0 .5.1.9.3 1.2s.6.4 1.1.4c.2 0 .4 0 .6-.1.2-.1.4-.2.5-.2v1.7c-.2.1-.4.1-.6.2-.2.1-.5.1-.8.1-.9 0-1.5-.2-2.1-.8s-.7-1.3-.7-2.2zM96 172.8c-2.4 0-4.3 1.9-4.3 4.3 0 2 1.4 3.7 3.3 4.2v20.1h2v-20.1c1.9-.5 3.3-2.1 3.3-4.2 0-2.3-1.9-4.3-4.3-4.3zM201.6 172.6c-2.4 0-4.3 1.9-4.3 4.3 0 2 1.4 3.7 3.3 4.2v19.8h2v-19.8c1.9-.5 3.3-2.1 3.3-4.2 0-2.4-1.9-4.3-4.3-4.3z"></path></svg>
  <svg title="A diagram of the INP thresholds. An INP at or below 200 milliseconds is considered good. Between 200 and 500 milliseconds suggests a page's responsiveness needs improvement. Anything over 500 milliseconds means that a page's responsiveness is poor." class="inp-desktop" version="1.1" id="Layer_1" xmlns="http://www.w3.org/2000/svg" x="0" y="0" viewBox="0 0 658.4 113.6" style="enable-background:new 0 0 658.4 113.6" xml:space="preserve"><style>.st0{fill: #2979FF} v.st1{fill-rule: evenodd;clip-rule: evenodd;fill: #0CCE6B} .st2 {fill: #191919} .st3{fill-rule: evenodd;clip-rule: evenodd;fill: #FFA400} .st4{fill-rule: evenodd;clip-rule: evenodd;fill: #FF4E42} @media screen and (prefers-color-scheme: light){.st2{fill: #191919}} @media screen and (prefers-color-scheme: dark){.st2{fill: #fff}} [data-user-theme=dark] .st2{fill: #fff}</style><path class="st0" d="M30.2 68.7V0h13v68.7h-13zm28.7 0V0H74l27.7 46.1h.8l-.8-13.2V0h12.9v68.7H101L71.7 20.1h-.8l.8 13.2v35.4H58.9zm71.3 0V0h24.2c4.4 0 8.4.9 11.9 2.7 3.5 1.8 6.3 4.4 8.4 7.6 2.1 3.3 3.1 7 3.1 11.3 0 4.3-1 8.1-3.1 11.4-2.1 3.3-4.9 5.8-8.4 7.7-3.5 1.8-7.5 2.7-11.9 2.7h-17V31.2h17.4c2.2 0 4.1-.4 5.7-1.3 1.5-.9 2.7-2.1 3.5-3.5.8-1.4 1.2-3 1.2-4.7 0-1.7-.4-3.2-1.2-4.6-.8-1.4-1.9-2.6-3.5-3.5-1.5-.9-3.4-1.3-5.7-1.3h-11.6v56.5h-13z"></path><path class="st1" d="M303.2 14.9h115.2v43.2H303.2V14.9z"></path><path class="st2" d="M345.3 41.5c-.7 0-1.3-.1-1.9-.4-.6-.2-1.1-.6-1.6-1s-.8-1-1.1-1.6c-.3-.6-.4-1.3-.4-2s.1-1.4.4-2c.3-.6.6-1.1 1.1-1.6.5-.5 1-.8 1.6-1 .6-.2 1.2-.4 1.9-.4s1.4.1 2 .4c.6.2 1.1.6 1.6 1.1l-1 1c-.2-.2-.4-.4-.7-.6-.3-.2-.5-.3-.9-.4-.3-.1-.6-.1-1-.1-.5 0-.9.1-1.3.3-.4.2-.8.4-1.1.7-.3.3-.6.7-.8 1.1-.2.4-.3.9-.3 1.5s.1 1 .3 1.5c.2.4.5.8.8 1.1.3.3.7.6 1.1.7.4.2.9.2 1.3.2s.8-.1 1.2-.2c.4-.1.7-.3 1-.5.3-.2.5-.5.7-.8.2-.3.3-.7.3-1.1h-3.3v-1.3h4.6v.8c0 .7-.1 1.3-.4 1.9-.2.6-.6 1-1 1.5-.4.4-.9.7-1.5.9-.3.2-.9.3-1.6.3zm10.5 0c-.7 0-1.4-.1-2-.4-.6-.3-1.1-.6-1.6-1.1-.4-.5-.8-1-1-1.6-.2-.6-.4-1.2-.4-1.9s.1-1.3.4-1.9c.2-.6.6-1.1 1-1.6s1-.8 1.6-1.1c.6-.3 1.3-.4 2-.4s1.4.1 2 .4c.6.2 1.1.6 1.6 1.1.5.5.8 1 1 1.6.2.6.4 1.2.4 1.9s-.1 1.3-.4 1.9c-.2.6-.6 1.1-1 1.6s-1 .8-1.6 1.1-1.2.4-2 .4zm0-1.4c.6 0 1.2-.2 1.8-.5.5-.3.9-.7 1.2-1.3s.5-1.2.5-1.9-.2-1.3-.5-1.9-.7-1-1.2-1.3c-.5-.3-1.1-.5-1.8-.5-.6 0-1.2.2-1.8.5-.5.3-.9.7-1.2 1.3s-.5 1.2-.5 1.9.2 1.3.5 1.9.7 1 1.2 1.3c.6.4 1.2.5 1.8.5zm11 1.4c-.7 0-1.4-.1-2-.4-.6-.3-1.1-.6-1.6-1.1-.4-.5-.8-1-1-1.6-.2-.6-.4-1.2-.4-1.9s.1-1.3.4-1.9c.2-.6.6-1.1 1-1.6s1-.8 1.6-1.1c.6-.3 1.3-.4 2-.4s1.4.1 2 .4c.6.2 1.1.6 1.6 1.1.5.5.8 1 1 1.6.2.6.4 1.2.4 1.9s-.1 1.3-.4 1.9c-.2.6-.6 1.1-1 1.6s-1 .8-1.6 1.1-1.3.4-2 .4zm0-1.4c.6 0 1.2-.2 1.8-.5.5-.3.9-.7 1.2-1.3s.5-1.2.5-1.9-.2-1.3-.5-1.9-.7-1-1.2-1.3c-.5-.3-1.1-.5-1.8-.5-.6 0-1.2.2-1.8.5-.5.3-.9.7-1.2 1.3s-.5 1.2-.5 1.9.2 1.3.5 1.9.7 1 1.2 1.3c.6.4 1.2.5 1.8.5zm6.6 1.2v-9.5h3c1 0 1.9.2 2.6.6.7.4 1.3 1 1.7 1.7s.6 1.5.6 2.5c0 .9-.2 1.8-.6 2.5s-1 1.3-1.7 1.7c-.7.4-1.6.6-2.6.6h-3zm1.5-1.4h1.5c.7 0 1.3-.1 1.8-.4.5-.3.9-.7 1.2-1.2.3-.5.4-1.1.4-1.8s-.1-1.3-.4-1.8c-.3-.5-.7-.9-1.2-1.2-.5-.3-1.1-.4-1.8-.4h-1.5v6.8z"></path><path class="st3" d="M418.4 14.9h124.8v43.2H418.4V14.9z"></path><path class="st2" d="M460.8 33.3v-9.5h1.7l4.3 7h.1l-.1-1.8v-5.2h1.5v9.5h-1.5l-4.5-7.4h-.1l.1 1.8v5.5h-1.5zm9.7 0v-9.5h5.8v1.4H472V32h4.3v1.4h-5.8zm.7-4.1v-1.4h4.6v1.4h-4.6zm6.9 4.1v-9.5h5.8v1.4h-4.3V32h4.3v1.4h-5.8zm.8-4.1v-1.4h4.6v1.4h-4.6zm6.8 4.1v-9.5h3c1 0 1.9.2 2.6.6.7.4 1.3 1 1.7 1.7s.6 1.5.6 2.5c0 .9-.2 1.8-.6 2.5s-1 1.3-1.7 1.7c-.7.4-1.6.6-2.6.6h-3zm1.5-1.4h1.5c.7 0 1.3-.1 1.8-.4.5-.3.9-.7 1.2-1.2.3-.5.4-1.1.4-1.8s-.1-1.3-.4-1.8c-.3-.5-.7-.9-1.2-1.2-.5-.3-1.1-.4-1.8-.4h-1.5v6.8zm10.9 1.6c-.5 0-1-.1-1.5-.3-.5-.2-.9-.5-1.2-.9-.3-.4-.6-.9-.8-1.5l1.4-.6c.1.5.4.9.8 1.3.4.3.8.5 1.3.5.3 0 .6-.1.8-.2.3-.1.5-.3.6-.5.2-.2.2-.5.2-.8 0-.3-.1-.5-.2-.7-.1-.2-.3-.4-.6-.5-.3-.2-.7-.3-1.1-.5l-.6-.2c-.3-.1-.5-.2-.8-.4-.3-.1-.5-.3-.7-.5-.2-.2-.4-.5-.5-.7-.1-.3-.2-.6-.2-1 0-.5.1-.9.4-1.3.2-.4.6-.7 1-.9.4-.2 1-.4 1.6-.4.6 0 1.1.1 1.5.3.4.2.7.5 1 .8.2.3.4.6.5.9l-1.3.6c-.1-.2-.2-.4-.3-.5-.1-.2-.3-.3-.5-.4-.2-.1-.5-.2-.8-.2-.3 0-.5.1-.8.2-.2.1-.4.2-.6.4-.1.2-.2.4-.2.6 0 .3.1.6.4.8s.7.4 1.2.6l.6.2c.3.1.6.2.9.4.3.1.6.3.8.6.2.2.4.5.6.8.1.3.2.7.2 1.2s-.1.9-.3 1.3c-.2.4-.4.6-.8.9-.3.2-.7.4-1 .5-.3 0-.7.1-1 .1zM434.4 49.3v-9.5h1.5v9.5h-1.5zm3.6 0v-9.5h2l2.8 7.3h.1l2.8-7.3h2v9.5h-1.4v-5.4l.1-1.7h-.1l-2.8 7.1h-1.2l-2.8-7.1h-.1l.1 1.7v5.4H438zm11.7 0v-9.5h3.3c.6 0 1.1.1 1.6.4.5.2.9.6 1.1 1 .3.4.4.9.4 1.5s-.1 1.1-.4 1.5c-.3.4-.7.8-1.1 1-.5.2-1 .4-1.6.4h-2.5v-1.4h2.5c.4 0 .7-.1.9-.2.2-.1.4-.3.5-.6.1-.2.2-.5.2-.8 0-.3-.1-.5-.2-.7-.1-.2-.3-.4-.5-.6-.2-.2-.5-.2-.9-.2h-1.8v8.2h-1.5zm8 0v-9.5h3.3c.6 0 1.1.1 1.6.4.5.2.8.6 1.1 1s.4.9.4 1.5c0 .4-.1.8-.2 1.1s-.4.7-.7.9c-.3.3-.6.5-1 .6-.4.1-.9.2-1.4.2h-2.3v-1.3h2.5c.3 0 .6-.1.8-.2.2-.1.4-.3.6-.6.2-.2.2-.5.2-.8 0-.3-.1-.5-.2-.7-.1-.2-.3-.4-.5-.6-.2-.1-.5-.2-.9-.2h-1.9v8.2h-1.4zm2.2-4.4h1.7l3 4.3v.1h-1.7l-3-4.4zm10.3 4.6c-.7 0-1.4-.1-2-.4-.6-.3-1.1-.6-1.6-1.1-.4-.5-.8-1-1-1.6-.2-.6-.4-1.2-.4-1.9s.1-1.3.4-1.9c.2-.6.6-1.1 1-1.6s1-.8 1.6-1.1c.6-.3 1.3-.4 2-.4s1.4.1 2 .4c.6.2 1.1.6 1.6 1.1.5.5.8 1 1 1.6.2.6.4 1.2.4 1.9s-.1 1.3-.4 1.9c-.2.6-.6 1.1-1 1.6s-1 .8-1.6 1.1c-.6.3-1.2.4-2 .4zm0-1.4c.6 0 1.2-.2 1.8-.5.5-.3.9-.7 1.2-1.3.3-.5.5-1.2.5-1.9s-.2-1.3-.5-1.9c-.3-.5-.7-1-1.2-1.3-.5-.3-1.1-.5-1.8-.5s-1.2.2-1.8.5c-.5.3-.9.7-1.2 1.3-.3.5-.5 1.2-.5 1.9s.2 1.3.5 1.9c.3.5.7 1 1.2 1.3.6.4 1.2.5 1.8.5zm8.8 1.2-3.4-9.5h1.6l2.2 6.3.3 1.1h.1l.4-1.1 2.2-6.3h1.6l-3.5 9.5H479zm6.2 0v-9.5h5.8v1.4h-4.3V48h4.3v1.4h-5.8zm.8-4.1v-1.4h4.6v1.4H486zm6.8 4.1v-9.5h2l2.8 7.3h.1l2.8-7.3h2v9.5H501v-5.4l.1-1.7h-.1l-2.8 7.1H497l-2.8-7.1h-.1l.1 1.7v5.4h-1.4zm11.8 0v-9.5h5.8v1.4h-4.3V48h4.3v1.4h-5.8zm.8-4.1v-1.4h4.6v1.4h-4.6zm6.8 4.1v-9.5h1.7l4.3 7h.1l-.1-1.8v-5.2h1.5v9.5h-1.5l-4.5-7.4h-.1l.1 1.8v5.5h-1.5zm11.7 0v-8.8h1.5v8.8h-1.5zm-2.7-8.2v-1.4h6.8v1.4h-6.8z"></path><path class="st4" d="M543.2 14.9h115.2v43.2H543.2V14.9z"></path><path class="st2" d="M582.9 41.3v-9.5h3.3c.6 0 1.1.1 1.6.4.5.2.9.6 1.1 1 .3.4.4.9.4 1.5s-.1 1.1-.4 1.5c-.3.4-.7.8-1.1 1-.5.2-1 .4-1.6.4h-2.5v-1.4h2.5c.4 0 .7-.1.9-.2.2-.1.4-.3.5-.6.1-.2.2-.5.2-.8 0-.3-.1-.5-.2-.7-.1-.2-.3-.4-.5-.6-.2-.2-.5-.2-.9-.2h-1.8v8.2h-1.5zm12.3.2c-.7 0-1.4-.1-2-.4-.6-.3-1.1-.6-1.6-1.1-.4-.5-.8-1-1-1.6-.2-.6-.4-1.2-.4-1.9s.1-1.3.4-1.9c.2-.6.6-1.1 1-1.6s1-.8 1.6-1.1c.6-.3 1.3-.4 2-.4s1.4.1 2 .4c.6.2 1.1.6 1.6 1.1.5.5.8 1 1 1.6.2.6.4 1.2.4 1.9s-.1 1.3-.4 1.9c-.2.6-.6 1.1-1 1.6s-1 .8-1.6 1.1c-.7.3-1.3.4-2 .4zm0-1.4c.6 0 1.2-.2 1.8-.5.5-.3.9-.7 1.2-1.3.3-.5.5-1.2.5-1.9s-.2-1.3-.5-1.9c-.3-.5-.7-1-1.2-1.3-.5-.3-1.1-.5-1.8-.5-.6 0-1.2.2-1.8.5-.5.3-.9.7-1.2 1.3-.3.5-.5 1.2-.5 1.9s.2 1.3.5 1.9c.3.5.7 1 1.2 1.3.6.4 1.1.5 1.8.5zm10.9 1.4c-.7 0-1.4-.1-2-.4-.6-.3-1.1-.6-1.6-1.1-.4-.5-.8-1-1-1.6-.2-.6-.4-1.2-.4-1.9s.1-1.3.4-1.9c.2-.6.6-1.1 1-1.6s1-.8 1.6-1.1c.6-.3 1.3-.4 2-.4s1.4.1 2 .4c.6.2 1.1.6 1.6 1.1.5.5.8 1 1 1.6.2.6.4 1.2.4 1.9s-.1 1.3-.4 1.9c-.2.6-.6 1.1-1 1.6s-1 .8-1.6 1.1c-.6.3-1.3.4-2 .4zm0-1.4c.6 0 1.2-.2 1.8-.5.5-.3.9-.7 1.2-1.3.3-.5.5-1.2.5-1.9s-.2-1.3-.5-1.9c-.3-.5-.7-1-1.2-1.3-.5-.3-1.1-.5-1.8-.5s-1.2.2-1.8.5c-.5.3-.9.7-1.2 1.3-.3.5-.5 1.2-.5 1.9s.2 1.3.5 1.9c.3.5.7 1 1.2 1.3.6.4 1.2.5 1.8.5zm6.7 1.2v-9.5h3.3c.6 0 1.1.1 1.6.4.5.2.8.6 1.1 1s.4.9.4 1.5c0 .4-.1.8-.2 1.1s-.4.7-.7.9c-.3.3-.6.5-1 .6-.4.1-.9.2-1.4.2h-2.3v-1.3h2.5c.3 0 .6-.1.8-.2.2-.1.4-.3.6-.6.2-.2.2-.5.2-.8 0-.3-.1-.5-.2-.7-.1-.2-.3-.4-.5-.6-.2-.1-.5-.2-.9-.2h-1.9v8.2h-1.4zm2.2-4.4h1.7l3 4.3v.1H618l-3-4.4zM517.7 102.9c-.6 0-1.1-.1-1.7-.3-.6-.2-1-.6-1.5-1-.4-.5-.7-1.1-.9-1.8l1.7-.7c.2.6.4 1.1.8 1.5.4.4.9.6 1.6.6.7 0 1.2-.2 1.6-.6.4-.4.7-1 .7-1.6 0-.7-.2-1.2-.6-1.6-.4-.4-1-.7-1.6-.7-.4 0-.8.1-1.1.2-.3.2-.6.4-.8.7l-1.8-.8.7-6h6.4v1.7h-4.9l-.4 3.2h.1c.3-.2.6-.4.9-.5.4-.1.8-.2 1.3-.2.7 0 1.3.2 1.9.5.6.3 1 .8 1.4 1.4.4.6.5 1.3.5 2 0 .8-.2 1.5-.5 2.1-.4.6-.8 1.1-1.5 1.4-.7.3-1.5.5-2.3.5zm10.8 0c-.7 0-1.4-.2-2-.5-.6-.3-1.1-.8-1.5-1.3-.4-.6-.8-1.2-1-2-.2-.8-.3-1.6-.3-2.4 0-.9.1-1.7.3-2.5.2-.8.6-1.4 1-2 .4-.6.9-1 1.5-1.3.6-.3 1.3-.5 2-.5.8 0 1.4.2 2 .5.6.3 1.1.8 1.5 1.3.4.6.8 1.2 1 2 .2.8.3 1.6.3 2.5 0 .9-.1 1.7-.3 2.4-.2.8-.5 1.4-1 2-.4.6-.9 1-1.5 1.3-.6.3-1.2.5-2 .5zm0-1.8c.6 0 1.1-.2 1.6-.6.4-.4.8-.9 1-1.6.2-.7.4-1.4.4-2.2 0-.8-.1-1.6-.4-2.3-.2-.7-.6-1.2-1-1.6-.4-.4-1-.6-1.6-.6-.6 0-1.2.2-1.6.6-.4.4-.8.9-1 1.6-.2.7-.4 1.4-.4 2.3 0 .8.1 1.6.4 2.2.2.7.6 1.2 1 1.6.5.4 1 .6 1.6.6zm11.4 1.8c-.7 0-1.4-.2-2-.5-.6-.3-1.1-.8-1.5-1.3-.4-.6-.8-1.2-1-2-.2-.8-.3-1.6-.3-2.4 0-.9.1-1.7.3-2.5.2-.8.6-1.4 1-2 .4-.6.9-1 1.5-1.3.6-.3 1.3-.5 2-.5.8 0 1.4.2 2 .5.6.3 1.1.8 1.5 1.3.4.6.8 1.2 1 2 .2.8.3 1.6.3 2.5 0 .9-.1 1.7-.3 2.4-.2.8-.5 1.4-1 2-.4.6-.9 1-1.5 1.3-.5.3-1.2.5-2 .5zm.1-1.8c.6 0 1.1-.2 1.6-.6.4-.4.8-.9 1-1.6.2-.7.4-1.4.4-2.2 0-.8-.1-1.6-.4-2.3-.2-.7-.6-1.2-1-1.6-.4-.4-1-.6-1.6-.6-.6 0-1.2.2-1.6.6-.4.4-.8.9-1 1.6-.2.7-.4 1.4-.4 2.3 0 .8.1 1.6.4 2.2.2.7.6 1.2 1 1.6.4.4.9.6 1.6.6zm10.8 1.5v-8.8h1.8V95h.1c.2-.3.4-.5.7-.8s.6-.4.9-.5c.4-.1.7-.2 1.1-.2.7 0 1.2.2 1.7.5s.8.7 1 1.2c.3-.5.7-.8 1.2-1.2.5-.3 1.1-.5 1.8-.5 1 0 1.8.3 2.3 1 .5.6.8 1.5.8 2.5v5.7h-1.9v-5.4c0-.7-.2-1.2-.5-1.5-.3-.3-.7-.5-1.3-.5-.4 0-.8.1-1.1.4-.3.2-.6.6-.8 1s-.3.9-.3 1.3v4.7h-1.9v-5.4c0-.7-.2-1.2-.5-1.5-.3-.3-.8-.5-1.3-.5-.4 0-.8.1-1.1.4-.3.2-.6.6-.7 1s-.3.9-.3 1.3v4.7h-1.7zm18.6.3c-.7 0-1.3-.1-1.8-.3-.5-.2-.9-.5-1.3-.9-.3-.4-.6-.8-.7-1.2l1.7-.7c.2.5.5.8.9 1.1.4.2.8.4 1.3.4s.9-.1 1.2-.2c.3-.2.5-.4.5-.8 0-.2-.1-.5-.2-.6s-.4-.3-.6-.4l-.9-.3-1.1-.2c-.4-.1-.8-.3-1.2-.5-.4-.2-.7-.5-.9-.9-.2-.4-.3-.8-.3-1.2 0-.5.2-1 .5-1.4.3-.4.7-.7 1.2-.9.5-.2 1.1-.3 1.7-.3.6 0 1.1.1 1.5.2.5.1.9.3 1.2.6.3.3.6.6.8 1l-1.6.7c-.2-.4-.5-.7-.8-.8-.3-.2-.7-.2-1.1-.2-.4 0-.8.1-1.1.3-.3.2-.4.4-.4.7 0 .3.1.5.4.7.3.2.6.3 1 .4l1.3.3c.9.2 1.5.6 2 1 .4.4.7 1 .7 1.6 0 .6-.2 1.1-.5 1.5-.3.4-.8.7-1.3 1-.8.2-1.5.3-2.1.3zM389.2 102.6v-1.8l.4-.4.9-.9c.4-.4.7-.8 1.1-1.2l1.1-1.1.8-.8c.3-.3.6-.6.8-.9.2-.3.3-.5.4-.8.1-.2.1-.5.1-.8 0-.3-.1-.6-.2-.8-.1-.3-.4-.5-.7-.6-.3-.2-.6-.2-1.1-.2-.4 0-.7.1-1 .2-.3.2-.5.4-.7.6-.2.2-.3.5-.3.7l-1.7-.7c.1-.3.2-.6.4-.9.2-.3.4-.6.8-.9.3-.3.7-.5 1.1-.7.4-.2.9-.3 1.5-.3.8 0 1.4.2 2 .5.6.3 1 .7 1.3 1.2.3.5.5 1.1.5 1.7 0 .5-.1 1-.3 1.5-.2.5-.4.9-.7 1.3-.3.4-.6.7-.9 1-.2.1-.4.3-.6.6-.2.2-.5.5-.7.8l-.8.8-.7.7-.4.4h5.2v1.7h-7.6zm14.2.3c-.7 0-1.4-.2-2-.5-.6-.3-1.1-.8-1.5-1.3-.4-.6-.8-1.2-1-2-.2-.8-.3-1.6-.3-2.4 0-.9.1-1.7.3-2.5.2-.8.6-1.4 1-2 .4-.6.9-1 1.5-1.3.6-.3 1.3-.5 2-.5.8 0 1.4.2 2 .5.6.3 1.1.8 1.5 1.3.4.6.8 1.2 1 2 .2.8.3 1.6.3 2.5 0 .9-.1 1.7-.3 2.4-.2.8-.5 1.4-1 2-.4.6-.9 1-1.5 1.3-.5.3-1.2.5-2 .5zm0-1.8c.6 0 1.1-.2 1.6-.6.4-.4.8-.9 1-1.6.2-.7.4-1.4.4-2.2 0-.8-.1-1.6-.4-2.3-.2-.7-.6-1.2-1-1.6-.4-.4-1-.6-1.6-.6-.6 0-1.2.2-1.6.6-.4.4-.8.9-1 1.6-.2.7-.4 1.4-.4 2.3 0 .8.1 1.6.4 2.2.2.7.6 1.2 1 1.6.5.4 1 .6 1.6.6zm11.5 1.8c-.7 0-1.4-.2-2-.5-.6-.3-1.1-.8-1.5-1.3-.4-.6-.8-1.2-1-2-.2-.8-.3-1.6-.3-2.4 0-.9.1-1.7.3-2.5.2-.8.6-1.4 1-2 .4-.6.9-1 1.5-1.3.6-.3 1.3-.5 2-.5.8 0 1.4.2 2 .5.6.3 1.1.8 1.5 1.3.4.6.8 1.2 1 2 .2.8.3 1.6.3 2.5 0 .9-.1 1.7-.3 2.4-.2.8-.5 1.4-1 2-.4.6-.9 1-1.5 1.3-.6.3-1.3.5-2 .5zm0-1.8c.6 0 1.1-.2 1.6-.6.4-.4.8-.9 1-1.6.2-.7.4-1.4.4-2.2 0-.8-.1-1.6-.4-2.3-.2-.7-.6-1.2-1-1.6-.4-.4-1-.6-1.6-.6-.6 0-1.2.2-1.6.6-.4.4-.8.9-1 1.6-.2.7-.4 1.4-.4 2.3 0 .8.1 1.6.4 2.2.2.7.6 1.2 1 1.6.4.4.9.6 1.6.6zm10.8 1.5v-8.8h1.8V95h.1c.2-.3.4-.5.7-.8s.6-.4.9-.5c.4-.1.7-.2 1.1-.2.7 0 1.2.2 1.7.5s.8.7 1 1.2c.3-.5.7-.8 1.2-1.2.5-.3 1.1-.5 1.8-.5 1 0 1.8.3 2.3 1 .5.6.8 1.5.8 2.5v5.7h-1.9v-5.4c0-.7-.2-1.2-.5-1.5-.3-.3-.7-.5-1.3-.5-.4 0-.8.1-1.1.4-.3.2-.6.6-.8 1s-.3.9-.3 1.3v4.7h-1.9v-5.4c0-.7-.2-1.2-.5-1.5-.3-.3-.8-.5-1.3-.5-.4 0-.8.1-1.1.4-.3.2-.6.6-.7 1s-.3.9-.3 1.3v4.7h-1.7zm18.6.3c-.7 0-1.3-.1-1.8-.3-.5-.2-.9-.5-1.3-.9-.3-.4-.6-.8-.7-1.2l1.7-.7c.2.5.5.8.9 1.1.4.2.8.4 1.3.4s.9-.1 1.2-.2c.3-.2.5-.4.5-.8 0-.2-.1-.5-.2-.6-.2-.2-.4-.3-.6-.4l-.9-.3-1.1-.2c-.4-.1-.8-.3-1.2-.5-.4-.2-.7-.5-.9-.9-.2-.4-.3-.8-.3-1.2 0-.5.2-1 .5-1.4.3-.4.7-.7 1.2-.9.5-.2 1.1-.3 1.7-.3.6 0 1.1.1 1.5.2.5.1.9.3 1.2.6.3.3.6.6.8 1l-1.6.7c-.2-.4-.5-.7-.8-.8-.3-.2-.7-.2-1.1-.2-.4 0-.8.1-1.1.3-.3.2-.4.4-.4.7 0 .3.1.5.4.7.3.2.6.3 1 .4l1.3.3c.9.2 1.5.6 2 1 .4.4.7 1 .7 1.6 0 .6-.2 1.1-.5 1.5-.3.4-.8.7-1.3 1-.8.2-1.4.3-2.1.3zM0 113.3V99h1.7v14.3H0zm4.6 0v-10.2h1.6v1.5h.1c.3-.5.7-.9 1.3-1.3.6-.4 1.3-.5 2-.5 1.2 0 2.2.4 2.8 1.1.6.7 1 1.7 1 2.9v6.5h-1.7V107c0-1-.2-1.7-.7-2.1-.5-.4-1.1-.6-1.8-.6-.6 0-1.1.2-1.5.5-.4.3-.8.7-1 1.2-.2.5-.4 1-.4 1.6v5.7H4.6zm10-10.2h6v1.5h-6v-1.5zm1.8 7.5v-10.4h1.7v10c0 .5.1.9.3 1.2.2.3.6.4 1.1.4.2 0 .4 0 .6-.1.2-.1.4-.2.5-.2v1.7c-.2.1-.4.1-.6.2-.2.1-.5.1-.8.1-.9 0-1.5-.2-2.1-.8-.5-.5-.7-1.2-.7-2.1zm10.3 3c-1 0-1.9-.2-2.6-.7-.8-.5-1.4-1.1-1.8-1.9-.4-.8-.6-1.7-.6-2.8 0-1 .2-1.9.6-2.7.4-.8 1-1.5 1.7-2s1.6-.8 2.6-.8 1.9.2 2.6.7c.7.4 1.3 1.1 1.7 1.8.4.8.6 1.7.6 2.7v.5h-8.8V107h7c0-.3-.1-.6-.2-.9-.1-.3-.3-.6-.5-.9-.2-.3-.6-.5-.9-.7-.4-.2-.8-.3-1.4-.3-.7 0-1.2.2-1.7.5s-.8.8-1.1 1.4c-.3.6-.4 1.2-.4 2 0 .9.2 1.6.5 2.2.3.6.8 1 1.3 1.3.5.3 1.1.4 1.7.4.8 0 1.4-.2 1.8-.5.5-.4.9-.8 1.2-1.3l1.4.7c-.4.8-1 1.4-1.7 1.9-1 .5-1.9.8-3 .8zm6.7-.3v-10.2H35v1.6h.1c.1-.4.4-.7.7-1 .3-.3.7-.5 1.1-.7.4-.2.8-.2 1.2-.2h.7c.2 0 .3.1.5.2v1.8c-.2-.1-.5-.2-.7-.2-.2-.1-.5-.1-.7-.1-.5 0-1 .1-1.4.4-.4.3-.7.7-1 1.1-.2.5-.4 1-.4 1.5v5.7h-1.7zm10.4.3c-.8 0-1.4-.1-2-.4-.6-.3-1-.7-1.3-1.2-.3-.5-.5-1.1-.5-1.8 0-.8.2-1.4.6-1.9.4-.5.9-.9 1.5-1.2.7-.3 1.4-.4 2.2-.4.4 0 .9 0 1.2.1.4.1.7.2 1 .3.3.1.5.2.7.3v-.6c0-.8-.3-1.4-.8-1.8-.5-.5-1.2-.7-2-.7-.6 0-1.1.1-1.6.4-.5.2-.9.6-1.1 1l-1.3-1c.3-.4.6-.7 1-1 .4-.3.9-.5 1.4-.7.5-.2 1.1-.2 1.6-.2 1.4 0 2.5.4 3.2 1.1.8.7 1.2 1.7 1.2 3v6.5h-1.6v-1.5h-.1c-.2.3-.4.6-.7.8-.3.3-.7.5-1.1.7-.5.1-1 .2-1.5.2zm.1-1.5c.6 0 1.1-.1 1.6-.4.5-.3.9-.7 1.2-1.2.3-.5.5-1 .5-1.6-.3-.2-.7-.4-1.2-.5-.5-.1-1-.2-1.5-.2-1 0-1.7.2-2.1.6-.4.4-.7.9-.7 1.5s.2 1 .6 1.4c.4.2 1 .4 1.6.4zm11.7 1.5c-1 0-1.9-.2-2.7-.7-.8-.5-1.4-1.1-1.8-1.9-.4-.8-.7-1.7-.7-2.8 0-1 .2-2 .7-2.8.4-.8 1.1-1.5 1.8-1.9.8-.5 1.7-.7 2.7-.7 1.1 0 2.1.3 2.8.8.7.5 1.3 1.2 1.6 2l-1.5.6c-.2-.6-.6-1.1-1.1-1.4-.5-.3-1.1-.5-1.8-.5-.6 0-1.2.2-1.7.5s-.9.8-1.2 1.4c-.3.6-.5 1.3-.5 2 0 .8.2 1.4.5 2 .3.6.7 1 1.2 1.4.5.3 1.1.5 1.7.5.7 0 1.3-.2 1.9-.5.5-.3.9-.8 1.2-1.4l1.5.6c-.3.8-.9 1.5-1.6 2-.9.5-1.8.8-3 .8zm5.5-10.5h6v1.5h-6v-1.5zm1.8 7.5v-10.4h1.7v10c0 .5.1.9.3 1.2.2.3.6.4 1.1.4.2 0 .4 0 .6-.1.2-.1.4-.2.5-.2v1.7c-.2.1-.4.1-.6.2-.2.1-.5.1-.8.1-.9 0-1.5-.2-2.1-.8-.4-.5-.7-1.2-.7-2.1zm6.5 2.7v-10.2h1.7v10.2h-1.7zm.9-12.1c-.3 0-.6-.1-.9-.4-.2-.2-.4-.5-.4-.9 0-.3.1-.6.4-.9.2-.2.5-.4.9-.4.3 0 .6.1.9.4.2.2.4.5.4.9 0 .3-.1.6-.4.9-.3.3-.6.4-.9.4zm8.1 12.4c-1 0-1.9-.2-2.7-.7-.8-.5-1.4-1.1-1.8-1.9-.4-.8-.7-1.7-.7-2.8 0-1 .2-1.9.7-2.8.4-.8 1.1-1.5 1.8-2 .8-.5 1.7-.7 2.7-.7 1 0 1.9.2 2.7.7.8.5 1.4 1.1 1.9 2 .4.8.7 1.7.7 2.7 0 1-.2 1.9-.7 2.8-.4.8-1.1 1.5-1.9 1.9-.8.5-1.7.8-2.7.8zm0-1.6c.6 0 1.2-.2 1.7-.5s1-.8 1.3-1.3c.3-.6.5-1.3.5-2.1s-.2-1.5-.5-2.1c-.3-.6-.8-1-1.3-1.3-.5-.3-1.1-.5-1.7-.5-.6 0-1.2.2-1.7.5s-1 .7-1.3 1.3c-.3.6-.5 1.3-.5 2.1s.2 1.5.5 2.1c.3.6.8 1 1.3 1.3.5.4 1.1.5 1.7.5zm7 1.3v-10.2H87v1.5h.1c.3-.5.7-.9 1.3-1.3.6-.4 1.3-.5 2-.5 1.2 0 2.2.4 2.8 1.1.6.7 1 1.7 1 2.9v6.5h-1.7V107c0-1-.2-1.7-.7-2.1-.5-.4-1.1-.6-1.8-.6-.6 0-1.1.2-1.5.5-.4.3-.8.7-1 1.2-.2.5-.4 1-.4 1.6v5.7h-1.7zm15.1-10.2h6v1.5h-6v-1.5zm1.8 7.5v-10.4h1.7v10c0 .5.1.9.3 1.2.2.3.6.4 1.1.4.2 0 .4 0 .6-.1.2-.1.4-.2.5-.2v1.7c-.2.1-.4.1-.6.2-.2.1-.5.1-.8.1-.9 0-1.5-.2-2.1-.8-.4-.5-.7-1.2-.7-2.1zm10.5 3c-1 0-1.9-.2-2.7-.7-.8-.5-1.4-1.1-1.8-1.9-.4-.8-.7-1.7-.7-2.8 0-1 .2-1.9.7-2.8.4-.8 1.1-1.5 1.8-2 .8-.5 1.7-.7 2.7-.7 1 0 1.9.2 2.7.7.8.5 1.4 1.1 1.9 2 .4.8.7 1.7.7 2.7 0 1-.2 1.9-.7 2.8-.4.8-1.1 1.5-1.9 1.9-.8.5-1.7.8-2.7.8zm0-1.6c.6 0 1.2-.2 1.7-.5s1-.8 1.3-1.3c.3-.6.5-1.3.5-2.1s-.2-1.5-.5-2.1c-.3-.6-.8-1-1.3-1.3-.5-.3-1.1-.5-1.7-.5-.6 0-1.2.2-1.7.5s-1 .7-1.3 1.3c-.3.6-.5 1.3-.5 2.1s.2 1.5.5 2.1c.3.6.8 1 1.3 1.3.5.4 1.1.5 1.7.5zm12.2 1.3V99h2.1l7.2 11.4h.1l-.1-2.8V99h1.7v14.3h-1.8l-7.5-11.9h-.1l.1 2.8v9.2H125zm18.2.3c-1 0-1.9-.2-2.6-.7-.8-.5-1.4-1.1-1.8-1.9-.4-.8-.6-1.7-.6-2.8 0-1 .2-1.9.6-2.7.4-.8 1-1.5 1.7-2s1.6-.8 2.6-.8 1.9.2 2.6.7c.7.4 1.3 1.1 1.7 1.8.4.8.6 1.7.6 2.7v.5h-8.8V107h7c0-.3-.1-.6-.2-.9-.1-.3-.3-.6-.5-.9-.2-.3-.6-.5-.9-.7-.4-.2-.8-.3-1.4-.3-.7 0-1.2.2-1.7.5s-.8.8-1.1 1.4c-.3.6-.4 1.2-.4 2 0 .9.2 1.6.5 2.2.3.6.8 1 1.3 1.3.5.3 1.1.4 1.7.4.8 0 1.4-.2 1.8-.5.5-.4.9-.8 1.2-1.3l1.4.7c-.4.8-1 1.4-1.7 1.9-1 .5-1.9.8-3 .8zm5.5-.3 4.1-5.9h.2l2.9-4.3h2l-4 5.6h-.1l-3.1 4.6h-2zm.1-10.2h1.9l3.2 4.5h.1l4 5.7h-2l-3-4.5h-.1l-4.1-5.7zm9.9 0h6v1.5h-6v-1.5zm1.8 7.5v-10.4h1.7v10c0 .5.1.9.3 1.2.2.3.6.4 1.1.4.2 0 .4 0 .6-.1.2-.1.4-.2.5-.2v1.7c-.2.1-.4.1-.6.2-.2.1-.5.1-.8.1-.9 0-1.5-.2-2.1-.8-.4-.5-.7-1.2-.7-2.1zm11.2 2.7V99h4.8c.8 0 1.5.2 2.2.5.7.4 1.2.8 1.6 1.5.4.6.6 1.4.6 2.2 0 .8-.2 1.6-.6 2.2-.4.6-.9 1.1-1.6 1.5-.7.4-1.4.5-2.2.5h-3.9v-1.6h4c.6 0 1-.1 1.4-.4.4-.3.7-.6.9-1 .2-.4.3-.8.3-1.2 0-.4-.1-.8-.3-1.2-.2-.4-.5-.7-.9-1-.4-.3-.9-.4-1.4-.4h-3.2v12.7h-1.7zm14 .3c-.8 0-1.4-.1-2-.4-.6-.3-1-.7-1.3-1.2-.3-.5-.5-1.1-.5-1.8 0-.8.2-1.4.6-1.9.4-.5.9-.9 1.5-1.2.7-.3 1.4-.4 2.2-.4.4 0 .9 0 1.2.1.4.1.7.2 1 .3.3.1.5.2.7.3v-.6c0-.8-.3-1.4-.8-1.8-.5-.5-1.2-.7-2-.7-.6 0-1.1.1-1.6.4-.5.2-.9.6-1.1 1l-1.3-1c.3-.4.6-.7 1-1 .4-.3.9-.5 1.4-.7.5-.2 1.1-.2 1.6-.2 1.4 0 2.5.4 3.2 1.1.8.7 1.2 1.7 1.2 3v6.5h-1.6v-1.5h-.1c-.2.3-.4.6-.7.8-.3.3-.7.5-1.1.7-.5.1-.9.2-1.5.2zm.2-1.5c.6 0 1.1-.1 1.6-.4.5-.3.9-.7 1.2-1.2.3-.5.5-1 .5-1.6-.3-.2-.7-.4-1.2-.5-.5-.1-1-.2-1.5-.2-1 0-1.7.2-2.1.6-.4.4-.7.9-.7 1.5s.2 1 .6 1.4c.4.2 1 .4 1.6.4zm7.4 1.2v-10.2h1.7v10.2h-1.7zm.8-12.1c-.3 0-.6-.1-.9-.4-.2-.2-.4-.5-.4-.9 0-.3.1-.6.4-.9.2-.2.5-.4.9-.4.3 0 .6.1.9.4.2.2.4.5.4.9 0 .3-.1.6-.4.9-.3.3-.5.4-.9.4zm3.5 12.1v-10.2h1.6v1.5h.1c.3-.5.7-.9 1.3-1.3.6-.4 1.3-.5 2-.5 1.2 0 2.2.4 2.8 1.1.6.7 1 1.7 1 2.9v6.5h-1.7V107c0-1-.2-1.7-.7-2.1-.5-.4-1.1-.6-1.8-.6-.6 0-1.1.2-1.5.5-.4.3-.8.7-1 1.2-.2.5-.4 1-.4 1.6v5.7h-1.7zm10-10.2h6v1.5h-6v-1.5zm1.8 7.5v-10.4h1.7v10c0 .5.1.9.3 1.2.2.3.6.4 1.1.4.2 0 .4 0 .6-.1.2-.1.4-.2.5-.2v1.7c-.2.1-.4.1-.6.2-.2.1-.5.1-.8.1-.9 0-1.5-.2-2.1-.8-.4-.5-.7-1.2-.7-2.1zM418.1 55.2c-1.8 0-3.3 1.5-3.3 3.3 0 1.5 1 2.7 2.3 3.1V83h2V61.6c1.3-.4 2.3-1.7 2.3-3.1 0-1.8-1.5-3.3-3.3-3.3zM546.5 58.6c0-1.8-1.5-3.3-3.3-3.3s-3.3 1.5-3.3 3.3c0 1.5 1 2.7 2.3 3.1v21.2h2V61.7c1.3-.4 2.3-1.6 2.3-3.1z"></path></svg>
</figure>
<h2 id="the-fuzzy-beginning">The fuzzy beginning <a class="headline-link" href="https://web.dev/economic-times-inp/#the-fuzzy-beginning">#</a></h2>
<p>When Google initially introduced INP as an experimental metric with the potential to evolve into one of the Core Web Vitals metrics, the Economic Times team took up the challenge to fix it before it graduates into one, since providing a world class user experience is crucial to our core business values.</p>
<p>INP has been one of the most difficult metrics to solve thus far. In the beginning, it was unclear on how to measure INP effectively. What made it more difficult was the lack of community support—including most Real User Monitoring (RUM) providers not supporting it yet. However, we had Google RUM tools like <a href="https://developer.chrome.com/docs/crux/about/" rel="noopener">Chrome User Experience Report (CrUX)</a>, the <a href="https://github.com/GoogleChrome/web-vitals" rel="noopener"><code>web-vitals</code> JavaScript library</a>, and others supporting it, which gave us a sense of where we stood while we were evaluating the path ahead. Our INP was close to 1,000 milliseconds at the origin level when we started.</p>
<p>One thing that emerged while fixing INP in <a href="https://web.dev/find-slow-interactions-in-the-field/">the field</a> was that one of the lab metrics to target could be <a href="https://web.dev/tbt/">Total Blocking Time (TBT)</a>. TBT was already well documented and supported by the community. Despite already meeting the thresholds for Core Web Vitals, however, we weren't doing as well on the TBT front, as it was over 3 seconds when we began.</p>
<h2 id="what-is-tbt,-and-what-steps-did-we-take-to-improve-it">What is TBT, and what steps did we take to improve it? <a class="headline-link" href="https://web.dev/economic-times-inp/#what-is-tbt,-and-what-steps-did-we-take-to-improve-it">#</a></h2>
<p>TBT is a lab metric that measures the responsiveness of a web page to user input during page load. Any task that takes more than 50 milliseconds to execute is considered a long task, and the time after the 50 millisecond threshold is known as the <strong>blocking time</strong>.</p>
<p>TBT is calculated by taking the sum of the blocking time of all long tasks during page load. For example, if there are two long tasks during load, the blocking time is determined as follows:</p>
<ul>
<li>Task A takes 80 milliseconds (30 milliseconds more than 50 milliseconds).</li>
<li>Task B takes 100 milliseconds (50 milliseconds more than 50 milliseconds).</li>
</ul>
<p>The page's TBT will be: 80 milliseconds (30 + 50). The lower the TBT, the better, and TBT also <a href="https://almanac.httparchive.org/en/2022/performance#inp-and-tbt" rel="noopener">correlates well with INP</a>.</p>
<p>Here’s a quick lab comparison of our TBT before and after taking steps to improve it:</p>
<figure>
  <img alt="A composite image of long tasks during startup as shown in the performance panel of Chrome DevTools, and a report of page metrics. The main thread is blocked during page load for 3,260 milliseconds." decoding="async" height="502" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format" srcset="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/UfZ9zaCLHjCMcPg74xHV.png?auto=format&w=1600 1600w" width="800" />
  <figcaption>
    The main thread during startup before optimizing TBT. The TBT is 3,260 milliseconds.
  </figcaption>
</figure>
<figure>
  <img alt="A composite image of long tasks during startup as shown in the performance panel of Chrome DevTools, and a report of page metrics. The main thread is blocked during page load for 120 milliseconds." decoding="async" height="701" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format" srcset="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/RLx2y7zTItkaklqxSG17.png?auto=format&w=1600 1600w" width="800" />
  <figcaption>
    The main thread during startup after optimizing TBT. The TBT is 120 milliseconds.
  </figcaption>
</figure>
<h3 id="minimize-main-thread-work">Minimize main thread work <a class="headline-link" href="https://web.dev/economic-times-inp/#minimize-main-thread-work">#</a></h3>
<p>The browser’s main thread handles everything from parsing HTML, building the DOM, to parsing CSS and applying styles, as well as evaluating and executing JavaScript. The main thread also handles user interactions—that is, click, tap, and keypresses. If the main thread is occupied with doing other work, it may not respond to user inputs efficiently, and may lead to a janky user experience.</p>
<p>This was the most difficult task for us, since we have our own algorithms to detect user identity for serving ads based on subscription status and third party scripts for A/B testing, analytics, and more.</p>
<p>We took small steps at first, such as de-prioritizing loading of less critical business assets. Second, we used <a href="https://developer.mozilla.org/docs/Web/API/Window/requestIdleCallback" rel="noopener"><code>requestIdleCallback</code></a> for non-critical work, which can help to reduce TBT.</p>
<div><pre class="language-js"><code class="language-js"><span class="token keyword">if</span> <span class="token punctuation">(</span><span class="token string">'requestIdleCallback'</span> <span class="token keyword">in</span> window<span class="token punctuation">)</span> <span class="token punctuation">{</span><br />  <span class="token keyword">this</span><span class="token punctuation">.</span>requestIdleCallbackId <span class="token operator">=</span> <span class="token function">requestIdleCallback</span><span class="token punctuation">(</span><span class="token function">fetchMarketsData</span><span class="token punctuation">.</span><span class="token function">bind</span><span class="token punctuation">(</span><span class="token keyword">this</span><span class="token punctuation">)</span><span class="token punctuation">,</span> <span class="token punctuation">{</span><span class="token literal-property property">timeout</span><span class="token operator">:</span> <span class="token number">3000</span><span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br /><span class="token punctuation">}</span> <span class="token keyword">else</span> <span class="token punctuation">{</span><br />  <span class="token function">fetchMarketsData</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">;</span> <span class="token comment">// Fallback in case requestIdleCallback is not supported</span><br /><span class="token punctuation">}</span></code></pre>
</div><p>Specifying a timeout is recommended when using <code>requestIdleCallback</code>, since it makes sure that if the given time is elapsed and the callback is not already been called, it executes the callback immediately after the timeout.</p>
<h3 id="minimize-script-evaluation-time">Minimize script evaluation time <a class="headline-link" href="https://web.dev/economic-times-inp/#minimize-script-evaluation-time">#</a></h3>
<p>We also lazy loaded third party libraries using <a href="https://loadable-components.com/" rel="noopener">Loadable components</a>. We also removed unused JavaScript and CSS by profiling the page with the <a href="https://developer.chrome.com/docs/devtools/coverage/" rel="noopener">coverage tool</a> in Chrome DevTools. It helped us to identify areas where <a href="https://webpack.js.org/guides/tree-shaking/" rel="noopener">tree shaking</a> was needed to ship less code during page load, and therefore reduce the initial bundle size of the application.</p>
<figure>
  <img alt="A screenshot of the coverage tool in Chrome DevTools. Here, the tool displays unused portions of JavaScript and CSS files during page load." decoding="async" height="100" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format" srcset="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/uynCVTUjcv4ujJva41PS.png?auto=format&w=1600 1600w" width="800" />
</figure>
<h3 id="reduce-dom-size">Reduce DOM size <a class="headline-link" href="https://web.dev/economic-times-inp/#reduce-dom-size">#</a></h3>
<p>Per Lighthouse, large DOM sizes increase memory usage, causes longer <a href="https://web.dev/economic-times-inp/reduce-the-scope-and-complexity-of-style-calculations/">style recalculations</a>, and produces costly <a href="https://developers.google.com/speed/docs/insights/browser-reflow" rel="noopener">layout reflows</a>.</p>
<figure>
  <img alt="A screenshot of the DOM size audit in Lighthouse. The number of DOM elements reported is 2,706 elements." decoding="async" height="86" loading="lazy" sizes="(min-width: 712px) 712px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/JLQfvWp1Fouc55Xbgy7X.png?auto=format" srcset="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/JLQfvWp1Fouc55Xbgy7X.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/JLQfvWp1Fouc55Xbgy7X.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/JLQfvWp1Fouc55Xbgy7X.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/JLQfvWp1Fouc55Xbgy7X.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/JLQfvWp1Fouc55Xbgy7X.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/JLQfvWp1Fouc55Xbgy7X.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/JLQfvWp1Fouc55Xbgy7X.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/JLQfvWp1Fouc55Xbgy7X.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/JLQfvWp1Fouc55Xbgy7X.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/JLQfvWp1Fouc55Xbgy7X.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/JLQfvWp1Fouc55Xbgy7X.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/JLQfvWp1Fouc55Xbgy7X.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/JLQfvWp1Fouc55Xbgy7X.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/JLQfvWp1Fouc55Xbgy7X.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/JLQfvWp1Fouc55Xbgy7X.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/JLQfvWp1Fouc55Xbgy7X.png?auto=format&w=1424 1424w" width="712" />
</figure>
<p>We reduced the number of DOM nodes in two ways:</p>
<ul>
<li>First, we rendered our menu items at the user’s request (on click). It decreased the DOM size by around 1,200 nodes.</li>
<li>Second, we lazy loaded less important widgets.</li>
</ul>
<p>Because of all these efforts, we reduced TBT significantly, and our INP was reduced accordingly by almost 50%:</p>
<figure>
  <img alt="A screenshot of the INP audit in CrUX. The INP for the page is 539 milliseconds, which exceeds the &#x27;poor&#x27; threshold." decoding="async" height="216" loading="lazy" sizes="(min-width: 574px) 574px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/ojm0miY1lwoFqxZWnYVM.png?auto=format" srcset="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/ojm0miY1lwoFqxZWnYVM.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/ojm0miY1lwoFqxZWnYVM.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/ojm0miY1lwoFqxZWnYVM.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/ojm0miY1lwoFqxZWnYVM.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/ojm0miY1lwoFqxZWnYVM.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/ojm0miY1lwoFqxZWnYVM.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/ojm0miY1lwoFqxZWnYVM.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/ojm0miY1lwoFqxZWnYVM.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/ojm0miY1lwoFqxZWnYVM.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/ojm0miY1lwoFqxZWnYVM.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/ojm0miY1lwoFqxZWnYVM.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/ojm0miY1lwoFqxZWnYVM.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/ojm0miY1lwoFqxZWnYVM.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/ojm0miY1lwoFqxZWnYVM.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/ojm0miY1lwoFqxZWnYVM.png?auto=format&w=1148 1148w" width="574" />
</figure>
<p>At this point, we nearly ran out of easy wins to further reduce TBT (and INP by proxy), but we knew we had a lot of room for improvement. This is when we decided to upgrade our custom-built UI boilerplate to the latest version of React along with <a href="https://nextjs.org/" rel="noopener">Next.js</a> to make better use of <a href="https://react.dev/reference/react" rel="noopener">hooks</a> to avoid unnecessary re-rendering of components.</p>
<p>Due to more frequent updates and comparatively lesser traffic as compared to the other portions of the website, we began to migrate our <a href="https://economictimes.indiatimes.com/topic/home" rel="noopener">topic pages</a> to Next.js. We also used <a href="https://partytown.builder.io/" rel="noopener">PartyTown</a> for offloading additional heavy main thread work to web workers, along with techniques like <code>requestIdleCallBack</code> for deferring non-critical tasks.</p>
<h2 id="how-has-improving-inp-helped-the-economic-times">How has improving INP helped The Economic Times? <a class="headline-link" href="https://web.dev/economic-times-inp/#how-has-improving-inp-helped-the-economic-times">#</a></h2>
<h3 id="current-tbt-and-inp-on-origin">Current TBT and INP on origin <a class="headline-link" href="https://web.dev/economic-times-inp/#current-tbt-and-inp-on-origin">#</a></h3>
<p>At the time of publishing this post, the TBT for our origin was 120 milliseconds, down from 3,260 milliseconds when we began our optimization efforts. Similarly, the INP for our origin was 257 milliseconds after our optimization efforts, down from over 1,000 milliseconds.</p>
<figure>
  <img alt="A screenshot of the INP audit in CrUX. The INP for the page is 257 milliseconds, which is within the &#x27;needs improvement&#x27; thresholds." decoding="async" height="218" loading="lazy" sizes="(min-width: 582px) 582px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/6cMvebBQKG2nhyc1eYeB.png?auto=format" srcset="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/6cMvebBQKG2nhyc1eYeB.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/6cMvebBQKG2nhyc1eYeB.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/6cMvebBQKG2nhyc1eYeB.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/6cMvebBQKG2nhyc1eYeB.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/6cMvebBQKG2nhyc1eYeB.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/6cMvebBQKG2nhyc1eYeB.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/6cMvebBQKG2nhyc1eYeB.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/6cMvebBQKG2nhyc1eYeB.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/6cMvebBQKG2nhyc1eYeB.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/6cMvebBQKG2nhyc1eYeB.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/6cMvebBQKG2nhyc1eYeB.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/6cMvebBQKG2nhyc1eYeB.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/6cMvebBQKG2nhyc1eYeB.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/6cMvebBQKG2nhyc1eYeB.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/6cMvebBQKG2nhyc1eYeB.png?auto=format&w=1164 1164w" width="582" />
</figure>
<h3 id="inp-crux-trend">INP CrUX trend <a class="headline-link" href="https://web.dev/economic-times-inp/#inp-crux-trend">#</a></h3>
<p>The traffic received on topic pages represents a significantly smaller portion of overall traffic. Hence, it was an ideal place for experimentation. The CrUX results along with the business outcomes were very encouraging, and led us to expand our efforts across the entire website to reap further benefits.</p>
<figure>
  <img alt="A screenshot of INP distributions as visualized in CrUX over a period of four months, starting in July 2022 and ending in October 2022. Values within the &#x27;poor&#x27; and &#x27;needs improvement&#x27; thresholds declined somewhat, while the values within the &#x27;good&#x27; threshold increased." decoding="async" height="190" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format" srcset="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/pkPEYIQIeEDKdIKOCFSY.png?auto=format&w=1600 1600w" width="800" />
</figure>
<h3 id="akamai-mpulse-tbt-analysis">Akamai mPulse TBT Analysis <a class="headline-link" href="https://web.dev/economic-times-inp/#akamai-mpulse-tbt-analysis">#</a></h3>
<p>We use <a href="https://www.akamai.com/products/mpulse-real-user-monitoring" rel="noopener">Akamai mPulse</a> as our RUM solution, which measures TBT in the field. We observed a consistent decrease in TBT, clearly mapping to the outcomes of our efforts to reduce INP. As can be seen in the screenshot below, TBT values eventually dropped from approximately 5 seconds in to around 200 milliseconds in the field.</p>
<figure>
  <img alt="A screenshot of a chart in Akamai mPulse, showing a decline in TBT over the course of roughly a month." decoding="async" height="118" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format" srcset="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/eS3iIvNxEUhe19GGdDBG.png?auto=format&w=1600 1600w" width="800" />
</figure>
<h2 id="business-outcome">Business outcome <a class="headline-link" href="https://web.dev/economic-times-inp/#business-outcome">#</a></h2>
<p>Overall, our efforts to bring down TBT by 30 times, along with migrating to Next.js helped us reduce INP nearly by 4 times, which eventually led to a <strong>50% decrease in bounce rate and 43% uplift in pageviews</strong> on topic pages.</p>
<figure>
  <img alt="A screenshot of Google Analytics comparing pageviews versus bounce rate. Because of the optimizations made to INP on The Economic Times website, a 50% decrease in bounce rate and a 43% increase in pageviews was realized." decoding="async" height="288" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format" srcset="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/WOzP0OjtPV6rsjqbtbfe.png?auto=format&w=1600 1600w" width="800" />
</figure>
<h2 id="conclusion">Conclusion <a class="headline-link" href="https://web.dev/economic-times-inp/#conclusion">#</a></h2>
<p>To summarize, INP extensively helped to determine runtime performance issues on parts of the Economic Times website. It has proven to be one of the most effective metrics to positively impact business outcomes. Due to the very encouraging numbers we've observed as the result of this effort, we are motivated to scale our optimization efforts to other areas of our website and reap additional benefits.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s new in Jetpack Compose]]></title>
<description><![CDATA[Posted by Jolanda Verhoef, Android Developer Relations Engineer




It has been almost two years since we launched the first stable version of Jetpack Compose, and since then, we’ve seen its adoption and feature set grow spectacularly. Whether you write an application for smartphones, foldables, ...]]></description>
<link>https://tsecurity.de/de/1886070/android-tipps/whats-new-in-jetpack-compose/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1886070/android-tipps/whats-new-in-jetpack-compose/</guid>
<pubDate>Wed, 24 May 2023 09:31:51 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi46a1FLWbsuwRekbDLraECukwVQXhGBEJa3OIpb2yb5hzzqzRH6Ou1KqXrBwLv-zqUw4Dn_HUsO1cdQgFRSuexqu5baygO4OGOeehZmQP9o5E1hRa9Q_9VOImZDm2nERmW2y0OiTfhu6JcjynLaN2Sn0OAzArfh7ouChr5B32WxEVdbBTTmXoJmO40/s1600/Android-Jetpack-compose-IO-22-blog_Social.png"><em>Posted by <a href="https://twitter.com/lojanda" target="_blank">Jolanda Verhoef</a>, Android Developer Relations Engineer</em>

<a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUC5WnCtiXuWYJSvw51Fifh3Q6Pw10V5BKGal-M41es9FB4TcngVWPFYLedm2C5zMGCJncFp2tnRblZY7eHHwPB1mwWWAwU8dG-JtUHT0zFsGQo-cAb7L6NbuZ70Of0EWoRf_0esNgRdosyrJGBxyPx_obiXAV6pRbevl-P5zIx0wGnOQ5fV21YNbU/s1600/Android-Jetpack-compose-IO-22-blog_Header.png"><img border="0" data-original-height="800" data-original-width="1058" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUC5WnCtiXuWYJSvw51Fifh3Q6Pw10V5BKGal-M41es9FB4TcngVWPFYLedm2C5zMGCJncFp2tnRblZY7eHHwPB1mwWWAwU8dG-JtUHT0zFsGQo-cAb7L6NbuZ70Of0EWoRf_0esNgRdosyrJGBxyPx_obiXAV6pRbevl-P5zIx0wGnOQ5fV21YNbU/s1600/Android-Jetpack-compose-IO-22-blog_Header.png"></a>


<p>It has been almost two years since we launched the first stable version of Jetpack Compose, and since then, we’ve seen its adoption and feature set grow spectacularly. Whether you write an application for smartphones, foldables, tablets, ChromeOS devices, smartwatches, or TVs, Compose has got you covered! We recommend you to use Compose for all new Wear OS, phone and large-screen apps. With new tooling and library features, extended Material Design 3, large screen, and Wear OS support, and alpha versions of Compose for homescreen widgets and TV… This is an exciting time!</p><p>
  
</p><h3><strong>Compose in the community</strong></h3>

<p>In the last year, we’ve seen many companies investigating and <a href="https://developer.android.com/jetpack/compose/adopt#what-developers-are-saying" target="_blank">choosing Compose to build new features and migrate screens</a> in their production applications. <strong>24% of the top 1000 apps on Google Play</strong> have already chosen to adopt Compose! For example, Dropbox engineers told us that they rewrote their search experience in Compose in just a few weeks, which was 40% less time than anticipated, and less than half the time it took the team to build the feature on iOS. They also shared that they were interested in adopting Compose <em>“because of its first-class support for design systems and tooling support”</em>. Our Google Drive team <b>cut their development time nearly in half</b> when using Compose combined with architecture improvements. </p>



<p>It’s great to see how these teams experience <b>faster development cycles</b>, and also feel their UI code is <b>more testable</b>. Inspired? Start by reading our guide <a href="https://developer.android.com/jetpack/compose/adopt/for-large-teams" target="_blank">How to Adopt Compose for your Team</a>, which outlines how and where to start, and shows the areas of development where Compose can bring huge added value.</p><div><br></div>

<h3><strong>Library features &amp; development</strong></h3>

<p>Since we released the first <a href="https://developer.android.com/jetpack/compose/bom" target="_blank">Compose Bill of Materials</a> in October last year, we’ve been working on new features, bug fixes, performance improvements, and bringing Compose to everywhere you build UI: phones, tablets, foldables, watches, TV, and your home screen. You can find all changes in the <a href="https://developer.android.com/jetpack/androidx/releases/compose#2023.05.01" target="_blank">May 2023 release</a> and the <a href="https://developer.android.com/jetpack/androidx/releases/compose#versions" target="_blank">latest alpha versions</a> of the Compose libraries.</p>

<p>We’ve heard from you that <b>performance</b> is something you care about, and that it’s not always clear how to create performant Compose applications. We’re continuously improving the performance of Compose. For example, as of last October, we started <b>migrating modifiers to a new and more efficient system</b>, and we’re starting to see the results of that migration. For text alone, this work resulted in an average <b>22% performance gain</b> that can be seen in the <a href="https://developer.android.com/jetpack/androidx/releases/compose-foundation" target="_blank">latest alpha release</a>, and these improvements apply across the board. To get these benefits in your app, all you have to do is update your Compose version!</p>

<p><span><b>Text</b></span> and <span><b>TextField</b></span> got many upgrades in the past months. Next to the performance improvements we already mentioned, Compose now supports the latest emoji version <emoji>🫶</emoji> and includes new text features such as outlining text, hyphenation support, and configuring line breaking behavior. Read more in the release notes of the <a href="https://developer.android.com/jetpack/androidx/releases/compose-foundation" target="_blank">compose-foundation</a> and <a href="https://developer.android.com/jetpack/androidx/releases/compose-ui#version_15_2" target="_blank">compose-ui</a> libraries.</p><p>

</p><p>The new <a href="https://developer.android.com/reference/kotlin/androidx/compose/foundation/pager/package-summary#HorizontalPager%28kotlin.Int,androidx.compose.ui.Modifier,androidx.compose.foundation.pager.PagerState,androidx.compose.foundation.layout.PaddingValues,androidx.compose.foundation.pager.PageSize,kotlin.Int,androidx.compose.ui.unit.Dp,androidx.compose.ui.Alignment.Vertical,androidx.compose.foundation.gestures.snapping.SnapFlingBehavior,kotlin.Boolean,kotlin.Boolean,kotlin.Function1,androidx.compose.ui.input.nestedscroll.NestedScrollConnection,kotlin.Function1%29" target="_blank">pager component</a> allows you to <b>horizontally or vertically flip through content</b>, which is similar to <a href="https://developer.android.com/reference/kotlin/androidx/viewpager2/widget/ViewPager2" target="_blank"><span>ViewPager2</span></a> in Views. It allows deep customization options, making it possible to create visually stunning effects:</p>

<div><table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody><tr><td><center><img alt="Moving image showing Hoizontal Pager composable" border="0" data-original-height="1504" data-original-width="720" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBopvOqaU9oxm3dscQAfvO9fudtyImPLkJTzivdOyc402J4xphVOGXNXI3zaGGmSAe1oTDB-HBXWicvdBMijw3uekqDEXsaq_23wCYO9BlzdrazcsfoOwxRkpKXaV8nfPJM0UUbhN8Kd47UEOZrcMf9P5S50fvq20oWdoelY_9fJWM4D4fX5fZjSOu/s1600/image7.gif" td=""></center></td></tr><tr><td class="tr-caption"><i>Choose a song using the </i><span><i>HorizontalPager</i></span><i> composable. Learn how to implement this and other fancy effects in <a href="https://medium.com/androiddevelopers/customizing-compose-pager-with-fun-indicators-and-transitions-12b3b69af2cc" target="_blank">Rebecca Franks' blog post</a>.</i></td></tr></tbody></table></div>

<p>The new flow layouts <span>FlowRow</span> and <span>FlowColumn</span> make it easy to arrange content in a vertical or horizontal flow, much like lines of text in a paragraph. They also enable dynamic sizing using weights to distribute the items across the container. </p>

<div><table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody><tr><td><center><img alt="Image of search filters in a real estate app created with flow layouts" border="0" data-original-height="1504" data-original-width="720" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMZWZVIHnYeKDOBKRnv_Spfm2F2CW-3AL1KBlEnlOCFMypA52dKcXm0oFyWFsBwZEbs0z1QI2EPi1vzaM2tU_nCtzpn_Dx7A7cH7mIeU3dr7AZGf47v2JwFJa7z7BHw0Cnxwc3QmRzUiixnJBV1KedWJcBmGeGyopPGH7l3RL2Ts5zn9qC53MeA8Dg/s1600/image1.png" td=""></center></td></tr><tr><td class="tr-caption"><i>Using flow layouts to show the search filters in a real estate app</i></td></tr></tbody></table></div>

<p>To learn more about the new features, performance improvements, and bug fixes, see the <a href="https://developer.android.com/jetpack/androidx/releases/compose#versions" target="_blank">release notes</a> of the latest stable and newest alpha release of the Compose libraries.</p>

<h3><strong>Tools</strong></h3>
<p>Developing your app using Jetpack Compose is much easier with the new and improved tools around it. <a href="https://android-developers.googleblog.com/2023/05/android-studio-io-23-announcing-studio-bot.html" target="_blank">We added tons of new features to Android Studio</a> to improve your workflow and efficiency. Here are some highlights:</p>

<p><a href="https://developer.android.com/studio/releases#new_in_compose" target="_blank">Android Studio Flamingo</a> is the latest stable release, bringing you:</p><p>
</p><ul><blockquote>
<li><b>Project templates that use Compose and Material 3 by default</b>, reflecting our recommended practices.</li>
<li><b>Material You dynamic colors in Compose previews</b> to quickly see how your composable responds to differently colored wallpapers on a user device.</li>
<li><b>Compose functions in system traces</b> when you use the System Trace profiler to help you understand which Compose functions are being recomposed.</li>
</blockquote></ul><p><a href="https://developer.android.com/studio/preview/features#2022.3.1" target="_blank">Android Studio Giraffe</a> is the latest beta release, containing features such as:</p>
<ul><blockquote>
<li><b><a href="https://developer.android.com/studio/preview/features#live-edit" target="_blank">Live Edit</a></b>, allowing you to quickly iterate on your code on emulator or physical device without rebuilding or redeploying your app.</li>
<li><b><a href="https://developer.android.com/studio/preview/features#new-apis-for-compose-animation-preview" target="_blank">Support for new animations APIs in Animation preview</a></b> so you can debug any animations using <span>animate*AsState</span>, <span>CrossFade</span>, <span>rememberInfiniteTransition</span>, and <span>AnimatedContent</span>.</li>
<li>Compose Preview now supports <b>live updates across multiple files</b>, for example, if you make a change in your Theme.kt file, you can see all Previews updates automatically in your UI files. </li>
<li><b>Improving auto-complete behavior</b>. For example, we now show icon previews when you’re adding Material icons, and we keep the @Composable annotation when running “Implement Members".</li>
</blockquote></ul><p><a href="https://developer.android.com/studio/preview/features#2023.1.1" target="_blank">Android Studio Hedgehog</a> contains canary features such as:</p>
<ul><blockquote>
<li><b>Showing Compose state information in the debugger</b>. While debugging your app, the debugger will tell you exactly which parameters have “Changed” or have remained “Unchanged”, so you can more efficiently investigate the cause of the recomposition.</li>
<li>You can try out the new <b>Studio Bot</b>, an experimental AI powered conversational experience in Android Studio to help you generate code, fix issues, and learn about best practices, including all things Compose. This is an early experiment, but we would love for you to give it a try!</li>
<li>Emulator support for the newly announced <b>Pixel Fold and Tablet Virtual Devices</b>, so that you can test your Compose app before these devices launch later this year.</li>
<li>A new <b>Espresso Device API</b> that lets you apply rotation changes, folds, and other synchronous configuration changes to your virtual devices under test.</li>
</blockquote></ul><p>We’re also actively working on <a href="https://developer.android.com/studio/releases/past-releases/as-electric-eel-release-notes#visual-linting" target="_blank">visual linting</a> and <a href="https://developer.android.com/guide/topics/ui/accessibility/testing#accessibility-scanner" target="_blank">accessibility checks</a> for previews so you can automatically audit your Compose UI and check for issues across different screen sizes, and on <a href="https://developer.android.com/jetpack/compose/tooling/previews#preview-multipreview" target="_blank">multipreview</a> templates to help you quickly add common sets of previews.</p>

<h3><strong>Material 3</strong></h3>

<p>Material 3 is the <b>recommended design system for Android apps</b>, and the latest <a href="https://material.io/blog/material-3-compose-1-1" target="_blank">1.1 stable release</a> adds a lot of great new features. We added new components like bottom sheets, date and time pickers, search bars, tooltips, and others. We also graduated many of the core components to stable, added more motion and interaction support, and included edge-to-edge support in many components. Watch this video to learn how to implement Material You in your app:</p>



<div><strong><br></strong></div><h3><strong>Extending Compose to more surfaces</strong></h3>

<p>We want Compose to be the programming model for UI <strong>wherever you run Android</strong>. This means including first-class support for large screens such as foldables and tablets and publishing libraries that make it possible to use Compose to write your homescreen widgets, smartwatch apps, and TV applications.</p>

<h2>Large screen support</h2>

<p>We’ve continued our efforts to make development for large screens easy when you use Compose. The <b>pager and flow layouts</b> that we released are common patterns on large screen devices. In addition, we added <a href="https://developer.android.com/reference/kotlin/androidx/compose/material3/windowsizeclass/package-summary" target="_blank">a new Compose library</a> that lets you <b>observe the device’s <a href="https://developer.android.com/guide/topics/large-screens/support-different-screen-sizes" target="_blank">window size class</a></b> so you can easily build adaptive UI. </p>

<p>When attaching a mouse to an Android device, Compose now correctly <b>changes the mouse cursor to a caret</b> when you hover the cursor over text fields or selectable text. This helps the user to understand what elements on screen they can interact with.</p>

<div><table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody><tr><td><center><img alt="Moving image of Compose adjusting the mouse cursor to a caret when the mouse is hovering over text field" border="0" data-original-height="1504" data-original-width="720" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1htuitY0mWshEjp4nZl5lkXlXA-ZartXtKotzZIf527LzCc1Ujrqh0gUBsim18Cy5vGrE8r4-pDCHZztAjSn6PEktIg6pKhdShvXkp5V8o7k_vXw7kHYEektAvmP47cSHcoAY9YZ8Ybf1l9IkRHPxYcOkV-f1YE_9RWjK0GJTgy3E6-T6SJB96qP0/s1600/image3.gif" td=""></center></td></tr><tr><td class="tr-caption"><i></i></td></tr></tbody></table></div>

<div><br></div><h2>Glance</h2>
<p>Today we publish the first beta version of the <a href="https://developer.android.com/jetpack/androidx/releases/glance" target="_blank">Jetpack Glance library</a>! Glance lets you develop <a href="https://developer.android.com/develop/ui/views/appwidgets/overview" target="_blank">widgets</a> optimized for Android phone, tablet, and foldable homescreens using Jetpack Compose. The library gives you the latest Android widget improvements out of the box, using Kotlin and Compose: </p>
<ul><blockquote>
<li>Glance <b>simplifies the implementation</b> of <b>interactive widgets</b>, so you can showcase your app’s top features, right on a user’s home screen.</li>
<li>Glance makes it easy to build <b>responsive widgets</b> that look great across form factors.</li>
<li>Glance enables <b>faster UI Iteration</b> with your designers, ensuring a high quality user experience.</li>
</blockquote></ul><div><table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody><tr><td><center><img alt="Image of search filters in a real estate app created with flow layouts" border="0" data-original-height="1504" data-original-width="720" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZ_Dl83Akv58zMaE8ykFk19Puc7Av0jrO9vjWOp7Qc-hFWFY7f9gsfZUdPpagh3qFLYIHkSmzKdOfTYodZ3Z4UK2RefhwT1SC4b1cebXGAUUaI6FHaqznMTH9pNk2bpESmhm-opJpS23RmirTc_a4_RLFBpdo7mbg1OaJL0zaVctDrAgG5I5j5l7oD/s1600/image6.gif" td=""></center></td></tr><tr><td class="tr-caption"><i></i></td></tr></tbody></table></div>
  
<div><br></div><h2>Wear OS</h2>
<p>We launched <a href="https://android-developers.googleblog.com/2022/12/compose-for-wear-os-11-stable.html" target="_blank">Compose for Wear OS 1.1 stable</a> last December, and we’re working hard on the new 1.2 release which is <a href="https://developer.android.com/jetpack/androidx/releases/wear-compose" target="_blank">currently in alpha</a>. Here’s some of the highlights of the continuous improvements and new features that we are bringing to your wrist:</p>
<ul><blockquote>
<li>The <code><a href="https://developer.android.com/reference/kotlin/androidx/wear/compose/material/package-summary#%28androidx.compose.ui.Modifier%29.placeholder%28androidx.wear.compose.material.PlaceholderState,androidx.compose.ui.graphics.Shape,androidx.compose.ui.graphics.Color%29" target="_blank">placeholder</a></code> and <code><a href="https://developer.android.com/reference/kotlin/androidx/wear/compose/material/package-summary#%28androidx.compose.ui.Modifier%29.placeholderShimmer%28androidx.wear.compose.material.PlaceholderState,androidx.compose.ui.graphics.Shape,androidx.compose.ui.graphics.Color%29" target="_blank">placeholderShimmer</a></code> add elegant <b>loading animations</b> that can be used on chips and cards while content is loading.</li>
<li><code>expandableItems</code> make it possible to <b>fold long lists or long text</b>, and only expand to show their full length upon user interaction.</li>
<li><b>Rotary input enhancements</b> available in <a href="https://github.com/google/horologist/blob/be9c5032503f04460f55edd55477a08b90819aef/compose-layout/src/main/java/com/google/android/horologist/compose/rotaryinput/Rotary.kt" target="_blank">Horologist</a> add intuitive <code>snap</code> and <code>fling</code> behaviors when a user is navigating lists with rotary input.</li>
<li>Android Studio now lets you <b>preview multiple watch screen and text sizes</b> while building a Compose app. Use the Annotations that we have added <a href="https://developer.android.com/reference/kotlin/androidx/wear/compose/ui/tooling/preview/package-summary" target="_blank">here</a>.</li>
</blockquote></ul><div><br></div><h2>Compose for TV</h2>

<p>You can now build pixel perfect living room experiences with the alpha release of Compose for TV! With the new <a href="https://developer.android.com/jetpack/androidx/releases/tv" target="_blank">AndroidX TV library</a>, you can <b>apply all of the benefits of Compose to the unique requirements for Android TV</b>. We worked closely with the community to build an intuitive API with powerful capabilities. Engineers from Soundcloud shared with us that <i>“thanks to Compose for TV, we are able to reuse components and <b>move much faster</b> than the old Leanback View APIs would have ever allowed us to.” And Plex shared that “TV focus and scrolling support on Compose has greatly improved our <b>developer productivity and app performance</b>.”</i></p><p>

</p><p>Compose for TV comes with a variety of components such as <span>ImmersiveList</span> and <span>Carousel</span> that are <b>specifically optimized for the living room experience</b>. With just a few lines of code, you can create great TV UIs.</p><p>


</p><div><table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody><tr><td><center><img alt="Moving image of TVLazyGrid on a screen" border="0" data-original-height="1504" data-original-width="720" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmT0TLo9AgMNSC9LS1VhdkQG3-6Rc1aNEv5fkD6LKfHBJ-YyYduup1Qh8gu_uBrVLt5Il8lYsTflsbGUFdTqdiDvEVYUQB0VS3ELYaH8Wj0mqhwqgyjHuqfgPhRTsnM6IUkYLjxZSnLc2DSKwH4I2o0MtjJouoB7UeR7P3bBHgk_BTtAzeR7iJLPHs/s1600/image5.gif" td=""></center></td></tr><tr><td class="tr-caption"><i></i></td></tr></tbody></table></div>


<br><table class="leading-snug"><colgroup></colgroup><tbody><tr><td><code class="m-0 p-0 whitespace-pre-wrap font-monospace"><span>TvLazyColumn {
  </span><span class="hljs-built_in">items</span><span>(contentList) { </span><span class="hljs-attribute">content</span><span> -&gt;
    TvLazyRow {
       </span><span class="hljs-built_in">items</span><span>(content) { cardItem -&gt;
          </span><span class="hljs-built_in">Card</span><span>(cardItem) 
       }
    }
}</span></code></td></tr></tbody></table><p>Learn more about the release <a href="https://android-developers.googleblog.com/2023/05/building-pixel-perfect-living-room-experiences-compose-for-tv.html" target="_blank">in this blog post</a>, check out the “<a href="https://youtu.be/_X4tswgV67Y" target="_blank">What’s new with TV and intro to Compose</a>” talk, or see the <a href="https://developer.android.com/jetpack/androidx/releases/tv" target="_blank">TV documentation</a>!</p>

<h3><strong>Compose support in other libraries</strong></h3>

<p>It’s great to see more and more internally and externally developed libraries add support for Compose. For example, loading pictures asynchronously can now be done with the <code>GlideImage</code> composable from the <a href="https://github.com/bumptech/glide" target="_blank">Glide library</a>. And <a href="https://developers.google.com/maps/documentation/android-sdk/maps-compose" target="_blank">Google Maps released a library</a> which makes it much easier to declaratively create your map implementations.</p><table class="leading-snug"><colgroup></colgroup><tbody><tr><td><code class="m-0 p-0 whitespace-pre-wrap font-monospace"><span><span class="hljs-selector-tag">GoogleMap</span>(
  <span class="hljs-comment">//...</span>
) {
    <span class="hljs-selector-tag">Marker</span>(
        state = <span class="hljs-built_in">MarkerState</span>(position = <span class="hljs-built_in">LatLng</span>(-<span class="hljs-number">34</span>, <span class="hljs-number">151</span>)),
        title = <span class="hljs-string">"Marker in Sydney"</span>
    )
    <span class="hljs-selector-tag">Marker</span>(
        state = <span class="hljs-built_in">MarkerState</span>(position = <span class="hljs-built_in">LatLng</span>(<span class="hljs-number">35.66</span>, <span class="hljs-number">139.6</span>)),
        title = <span class="hljs-string">"Marker in Tokyo"</span>
    )
}</span></code></td></tr></tbody></table><br><div>

<h3><strong>New and updated guidance</strong></h3>

<p>No matter where you are in your learning journey, we’ve got you covered! We added and revamped a lot of the guidance on Compose:</p>
<ul><blockquote>
<li>Learn hands-on with the <a href="https://developer.android.com/courses/jetpack-compose/course" target="_blank">Compose for Android Developers course</a>, where you can learn the basics and deep dive into layouts, state, form factors, and more. We updated the course to include all the latest resources.</li>
<li>If you prefer watching videos, following on the well-received <a href="https://youtube.com/playlist?list=PLWz5rJ2EKKc-CG9riunK996aI6cRhXFDC" target="_blank">Compose Basics MAD Skills series</a>, we recently published a <a href="https://youtube.com/playlist?list=PLWz5rJ2EKKc94tpHND8pW8Qt8ZfT1a4cq" target="_blank">new MAD Skills series on Layouts and Modifiers</a>. With five episodes covering everything from the fundamentals to advanced concepts and functionality, a Q&amp;A with Googlers, and a community tip, this series will help you to quickly improve your Compose Layout knowledge.</li>
<li>Make sure to check out all compose-related I/O talks: <a href="https://youtu.be/Kp-aiSU8qCU" target="_blank">Debugging Jetpack Compose</a>, <a href="https://youtu.be/_X4tswgV67Y" target="_blank">What's new with TV and intro to Compose</a>, <a href="https://youtu.be/5JQjk3ZqPWc" target="_blank">How to build great Android apps for large screens and foldables</a>, <a href="https://youtu.be/YHeWQ9MNuWg" target="_blank">How to test for all screen sizes</a>, and <a href="https://youtu.be/tu0UtDGC31A" target="_blank">Build modern Android apps with Material You for Compose</a>, or code along with the instructor-led workshop on <a href="https://youtu.be/TbxCz5AljQk" target="_blank">Advanced State and Side effects in Compose</a>.</li>
<li>Read the expanded guidance on <a href="https://developer.android.com/jetpack/compose/touch-input" target="_blank">Touch and input</a>, including a new page on <a href="https://developer.android.com/jetpack/compose/touch-input/pointer-input/understand-gestures" target="_blank">understanding gestures</a>, and a brand-new section on <a href="https://developer.android.com/jetpack/compose/touch-input/focus" target="_blank">how to handle focus</a>.</li>
<li>Learn how to implement Material 3 theming in your app with the <a href="https://developer.android.com/codelabs/jetpack-compose-theming#0" target="_blank">new codelab</a>.</li>
</blockquote></ul><h3><strong>Happy Composing!</strong></h3>
  
<p>We hope you're as excited by these developments as we are! If you haven't started yet, it's time to learn <a href="https://developer.android.com/jetpack/compose" target="_blank">Jetpack Compose</a> and see how your team and development process can benefit from it. Get ready for improved velocity and productivity. Happy Composing!</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[UI-Tool: Storybook 7.0 erweitert den Support für Vite, Next.js und SvelteKit]]></title>
<description><![CDATA[Das Major Release erscheint mit einem überarbeiteten User Interface sowie umfangreicherem Support für das Build-Tool Vite.]]></description>
<link>https://tsecurity.de/de/1866061/it-nachrichten/ui-tool-storybook-70-erweitert-den-support-fuer-vite-nextjs-und-sveltekit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1866061/it-nachrichten/ui-tool-storybook-70-erweitert-den-support-fuer-vite-nextjs-und-sveltekit/</guid>
<pubDate>Fri, 14 Apr 2023 16:36:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Major Release erscheint mit einem überarbeiteten User Interface sowie umfangreicherem Support für das Build-Tool Vite.]]></content:encoded>
</item>
<item>
<title><![CDATA[Illuminations 2.1 - Action game centered around fireworks.]]></title>
<description><![CDATA[Illuminations is an action game centered around fireworks. The goal is to shoot the rising rockets in order to set them off. Do a good job and you'll create a spectacular show of light. Miss too many rockets, and it's game over. Enemies will spawn to slow down your attempts. Shoot them as well to...]]></description>
<link>https://tsecurity.de/de/1863722/ios-mac-os/illuminations-21-action-game-centered-around-fireworks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1863722/ios-mac-os/illuminations-21-action-game-centered-around-fireworks/</guid>
<pubDate>Thu, 13 Apr 2023 08:15:57 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<br><br><p><strong>Illuminations</strong> is an action game centered around fireworks. The goal is to shoot the rising rockets in order to set them off. Do a good job and you'll create a spectacular show of light. Miss too many rockets, and it's game over. Enemies will spawn to slow down your attempts. Shoot them as well to add to the show, and to prevent them from stopping you. Each rocket you miss will lower the crowd excitement meter, as will each stun shot you receive from enemies. Hitting rockets will raise the meter. If the meter reaches zero, it's game over.</p><br><br><ul><li>Rewrote the graphics engine to use Metal instead of OpenGL.</li>
    <li>Modern system support.</li>
    <li>Minor bug fixes exposed by the graphics rewrite.</li>
</ul><br><br><a href="https://www.macupdate.com/app/mac/28081/illuminations">Download Now</a><img src="https://desktop.macupdate.com/api/620/discover/ttra" height="1" width="1">]]&gt;]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-29008]]></title>
<description><![CDATA[The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit provides out-of-the-box cross-site request forgery (CSRF) protection to its users. The protection is imp...]]></description>
<link>https://tsecurity.de/de/1852986/sicherheitsluecken/cve-2023-29008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1852986/sicherheitsluecken/cve-2023-29008/</guid>
<pubDate>Fri, 07 Apr 2023 01:06:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit provides out-of-the-box cross-site request forgery (CSRF) protection to its users. The protection is implemented at `kit/src/runtime/server/respond.js`. While the implementation does a sufficient job of mitigating common CSRF attacks, the protection can be bypassed in versions prior to 1.15.2 by simply specifying an upper-cased `Content-Type` header value. The browser will not send uppercase characters, but this check does not block all expected CORS requests. If abused, this issue will allow malicious requests to be submitted from third-party domains, which can allow execution of operations within the context of the victim's session, and in extreme scenarios can lead to unauthorized access to users’ accounts. This may lead to all POST operations requiring authentication being allowed in the following cases: If the target site sets `SameSite=None` on its auth cookie and the user visits a malicious site in a Chromium-based browser; if the target site doesn't set the `SameSite` attribute explicitly and the user visits a malicious site with Firefox/Safari with tracking protections turned off; and/or if the user is visiting a malicious site with a very outdated browser. SvelteKit 1.15.2 contains a patch for this issue. It is also recommended to explicitly set `SameSite` to a value other than `None` on authentication cookies especially if the upgrade cannot be done in a timely manner. (CVSS:0.0) (Last Update:2023-04-06)]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-29008]]></title>
<description><![CDATA[The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit provides out-of-the-box cross-site request forgery (CSRF) protection to its users. The protection is imp...]]></description>
<link>https://tsecurity.de/de/1852795/sicherheitsluecken/cve-2023-29008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1852795/sicherheitsluecken/cve-2023-29008/</guid>
<pubDate>Thu, 06 Apr 2023 20:39:07 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit provides out-of-the-box cross-site request forgery (CSRF) protection to its users. The protection is implemented at `kit/src/runtime/server/respond.js`. While the implementation does a sufficient job of mitigating common CSRF attacks, the protection can be bypassed in versions prior to 1.15.2 by simply specifying an upper-cased `Content-Type` header value. The browser will not send uppercase characters, but this check does not block all expected CORS requests. If abused, this issue will allow malicious requests to be submitted from third-party domains, which can allow execution of operations within the context of the victim's session, and in extreme scenarios can lead to unauthorized access to usersâ€™ accounts. This may lead to all POST operations requiring authentication being allowed in the following cases: If the target site sets `SameSite=None` on its auth cookie and the user visits a malicious site in a Chromium-based browser; if the target site doesn't set the `SameSite` attribute explicitly and the user visits a malicious site with Firefox/Safari with tracking protections turned off; and/or if the user is visiting a malicious site with a very outdated browser. SvelteKit 1.15.2 contains a patch for this issue. It is also recommended to explicitly set `SameSite` to a value other than `None` on authentication cookies especially if the upgrade cannot be done in a timely manner.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-29003]]></title>
<description><![CDATA[SvelteKit is a web development framework. The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit provides out-of-the-box cross-site request forgery (CSRF) prot...]]></description>
<link>https://tsecurity.de/de/1849937/sicherheitsluecken/cve-2023-29003/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1849937/sicherheitsluecken/cve-2023-29003/</guid>
<pubDate>Wed, 05 Apr 2023 05:06:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[SvelteKit is a web development framework. The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit provides out-of-the-box cross-site request forgery (CSRF) protection to its users. While the implementation does a sufficient job in mitigating common CSRF attacks, prior to version 1.15.1, the protection can be bypassed by simply specifying a different `Content-Type` header value. If abused, this issue will allow malicious requests to be submitted from third-party domains, which can allow execution of operations within the context of the victim's session, and in extreme scenarios can lead to unauthorized access to users’ accounts. SvelteKit 1.15.1 updates the `is_form_content_type` function call in the CSRF protection logic to include `text/plain`. As additional hardening of the CSRF protection mechanism against potential method overrides, SvelteKit 1.15.1 is now performing validation on `PUT`, `PATCH` and `DELETE` methods as well. This latter hardening is only needed to protect users who have put in some sort of `?_method= override` feature themselves in their `handle` hook, so that the request that resolve sees could be `PUT`/`PATCH`/`DELETE` when the browser issues a `POST` request. (CVSS:0.0) (Last Update:2023-04-04)]]></content:encoded>
</item>
<item>
<title><![CDATA[4/4/2023]]></title>
<description><![CDATA[In His New Cybersecurity Strategy, Biden Identifies Cloud Security as a Major Threat Broad Pay Ranges Can Hamper Cybersecurity HiringBank Rewrote Ads for Infosec Jobs to Stop Scaring Away WomenAlcohol Counseling Companies Monument and Tempest Leaked Patient Data to Advertisers for YearsIRS-Author...]]></description>
<link>https://tsecurity.de/de/1849915/it-security-nachrichten/442023/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1849915/it-security-nachrichten/442023/</guid>
<pubDate>Wed, 05 Apr 2023 03:34:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In His New Cybersecurity Strategy, Biden Identifies Cloud Security as a Major Threat Broad Pay Ranges Can Hamper Cybersecurity HiringBank Rewrote Ads for Infosec Jobs to Stop Scaring Away WomenAlcohol Counseling Companies Monument and Tempest Leaked Patient Data to Advertisers for YearsIRS-Authorized eFile.com Tax Return Software Caught Serving JS MalwareKrebs: A Serial Tech Investment Scammer … <a href="https://thecyberbeat.com/2023/04/05/4-4-2023/" class="more-link">Continue reading <span class="screen-reader-text">4/4/2023</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-29003]]></title>
<description><![CDATA[SvelteKit is a web development framework. The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit provides out-of-the-box cross-site request forgery (CSRF) prot...]]></description>
<link>https://tsecurity.de/de/1849877/sicherheitsluecken/cve-2023-29003/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1849877/sicherheitsluecken/cve-2023-29003/</guid>
<pubDate>Wed, 05 Apr 2023 02:22:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[SvelteKit is a web development framework. The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit provides out-of-the-box cross-site request forgery (CSRF) protection to its users. While the implementation does a sufficient job in mitigating common CSRF attacks, prior to version 1.15.1, the protection can be bypassed by simply specifying a different `Content-Type` header value. If abused, this issue will allow malicious requests to be submitted from third-party domains, which can allow execution of operations within the context of the victim's session, and in extreme scenarios can lead to unauthorized access to usersâ€™ accounts. SvelteKit 1.15.1 updates the `is_form_content_type` function call in the CSRF protection logic to include `text/plain`. As additional hardening of the CSRF protection mechanism against potential method overrides, SvelteKit 1.15.1 is now performing validation on `PUT`, `PATCH` and `DELETE` methods as well. This latter hardening is only needed to protect users who have put in some sort of `?_method= override` feature themselves in their `handle` hook, so that the request that resolve sees could be `PUT`/`PATCH`/`DELETE` when the browser issues a `POST` request.]]></content:encoded>
</item>
<item>
<title><![CDATA[Bank rewrote ads for infosec jobs to stop scaring away women]]></title>
<description><![CDATA[Blokes happily bluffed; women played it by the book, leaving the bank struggling to hire Australia's Westpac bank re-wrote its job ads for infosec roles after finding the language it used deterred female candidates.…]]></description>
<link>https://tsecurity.de/de/1848419/it-security-nachrichten/bank-rewrote-ads-for-infosec-jobs-to-stop-scaring-away-women/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1848419/it-security-nachrichten/bank-rewrote-ads-for-infosec-jobs-to-stop-scaring-away-women/</guid>
<pubDate>Tue, 04 Apr 2023 07:49:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Blokes happily bluffed; women played it by the book, leaving the bank struggling to hire</h4> <p>Australia's Westpac bank re-wrote its job ads for infosec roles after finding the language it used deterred female candidates.…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Big Tech Rewrote America's First Cell Phone Repair Law]]></title>
<description><![CDATA[Two non-profit news site, the Markup and Grist, have co-published their investigation into how big tech rewrote America's first cellphone repair law. 

"That New York passed any electronics right-to-repair bill is 'huge,' Repair.org executive director Gay Gordon-Byrne told Grist. But 'it could ha...]]></description>
<link>https://tsecurity.de/de/1792954/it-security-nachrichten/how-big-tech-rewrote-americas-first-cell-phone-repair-law/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1792954/it-security-nachrichten/how-big-tech-rewrote-americas-first-cell-phone-repair-law/</guid>
<pubDate>Sat, 11 Feb 2023 18:49:30 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Two non-profit news site, the Markup and Grist, have co-published their investigation into how big tech rewrote America's first cellphone repair law. 

"That New York passed any electronics right-to-repair bill is 'huge,' Repair.org executive director Gay Gordon-Byrne told Grist. But 'it could have been huger' if not for tech industry interference."

The passage of the Digital Fair Repair Act last June reportedly caught the tech industry off guard, but it had time to act before Governor Kathy Hochul would sign it into law. Corporate lobbyists went to work, pressing for exemptions and changes that would water the bill down. They were largely successful: While the bill Hochul signed in late December remains a victory for the right-to-repair movement, the more corporate-friendly text gives consumers and independent repair shops less access to parts and tools than the original proposal called for. (The state Senate still has to vote to adopt the revised bill, but it's widely expected to do so.) 

The new version of the law applies only to devices built after mid-2023, so it won't help people to fix stuff they currently own. It also exempts electronics used exclusively by businesses or the government. All those devices are likely to become electronic waste faster than they would have had Hochul, a Democrat, signed a tougher bill. And more greenhouse gases will be emitted manufacturing new devices to replace broken electronics.... 


Jessa Jones, who founded iPad Rehab, an independent repair shop in Honeoye Falls, about 20 miles south of Rochester, New York, says the original bill included provisions that would have made it far easier for independent shops like hers to get the tools, parts, and know-how needed to make repairs. She pointed to changes that allow manufacturers to release repair tools that only work with spare parts they make, while at the same time controlling how those spare parts are used... "If you keep going down this road, allowing manufacturers to force us to use their branded parts and service, where they're allowed to tie the function of the device to their branded parts and service, that's not repair," Jones said. "That's authoritarian control." 

The bill's sponsor believes it could create momentum for dozens of other states trying to pass similar laws, the article points out, possibly leading ultimately to one national agreement between electronics manufacturers and the repair community. A lawmaker from another state argued that New York's law "gives us something to work from. We're going to take that now and try to do a better piece of legislation." 
Thanks to long-time Slashdot reader Z00L00K for submitting the article.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=How+Big+Tech+Rewrote+America's+First+Cell+Phone+Repair+Law%3A+https%3A%2F%2Fbit.ly%2F3YolVTD"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fapple.slashdot.org%2Fstory%2F23%2F02%2F11%2F0426247%2Fhow-big-tech-rewrote-americas-first-cell-phone-repair-law%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://apple.slashdot.org/story/23/02/11/0426247/how-big-tech-rewrote-americas-first-cell-phone-repair-law?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Deciphering clinical abbreviations with privacy protecting ML]]></title>
<description><![CDATA[Posted by Posted by Alvin Rajkomar, Research Scientist, and Eric Loreaux, Software Engineer, Google Research Today many people have digital access to their medical records, including their doctor’s clinical notes. However, clinical notes are hard to understand because of the specialized language ...]]></description>
<link>https://tsecurity.de/de/1786023/ai-nachrichten/deciphering-clinical-abbreviations-with-privacy-protecting-ml/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1786023/ai-nachrichten/deciphering-clinical-abbreviations-with-privacy-protecting-ml/</guid>
<pubDate>Wed, 08 Feb 2023 04:49:28 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="byline-author">Posted by Posted by Alvin Rajkomar, Research Scientist, and Eric Loreaux, Software Engineer, Google Research</span> <img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg6J7MjCraKbiEpEucwE5YChDggRVu17ozvyttinl6VrlS-2g79ZyX9xrE4vKtkWGQwxXdzFBnhAK7A6vAWmwHIQW6k9ANFvOF_CKTi-sAjinySWvz78_RaTAnwSHfkE-iJX2st8WGYHh4VUXmn_hUe2VTsaz5KFCbIFwsRtSzron2DWcaSof-skAPmIg/s1600/MedAbbreviations.jpg"><p>Today many people have <a href="https://www.statnews.com/2022/10/06/health-data-information-blocking-records/">digital access to their medical records</a>, including their doctor’s clinical notes. However, clinical notes are hard to understand because of the specialized language that clinicians use, which contains <a href="https://www.nytimes.com/2021/09/30/well/live/medical-records-misunderstanding.html">unfamiliar shorthand and abbreviations</a>. In fact, there are thousands of such abbreviations, many of which are specific to certain medical specialities and locales or can mean multiple things in different contexts. For example, a doctor might write in their clinical notes, “pt referred to pt for lbp“, which is meant to convey the statement: “Patient referred to physical therapy for low back pain.”  Coming up with this translation is tough for laypeople and computers because some abbreviations are uncommon in everyday language (e.g., “lbp” means “low back pain”), and even familiar abbreviations, such as “pt” for “patient”, can have alternate meanings, such as “physical therapy.” To disambiguate between multiple meanings, the surrounding context must be considered. It’s no easy task to decipher all the meanings, and <a href="https://jamanetwork.com/journals/jamanetworkopen/fullarticle/2792294">prior research</a> suggests that expanding the shorthand and abbreviations can help patients better understand their health, diagnoses, and treatments.    </p><a name="more"></a>   <p>In “<a href="https://www.nature.com/articles/s41467-022-35007-9">Deciphering clinical abbreviations with a privacy protecting machine learning system</a>”, published in <em><a href="https://www.nature.com/ncomms/">Nature Communications</a></em>, we report our findings on a general method that deciphers clinical abbreviations in a way that is both state-of-the-art and is on-par with board certified physicians in this task. We built the model using only public data on the web that wasn't associated with any patient (i.e., no potentially sensitive data) and evaluated performance on real, de-identified notes from inpatient and outpatient clinicians from different health systems.  To enable the model to generalize from web-data to notes, we created a way to algorithmically re-write large amounts of internet text to look as if it were written by a doctor (called <em>web-scale reverse substitution</em>), and we developed a novel inference method, (called <em>elicitive inference</em>). </p> <table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody><tr><td><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC-qDZQplvqqtp9a11GGy5GMv24IDybiK3QkmvjKejQ19HIfJPXfCsZ0udIxqF0sAEAYaauk6zZ_ASqyD_U2TxjPHYWT3HisARJmIQzxiBOTaw2VtJ5Ov9N-FdoD8YIO313Y_PBSfHsx3e4Hmp1z6neWZol1_e6mkvwpRksXSIW56fUjLjyCM9o-yGHQ/s1999/image3.png" imageanchor="1"><img border="0" data-original-height="426" data-original-width="1999" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC-qDZQplvqqtp9a11GGy5GMv24IDybiK3QkmvjKejQ19HIfJPXfCsZ0udIxqF0sAEAYaauk6zZ_ASqyD_U2TxjPHYWT3HisARJmIQzxiBOTaw2VtJ5Ov9N-FdoD8YIO313Y_PBSfHsx3e4Hmp1z6neWZol1_e6mkvwpRksXSIW56fUjLjyCM9o-yGHQ/s16000/image3.png"></a></td></tr><tr><td class="tr-caption">The model input is a string that may or may not contain medical abbreviations. We trained a model to output a corresponding string in which all abbreviations are simultaneously detected and expanded. If the input string does not contain an abbreviation, the model will output the original string. By <a href="https://www.nature.com/articles/s41467-022-35007-9">Rajkomar et al</a> used under <a href="https://creativecommons.org/licenses/by/4.0/">CC BY 4.0</a>/ Cropped from original.</td></tr></tbody></table><div>    <br></div><h2>Rewriting Text to Include Medical Abbreviations</h2>  <p>Building a system to translate doctors’ notes would usually start with a large, representative dataset of clinical text where all abbreviations are labeled with their meanings. But no such dataset for general use by researchers exists. We therefore sought to develop an automated way to create such a dataset but without the use of any actual patient notes, which might include sensitive data. We also wanted to ensure that models trained on this data would still work well on real clinical notes from multiple hospital sites and types of care, such as both outpatient and inpatient. </p><p>To do this, we referenced a dictionary of thousands of clinical abbreviations and their expansions, and found sentences on the web that contained uses of the expansions from this dictionary. We then “rewrote” those sentences by abbreviating each expansion, resulting in web data that looked like it was written by a doctor. For instance, if a website contained the phrase “patients with atrial fibrillation can have chest pain,” we would rewrite this sentence to “pts with af can have cp.” We then used the abbreviated text as input to the model, with the original text serving as the label. This approach provided us with large amounts of data to train our model to perform abbreviation expansion. </p><p>The idea of “reverse substituting” the long-forms for their abbreviations was introduced in <a href="https://pubmed.ncbi.nlm.nih.gov/28269852/">prior research</a>, but our distributed algorithm allows us to extend the technique to large, web-sized datasets. Our algorithm, called <em>web-scale reverse substitution</em> (WSRS), is designed to ensure that rare terms occur more frequently and common terms are down-sampled across the public web to derive a more balanced dataset. With this data in-hand, we trained a series of large transformer-based language models to expand the web text.  </p> <table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody><tr><td><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgGF-rx0h6NlblTRbuvRkMStLpBYIuLX1DaJxQHo9-SXgd--bWnNd2HWNHk85D3BmKaI8iTTe-Dg6b7yUl3MJnyjQEh1EPfySd3uR4OXi89Y0N5SNWLaQbKaX0GYtkeYPSb0EBBZ2FIBuWMaGCVCtzwoX2uLJCGjM5qGiNhOA7zAVaNJnENvoNroQi1Cg/s1999/image1.png" imageanchor="1"><img border="0" data-original-height="1369" data-original-width="1999" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgGF-rx0h6NlblTRbuvRkMStLpBYIuLX1DaJxQHo9-SXgd--bWnNd2HWNHk85D3BmKaI8iTTe-Dg6b7yUl3MJnyjQEh1EPfySd3uR4OXi89Y0N5SNWLaQbKaX0GYtkeYPSb0EBBZ2FIBuWMaGCVCtzwoX2uLJCGjM5qGiNhOA7zAVaNJnENvoNroQi1Cg/s16000/image1.png"></a></td></tr><tr><td class="tr-caption">We generate text to train our model on the decoding task by extracting phrases from public web pages that have corresponding medical abbreviations (shaded boxes on the left) and then substituting in the appropriate abbreviations (shaded dots, right).  Since some words are found much more frequently than others ("patient" more than "posterior tibialis", both of which can be abbreviated “pt”), we downsampled common expansions to derive a more balanced dataset across the thousands of abbreviations. By <a href="https://www.nature.com/articles/s41467-022-35007-9">Rajkomar et al</a> used under <a href="https://creativecommons.org/licenses/by/4.0/">CC BY 4.0</a>. </td></tr></tbody></table><div>    <br></div><h2>Adapting Protein Alignment Algorithms to Unstructured Clinical Text </h2>  <p>Evaluation of these models on the particular task of abbreviation expansion is difficult. Because they produce unstructured text as output, we had to figure out which abbreviations in the input correspond to which expansion in the output. To achieve this, we created a modified version of the <a href="https://en.wikipedia.org/wiki/Needleman%E2%80%93Wunsch_algorithm">Needleman Wunsch algorithm</a>, which was originally designed for <a href="https://pubmed.ncbi.nlm.nih.gov/5420325/">divergent sequence alignment</a> in molecular biology, to align the model input and output and extract the corresponding abbreviation-expansion pairs. Using this alignment technique, we were able to evaluate the model’s capacity to detect and expand abbreviations accurately. We evaluated <a href="https://ai.googleblog.com/2020/02/exploring-transfer-learning-with-t5.html">Text-to-Text Transfer Transformer</a> (T5) models of various sizes (ranging from 60 million to over 60 billion parameters) and found that larger models performed translation better than smaller models, with the biggest model achieving the <a href="https://www.nature.com/articles/s41467-022-35007-9/figures/3">best performance</a>. </p> <div>    <br></div><h2>Creating New Model Inference Techniques to Coax the Model</h2>  <p>However, we did find something unexpected.  When we evaluated the performance on multiple external test sets from real clinical notes, we found the models would leave some abbreviations unexpanded, and for larger models, the problem of incomplete expansion was even worse. This is mainly due to the fact that while we substitute expansions on the web for their abbreviations, we have no way of handling the abbreviations that are already present. This means that the abbreviations appear in both the original and rewritten text used as respective labels and input, and the model learns not to expand them.  </p><p>To address this, we developed a new inference-chaining technique in which the model output is fed again as input to coax the model to make further expansions as long as the model is confident in the expansion. In technical terms, our best-performing technique, which we call <em>elicitive inference</em>, involves examining the outputs from a <a href="https://en.wikipedia.org/wiki/Beam_search">beam search</a> above a certain log-likelihood threshold. Using elicitive inference, we were able to achieve state-of-the-art capability of expanding abbreviations in multiple external test sets. </p> <table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody><tr><td><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzfzK8rT9WBUOUm_BMBr3fec0PX9xEaVc5Otbgnms8lY6p2TeNkurysSqsySAgJ7qpEbdY2fsM18inHYQS0mOmmlUifXDgfcMXRBS6dKKvpylwXMiPNYHPFg9-C0b_bTnXZ-UO8R8qGFiFhTDd7Iyn4BSoh-zr3PLud-ZKBAGhdmcdsb459eCLi5CBJw/s1498/image2.png" imageanchor="1"><img border="0" data-original-height="1316" data-original-width="1498" height="351" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzfzK8rT9WBUOUm_BMBr3fec0PX9xEaVc5Otbgnms8lY6p2TeNkurysSqsySAgJ7qpEbdY2fsM18inHYQS0mOmmlUifXDgfcMXRBS6dKKvpylwXMiPNYHPFg9-C0b_bTnXZ-UO8R8qGFiFhTDd7Iyn4BSoh-zr3PLud-ZKBAGhdmcdsb459eCLi5CBJw/w400-h351/image2.png" width="400"></a></td></tr><tr><td class="tr-caption">Real example of the model’s input (<strong>left</strong>) and output (<strong>right</strong>).</td></tr></tbody></table><div>    <br></div><h2>Comparative Performance</h2>  <p>We also sought to understand how patients and doctors currently perform at deciphering clinical notes, and how our model compared. We found that lay people (people without specific medical training) demonstrated less than 30% comprehension of the abbreviations present in the sample medical texts. When we allowed them to use Google Search, their comprehension increased to nearly 75%, still leaving 1 out of 5 abbreviations indecipherable. Unsurprisingly, medical students and trained physicians performed much better at the task with an accuracy of 90%. We found that our largest model was capable of matching or exceeding experts, with an accuracy of 98%.   </p><p>How does the model perform so well compared to physicians in this task? There are two important factors in the model’s high comparative performance. Part of the discrepancy is that there were some abbreviations that clinicians did not even attempt to expand (such as "cm" for centimeter), which partly lowered the measured performance. This might seem unimportant, but for non-english speakers, these abbreviations may not be familiar, and so it may be helpful to have them written out. In contrast, our model is designed to comprehensively expand abbreviations. In addition, clinicians are familiar with abbreviations they commonly see in their speciality, but other specialists use shorthand that are not understood by those outside their fields. Our model is trained on thousands of abbreviations across multiple specialities and therefore can decipher a breadth of terms. </p><div>    <br></div><h2>Towards Improved Health Literacy</h2>  <p>We think there are numerous avenues in which large language models (LLMs) can help advance the health literacy of patients by augmenting the information they see and read. Most LLMs are trained on data that does not look like clinical note data, and the unique distribution of this data makes it challenging to deploy these models in an out-of-the-box fashion. We have demonstrated how to overcome this limitation. Our model also serves to "normalize" clinical note data, facilitating additional capabilities of ML to make the text easier for patients of all educational and health-literacy levels to understand.   </p><div>    <br></div><h2>Acknowledgements</h2>  <p><em>This work was carried out in collaboration with Yuchen Liu, Jonas Kemp, Benny Li, Ming-Jun Chen, Yi Zhang, Afroz Mohiddin, and Juraj Gottweis.  We thank Lisa Williams, Yun Liu, Arelene Chung, and Andrew Dai for many useful conversations and discussions about this work.  </em></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Netdata release 1.38.0]]></title>
<description><![CDATA[Release Notes edited for brevity, original links maintained. Full Release notes at https://github.com/netdata/netdata/releases/tag/v1.38.0 ​ Highlights:  DBENGINE v2 The new open-source database engine for Netdata Agents, offering huge performance, scalability and stability improvements, with a f...]]></description>
<link>https://tsecurity.de/de/1784336/linux-tipps/netdata-release-1380/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1784336/linux-tipps/netdata-release-1380/</guid>
<pubDate>Mon, 06 Feb 2023 20:15:55 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Release Notes edited for brevity, original links maintained.</p> <p><em>Full Release notes at</em> <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0"><em>https://github.com/netdata/netdata/releases/tag/v1.38.0</em></a></p> <p>​</p> <p>Highlights: </p> <ul><li><a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-dbenginev2"><strong>DBENGINE v2</strong></a><br> The new open-source database engine for Netdata Agents, offering huge performance, scalability and stability improvements, with a fraction of memory footprint!</li> <li><a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-functions"><strong>FUNCTION: Processes</strong></a><br> Netdata beyond metrics! We added the ability for <strong>runtime functions</strong>, that can be implemented by any data collection plugin, to offer unlimited visibility to anything, even not-metrics, that can be valuable while troubleshooting.</li> <li><a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-feed"><strong>Events Feed</strong></a><br> Centralized view of Space and Infrastructure level events about topology changes and alerts.</li> <li><a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-notifications"><strong>NOTIFICATIONS: Slack, PagerDuty, Discord, Webhooks</strong></a><br> Netdata Cloud now supports <strong>Slack</strong>, <strong>PagerDuty</strong>, <strong>Discord</strong>, <strong>Webhooks</strong>.</li> <li><a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-rbac"><strong>Role-based access model</strong></a><br> Netdata Cloud supports more roles, offering finer control over access to infrastructure.<br></li> </ul><h3>Netdata open-source growth</h3> <ul><li>Almost 62,000 GitHub Stars</li> <li>Over four million monitored servers</li> <li>Almost 88 million sessions served</li> <li>Over 600 thousand total nodes in Netdata Cloud</li> </ul><h2>Release highlights</h2> <h3>Dramatic performance and stability improvements, with a smaller agent footprint</h3> <p>We completely reworked our custom-made, time series database (dbengine), resulting in stunning improvements to performance, scalability, and stability, while at the same time significantly reducing the <a href="https://github.com/netdata/netdata/tree/master/database/engine#memory-requirements">agent memory requirements</a>.</p> <p>On production-grade hardware (e.g. 48 threads, 32GB ram) Netdata Agent Parents can easily collect 2 million points/second while servicing data queries for 10 million points / second, and running ML training and Health querying 1 million points / second each!</p> <p>For standalone installations, the 64bit version of Netdata runs stable at about 150MB RAM (Reside Set Size + SHARED), with everything enabled (the 32bit version at about 80MB RAM, again with everything enabled).</p> <p>​</p> <p><a href="https://preview.redd.it/9rgk6i3h7mga1.png?width=2439&amp;format=png&amp;auto=webp&amp;s=801420291d1670746611e8ce4b472f207a8dbeb0">DBENGINE v2</a></p> <h3>Functions</h3> <p>After the groundwork done on the Netdata Agent in v1.37.0, Netdata Agent collectors are able to expose functions that can be executed on-demand, at run-time, by the data collecting agent, even when queries are executed via a Netdata Agent Parent. We are now utilizing this capability to provide the first of many powerful features via the Netdata Cloud UI.</p> <p>Netdata Functions on Netdata Cloud allow you to trigger specific routines to be executed by a given Agent on request. These routines can range from a simple reader that fetches real time information to help you troubleshoot (like the list of currently running processing, currently running db queries, currently open connections, etc.), to routines that trigger an action on your behalf (restart a service, rotate logs, etc.), directly on the node. The key point is to remove the need to open an ssh connection to your node to execute a command like top<br> while you are troubleshooting.</p> <p>The routines are triggered directly from the Netdata Cloud UI, with the request going through the secure, already established by the agent <a href="https://learn.netdata.cloud/docs/agent/aclk">Agent-Cloud Link (ACLK)</a>. Moreover, unlike many of the commands you'd issue from the shell, Netdata Functions come with powerful capabilities like auto-refresh, sorting, filtering, search and more! And, as everything about Netdata, they are fast!</p> <h4>What functions are currently available?</h4> <p>At the moment, just one, to display detailed information on the currently running processes on the node, replacing top and iotop</p> <p>​</p> <p><a href="https://preview.redd.it/ovjkobxk7mga1.png?width=3840&amp;format=png&amp;auto=webp&amp;s=88471c09c0cbaae3c05d6fad2740a35d85f4d217">Real time top/iotop info</a></p> <h3>Events feed</h3> <p><em>Coming by Feb 15th</em></p> <p>The <strong>Events feed</strong> is a powerful new feature that tracks events that happen on your infrastructure, or in your Space. The feed lets you investigate events that occurred in the past, which is obviously invaluable for troubleshooting. Common use cases are ones like when a node goes offline, and you want to understand what events happened before that. A detailed event history can also assist in attributing sudden pattern changes in a time series to specific changes in your environment.</p> <p>We start from humble beginnings, capturing <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#topology-events">topology events</a> (node state transitions) and <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#alert-events">alert state transitions</a>. We intend to expand the events we capture to include infrastructure changes like deployments or services starting/stopping and we plan to provide a way to display the events in the standard Netdata charts.</p> <h3>Additional alert notification methods on Netdata Cloud</h3> <p><em>Coming by Feb 15th</em></p> <p>Every Netdata Agent comes with hundreds of pre-installed health alerts designed to notify you when an anomaly or performance issue affects your node or the applications it runs. All these events, from all your nodes, are centralized at Netdata Cloud.</p> <p>Before this release, Netdata Cloud was only dispatching centralized email alert notifications to your team whenever an alert enters a warning, critical, or unreachable state. However, the agent supported tens of notification delivery methods, which we hadn't provided via the cloud.</p> <p>We are now adding to Netdata Cloud more alert notification integration methods. We categorize them similarly to our <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-paidplans">subscription plans</a>, as Community, Pro and Business. On this release, we added <strong>Discord</strong> (Community Plan), <strong>web hook</strong> (Pro Plan), <strong>PagerDuty</strong> and <strong>Slack</strong> (Business Plan).</p> <h3>Improved role-based access model</h3> <p><em>Coming by Feb 15th</em></p> <p>Netdata Cloud already provides a role-based-access mechanism, that allows you to control what functionalities in the app users can access.<br> Each user can be assigned only one role, which fully specifies all the capabilities they are afforded.</p> <p>With the advent of the <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-paidplans">paid plans</a> we revamped the roles to cover needs expressed by our users, like providing more limited access to your customers, or being able to join any room. We also aligned the offered roles to the target audience of each plan. </p> <h2>Integrations</h2> <h3>Collectors</h3> <h4>Proc</h4> <p>The <a href="https://learn.netdata.cloud/docs/collect/system-metrics">proc plugin</a> gathers metrics from the /proc and /sys folders in Linux<br> systems, along with a few other endpoints, and is responsible for the bulk of the system metrics collected and visualized by Netdata. It collects CPU, memory, disks, load, networking, mount points, and more.</p> <p>We added a "cpu" label to the per core utilization % charts. Previously, the only way to filter or group by core was to use the "instance", i.e. the chart name. The new label makes the displayed dimensions much more user-friendly.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14255">fixed</a> the issues we had with collection of CPU/memory metrics when running inside an LXC container as a systemd service.</p> <p>We also <a href="https://github.com/netdata/netdata/pull/14252">fixed</a> the missing network stack metrics, when IPv6 is disabled.</p> <p>Finally, we improved how the loadavg alerts behave when the number of processors <a href="https://github.com/netdata/netdata/pull/14286">is 0</a>, or <a href="https://github.com/netdata/netdata/pull/14265">unknown</a>.</p> <h4>Apps</h4> <p>The <a href="https://learn.netdata.cloud/docs/collect/application-metrics">apps plugin</a> breaks down system resource usage<br> to processes, users and user groups, by reading whole process tree, collecting resource usage information for every process found running.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14156">fixed</a> the nodejs application group node, which incorrectly included node_exporter. The rule now is that the process must be called node to be included in that group.</p> <p>We also <a href="https://github.com/netdata/netdata/pull/14188">added a telegraf application group</a>.</p> <h4>Containers and VMs (CGROUPS)</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/cgroups.plugin">cgroups plugin</a> reads information on Linux Control Groups to monitor containers, virtual machines and systemd services.</p> <p>The "net" section in a cgroups container would occasionally pick the wrong / random interface name to display in the navigation menu. We <a href="https://github.com/netdata/netdata/pull/14174">removed the interface name</a> from the cgroup "net" family. The information is available in the cloud as labels and on the agent as chart names and ids.</p> <h4>eBPF</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/ebpf.plugin">eBPF plugin</a> helps you troubleshoot and debug how applications interact with the Linux kernel.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14270">improved</a> the speed and resource impact of the collector shutdown, by reducing the number of threads running in parallel.</p> <p>We fixed a bug with eBPF routines that would sometimes cause kernel panic and system reboot on RedHat 8.* family OSs. <a href="https://github.com/netdata/netdata/pull/14090">#14090</a>, <a href="https://github.com/netdata/netdata/pull/14131">#14131</a></p> <p>We <a href="https://github.com/netdata/netdata/pull/14131">fixed</a> an ebpf.d crash: sysmalloc Assertion failed, then killed with SIGTERM.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14131">fixed</a> a crash when building eBPF while using a memory address sanitizer.</p> <p>The eBPF collector also creates charts for each running application through an integration with the apps.plugin. This integration helps you understand how specific applications interact with the Linux kernel. In systems with many VMs (like Proxmox), this integration<br> can cause a large load. We used to have the integration turned on by default, with the ability to disable it from ebpf.d.conf. We have now done the opposite, having the integration disabled by default, with the ability to enable it. <a href="https://github.com/netdata/netdata/pull/14147">#14147</a></p> <h4>Windows Monitoring</h4> <p>We have been making tremendous improvements on how we <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/wmi">monitor Windows Hosts</a>. The work will be completed in the next release. For now, we can say that we have done some preparatory work by <a href="https://github.com/netdata/netdata/pull/14001">adding more info to existing charts</a>, adding metrics for <a href="https://github.com/netdata/go.d.plugin/pull/1041">MS SQL Server</a>, <a href="https://github.com/netdata/go.d.plugin/pull/972">IIS</a> in 1.37, <a href="https://github.com/netdata/go.d.plugin/pull/1003">Active Directory</a>, <a href="https://github.com/netdata/go.d.plugin/pull/1013">ADFS</a> and <a href="https://github.com/netdata/go.d.plugin/pull/1007">ADCS</a>.</p> <p>We also <a href="https://github.com/netdata/go.d.plugin/pull/1065">reorganized the navigation menu</a>, so that Windows application metrics don't appear under the generic "WMI" category, but on their own category, just like Linux applications.</p> <p>We invite you to try out with these collectors either from a remote Linux machine, or using our new <a href="https://github.com/netdata/msi-installer">MSI installer</a>, which however is not suitable for production. Your feedback will be really appreciated, as we invest on making Windows Monitoring a first class citizen of Netdata.</p> <h4>Generic Prometheus Endpoint Monitoring</h4> <p>Our <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/prometheus">Generic Prometheus Collector</a> gathers metrics from any <a href="https://prometheus.io/">Prometheus</a> endpoint that uses<br> the <a href="https://prometheus.io/docs/instrumenting/exposition_formats/">OpenMetrics exposition format</a>.</p> <p>To allow better grouping and filtering of the collected metrics we now <a href="https://github.com/netdata/go.d.plugin/pull/1004">create a chart with labels per label set</a>.</p> <p>We also <a href="https://github.com/netdata/go.d.plugin/pull/1027">fixed the handling of Summary/Histogram NaN values</a>.</p> <h4>TCP endpoint monitoring</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/portcheck">TCP endpoint (portcheck) collector</a> monitors TCP service availability and response time.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14137">enriched</a> the portcheck alarms with labels that show the problematic host and port.</p> <h4>HTTP endpoint monitoring</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/httpcheck">HTTP endpoint monitoring collector (httpcheck)</a> monitors their availability and response time.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14133">enriched the alerts</a> with labels that show the slow or unavailable URL relevant to the alert.</p> <h4>Host reachability (ping)</h4> <p>The new <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/ping">host reachability collector</a> replaced fping in v1.37.0.<br> We <a href="https://github.com/netdata/netdata/pull/14073">removed</a> the deprecated fping.plugin, in accordance with the v1.37.0 deprecation notice.</p> <h4>RabbitMQ</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/rabbitmq">RabbitMQ collector</a> monitors the open source message broker, by querying its overview, node<br> and vhosts HTTP endpoints.</p> <p>We <a href="https://github.com/netdata/go.d.plugin/pull/1047">added monitoring of the RabitMQ queues</a> that was available in the older Python module and<br><a href="https://github.com/netdata/go.d.plugin/pull/1052">fixed an issue</a> with the new metrics.</p> <h4>MongoDB</h4> <p>We monitor the <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/mongodb">MongoDB</a> NoSQL database <a href="https://www.mongodb.com/docs/manual/reference/command/serverStatus/#mongodb-dbcommand-dbcmd.serverStatus">serverStatus</a> and <a href="https://github.com/netdata/netdata/blob/v1.38.0/mongodb.com/docs/manual/reference/command/dbStats/#dbstats">dbStats</a>.</p> <p>To allow better grouping and filtering of the collected metrics we now <a href="https://github.com/netdata/go.d.plugin/pull/1042">create a chart per database, repl set member, shard and additional metrics</a>. We also <a href="https://github.com/netdata/go.d.plugin/pull/1046">improved</a> the cursors_by_lifespan_count<br> chart dimension names, to make them clearer.</p> <h4>PostgreSQL</h4> <p>Our powerful <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/postgressql">PostgreSQL database collector</a> has been enhanced with an improved <a href="https://github.com/netdata/go.d.plugin/pull/1039">WAL replication lag calculation</a> and <a href="https://github.com/netdata/go.d.plugin/pull/1018">better support of versions before 10</a>.</p> <h4>Redis</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/redis">Redis collector</a> monitors the in-memory data structure store via its <a href="https://redis.io/commands/info/">INFO ALL</a> command.</p> <p>We now support password protected Redis instances, by <a href="https://github.com/netdata/go.d.plugin/pull/1051">allowing users to set the username/password</a> in the collector configuration.</p> <h4>Consul</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/consul">Consul collector</a> is production ready! <a href="https://www.consul.io/">Consul by HashiCorp</a> is a powerful and complex identity-based networking solution, which is not trivial to monitor. We were lucky to have the assistance of HashiCorp itself in this endeavor, which resulted in a monitoring solution of exceptional quality. Look for common blog posts and announcements in the coming weeks!</p> <h4>NGINX Plus</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/nginxplus">NGINX Plus collector</a> monitors the load balancer, API gateway, and reverse proxy built on top of NGINX, by utilizing its <a href="https://docs.nginx.com/nginx/admin-guide/monitoring/live-activity-monitoring/">Live Activity Monitoring</a> capabilities.</p> <p>We improved the collector that was launched last November with <a href="https://github.com/netdata/netdata/pull/14080">additional information</a> explaining the charts and the <a href="https://github.com/netdata/go.d.plugin/pull/1010">addition of SSL error metrics</a>.</p> <h4>Elastic Search</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/elasticsearch">Elastic Search collector</a> monitors the search engine's instances<br> via several of the provided local interfaces.</p> <p>To allow better grouping and filtering of the collected metrics we now <a href="https://github.com/netdata/go.d.plugin/pull/1040">create a chart per node index, a dimension per health status</a>. We also <a href="https://github.com/netdata/netdata/pull/14197">added several OOB alerts</a>.</p> <h4>NVIDIA GPU</h4> <p>Our <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/nvidia_smi">NVIDIA GPU Collector</a> monitors memory usage, fan speed, PCIE bandwidth utilization, temperature, and other GPU performance metrics using the nvidia-smi cli tool.</p> <p>Multi-Instance GPU (MIG) is a feature from NVIDIA that lets users partition a single GPU to smaller GPU instances. We <a href="https://github.com/netdata/go.d.plugin/pull/1067">added MIG metrics</a> for uncorrectable errors and memory usage.</p> <p>We also <a href="https://github.com/netdata/go.d.plugin/pull/1048">added metrics for voltage</a> and <a href="https://github.com/netdata/netdata/pull/14315">PCIe bandwidth utilization percentage</a>.</p> <p>Last but not least, we significantly improved the collector's performance, by switching to <a href="https://github.com/netdata/go.d.plugin/pull/1023">collecting data using the CSV format</a>.</p> <h4>Pi-hole</h4> <p>We monitor <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/pihole">Pi-hole</a>, the Linux network-level advertisement and Internet tracker blocking application via its <a href="https://github.com/pi-hole/AdminLTE">PHP API</a>.</p> <p>We <a href="https://github.com/netdata/go.d.plugin/pull/1037">fixed</a> an issue with the requests failing against an authenticated API.</p> <h4>Network Time Protocol (NTP) daemon</h4> <p>The ntpd program is an operating system daemon which sets and maintains the system time of day in synchronism with Internet standard time-servers (<a href="https://linux.die.net/man/8/ntpd">man page</a>).</p> <p>We rewrote our previous python.d collector in go, improving its performance and maintainability.<br> The new collector still monitors the system variables of a local ntpd daemon and optionally the variables of its polled peers. Similarly to ntpq, the <a href="http://doc.ntp.org/current-stable/ntpq.html">standard NTP query program</a>, we used the NTP Control Message Protocol over a UDP socket.</p> <p>The python collector <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-deprecation">will be deprecated in the next release</a>, with no effect on current users.</p> <h3>Notifications</h3> <p>See <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-notifications">Additional alert notification methods on Netdata Cloud</a></p> <p>The agents can now <a href="https://github.com/netdata/netdata/pull/14153">send notifications to Mattermost</a>, using the Slack integration! <a href="https://mattermost.com/">Mattermost</a> has a <a href="https://jeffschering.github.io/mmdocs/monolith/developer/api.html#incoming-webhooks">Slack-compatible API</a> that only required a couple of additional parameters. Kudos to <a href="https://github.com/je2555">@je2555</a>!</p> <h3>Exporters</h3> <p>Netdata can <a href="https://learn.netdata.cloud/guides/export/export-netdata-metrics-graphite">export and visualize Netdata metrics in Graphite</a>.</p> <p>Our exporter was broken in v1.37.0 due to our host labels for ephemeral nodes. we fixed the issue with <a href="https://github.com/netdata/netdata/pull/14105">#14105</a>.</p> <h2>Alerts and Notification Engine</h2> <h3>Health Engine</h3> <p>To improve performance and stability, we made <a href="https://github.com/netdata/netdata/pull/14244">health run in a single thread</a>.</p> <h3>Notifications Engine</h3> <p>The agent alert notifications are controlled by the configuration file <a href="https://github.com/netdata/netdata/blob/master/health/notifications/health_alarm_notify.conf">health_alarm_notify.conf</a>. Previously, if one used the |critical modifier, the recipients would always get at least 2 notifications: critical and clear. There was no way how to stop sending clear/warning notifications afterwards. We <a href="https://github.com/netdata/netdata/pull/14330">added</a> the |nowarn and |noclear notification modifiers, to allow users to really receive just the transitions to the critical state.</p> <p>We also <a href="https://github.com/netdata/netdata-cloud/issues/656">fixed the broken redirects from alert notifications to cleared alerts</a>.</p> <h3>Alerts</h3> <h4>Chart labels in alerts</h4> <p>We constantly strive to improve the clarity of the information provided by the hundreds of out of the box alerts we provide. We can now provide more fine-tuned information on each alert, as we <a href="https://github.com/netdata/netdata/pull/14173">started using specific chart labels instead of family</a>. To provide the capability we also had to <a href="https://github.com/netdata/netdata/pull/14206">change the format of alert info variables</a> to support the more complex syntax.</p> <h4>Globally enable/disable specific alerts</h4> <p>Administrators can now globally, permanently disable specific OOB alerts via netdata.conf<br> . Previously the options where to <a href="https://learn.netdata.cloud/docs/monitor/configure-alarms">edit individual alert configuration files</a>, or to use the <a href="https://learn.netdata.cloud/docs/agent/web/api/health#health-management-api">health management API</a>.</p> <p>The [health] section of netdata.conf now support the setting enabled_alarms. It's value defines which alarms to load from both user and stock directories. The value is a <a href="https://github.com/netdata/netdata/blob/v1.38.0/libnetdata/simple_pattern/README.md">simple pattern</a> list of alarm or template names, with the default value of *, meaning that all alerts are loaded. For example, to disable specific alarms, you can provide enabled alarms = !oom_kill *, which will load all alarms except oom_kill.</p> <h2>Visualizations / Charts and Dashboards</h2> <p>Our main focus for visualization is on the Netdata Cloud <strong>Overview</strong> dashboard. This dashboard is our flagship, on which everything we do, all slicing and dicing capabilities of Netdata, are added and integrated. We are working hard to make this dashboard powerful enough, so that the need to learn a query language for configuring and customizing monitoring dashboards, will be eliminated.</p> <p>On this release, we virtualized all items on the dashboard, allowing us to achieve exceptional performance on page rendering. In previous releases there were issues on dashboards with thousands of charts. Now the number of items in the page is irrelevant!</p> <p>To make slicing and dicing of data easier, we ordered the on-chart selectors in a way that is more natural for most users:</p> <p>​</p> <p><a href="https://preview.redd.it/bnwtlvqc7mga1.png?width=2774&amp;format=png&amp;auto=webp&amp;s=ad41b2f9ca2fa5190748387ffe48adcdcb3dd66c">https://preview.redd.it/bnwtlvqc7mga1.png?width=2774&amp;format=png&amp;auto=webp&amp;s=ad41b2f9ca2fa5190748387ffe48adcdcb3dd66c</a></p> <p>This bar above the chart now describes the data presented, in plain English: <strong>On 6 out of 20 Nodes, group by dimension, the SUM() of 23 Instances, using All dimensions, each as AVG() every 3s</strong></p> <p>A tool-tip provides more information about the missing nodes.</p> <p><a href="https://preview.redd.it/mfdngdzt7mga1.png?width=2790&amp;format=png&amp;auto=webp&amp;s=2886138f488e76278ecbe87f14805095d8a8a88e">https://preview.redd.it/mfdngdzt7mga1.png?width=2790&amp;format=png&amp;auto=webp&amp;s=2886138f488e76278ecbe87f14805095d8a8a88e</a></p> <p>And the drop-down menu now shows the exact nodes that contributed data to the query, together with a short explanation on why nodes did not provide any data: </p> <p><a href="https://preview.redd.it/az6j4f8v7mga1.png?width=2790&amp;format=png&amp;auto=webp&amp;s=ae343ae012f8eda5ee325d96e9b5946a309137e5">https://preview.redd.it/az6j4f8v7mga1.png?width=2790&amp;format=png&amp;auto=webp&amp;s=ae343ae012f8eda5ee325d96e9b5946a309137e5</a></p> <p>Additionally, the pop-out icon next to each node can be used to jump to the single node dashboard of this node.</p> <p>All the slicing and dicing controls (Nodes, Dimensions, Instances), now support filtering. As shown above, there is a search box in the drop-down and a tick-mark to the left of each item in the list, which can be used to instantly filter the data presented.</p> <p>At the same time, we re-worked most of the Netdata collectors to add labels to the charts, allowing the chart to be pivoted directly from the <strong>group by</strong> drop-down menu. On the following image, we see the same chart as above, but now the data have been grouped by the label device, the values of which became dimensions of the chart.</p> <p>​</p> <p><a href="https://preview.redd.it/xp6qztwx7mga1.png?width=2772&amp;format=png&amp;auto=webp&amp;s=7b1f5172742a0725dfe31330ae75f6bdcb73ee2f">https://preview.redd.it/xp6qztwx7mga1.png?width=2772&amp;format=png&amp;auto=webp&amp;s=7b1f5172742a0725dfe31330ae75f6bdcb73ee2f</a></p> <p>The data can be instantly be filtered by original dimension (reads and writes in this example), like this: </p> <p><a href="https://preview.redd.it/43v2lck08mga1.png?width=2762&amp;format=png&amp;auto=webp&amp;s=d17a0d9ab8aa82bd441df804c7f5c96cdd663895">https://preview.redd.it/43v2lck08mga1.png?width=2762&amp;format=png&amp;auto=webp&amp;s=d17a0d9ab8aa82bd441df804c7f5c96cdd663895</a></p> <p>or even by a specific instance (disk in this example), like this: </p> <p><a href="https://preview.redd.it/26px2pf28mga1.png?width=2776&amp;format=png&amp;auto=webp&amp;s=fa64868dbf996c1d4b5ea694ebd05d303b2139bb">https://preview.redd.it/26px2pf28mga1.png?width=2776&amp;format=png&amp;auto=webp&amp;s=fa64868dbf996c1d4b5ea694ebd05d303b2139bb</a></p> <p>On the Instances drop down list (shown above), the pop-out icon to the right of each instance can be used to quickly jump to the single node dashboard, and we also made this function automatically scroll the dashboard to relative chart's position and filter on that chart the specific instance from which the jump was made.</p> <p>Our goal is to polish and fine tune this interface, to the degree that it will be possible to slice and dice any data, without learning a query language, directly from the dashboard. We believe that this will simplify monitoring significantly, make it more accessible to people, and it will eventually allow all of us to troubleshoot issues without any prior knowledge of the underlying data structures.</p> <p>At the same time, we worked to improve switching between rooms and tabs within a room, by saving the last visible chart and the selected page filters, we are restored automatically when the user switches back to the same room and tab.</p> <p>For the ordering of the sections and subsections on the dashboard menu, we made a change to allow currently collected charts to overwrite the position of the section and subsection (we call it priority<br> ). Before this change, archived metrics (old metrics that are retained due to retention), were participating in the election of the priority<br> for a section or subsection and because the retention Netdata maintains by default is more than a year, changes to the priority<br> were never propagated to the UI.</p> <h4>Bug fixes</h4> <p>We fixed:</p> <ul><li><a href="https://github.com/netdata/netdata-cloud/issues/662">The alignment of the anomaly rate pop-down chart</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/704">The width of the right-hand menu bar</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/695">A crash when filtering dimensions</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/649">The warning when a user tries to leave the last space</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/653">The filters of the Metric Correlation screen incorrectly persisting</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/692">The wrong value being shown for whether a node has ML enabled</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/688">The node filter on the anomalies tab</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/648">The visibility of the chart actions menu that appears inside a chart</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/667">Logstash metrics not being displayed in Netdata Cloud</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/679">The home tab not being updated with the correct number of nodes, after deleting a node</a></li> </ul><h3>Real Time Functions</h3> <p>See <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-functions">Functions</a></p> <h3>Events Feed</h3> <p>See <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-feed">Events Feed</a>.</p> <h2>Database</h2> <h3>New database engine</h3> <p>See <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-dbenginev2">Dramatic performance and stability improvements, with a smaller agent footprint</a></p> <h3>Metadata sync</h3> <p>Saving metadata to SQLite is now faster. Metadata saving starts asynchronously when the agent starts and continues as long as there are metadata to be saved. We implemented optimizations by grouping queries into transactions. At runtime this grouping happens per chart, which on shutdown it happens per host. These changes made metadata syncing up to 4x faster.</p> <h2>Streaming and Replication</h2> <p>We introduced very significant reliability and performance improvements to the streaming protocol and the database replication. See <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-stream">Streaming</a>, <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-repl">Replication</a>.</p> <p>At the same time, we fixed SSL handshake issues on established SSL connections, provide stable streaming SSL connectivity between Netdata agents.</p> <h2>API</h2> <p>Data queries for charts and contexts now have the following additional features:</p> <ol><li>The query planner that decided which tier to use for each query, now prefers higher tiers, to speed up queries</li> <li>Joining of multiple tiers to the same query now prefers higher resolution tiers and joining is accurate. To achieve that, behind the scenes the query planner expands the query of each tier to overlap with its previous and next and at the time they intersect, it reads points from all the overlapping tiers to decide how exactly the join should happen.</li> <li>Data queries now utilize the parallelism of the new dbengine, to pipeline query preparation of the dimensions of the chart or context being queried, and then preloading metric data for dimensions that are in the pipeline.</li> </ol><h2>Machine Learning</h2> <p>We have been busy at work under the hood of the Netdata agent to introduce new capabilities that let you extend the "training window" used by Netdata's <a href="https://learn.netdata.cloud/docs/nightly/setup/configure-machine-learning-ml-powered-anomaly-detection">native anomaly detection capabilities</a>.</p> <p><a href="https://preview.redd.it/ij8xh9rw8mga1.png?width=955&amp;format=png&amp;auto=webp&amp;s=df442f7f5722a6959c66b9498920884b8568e2cd">https://preview.redd.it/ij8xh9rw8mga1.png?width=955&amp;format=png&amp;auto=webp&amp;s=df442f7f5722a6959c66b9498920884b8568e2cd</a></p> <p>We have <a href="https://learn.netdata.cloud/docs/nightly/setup/configure-machine-learning-ml-powered-anomaly-detection#descriptions-minmax">introduced a new ML parameter</a> called number of models per dimension<br> which will control the number of most recently trained models used during scoring.</p> <p>Below is some pseudo-code of how the trained models are actually used in producing <a href="https://learn.netdata.cloud/docs/nightly/setup/configure-machine-learning-ml-powered-anomaly-detection#anomaly-bit">anomaly bits</a> (which give you an "<a href="https://learn.netdata.cloud/docs/nightly/setup/configure-machine-learning-ml-powered-anomaly-detection#anomaly-rate">anomaly rate</a>" over any window of time) each second.</p> <p><code># preprocess recent observations into a "feature vector"</code></p> <p><code>latest_feature_vector = preprocess_data([recent_data])</code></p> <p><code># loop over each trained model</code></p> <p><code>for model in models:</code></p> <p><code># if recent feature vector is considered normal by any model, stop scoring</code></p> <p><code>if model.score(latest_feature_vector) &lt; dimension_anomaly_score_threshold:</code></p> <p><code>anomaly_bit = 0</code></p> <p><code>break</code></p> <p><code>else:</code></p> <p><code># only if all models agree the feature vector is anomalous is it considered anomalous by netdata</code></p> <p><code>anomaly_bit = 1</code></p> <p>​</p> <p>The aim here is to only use those additional stored models when we need to. So essentially once one model suggests a feature vector looks anomalous we check all saved models and only when they all agree that something is anomalous does the anomaly bit get to be finally set to 1 to signal that Netdata considered the most recent feature vector unlike anything seen in all the models (spanning a wider training window) checked.</p> <p>Read more in <a href="https://blog.netdata.cloud/extending-anomaly-detection-training-window/">this blog post</a>!</p> <p>We now <a href="https://github.com/netdata/netdata/pull/14207">create ML charts on child hosts</a>, when a parent runs a ML for a child. These charts use the parent's hostname to differentiate multiple parents that might run ML for a child.</p> <p>Finally, we <a href="https://github.com/netdata/netdata/pull/14198">refactored the ML code and added support for multiple KMeans models</a>.</p> <h2>Installation and Packaging</h2> <h3>New hosting of build artifacts</h3> <p>We are always looking to improve the ways we make the agent available to users. Where we host our build artifacts is an important piece of the puzzle, and we've taken some significant steps in the past couple of months.</p> <h4>New hosting of nightly build artifacts</h4> <p>As of 2023-01-16, our nightly build artifacts are being hosted as GitHub releases on the new <a href="https://github.com/netdata/netdata-nightlies/">https://github.com/netdata/netdata-nightlies/</a> repository instead of being hosted on Google Cloud Storage. In most cases, this should have no functional impact for users, and no changes should be required on user systems.</p> <h4>New hosting of native package repositories</h4> <p>As part of improving support for our native packages, we are migrating off of Package Cloud to our own self-hosted package repositories located at <a href="https://repo.netdata.cloud/repos/">https://repo.netdata.cloud/repos/</a>. This new infrastructure provides a number of benefits, including signed packages, easier on-site caching, more rapid support for newly released distributions, and the ability to support native packages for a wider variety of distributions.</p> <p>Our RPM repositories <a href="https://github.com/netdata/netdata/discussions/14161">have already been fully migrated</a> and the DEB repositories <a href="https://github.com/netdata/netdata/discussions/14300">are currently in the process of being migrated</a>.</p> <h4>Official Docker images now available on GHCR and Quay</h4> <p>In addition to Docker Hub, our official Docker images are now available on <a href="https://github.com/netdata/netdata/pkgs/container/netdata">GHCR</a> and <a href="https://quay.io/repository/netdata/netdata">Quay</a>. The images are identical across all three registries, including using the same tagging.</p> <p>You can use our Docker images from GHCR or Quay by either configuring them as registries with your local container tooling, or by using <a href="https://ghcr.io/netdata/netdata">ghcr.io/netdata/netdata</a> or <a href="https://quay.io/netdata/netdata">quay.io/netdata/netdata</a> instead of netdata/netdata.</p> <h3>kickstart</h3> <p>The directives --local-build-options and --static-install-options used to only accept a single option each. We now <a href="https://github.com/netdata/netdata/pull/14287">allow multiple options to be entered</a>.</p> <p>We <a href="https://github.com/netdata/netdata/pull/13881">renamed</a> the --install option to --install-prefix, to clarify that it affects the directory under which the Netdata agent will be installed.</p> <p>To help prevent user errors, passing an unrecognized option to the kickstart script <a href="https://github.com/netdata/netdata/pull/12943">now results in a fatal error</a> instead of just a warning.</p> <p>We previously used grep to get some info on login or group, which could not handle cases with centralized authentication like Active Directory or FreeIPA or pure LDAP. We <a href="https://github.com/netdata/netdata/pull/14316">now use "getent group"</a> to get the group information.</p> <h3>RPMs</h3> <p>We <a href="https://github.com/netdata/netdata/pull/14140">fixed the required permissions</a> of the cgroup-network and ebpf.plugin in RPM packages.</p> <h3>OpenSUSE</h3> <p>We <a href="https://github.com/netdata/netdata/pull/14260">fixed the binary package updates</a> that were failing with an error on "Zypper upgrade".</p> <h3>FreeBSD</h3> <p>We <a href="https://github.com/netdata/netdata/pull/14095">fixed the missing required package installation of "tar"</a>.</p> <h3>MacOS</h3> <p>We <a href="https://github.com/netdata/netdata/pull/14304">fixed some crashes on MacOS</a>.</p> <h3>Proxmox</h3> <p>Netdata on Proxmox virtualization management servers must be allowed to resolve VM/container names and read their CPU and memory limits. </p> <p>We now <a href="https://github.com/netdata/netdata/pull/14168">explicitly add</a> the netdata user to the www-data group on Proxmox, so that users don't have to do it manually.</p> <h3>Other</h3> <p>We <a href="https://github.com/netdata/netdata/pull/14180">fixed the path to "netdata.pid"</a> in the logrotate postrotate script, which causes some errors during log rotation.</p> <p>We also <a href="https://github.com/netdata/netdata/pull/14239">added pre gcc v5 support</a> and allowed building without dbengine.</p> <h2>Administration</h2> <h3>Logging</h3> <p>We have improved the readability of our main error log file error.log<br> , by <a href="https://github.com/netdata/netdata/pull/14309">moving data collection specific log messages</a> to collector.log<br> . For the same reason we <a href="https://github.com/netdata/netdata/pull/14117">reduced the log verbosity of streaming connections</a>.</p> <h3>New configuration editing script</h3> <p>We reimplemented the edit-config script we install in the user config directory, adding a few new features, and fixing a number of outstanding issues with the previous script.</p> <h3>Netdata Monitoring</h3> <p>The new Netdata Monitoring section on our dashboard has dozens of charts detailing the operation of Netdata. All new components have their charts, dbengine, metrics registry, the new caches, the dbengine query router, etc.</p> <p>At the same time, we added a chart detailing the memory used by the agent and the function it is used for. This was the hardest to gather, since information was spread all over the place, but thankfully the internals of the agents have changed drastically in the last few months, allowing us to have a better visibility on memory consumption. At its heart, the agent is now mainly an array allocator (ARAL) and a dictionary (indexed and ordered lists of objects), carefully crafted to achieve their maximum performance when multithreaded. Everything we do, from data collection, to health, streaming, replication, etc., is actually business logic on top of these elements.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Chris-1235"> /u/Chris-1235 </a> <br><span><a href="https://www.reddit.com/r/linux/comments/10vf42u/netdata_release_1380/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/10vf42u/netdata_release_1380/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[JavaScript-Framework: SvelteKit 1.0 stellt kompletten Stack für Svelte bereit]]></title>
<description><![CDATA[Mit Version 1.0 des SvelteKit steht ein komplettes Framework zur Entwicklung von Full-Stack Web-Anwendungen mit Hilfe des Svelt UI Commponent Framework bereit.]]></description>
<link>https://tsecurity.de/de/1742108/it-nachrichten/javascript-framework-sveltekit-10-stellt-kompletten-stack-fuer-svelte-bereit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1742108/it-nachrichten/javascript-framework-sveltekit-10-stellt-kompletten-stack-fuer-svelte-bereit/</guid>
<pubDate>Wed, 21 Dec 2022 17:47:31 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit Version 1.0 des SvelteKit steht ein komplettes Framework zur Entwicklung von Full-Stack Web-Anwendungen mit Hilfe des Svelt UI Commponent Framework bereit.]]></content:encoded>
</item>
<item>
<title><![CDATA[How QuintoAndar increased conversion rates and pages per session by improving page performance]]></title>
<description><![CDATA[QuintoAndar is a Brazilian proptech company whose products offer digital end-to-end solutions for real estate. This year, we carried out a project focused on improving the performance of a content hub in our app, and had encouraging results in increasing user traffic and conversion metrics.

 
  ...]]></description>
<link>https://tsecurity.de/de/1725692/web-tipps/how-quintoandar-increased-conversion-rates-and-pages-per-session-by-improving-page-performance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1725692/web-tipps/how-quintoandar-increased-conversion-rates-and-pages-per-session-by-improving-page-performance/</guid>
<pubDate>Thu, 08 Dec 2022 19:45:05 +0100</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>QuintoAndar is a Brazilian proptech company whose products offer digital end-to-end solutions for real estate. This year, we carried out a project focused on improving the performance of a content hub in our app, and had encouraging results in increasing user traffic and conversion metrics.</p>
<div class="stats">
 <div class="stats__item">
   <p class="stats__figure">46<sub>%</sub></p>
   <p>reduction in bounce rate</p>
 </div>
 <div class="stats__item">
   <p class="stats__figure">87<sub>%</sub></p>
   <p>increase in pages per session</p>
 </div>
 <div class="stats__item">
   <p class="stats__figure">5<sub>%</sub></p>
   <p>improvement in conversion during validation phase</p>
 </div>
</div>
<h2 id="challenges">Challenges <a class="w-headline-link" href="https://web.dev/quintoandar/#challenges">#</a></h2>
<p>Our app has a condominium content hub with over 40,000 pages, where users can get information about their properties, check photos of the common areas, read about the neighborhood, and find available listings for rent or sale. These pages are very important for QuintoAndar:</p>
<ul>
<li>They are an important source of <a href="https://en.wikipedia.org/wiki/Organic_search_results" rel="noopener">organic traffic</a>, with a steadily increasing number of users coming from search engine results.</li>
<li>They have high conversion rates in the medium to long-term compared to other pages.</li>
</ul>
<p>However, there were challenges when it came to the performance and user experience in these pages:</p>
<ul>
<li>Their performance as measured by <a href="https://web.dev/vitals/">Core Web Vitals</a> was not optimized, and there were known issues regarding slow page loads, slow responsiveness to user input, and layout instability.</li>
<li>Their <a href="https://en.wikipedia.org/wiki/Bounce_rate" rel="noopener">bounce rates</a> were high, even if we expected them to be higher than in other parts of the app.</li>
<li>The <a href="https://developers.google.com/search/blog/2020/11/timing-for-page-experience" rel="noopener">page experience update in Google Search</a>—which, at that time, was not yet released—would include Core Web Vitals into the ranking algorithm, which meant page performance could affect how search results were going to be displayed.</li>
</ul>
<p>At the same time, we identified some developer experience opportunities that could unlock gains in other projects across the company:</p>
<ul>
<li>Our server-side rendering logic—which renders all high-traffic pages, including condominium pages—was created in-house, and became too complex to maintain and onboard new hires.</li>
<li>Essential features to achieve good app performance, such as <a href="https://developer.mozilla.org/docs/Glossary/Code_splitting" rel="noopener">code splitting</a>, also required a custom setup plus manual work from the developers.</li>
<li>QuintoAndar has over 30 <a href="https://reactjs.org/" rel="noopener">React</a> web applications. Delivering updates to these applications and maintaining them in accordance to best practices is an arduous task.</li>
</ul>
<h2 id="approach">Approach <a class="w-headline-link" href="https://web.dev/quintoandar/#approach">#</a></h2>
<p>We began a performance optimization project of the condominium content hub to improve its user experience, as these improvements could lead to conversion gains, better SEO, and better usability. This initiative was also a fitting opportunity to improve the developer experience as well.</p>
<h3 id="migrating-to-nextjs">Migrating to Next.js <a class="w-headline-link" href="https://web.dev/quintoandar/#migrating-to-nextjs">#</a></h3>
<p>The new version of the condominium page was implemented with <a href="http://nextjs.org/" rel="noopener">Next.js</a>. Being largely independent from other parts of the app, the condominium content hub seemed like a good candidate for trying out a new framework. We would be able to understand the magnitude of migration efforts and evaluate how its features could help without affecting the other React apps in QuintoAndar.</p>
<p>A hard requirement was to ensure pages remained crawlable by search engines. Next.js meets this requirement by supporting server-side rendering out-of-the-box, and removes the need for a custom setup. The documentation makes it much easier to share knowledge on how to do tasks such as <a href="https://nextjs.org/docs/basic-features/data-fetching" rel="noopener">data fetching</a> on the server and onboard new developers. Server-side rendering is also known to <a href="https://developers.google.com/web/updates/2019/02/rendering-on-the-web#server-rendering" rel="noopener">improve performance</a> metrics such as <a href="https://web.dev/fcp/">First Contentful Paint</a> (FCP).</p>
<p>The framework provides other performance-friendly features such as automatic <a href="https://web.dev/reduce-javascript-payloads-with-code-splitting/">code splitting</a> and <a href="https://web.dev/link-prefetch/">prefetching</a>. Even though the existing structure already provided such features, the additional work required from developers stalled their adoption. For example, code splitting at page or component-level had to be done manually.</p>
<h3 id="optimizing-javascript-resources">Optimizing JavaScript resources <a class="w-headline-link" href="https://web.dev/quintoandar/#optimizing-javascript-resources">#</a></h3>
<p>The first step was to <a href="https://web.dev/remove-unused-code/">remove unused code</a>. We looked at the <a href="https://github.com/webpack-contrib/webpack-bundle-analyzer" rel="noopener">Webpack Bundle Analyzer</a> reports, which shows the contents of each JS bundle, and carefully reviewed all third-party scripts. As a result, we were able to clean up some tracking libraries that were not used in this specific page.</p>
<p>Our team went further and evaluated the performance cost of existing features. For instance, the &quot;like&quot; button required quite a lot of JS to work. However, in the condominium page, less than 0.5% of the users interacted with the button, which is available and used more frequently in other parts of our app. After a discussion involving both Engineering and Product, we decided to remove this feature.</p>
<figure>
  <video autoplay="" controls="" loop="" muted="" playsinline="">      <source src="https://storage.googleapis.com/web-dev-uploads/video/jL3OLOhcWUQDnR4XjewLBx4e3PC3/2uEL2YxbuGGlmJDlvW9F.mp4" type="video/mp4" />    </video>
  <figcaption>
    An animation showing the “like” button feature. There is a card about an apartment available for rent. In the bottom right corner of the card, there is a grey heart-shaped button that turns blue when clicked.
  </figcaption>
</figure>
<p>Other JS optimizations were already in place, such as <a href="https://web.dev/reduce-network-payloads-using-text-compression/#static-compression">static compression with Brotli</a>, which was done at build time using <a href="https://github.com/mynameiswhm/brotli-webpack-plugin" rel="noopener"><code>BrotliWebpackPlugin</code></a>, and was also applied to other types of static resources. At first, we were relying on the compression provided by the CDN, and Brotli reduced JS size by 18% compared to gzip. But then, we switched to Brotli compression at build time, and were able to achieve a 24% reduction.</p>
<h3 id="optimizing-image-resources">Optimizing image resources <a class="w-headline-link" href="https://web.dev/quintoandar/#optimizing-image-resources">#</a></h3>
<p>There is a hero image occupying most of the area above the fold in the mobile version. It also happens to be the <a href="https://web.dev/lcp/">Largest Contentful Paint</a> (LCP) of the page.</p>
<figure>
  <img alt="The condominium page for Edifício Copan (São Paulo, Brazil). A photo taken from the ground level shows the curves of the building structure." decoding="async" height="640" loading="lazy" sizes="(min-width: 360px) 360px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/W7koRinBm3QXErIzwGP8.png?auto=format" srcset="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/W7koRinBm3QXErIzwGP8.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/W7koRinBm3QXErIzwGP8.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/W7koRinBm3QXErIzwGP8.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/W7koRinBm3QXErIzwGP8.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/W7koRinBm3QXErIzwGP8.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/W7koRinBm3QXErIzwGP8.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/W7koRinBm3QXErIzwGP8.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/W7koRinBm3QXErIzwGP8.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/W7koRinBm3QXErIzwGP8.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/W7koRinBm3QXErIzwGP8.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/W7koRinBm3QXErIzwGP8.png?auto=format&w=720 720w" width="360" />
  <figcaption>
    The hero image of a condominium page.
  </figcaption>
</figure>
<p>Previously, all images already had <code>srcset</code> and <code>sizes</code> attributes to <a href="https://web.dev/serve-responsive-images/">serve responsive images</a>. We also used <a href="https://github.com/thumbor/thumbor" rel="noopener">Thumbor</a> to resize images on-demand and configured our CDN to cache them efficiently.</p>
<p>Modern mobile devices have displays with very high pixel density, meaning the browser would render 3x or 4x versions of the image, if available. As resolution increases, it gets harder for the human eye to perceive the differences, but file sizes will increase regardless. <a href="https://blog.twitter.com/engineering/en_us/topics/infrastructure/2019/capping-image-fidelity-on-ultra-high-resolution-devices" rel="noopener">Capping the maximum image resolution</a> improved image size without compromising the user experience. We limited the hero image to serve its 2x version at most, which is approximately 35% smaller than the 3x version and 50% smaller than the 4x one.</p>
<p>To finish, we used a <a href="https://web.dev/preload-critical-assets/">preloading</a> strategy to download and display it as soon as possible, looking forward to improving the LCP metric.</p>
<div><pre class="language-html"><code class="language-html"><span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>link</span> <span class="token attr-name">rel</span><span class="token attr-value"><span class="token punctuation attr-equals">=</span><span class="token punctuation">"</span>preload<span class="token punctuation">"</span></span> <span class="token attr-name">href</span><span class="token attr-value"><span class="token punctuation attr-equals">=</span><span class="token punctuation">"</span>/img/450x450/892847321-143.0038687080606IMG20180420WA0037.jpg<span class="token punctuation">"</span></span> <span class="token attr-name">as</span><span class="token attr-value"><span class="token punctuation attr-equals">=</span><span class="token punctuation">"</span>image<span class="token punctuation">"</span></span><span class="token punctuation">></span></span></code></pre>
</div><p>The <a href="https://nextjs.org/docs/basic-features/image-optimization" rel="noopener">Next.js built-in image component</a> includes many of these optimizations such as responsive resizing and prioritized loading. During this project, we did not migrate the existing images to use this component, but we are planning to adopt it in new features.</p>
<h3 id="reducing-layout-shift">Reducing layout shift <a class="w-headline-link" href="https://web.dev/quintoandar/#reducing-layout-shift">#</a></h3>
<p>The condominium page had a few issues with <a href="https://web.dev/cls/">Cumulative Layout Shift</a> (CLS). The elements responsible for the layout shifts were rendered only in the client—for instance, hydrating server-side markup with client-rendered components, or images without defined <code>width</code> and <code>height</code> attributes.</p>
<p>To solve these problems, we set exact dimensions for these elements when possible, or estimated values with <code>min-height</code>. There are more options, such as using the <a href="https://developer.mozilla.org/docs/Web/CSS/aspect-ratio" rel="noopener"><code>aspect-ratio</code> CSS property</a>. We also created placeholders to prevent dynamically rendered components from causing layout shifts.</p>
<figure>
  <img alt="An image showing an urban area in Google Maps with a red marker in the center." decoding="async" height="174" loading="lazy" sizes="(min-width: 397px) 397px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/VqFwUiJOtNmyNc14xljP.png?auto=format" srcset="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/VqFwUiJOtNmyNc14xljP.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/VqFwUiJOtNmyNc14xljP.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/VqFwUiJOtNmyNc14xljP.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/VqFwUiJOtNmyNc14xljP.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/VqFwUiJOtNmyNc14xljP.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/VqFwUiJOtNmyNc14xljP.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/VqFwUiJOtNmyNc14xljP.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/VqFwUiJOtNmyNc14xljP.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/VqFwUiJOtNmyNc14xljP.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/VqFwUiJOtNmyNc14xljP.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/VqFwUiJOtNmyNc14xljP.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/VqFwUiJOtNmyNc14xljP.png?auto=format&w=794 794w" width="397" />
  <figcaption>
    Defining dimensions for elements such as the map image reduced the CLS.
  </figcaption>
</figure>
<h3 id="progressively-rolling-out-changes">Progressively rolling out changes <a class="w-headline-link" href="https://web.dev/quintoandar/#progressively-rolling-out-changes">#</a></h3>
<p>Our team wanted to validate that the optimized version of the condominium hub page to make sure the user experience would be better. To achieve this, we adopted a progressive rollout strategy:</p>
<ol>
<li>In the first phase, the new version was published for a few hand-picked URLs, so only a few hundreds of users per day would see them;</li>
<li>In the second phase, it was published for more pages, accounting to a few thousand users per day;</li>
<li>In the third and final phase, it was published for all pages, and the roll-out was completed for all users.</li>
</ol>
<p>During this period, the engineering team continuously measured page performance in production and kept working on improvements. Additionally, the team compared business metrics between the new and previous versions. The results in this validation period were promising.</p>
<h2 id="results">Results <a class="w-headline-link" href="https://web.dev/quintoandar/#results">#</a></h2>
<p>The team used <a href="https://speedcurve.com/" rel="noopener">SpeedCurve</a> to continuously run <a href="https://web.dev/user-centric-performance-metrics/#how-metrics-are-measured">lab tests</a> against the condominium page. These are the results for the mobile version:</p>
<div class="table-wrapper">
  <table>
    <thead>
      <tr>
        <th>Lab metric</th>
        <th>Before</th>
        <th>After</th>
        <th>Difference</th>
      </tr>
    </thead>
    <tbody>
      <tr>
        <td>Largest Contentful Paint (LCP)</td>
        <td>2.41 seconds</td>
        <td>1.48 seconds</td>
        <td>-39%</td>
      </tr>
      <tr>
        <td>Time to Interactive (TTI)</td>
        <td>12.16 seconds</td>
        <td>7.48 seconds</td>
        <td>-39%</td>
      </tr>
      <tr>
        <td>Total Blocking Time (TBT)</td>
        <td>1124 milliseconds</td>
        <td>1056 milliseconds</td>
        <td>-4%</td>
      </tr>
      <tr>
        <td>Cumulative Layout Shift (CLS)</td>
        <td>0.0402</td>
        <td>0.0093</td>
        <td>-77%</td>
      </tr>
    </tbody>
    <caption>
      Lab metrics results collected with SpeedCurve.
    </caption>
  </table>
</div>
<p>We also wanted to check the impact on our real users. Using field data collected with <a href="https://www.instana.com/website-end-user-monitoring/" rel="noopener">Instana Website Monitoring</a>, we looked at the 1-month period before and after the roll-out. Comparing the 75th percentile for mobile users, we found that LCP decreased by 26%, and FID decreased by 72%.</p>
<figure>
  <img alt="A line graph with LCP values comparing the new and previous versions during the current and past month. The curve for the new version floats between 2 and 4 seconds, staying below the curve for the previous version most of the time." decoding="async" height="495" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format" srcset="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/IAVpmg7O1Moxk8qA7zcq.png?auto=format&w=1600 1600w" width="800" />
</figure>
<figure>
  <img alt="A line graph with FID values comparing the new and previous versions during the current and past month. The curve for the new version stays below 100ms most of the time, while in the curve for the previous version there are a few spikes crossing 250ms." decoding="async" height="494" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format" srcset="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/QWkHnGHi4YTdBR6q17sw.png?auto=format&w=1600 1600w" width="800" />
  <figcaption>
    Field metrics results collected with Instana.
  </figcaption>
</figure>
<p><a href="https://pagespeed.web.dev/" rel="noopener">PageSpeed Insights</a> provides a field data report for the last 28 days. <a href="https://www.quintoandar.com.br/condominio/ed-copan-centro-historico-de-sao-paulo-sao-paulo-ndv7sq7j2d" rel="noopener">The most accessed condominium page</a> alone had enough data to generate a report for mobile users. As of November 2021, all Core Web Vitals are in the &quot;good&quot; bucket.</p>
<figure>
  <img alt="A screenshot of the PageSpeed Insights report focusing on the Field Data section. All Core Web Vitals metrics (FCP, FID, LCP, CLS) are in the good bucket." decoding="async" height="483" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format" srcset="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/83nulYFqSAAWNLLPHXut.png?auto=format&w=1600 1600w" width="800" />
  <figcaption>
    PageSpeed Insights shows that mobile users are having a good experience in the most accessed condominium page.
  </figcaption>
</figure>
<p>During the progressive roll-out, we noticed a drop in bounce rates. By the time we had finished the release for all pages, <a href="https://analytics.google.com/" rel="noopener">Google Analytics</a> showed a 46% decrease in bounce rate, a 87% increase in pages per session, and a 49% increase in average session duration. The bounce rate reduction was even bigger for paid searches, reaching a 59% drop — a positive sign when it comes to the investments in <a href="https://en.wikipedia.org/wiki/Pay-per-click" rel="noopener">pay-per click</a> (PPC) ads.</p>
<figure>
  <img alt="A screenshot of a graph from Google Analytics. It compares the bounce rates between two distinct periods in March 2021. Starting from March 17th, there is a slight drop in the bounce rate. The drop is accentuated on March 24th." decoding="async" height="169" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format" srcset="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/f31hvBafirHtDBlKINwI.png?auto=format&w=1600 1600w" width="800" />
  <figcaption>
    Google Analytics shows the bounce rate decreasing as we rolled-out the new version in more pages.
  </figcaption>
</figure>
<p>As for the impact in business metrics, we analyzed conversion rates for transactions like scheduling a tour and applying to rent or buy an estate. While improvements were still being rolled out, our team compared the conversion between the previous and new versions. In the same week, the group of pages with the new version showed a 5% conversion increase, while the other pages had a slight decrease in the same metric.</p>
<figure>
  <img alt="Two line graphs side-by-side, each one comparing the conversion between the current and previous week. The left one is for the previous version of the page, showing the conversion curve for the current week is a bit below the one for the previous week. The right one is for the new version, and the conversion curve for the current week is a bit above the one for the previous week." decoding="async" height="447" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format" srcset="https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/jL3OLOhcWUQDnR4XjewLBx4e3PC3/8duPNi2huaphIWCU7DBb.png?auto=format&w=1600 1600w" width="800" />
  <figcaption>
    In the same week, the conversion for the new version increased, while the previous version had a small decrease.
  </figcaption>
</figure>
<h2 id="conclusion">Conclusion <a class="w-headline-link" href="https://web.dev/quintoandar/#conclusion">#</a></h2>
<p>This project is the first part of a long-term migration effort from framework-less React to Next.js. The teams who worked on the condominium page since then gave positive feedback about the improved developer experience. Other teams who had to bootstrap new web apps have already done so with Next.js. We believe Next.js will simplify maintenance efforts and establish a common ground between different apps.</p>
<p>Overall, the condominium content hub has been continuously growing in terms of absolute number of users and transactions. In the long-term analysis, there are many factors contributing to this, like the expansion of QuintoAndar’s operation and SEO initiatives such as improved page indexing. During this project, we have seen that page performance is also one of these factors with great potential for positive conversion impact.</p>
<p><em>Special thanks to <a href="https://www.linkedin.com/in/pasrcarmo/" rel="noopener">Pedro Carmo</a>, Product Manager of the SEO team, for diving into the user data and creating all the conversion analysis seen in this case study.</em></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Improving Core Web Vitals on the Mail.ru home page resulted in an average 10% increase in conversion rates]]></title>
<description><![CDATA[Where we started #
Mail.ru is one of the leading e-mail services on the Russian-speaking Internet and is in the top 5 sites in Russia in terms of traffic. Mail.ru is an important resource for many people. It receives several hundred million visits per month, and is a portal from where people can ...]]></description>
<link>https://tsecurity.de/de/1725695/web-tipps/improving-core-web-vitals-on-the-mailru-home-page-resulted-in-an-average-10-increase-in-conversion-rates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1725695/web-tipps/improving-core-web-vitals-on-the-mailru-home-page-resulted-in-an-average-10-increase-in-conversion-rates/</guid>
<pubDate>Thu, 08 Dec 2022 19:45:05 +0100</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2 id="where-we-started">Where we started <a class="w-headline-link" href="https://web.dev/mailru-cwv/#where-we-started">#</a></h2>
<p>Mail.ru is one of the leading e-mail services on the Russian-speaking Internet and is <a href="https://www.alexa.com/topsites/countries/RU" rel="noopener">in the top 5 sites in Russia in terms of traffic</a>. Mail.ru is an important resource for many people. It receives several hundred million visits per month, and is a portal from where people can access email, news, social media, performance internet searches and more.</p>
<p>Mail.ru wanted to provide its visitors with a high quality user experience, so work began to improve Core Web Vitals. Before discussing our optimization strategy, a few technical details of the Mail.ru home page should first be noted.</p>
<p>Though the project had long been developed using our in-house templating engine <a href="https://github.com/mailru/fest" rel="noopener">Fest</a>, we began to migrate to <a href="https://svelte.dev/" rel="noopener">Svelte 3</a> in 2019.</p>
<aside class="aside flow bg-state-info-bg color-state-info-text"><div class=" flow"> You can find out more about Fest and our reasons for changing the technology stack to Svelte in <a href="https://youtu.be/H2l3pK42f38?t=2913">our team's presentation</a> at Svelte Russia Meetup #1. </div></aside>
<p>Svelte implements reactivity in a way that <a href="https://svelte.dev/blog/virtual-dom-is-pure-overhead" rel="noopener">doesn't use Virtual DOM</a>, which makes it less resource-intensive. <a href="https://svelte.dev/blog/frameworks-without-the-framework" rel="noopener">Svelte's approach removes unused functions from production bundles</a> because the code implementing them isn't generated by the compiler if the functions aren't used. Unused code is removed during compilation, resulting in smaller bundles. This may help reduce <a href="https://web.dev/tbt/">Total Blocking Time (TBT)</a> during page startup.</p>
<h2 id="tracking-performance-metrics">Tracking performance metrics <a class="w-headline-link" href="https://web.dev/mailru-cwv/#tracking-performance-metrics">#</a></h2>
<p>Before optimizing Core Web Vitals, it's helpful to <a href="https://web.dev/vitals-field-measurement-best-practices/">evaluate performance in the field</a>. Before Core Web Vitals, we tracked other metrics, such as <a href="https://web.dev/fcp/">First Contentful Paint (FCP)</a>, in our internal performance dashboard.</p>
<p>Our metrics collection script was modified to collect Core Web Vitals and transmit them to our performance dashboard for visualization. In line with Google's recommendations, our script uses <a href="https://developer.mozilla.org/docs/Web/API/PerformanceObserver" rel="noopener">PerformanceObserver API</a> to obtain metrics, which is part of <a href="https://github.com/mail-core" rel="noopener">the universal frontend &quot;Platform&quot;</a> inside Mail.ru.</p>
<p>The dashboard displayed the following metrics for users (mean values for the week of 15-21 March 2021):</p>
<div class="table-wrapper">
  <table>
    <thead>
      <tr>
        <th colspan="2" width="40%">Metrics group name</th>
        <th colspan="3" width="30%">Core Web Vitals</th>
        <th colspan="3" width="30%">Other Web Vitals</th>
      </tr>
    </thead>
    <tbody>
      <tr>
        <td colspan="2">Metric name</td>
        <td>LCP</td>
        <td>FID</td>
        <td>CLS</td>
        <td>FCP</td>
        <td>TBT</td>
        <td>TTI</td>
      </tr>
      <tr>
        <td rowspan="3">Share of users in accordance with Core Web Vitals thresholds</td>
        <td>good</td>
        <td>52%</td>
        <td>92%</td>
        <td>33%</td>
        <td>35%</td>
        <td>42%</td>
        <td>43%</td>
      </tr>
      <tr>
        <td>needs-improvement</td>
        <td>19%</td>
        <td>5%</td>
        <td>23%</td>
        <td>38%</td>
        <td>16%</td>
        <td>25%</td>
      </tr>
      <tr>
        <td>poor</td>
        <td>29%</td>
        <td>3%</td>
        <td>44%</td>
        <td>27%</td>
        <td>42%</td>
        <td>32%</td>
      </tr>
    </tbody>
    <caption>Metrics for the week of 15-21 March 2021</caption>
  </table>
</div>
<figure>
  <img alt="Core Web Vitals before optimization show roughly 1/3 of users in the poor bucket." decoding="async" height="479" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format" srcset="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ZL7y3ZCpbMcqlOv9mLpV.png?auto=format&w=1600 1600w" width="800" />
  <figcaption>Web Vitals values before the improvements.</figcaption>
</figure>
<h2 id="improving-core-web-vitals">Improving Core Web Vitals <a class="w-headline-link" href="https://web.dev/mailru-cwv/#improving-core-web-vitals">#</a></h2>
<p>While plenty of guidance exists for improving Core Web Vitals, every project has unique challenges. For the Mail.ru home page, the following opportunities were identified:</p>
<ul>
<li>Implementing placeholders for ad banners to reduce <a href="https://web.dev/cls/">CLS</a>.</li>
<li>Using server-side rendering (SSR) to reduce <a href="https://web.dev/lcp/">Largest Contentful Paint (LCP)</a>.</li>
<li>Code splitting to reduce LCP and <a href="https://web.dev/fid/">First Input Delay (FID)</a>.</li>
</ul>
<h2 id="skeletons-for-cls-improvement">Skeletons for CLS improvement <a class="w-headline-link" href="https://web.dev/mailru-cwv/#skeletons-for-cls-improvement">#</a></h2>
<p>CLS was one of the worst performing field metrics for the Mail.ru home page. Subsequent profiling of this page in the <a href="https://developer.chrome.com/docs/devtools/evaluate-performance/" rel="noopener"><strong>Performance</strong> panel</a> of Chrome's DevTools revealed that ads were the source of the problem. To improve layout stability, our team decided to use placeholders to reserve space for ads before they load.</p>
<p>When implementing placeholders, the first step is to determine the dimensions of the content that will replace them. Luckily, the desktop version of Mail.ru home page has strictly documented sizes for ads. After talking with the design team, SVG-animated UI skeletons were used as placeholders as <a href="https://uxdesign.cc/what-you-should-know-about-skeleton-screens-a820c45a571a" rel="noopener">they reduce the perceived load time of the content</a>.</p>
<aside class="aside flow bg-state-bad-bg color-state-bad-text"><p class="cluster color-state-bad-text"><span class="aside__icon box-block "><svg width="24" height="24" viewBox="0 0 24 24" fill="currentColor" xmlns="http://www.w3.org/2000/svg" role="img" aria-label="Error sign">   <path fill-rule="evenodd" clip-rule="evenodd" d="M12 2C6.48 2 2 6.48 2 12s4.48 10 10 10 10-4.48 10-10S17.52 2 12 2zm-1 15v-2h2v2h-2zm0-10v6h2V7h-2z"></path> </svg></span><strong>Caution</strong></p><div class=" flow"> SVG animations are not supported in Internet Explorer 11, consider using CSS if legacy browser support is essential to your application. </div></aside>
<h2 id="the-return-of-ssr">The return of SSR <a class="w-headline-link" href="https://web.dev/mailru-cwv/#the-return-of-ssr">#</a></h2>
<p>To ease the transition from Fest to Svelte, we incrementally rewrote the existing project rather than start over. By March 2021, we had migrated most of the frontend to Svelte, and eventually brought SSR to our production application after triaging and fixing backend performance issues.</p>
<aside class="aside flow bg-state-info-bg color-state-info-text"><div class=" flow"> SSR was not used for the entire application, as <a href="https://malloc.fi/performance-cost-of-server-side-rendered-react-node-js">it can be an expensive process</a> that can delay <a href="https://web.dev/ttfb/">Time to First Byte (TTFB)</a>, which <a href="https://web.dev/optimize-lcp/#optimize-your-server">may affect LCP</a>. We decided to use SSR for crucial content that the user will see on initial render, and offload rendering of hidden content on the client. At the moment, Mail.ru is experimenting with <a href="https://jasonformat.com/islands-architecture/">Islands Architecture</a> to see if further performance gains can be had. </div></aside>
<p>After implementing SSR, the team discovered the cause of CLS regression that initially went unnoticed: the news section was not inserted at the moment of rendering the first content on the page. There was a delay between the initial painting of the page markup provided by the server and the insertion of news section on the client. This behaviour resulted in an ad skeleton shift, which worsened CLS.</p>
<p>Although Chrome's DevTools showed Layout Shift events, we couldn't find the reason for it at first. Though SSR itself wasn't the problem, it helped in discovering the solution later on. Fixing the code responsible for the painting delay improved layout stability of the news component.</p>
<figure>
  <img alt="Active JavaScript just shows an empty page in the news section, hidding the layout jumps." decoding="async" height="443" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format" srcset="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/X5ZgXiNPGEqz6oOlvY5v.png?auto=format&w=1600 1600w" width="800" />
  <figcaption>Finding the news painting problem with JavaScript disabled.</figcaption>
</figure>
<figure>
  <img alt="Disabling JavaScript revealed layout shifts, previously hidden from human eyes." decoding="async" height="448" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format" srcset="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/aXnxfjZCk4oZN8s6ag5o.png?auto=format&w=1600 1600w" width="800" />
  <figcaption>Fixing the news painting problem with JavaScript disabled.</figcaption>
</figure>
<p>Another effect SSR can have on CLS is the movement of components before and after hydration, which can lead to further layout shifts. We encountered this on the mobile version in particular and it required paying special attention to the hydrated component markup. A good solution to this problem was transferring as much display logic from JavaScript to CSS when possible.</p>
<h2 id="code-splitting-and-unused-polyfills">Code splitting and unused polyfills <a class="w-headline-link" href="https://web.dev/mailru-cwv/#code-splitting-and-unused-polyfills">#</a></h2>
<p>To improve the perceived page load speed, work was required to decrease LCP and FID values. One way to achieve this is through <a href="https://web.dev/codelab-code-splitting/">code splitting</a>. In addition to the Mail.ru home page itself, our team is developing a widget for portal navigation. It is currently embedded in <a href="https://vk.company/en/projects/" rel="noopener">many of our company's projects</a>.</p>
<p>For historical reasons, the widget is inserted at the very beginning of the page as a synchronously loading script. The share of polyfills in this script grew over time. To limit the negative performance effects of loading these polyfills, we implemented code splitting for both modern and legacy browsers.</p>
<p>We decided against the <a href="https://philipwalton.com/articles/deploying-es2015-code-in-production-today/" rel="noopener"><code>module</code>/<code>nomodule</code> pattern</a> for loading JavaScript bundles for modern or legacy browsers, as the <code>&lt;script&gt;</code> element's <a href="https://developer.mozilla.org/docs/Web/JavaScript/Guide/Modules" rel="noopener"><code>type=&quot;module&quot;</code> attribute</a> didn't target browsers that were modern enough for our needs. To address this, Mail.ru uses an in-house tool for identifying modern browser versions on the backend, and can adapt to those browsers accordingly.</p>
<aside class="aside flow bg-state-info-bg color-state-info-text"><div class=" flow"> The <a href="https://github.com/browserslist/browserslist-useragent">Browserslist Useragent</a> package is a publicly available alternative to custom tooling for comparing a project's <code>.browserslistrc</code> to the User-Agent string in an application backend. However, our team strongly recommends considering using <a href="https://github.com/WICG/ua-client-hints#differential-serving">User-Agent Client Hints</a> (for example, <a href="https://web.dev/user-agent-client-hints/#user-agent-response-and-request-headers">Sec-CH-UA header</a>, as Mail.ru does in our in-house tool. </div></aside>
<p>Once browsers could be identified in the backend, we implemented code splitting for modern and legacy browsers. The result was a 43.3% reduction in size of the synchronously-loaded JavaScript widget for modern browsers. This practice has been applied to some other portal scripts as well.</p>
<p>In addition to bundle size reduction and positive effects on Core Web Vitals, code splitting improves the developer experience as well. Only 3.5% of our users use legacy browsers and that share is on a downward trend, so implementing code-splitting allowed our developers to use the latest browser APIs without introducing the polyfill bloat necessary for legacy browsers to all users.</p>
<h2 id="results">Results <a class="w-headline-link" href="https://web.dev/mailru-cwv/#results">#</a></h2>
<p>After the optimization effort, we observed the mean values for the week of 24-30 May 2021 in our field data:</p>
<div>
  <table>
    <thead>
      <tr>
        <th colspan="2" width="40%">Metrics group name</th>
        <th colspan="3" width="30%">Core Web Vitals</th>
        <th colspan="3" width="30%">Other Web Vitals</th>
      </tr>
    </thead>
    <tbody>
      <tr>
        <td colspan="2">Metric name</td>
        <td>LCP</td>
        <td>FID</td>
        <td>CLS</td>
        <td>FCP</td>
        <td>TBT</td>
        <td>TTI</td>
      </tr>
      <tr>
        <td rowspan="3">Share of users in accordance with Core Web Vitals thresholds</td>
        <td>good</td>
        <td>58% (+6%)</td>
        <td>93% (+1%)</td>
        <td>93% (+60%)</td>
        <td>43% (+8%)</td>
        <td>49% (+7%)</td>
        <td>51% (+8%)</td>
      </tr>
      <tr>
        <td>needs-improvement</td>
        <td>18%</td>
        <td>4%</td>
        <td>3%</td>
        <td>34%</td>
        <td>17%</td>
        <td>24%</td>
      </tr>
      <tr>
        <td>poor</td>
        <td>24%</td>
        <td>3%</td>
        <td>4%</td>
        <td>23%</td>
        <td>34%</td>
        <td>25%</td>
      </tr>
    </tbody>
    <caption>Metrics for the week of 24-30 March 2021</caption>
  </table>
</div>
<figure>
  <img alt="All metrics in the good bucket improved by at least 1%. CLS even by 60%." decoding="async" height="376" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format" srcset="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7FIE2St8w6EEowUIqV9K.png?auto=format&w=1600 1600w" width="800" />
  <figcaption>Comparison of Web Vitals before and after (change in 'good' group is shown in brackets).</figcaption>
</figure>
<p>The graphs below show changes in web page performance metrics values according to the &quot;Platform&quot;. Note the two important dates on the graphs:</p>
<ul>
<li>23 March 2021: the release of iteration with the last page sections migrated to Svelte;</li>
<li>19 April 2021: the release of iteration with returned SSR and layout modified to correct CLS regressions.</li>
</ul>
<p>The decrease in values from May 1 to May 10 is due to May holidays in Russia.</p>
<figure>
  <img alt="LCP from March to 1 June 2021 showing small improvments over time." decoding="async" height="344" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format" srcset="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/8wq9d0uj3EJp5vK6kI49.png?auto=format&w=1600 1600w" width="800" />
  <figcaption>LCP graph in 'Platform': 16 March to 1 June 2021.</figcaption>
</figure>
<figure>
  <img alt="FID from 16 March to 1 June 2021 showing tiny improvements on a high level." decoding="async" height="345" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format" srcset="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/bxANzHIw78TvdS1RFyWG.png?auto=format&w=1600 1600w" width="800" />
  <figcaption>FID graph in 'Platform': 16 March to 1 June 2021.</figcaption>
</figure>
<figure>
  <img alt="CLS from 16 March to 1 June 2021 showing huge improvements starting at April 23rd." decoding="async" height="344" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format" srcset="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/7woJXpiHLZU3l7PCdspi.png?auto=format&w=1600 1600w" width="800" />
  <figcaption>CLS graph in 'Platform': 16 March to 1 June 2021.</figcaption>
</figure>
<p>Results obtained using the &quot;Platform&quot; are in line with the growth of metric values in <a href="https://developer.chrome.com/docs/crux/" rel="noopener">Chrome UX Report (CrUX)</a>.</p>
<figure>
  <img alt="LCP metric from CrUX showing increase from 51% to 58% in the good bucket." decoding="async" height="499" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format" srcset="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/41Czys52EyEMyYv3fI2w.png?auto=format&w=1600 1600w" width="800" />
  <figcaption>LCP metric change in CrUX in 2021.</figcaption>
</figure>
<figure>
  <img alt="FID metric from CrUX showing slight improvment in FID from 91% to 93% in good bucket." decoding="async" height="498" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format" srcset="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/c8LWvsC52Q58uvKOIZXc.png?auto=format&w=1600 1600w" width="800" />
  <figcaption>FID metric change in CrUX in 2021.</figcaption>
</figure>
<figure>
  <img alt="CLS metric in CrUX showing hugh improvements from 46% to 98% in the good bucket." decoding="async" height="492" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format" srcset="https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/dB6B4Sr8kaaT0KZujRBFC303oFR2/ilAn6vKt93uh4ioqGKj1.png?auto=format&w=1600 1600w" width="800" />
  <figcaption>CLS metric change in CrUX in 2021.</figcaption>
</figure>
<p>A comparison of mean user session duration values a week before the roll-out of initial improvements and a week after the roll-out shows 2.7% growth. Moreover, there is an overall significant increase in conversion in most sections of the page. In particular, conversions to the Mail.ru email app increased by 11.6%, the conversion of the news section increased by 13.5%.</p>
<div class="stats">
  <div class="stats__item">
    <p class="stats__figure">181<sub>%</sub></p>
    <p>Boost of share of good CLS threshold</p>
  </div>
  <div class="stats__item">
    <p class="stats__figure">2.7<sub>%</sub></p>
    <p>Higher mean session duration</p>
  </div>
  <div class="stats__item">
    <p class="stats__figure">13.5<sub>%</sub></p>
    <p>Increase of news section conversion rate</p>
  </div>
</div>
<p>The most unexpected result we got was a 17.4% increase in the Click-Through Rate (CTR) of the marketing banner (its rendering time was significantly reduced by the introduction of SSR and preload tags).</p>
<aside class="aside flow bg-state-info-bg color-state-info-text"><div class=" flow"> An unintended consequence of our work was that we saw a decrease in the conversion rate of some sections on the page. The search section in particular saw a decrease of 6.7%. Our team associates this with a change in the rendering of the page, as earlier on, this component was one of the first to render. We were able to reverse this decrease by introducing new product features into this section. </div></aside>
<p>After analyzing the rest of the sections on the page, we noticed significant performance improvement in the vast majority of them. Even for sections such as Weather and Coronavirus—which are not key on our page—we see an increase in conversion by 9.6% and 9.5%, respectively.</p>
<h2 id="conclusion">Conclusion <a class="w-headline-link" href="https://web.dev/mailru-cwv/#conclusion">#</a></h2>
<p>Improving performance is challenging in that the work involved may be prolonged. You should regularly monitor changes in metrics over time and ensure that all new product features don't cause regressions in Core Web Vitals. To achieve this, we monitor changes in Core Web Vitals in our <a href="https://web.dev/performance-budgets-101/">performance budget</a>.</p>
<p>Most importantly, we stressed the importance of Core Web Vitals to all members of our product team, from managers and designers to testers and QA. Each team member should be aware of performance metrics and be empowered to improve them. We also incorporate performance optimization objectives into our business processes on a regular cadence. Successfully providing a high-quality user experience is only possible through a joint effort by all team members.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s new in Jetpack Compose]]></title>
<description><![CDATA[Posted by Jolanda Verhoef, Android Developer Relations Engineer


  
  
We launched Jetpack Compose over a year ago, and have been busy improving it ever since. We’ve added new features and invented powerful tools to make your experience developing Android UI as productive, intuitive and fun as p...]]></description>
<link>https://tsecurity.de/de/1673716/android-tipps/whats-new-in-jetpack-compose/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1673716/android-tipps/whats-new-in-jetpack-compose/</guid>
<pubDate>Mon, 24 Oct 2022 19:15:13 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgD57qOWeCNuSagChKRfqBBNn3IN1j7SEbohUhWXXzEwtsM6m9uHkzv_N5yCsBcLDhJhDV1J-7Omwf9vFe7DP31UNxnFzooj8JWgL9DRNvgHuoF7BtnKl38yqoZ5NGR0AnkXxeOO1-XCm8jzwtqbHhooKkqLZg28idBo1QHhGWXaAk3vOtHpAzQjhUw/s1600/ADS_22%20-%20What_s%20new%20in%20Jetpack%20Compose%20ADS22-SOCIAL.png"><p><em>Posted by <a href="https://twitter.com/lojanda" target="_blank">Jolanda Verhoef</a>, Android Developer Relations Engineer</em></p><p>

<a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8DjU1NkAz6KDyTpTK2bNnJDk67OwdEQiaBN5d2pMmMCd0B77D2S-gCqrT6ZDvojuhSrj9KGSqip3o0DFCsGmtgv3DF2j1Nr1tsaglwnBwO4UIVl9LRHei4B6XVlHGMjoWwdm9NPm5U7W_g7oXsg0hL49cwU51VbyKwUyLfEIE0zYFbYGIXM9zGypI/s1600/ADS_22%20-%20What_s%20new%20in%20Jetpack%20Compose%20ADS22.png"><img border="0" data-original-height="800" data-original-width="1058" height="204" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8DjU1NkAz6KDyTpTK2bNnJDk67OwdEQiaBN5d2pMmMCd0B77D2S-gCqrT6ZDvojuhSrj9KGSqip3o0DFCsGmtgv3DF2j1Nr1tsaglwnBwO4UIVl9LRHei4B6XVlHGMjoWwdm9NPm5U7W_g7oXsg0hL49cwU51VbyKwUyLfEIE0zYFbYGIXM9zGypI/w687-h204/ADS_22%20-%20What_s%20new%20in%20Jetpack%20Compose%20ADS22.png" width="687"></a>
  
  </p><p>
We launched <a href="https://developer.android.com/jetpack/compose" target="_blank">Jetpack Compose</a> over a year ago, and have been busy improving it ever since. We’ve added new features and invented powerful tools to make your experience developing Android UI as productive, intuitive and fun as possible. So, if you're starting a new app, it's time to write it with Compose! With Material Design 3 support, new Bill Of Materials, <a href="https://android-developers.googleblog.com/2022/07/compose-for-wear-os-10-stable.html" target="_blank">Compose WearOS Stable</a> and Android TV (alpha), Compose Camp, and many other pieces of news… It's an exciting release! 
</p>
<h2>Compose in the Community</h2>


<div>
In the last year, we’ve seen many companies <a href="https://developer.android.com/jetpack/compose/adopt#what-developers-are-saying" target="_blank">developing with Compose at scale</a>, implementing new features and migrating screens from views to Compose. For example, we talked to the engineers at Lyft, who told us that<strong> over 90% of their new feature code is written in Compose, and <a href="https://android-developers.googleblog.com/2022/10/lyft-reduced-their-code-for-ui-components-using-jetpack-compose.html" target="_blank">moving to Compose made their code much simpler and easier to maintain</a></strong>. They also shared <em>“We rewrote the button component in our app using Compose. Before it required 800 lines of code across three files plus 17 different XML files, and it is now down to a single Kotlin file with 300 lines of code. This is a 60% reduction in the Kotlin code alone“.</em> The team at Zepeto has also been implementing Compose across many features, and are enjoying the experience, as <em>“Compose simplified our UI layer logic, making it <a href="https://android-developers.googleblog.com/2022/10/zepeto-plans-to-migrate-80-percent-of-apps-ui-to-jetpack-compose.html">easier to understand code written by my colleagues</a>.”</em></div><div></div><div>It’s great to see how these teams experience faster development cycles, and also feel their UI code is more concise and readable. And they’re not the only ones. Since this year’s Google I/O, the number of top 1000 apps on Google Play using Compose has increased by 50%! To help your team follow in the footsteps of the teams at Lyft, Zepeto, and others, we published a guide on <a href="https://developer.android.com/jetpack/compose/adopt/for-large-teams" target="_blank">How to Adopt Compose for your Team</a>. It outlines how and where to start, and shows the areas of development where Compose can bring huge added value.</div><p><br></p>
<h2>Compose, October ‘22 release</h2>


<p>
Today we’re releasing a new stable version of Compose, with some exciting features and news.
</p>
<p>
First of all, we’ve heard from you how it can be daunting to track versions across different artifacts that might go on different release schedules, so we’re now publishing, together with every Stable release of any of the Compose artifacts, a Bill of Materials, or BOM, to make your life easier. 
</p>
<p>
Our first BOM release, Compose October ‘22, brings support for Staggered Grids, drawing Text directly to Canvas, Pull to Refresh, as well as performance improvements and bug fixes.
</p><p><br></p>
<h3>Compose Bill of Materials</h3>


<p>
A BOM is a Maven module that declares a set of libraries with their versions. It will greatly simplify the way you define Compose library versions in your Gradle dependencies block, especially now that we <a href="https://android-developers.googleblog.com/2022/06/independent-versioning-of-Jetpack-Compose-libraries.html" target="_blank">moved the various Jetpack Compose libraries to independent versioning schemes</a>. Instead of defining each version separately, which can become cumbersome and prone to errors when library versions start to differ, you now only need to define one BOM version and all Compose library versions will be extracted from that. We will publish a new version of the BOM every time a Compose artifact has a new stable release, so moving from stable release to stable release is going to be much simpler.
</p><p><span></span></p><div align="left" dir="ltr"><table><colgroup><col width="719"></colgroup><tbody><tr><td><p dir="ltr"><span><span>dependencies {</span><span><br></span><span>    </span><span>// Import the Compose BOM</span><span><br></span><span>    </span><span>implementation</span><span> platform(</span><span>'androidx.compose:compose-bom:2022.10.00'</span><span>)</span><span><br></span><span><br></span><span>    </span><span>// Declare dependencies for the desired Compose libraries without versions</span><span><br></span><span>    </span><span>implementation</span><span> </span><span>'androidx.compose.foundation:foundation'</span><span><br></span><span>    androidTestImplementation </span><span>'androidx.compose.ui:ui-test-junit4'</span><span><br></span><span><br></span><span>    ...</span><span><br></span><span>}</span></span></p></td></tr></tbody></table><br></div>We’ve added the instructions on how to add the Compose BOM to our <a href="https://developer.android.com/jetpack/compose/setup" target="_blank">Quick start guide</a>. Note that you can still choose to define your dependencies using hard-coded versions. The BOM is added as a useful way to simplify dependencies and make upgrades easier.<div><span>    </span></div><div><br><h3>Modifiers on overdrive</h3>


<p>
Behind the scenes, we’re always working on improving Compose performance.  The October ‘22  release includes a major refactor of how Modifiers work under the hood. While you will not notice anything changing in the APIs, this refactor paves the way for greatly improving Modifier performance. Learn more about the rationale behind the changes, and what’s planned for the near future in the ADS talk <a href="https://developer.android.com/events/dev-summit/technical-talks" target="_blank">Compose Modifiers deep dive</a>.</p><p><br></p>
<h3>Popup &amp; Dialog elevation change</h3>


<p>
Accessibility  is always a first-class citizen for Compose, and this release contains a behavior change that helps fix an Accessibility bug with Popups and Dialogs: their maximum elevation is decreased from 30dp to 8dp. Your app will be impacted only if it uses a custom dialog or popup implementation with an elevation higher than 8dp. The <a href="https://developer.android.com/jetpack/androidx/releases/compose-ui" target="_blank">release notes</a> contain more information about the change, including a way to override the new behavior as an interim solution (keep in mind that we always recommend using 8dp maximum when customizing popups or dialogs).
</p><p><br></p>
<h3>New features</h3>


<div><p>
We added a lot of new functionality to Compose. Here are some highlights:
</p><ul><li>
Implement staggered grids using the new <code><a href="https://developer.android.com/reference/kotlin/androidx/compose/foundation/lazy/staggeredgrid/package-summary#LazyHorizontalStaggeredGrid(androidx.compose.foundation.lazy.staggeredgrid.StaggeredGridCells,androidx.compose.ui.Modifier,androidx.compose.foundation.lazy.staggeredgrid.LazyStaggeredGridState,androidx.compose.foundation.layout.PaddingValues,androidx.compose.foundation.layout.Arrangement.Vertical,androidx.compose.foundation.layout.Arrangement.Horizontal,androidx.compose.foundation.gestures.FlingBehavior,kotlin.Boolean,kotlin.Function1)" target="_blank"><span>LazyHorizontalStaggeredGrid</span></a></code> and <code><a href="https://developer.android.com/reference/kotlin/androidx/compose/foundation/lazy/staggeredgrid/package-summary#LazyVerticalStaggeredGrid(androidx.compose.foundation.lazy.staggeredgrid.StaggeredGridCells,androidx.compose.ui.Modifier,androidx.compose.foundation.lazy.staggeredgrid.LazyStaggeredGridState,androidx.compose.foundation.layout.PaddingValues,androidx.compose.foundation.layout.Arrangement.Vertical,androidx.compose.foundation.layout.Arrangement.Horizontal,androidx.compose.foundation.gestures.FlingBehavior,kotlin.Boolean,kotlin.Function1)" target="_blank"><span>LazyVerticalStaggeredGrid</span></a></code></li><li>Draw text directly to Canvas using <code><span><a href="http://drawscope.drawtext/" target="_blank">DrawScope.drawText</a></span></code></li><li>You can add a <a href="https://fonts.google.com/knowledge/topics/variable_fonts" target="_blank">variable font</a> to your app and change its properties using the <code><a href="https://developer.android.com/reference/kotlin/androidx/compose/ui/text/font/FontVariation" target="_blank"><span>FontVariation</span></a></code> object.</li><li>Add a <a href="https://developer.android.com/reference/kotlin/androidx/compose/ui/text/UrlAnnotation" target="_blank"><span>UrlAnnotation</span></a><span> </span>to your annotated string to improve Accessibility services interacting with the text.</li><li>Add hyphenation to your text using the new <span><a href="https://developer.android.com/reference/kotlin/androidx/compose/ui/text/style/LineBreak" target="_blank"><span>LineBreak</span></a> </span>API.</li><li><a href="https://material.io/design/platform-guidance/android-swipe-to-refresh" target="_blank">Swipe to refresh</a> with the new <code><a href="https://developer.android.com/reference/kotlin/androidx/compose/material/pullrefresh/package-summary#(androidx.compose.ui.Modifier).pullRefresh(androidx.compose.material.pullrefresh.PullRefreshState,kotlin.Boolean)" target="_blank"><span>pullRefresh</span></a></code> modifier.</li><li>Add snapping behavior to your lazy lists using <a href="https://developer.android.com/reference/kotlin/androidx/compose/foundation/gestures/snapping/SnapFlingBehavior" target="_blank">SnapFlingBehavior</a>.</li><li><code><a href="https://developer.android.com/reference/kotlin/androidx/compose/ui/layout/package-summary#LookaheadLayout(kotlin.Function1,androidx.compose.ui.Modifier,androidx.compose.ui.layout.MeasurePolicy)" target="_blank"><span>LookAheadLayout</span></a></code> is a new type of layout that provides information about final measurement and placement of its children so you can decide on intermediate layouts.</li></ul></div>
  
  <div><h2>Compose Material 3 stable</h2></div>
  <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBITldrbxnjPjiWhqzeO4ftBFoVNxXHLpqmk7OpJMfsCbNd1s6H4NHEKn1k1MNCFHumWnBIDKx3DJKd3IL_fV9oftKghZp3-fNe4ReDb6MiLQbmhBPtgC2pPA8qGtvR_66cTImgqHnHRXhtmph98ILXH62b_QB409tisYkKZpoMsL4exIkVixvQHB-/s1600/image2.png"><img border="0" data-original-height="800" data-original-width="1058" height="357" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBITldrbxnjPjiWhqzeO4ftBFoVNxXHLpqmk7OpJMfsCbNd1s6H4NHEKn1k1MNCFHumWnBIDKx3DJKd3IL_fV9oftKghZp3-fNe4ReDb6MiLQbmhBPtgC2pPA8qGtvR_66cTImgqHnHRXhtmph98ILXH62b_QB409tisYkKZpoMsL4exIkVixvQHB-/w640-h357/image2.png" width="640"></a>
  <div><p>Today we also announce the first stable release of the <a href="https://developer.android.com/jetpack/androidx/releases/compose-material3" target="_blank">Compose Material 3 library</a>! You can build an app using Compose and theme it according to <a href="https://m3.material.io/" target="_blank">Material Design 3</a>, our latest iteration of Material Design. Use Material Design 3 to further customize your app’s colors, typography and shapes to make your brand stand out! The library contains fresh and updated versions of many UI components, such as buttons, cards, checkboxes, switches, navigation bars, drawers, and many more, with support for others on its way. See a list of all the supported components in the <a href="https://developer.android.com/reference/kotlin/androidx/compose/material3/package-summary#overview" target="_blank">documentation</a>.</p></div>
<p>
To help you adopt Material 3 check out our new <a href="https://developer.android.com/jetpack/compose/themes/material2-material3" target="_blank">migration guide</a> with clear guidance on how Material 2 concepts translate to Material 3. The default template in Android Studio Flamingo now uses Material 3, to get you up and running in no time. We’ve also updated many of our sample apps, tutorials, templates, and codelabs to use Material 3 so you can learn as you go!
</p>
<h2>New tools</h2>


<p>
Developing your app using Jetpack Compose is much easier with the new and improved tools around it. We’ve added tons of new features to Android Studio to improve your workflow and efficiency:
</p>
<p>
<a href="https://developer.android.com/studio/releases#new_in_compose" target="_blank">Android Studio Dolphin</a> is the latest <strong>stable release</strong>, bringing you: 
</p>
<ul><li>Animation Coordination

</li><li>Multipreview annotations

</li><li>Recomposition counts in Layout Inspector
</li>
</ul><p>
<a href="https://developer.android.com/studio/preview/features#2022.1.1" target="_blank">Android Studio Electric Eel</a> contains <strong>beta features</strong>, like:
</p>
<ul><li>Live Edit (experimental)

</li><li>Composition rendering highlighting

</li><li>Configuring Preview devices

</li><li>Live updates in Previews
</li>
</ul><p>
<a href="https://developer.android.com/studio/preview/features#2022.2.1" target="_blank">Android Studio Flamingo</a> contains <strong>canary features</strong> such as:
</p>
<ul><li>New project templates use Compose and Material 3 by default

</li><li>Live Edit turned on by default

</li><li>Improved composition tracing to help you better inspect performance issues.</li></ul><br><ul></ul><h3><strong>Relay</strong></h3><p>
Today we also launch the first alpha version of <a href="https://relay.material.io/" target="_blank">Relay</a>, a design-to-code solution for improving designer-developer collaboration. Designers create UI components using the <a href="https://www.figma.com/community/plugin/1041056822461507786" target="_blank">Figma plugin</a>, and developers use the <a href="https://plugins.jetbrains.com/plugin/19721-relay-for-android-studio/" target="_blank">Android Studio plugin</a> to automatically use these components in their apps. The generated components are composable functions and can be integrated directly into your Compose app. Learn more about Relay in the <a href="https://developer.android.com/jetpack/compose/tooling/relay" target="_blank">documentation</a>.
</p><p><br></p>
<h2>Compose on WearOS, Large Screens and TV</h2>


<p>
In July we released the first Stable version of <a href="https://android-developers.googleblog.com/2022/07/compose-for-wear-os-10-stable.html" target="_blank">Wear Compose</a>, ready to build production apps. <strong>Compose for Wear OS is our recommended approach for building UIs for Wear OS apps</strong>. We’ve included over twenty Compose UI components that were designed specifically for Wearables, like <code><span>TimeText</span></code>, <code><span>PositionIndicator</span></code>, and <code><span>ScalingLazyColumn</span></code>. 
</p>
<p>
We’re also continuing to make it easier to design, develop, and test <strong>apps for large screens</strong> such as foldables, tablets, and Chrome OS. The <code><a href="https://developer.android.com/jetpack/androidx/releases/compose-material3" target="_blank"><span>material3-window-size-class</span></a></code> library graduated to Stable, giving you a set of opinionated viewport breakpoints to work with. Large screen designs often contain staggered grids, and the addition of <code><a href="https://developer.android.com/reference/kotlin/androidx/compose/foundation/lazy/staggeredgrid/package-summary#LazyHorizontalStaggeredGrid(androidx.compose.foundation.lazy.staggeredgrid.StaggeredGridCells,androidx.compose.ui.Modifier,androidx.compose.foundation.lazy.staggeredgrid.LazyStaggeredGridState,androidx.compose.foundation.layout.PaddingValues,androidx.compose.foundation.layout.Arrangement.Vertical,androidx.compose.foundation.layout.Arrangement.Horizontal,androidx.compose.foundation.gestures.FlingBehavior,kotlin.Boolean,kotlin.Function1)" target="_blank"><span>LazyHorizontalStaggeredGrid</span></a></code> and <span><a href="https://developer.android.com/reference/kotlin/androidx/compose/foundation/lazy/staggeredgrid/package-summary#LazyVerticalStaggeredGrid(androidx.compose.foundation.lazy.staggeredgrid.StaggeredGridCells,androidx.compose.ui.Modifier,androidx.compose.foundation.lazy.staggeredgrid.LazyStaggeredGridState,androidx.compose.foundation.layout.PaddingValues,androidx.compose.foundation.layout.Arrangement.Vertical,androidx.compose.foundation.layout.Arrangement.Horizontal,androidx.compose.foundation.gestures.FlingBehavior,kotlin.Boolean,kotlin.Function1)" target="_blank">LazyVerticalStaggeredGrid</a></span><span> </span>will help implement these.

</p><p>
Finally, we’re happy to announce the <strong>first alpha release of <a href="https://developer.android.com/jetpack/androidx/releases/tv" target="_blank">Compose for Android TV</a></strong>. It contains components like <code><a href="https://developer.android.com/reference/kotlin/androidx/tv/material/carousel/package-summary#Carousel(kotlin.Int,androidx.compose.ui.Modifier,androidx.tv.material.carousel.CarouselState,kotlin.Long,androidx.compose.animation.EnterTransition,androidx.compose.animation.ExitTransition,kotlin.Function1,kotlin.Function1)" target="_blank"><span>Carousel</span></a></code> and <span><a href="https://developer.android.com/reference/kotlin/androidx/tv/material/immersivelist/package-summary#ImmersiveList(kotlin.Function3,androidx.compose.ui.Modifier,androidx.compose.ui.Alignment,kotlin.Function1)" target="_blank">ImmersiveList</a></span><span>,</span> with more components coming soon. Try it out and give us feedback, to help us make the best product for your apps on Android TV.

</p><span><a name="more"></a></span><p><br></p><p><br></p><p>Feedback from the Android community always moves us forward. With your input we have updated our <a href="https://developer.android.com/jetpack/androidx/compose-roadmap" target="_blank">roadmap</a>, focusing on areas that will help you implement Compose successfully. We’re now focusing on supporting more advanced use cases, covering more Material 3 components, improving platform support, tooling and performance.</p><p><br></p>
<h2>New and updated guidance</h2>


<p>
No matter where you are in your learning journey, we’ve got you covered! We added and revamped a lot of the guidance on Compose:
</p><ul><li>
For hands-on work, head on to the revamped <a href="https://developer.android.com/courses/jetpack-compose/course" target="_blank">Compose for Android Developers course.</a> It covers a wide range of topics, from basics to advanced.</li><li>If you prefer watching videos, check out the <a href="https://youtube.com/playlist?list=PLWz5rJ2EKKc-CG9riunK996aI6cRhXFDC" target="_blank">MAD Skills: Compose Basics</a> series and of course, all the Compose talks at the <a href="https://developer.android.com/events/dev-summit/technical-talks#modern-android-development" target="_blank">Android Dev Summit</a></li><li>Read the expanded documentation on <a href="https://developer.android.com/jetpack/compose/graphics" target="_blank">Images and Graphics</a>.</li><li>Wondering what animation to use? The new <a href="https://storage.googleapis.com/android-stories/compose/Compose_Animation_Cheat_Sheet.pdf" target="_blank">animation cheat sheet</a> has the answer!</li><li>Learn how to find and fix performance issues with the new debugging recomposition <a href="https://youtu.be/SWBN0y0lFNY" target="_blank">screencast</a> and <a href="https://medium.com/androiddevelopers/jetpack-compose-debugging-recomposition-bfcf4a6f8d37" target="_blank">blog post</a>.</li><li>If you’re considering adopting Compose to your existing app, read the expanded <a href="https://developer.android.com/jetpack/compose/interop" target="_blank">Adopting Compose in your app</a> guide.</li><p> </p></ul><h2>Compose Camp<a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyzO_YzBiL1Ra0oykI6xunLmAPY_8aTKOvxH5o_Nei5Dyk8qStI9Jx2Q69zcMq7w2A_-NyM6YOhPo6Fsj_kdxV0e9Ot-AnWQA7tjCj9DIeNrWRDZI-qAjic6P7uOmH5d2dnN7aJYWroRZoN_7wwtWM9W7Kts01HB5LEfQ2eTj3szscWnbtbzy29NJC/s1600/ComposeCamp_AndroidBlogHeader_4209x1253.png"><img border="0" data-original-height="800" data-original-width="1058" height="203" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyzO_YzBiL1Ra0oykI6xunLmAPY_8aTKOvxH5o_Nei5Dyk8qStI9Jx2Q69zcMq7w2A_-NyM6YOhPo6Fsj_kdxV0e9Ot-AnWQA7tjCj9DIeNrWRDZI-qAjic6P7uOmH5d2dnN7aJYWroRZoN_7wwtWM9W7Kts01HB5LEfQ2eTj3szscWnbtbzy29NJC/w683-h203/ComposeCamp_AndroidBlogHeader_4209x1253.png" width="683"></a></h2><p>
Running from September through December is a world-wide community-organized event series called <a href="https://developer.android.com/compose-camp" target="_blank">Compose Camp</a>! With both a beginner and an experienced track, developers of all levels can join Compose Camp to learn together with others. We already see lots of <a href="https://twitter.com/search?q=%23ComposeCamp&amp;src=typeahead_click" target="_blank">traction</a>, with many <a href="https://www.youtube.com/results?search_query=compose%20camp" target="_blank">videos</a> being posted by GDGs and GDSCs all over the globe, and many events hosted on our Community platform. 
</p><p><br></p>
<h2>Happy Composing!</h2>


<p>
We hope that you’re as excited by these developments as we are! If you haven't started yet, it's time to learn <a href="https://developer.android.com/jetpack/compose" target="_blank">Jetpack Compose</a> and see how your team and development process can benefit from it. Get ready for improved velocity and developer productivity. Happy Composing!
</p>

<p></p><p></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ZEPETO plans to migrate at least 80% of the app’s UI to Jetpack Compose]]></title>
<description><![CDATA[ZEPETO is a 3D social universe built by NAVER Z with more than 300 million users in over 200 countries. Those users can create unique avatars, foster friendships, and explore virtual realms of their own design. ZEPETO commits itself to creating spaces that prioritize the user’s experience. For it...]]></description>
<link>https://tsecurity.de/de/1673718/android-tipps/zepeto-plans-to-migrate-at-least-80-of-the-apps-ui-to-jetpack-compose/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1673718/android-tipps/zepeto-plans-to-migrate-at-least-80-of-the-apps-ui-to-jetpack-compose/</guid>
<pubDate>Mon, 24 Oct 2022 19:15:13 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGkqWKC1TNuNpDOdxBNDPrpEUUiFSUgofjb5WIR3uu7u9PkrU2Pc7WmpLCG9N6TDRgrDV71vCwQi5PlvZRSTi035e7eRKui8qHn_eKprkNCsT3zg507BxfxtJLcPWPwc627yUaGUE_va5KXALBOvpwVgqMUXkGOcPAKADVYNsAnz6CWk7hdGMs8M-2/s1600/image2.gif"><p>
<a href="https://play.google.com/store/apps/details?id=me.zepeto.main&amp;hl=en_US&amp;gl=US" target="_blank">ZEPETO</a> is a 3D social universe built by <a href="https://www.naverz-corp.com/" target="_blank">NAVER Z</a> with more than 300 million users in over 200 countries. Those users can create unique avatars, foster friendships, and explore virtual realms of their own design. ZEPETO commits itself to creating spaces that prioritize the user’s experience. For its engineers, that meant making the switch to <a href="https://developer.android.com/jetpack/compose" target="_blank">Jetpack Compose</a>, Android’s modern toolkit for building native UI.<a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGkqWKC1TNuNpDOdxBNDPrpEUUiFSUgofjb5WIR3uu7u9PkrU2Pc7WmpLCG9N6TDRgrDV71vCwQi5PlvZRSTi035e7eRKui8qHn_eKprkNCsT3zg507BxfxtJLcPWPwc627yUaGUE_va5KXALBOvpwVgqMUXkGOcPAKADVYNsAnz6CWk7hdGMs8M-2/s1600/image2.gif"><img alt="ZEPETO plans to migrate at least 80% of the app's UI to Jetpack Compose" border="0" data-original-height="800" data-original-width="1058" height="377" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGkqWKC1TNuNpDOdxBNDPrpEUUiFSUgofjb5WIR3uu7u9PkrU2Pc7WmpLCG9N6TDRgrDV71vCwQi5PlvZRSTi035e7eRKui8qHn_eKprkNCsT3zg507BxfxtJLcPWPwc627yUaGUE_va5KXALBOvpwVgqMUXkGOcPAKADVYNsAnz6CWk7hdGMs8M-2/w670-h377/image2.gif" width="670"></a></p><p>
</p><h2>Embracing Jetpack Compose</h2>
<p></p>
<div>
ZEPETO was originally designed and developed using Views, Unity and OpenGL, but today 20% of the UI originally written in Views has been rewritten with Jetpack Compose. ZEPETO’s developers began to sequentially integrate the toolkit knowing it would resolve a number of recurring engineering friction points. With the Views system, implementing custom UI with some specific shapes, such as sliders or switches, required implementing the onDraw method with a Canvas. Jetpack Compose allows ZEPETO’s developers to implement these types of UI in Kotlin without needing to implement custom classes, simplifying the process and eliminating the extra steps required.</div><div></div><p>
</p><h2>Cleaning up the codebase</h2>
<p></p>
<p>
With Jetpack Compose, ZEPETO’s developers rewrote complex UI features. They built a design system that helped organize fonts and sizes in a more intuitive way, improving maintainability, efficiency, and the UX. “Using Compose, we rewrote parts of the app where the UI is relatively complex and various business logics exist, such as the character shop, gift giving, and face decoration,” said Android Developer Hojung Kim. In places like the pager and grid areas of the character shop, <strong>Composable functions helped reduce the amount of code by more than 10%</strong>.
</p>
<p>
The ZEPETO team decided to migrate its common dialog components to Compose too. This enabled its engineers to use the desired type of dialog needed throughout all parts of the app. “Each element of the common dialog can now be made into a component, making it possible to create a common dialog, just like assembling a Lego,” said Juhyung Park, Android Developer at ZEPETO. Modularizing the code allowed the engineers to implement commonly used app components much faster than before. By migrating these dialog components, the team was able to clean up <strong>1600+ lines of code</strong>, making it much more readable, understandable, and significantly easier to maintain.
</p><div><br></div>
<p>
</p><h2>Refining the developer experience</h2>
<p></p>
<p>
Jetpack Compose drastically increased the efficiency of previewing, developing, and implementing UI by allowing developers to reuse and share UI elements. ZEPETO developers have already created more than <strong>230 preview functions</strong> to effortlessly test and debug features across the application.
</p>
<p>
It was also relatively easy for the team to learn how to use Jetpack Compose. “It doesn’t take long for developers familiar with the existing Android View system to reach a level where they can use Compose in actual practice,” said Hojung.
</p>

<div><table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody><tr><td><center><img alt="We rewrote the Character Shop feature in Compose. It was much faster to write it in Compose, and we reduced the amount of code by over 10% ≫
Hojung Kim Android developer, ZEPETO" border="0" data-original-height="1504" data-original-width="720" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhvSCafQZeROTEqZ9KZSoDYe3NsJ0f_9SZd4nUdsbucJiKJGSqO3-VEUM1FfBiTf2W8VyWe8LmTrsjyG982BGsKCowiCauki7GTidwXm7SS8ttYCPOdm_Z1R0QUQc09CNk3UcwDYgNDMnNM5LcXyRH2hy7OvwpQwJmiAnLqoK38_hugQ21dfBKFCZuc/s1600/image1.png" td=""></center></td></tr><tr><td class="tr-caption"></td></tr></tbody></table></div>

<p>
</p><h2>Moving forward with Compose</h2>
<p></p>
<p>
The ZEPETO team is motivated by Google’s increasing support for Jetpack Compose as it’s clear Compose is a huge priority for Google. They’re excited about how Google is integrating more Android APIs with Compose, and are looking forward to further development of the toolkit. 
</p>
<p>
Several of ZEPETO’s features are now built with Jetpack Compose alongside the graphics built with Unity and OpenGL, such as the character shop, video and photo editors, and dialog components, but the team doesn’t plan to stop there. Given the improvements they’ve seen with development speed, code maintenance, and code reduction, they’ll continue migrating existing screens and building new features with Compose. “In the long run,” finished Hojung, “more than 80% of the UI will be written with Compose,” with the remaining UI and graphics with Unity and OpenGL.
</p><div><br></div>
<p>
</p><h2>Optimize your app</h2>
<p></p>
<p>
Learn how you can upgrade your UI development with <a href="https://developer.android.com/jetpack/compose" target="_blank">Jetpack Compose</a>.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[heise+ | Web-Apps mit SvelteKit erstellen]]></title>
<description><![CDATA[SvelteKit verspricht, schlanke Apps schnell zu erstellen. Den Umgang mit der Svelte-Erweiterung erläutern wir an einem konkreten Beispiel in diesem Artikel.]]></description>
<link>https://tsecurity.de/de/1645380/it-nachrichten/heise-web-apps-mit-sveltekit-erstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1645380/it-nachrichten/heise-web-apps-mit-sveltekit-erstellen/</guid>
<pubDate>Wed, 28 Sep 2022 18:04:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[SvelteKit verspricht, schlanke Apps schnell zu erstellen. Den Umgang mit der Svelte-Erweiterung erläutern wir an einem konkreten Beispiel in diesem Artikel.]]></content:encoded>
</item>
<item>
<title><![CDATA[Use-after-freedom: MiraclePtr]]></title>
<description><![CDATA[Posted by Adrian Taylor, Bartek Nowierski and Kentaro Hara on behalf of the MiraclePtr team Memory safety bugs are the most numerous category of Chrome security issues and we’re continuing to investigate many solutions – both in C++ and in new programming languages. The most common type of memory...]]></description>
<link>https://tsecurity.de/de/1629762/it-security-nachrichten/use-after-freedom-miracleptr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1629762/it-security-nachrichten/use-after-freedom-miracleptr/</guid>
<pubDate>Tue, 13 Sep 2022 21:16:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="byline-author"> Posted by Adrian Taylor, Bartek Nowierski and Kentaro Hara on behalf of the MiraclePtr team</span> <p>Memory safety bugs are the most numerous category of Chrome security issues and we’re continuing to <a href="https://security.googleblog.com/2021/09/an-update-on-memory-safety-in-chrome.html">investigate many solutions</a> – both in C++ and in new programming languages. The most common type of memory safety bug is the “use-after-free”. We <a href="https://security.googleblog.com/2022/05/retrofitting-temporal-memory-safety-on-c.html">recently posted about</a> an exciting series of technologies designed to prevent these. Those technologies (collectively, *Scan, pronounced “star scan”) are very powerful but likely require hardware support for sufficient performance. </p><p>Today we’re going to talk about a different approach to solving the same type of bugs. </p><p>It’s hard, if not impossible, to avoid use-after-frees in a non-trivial codebase. It’s rarely a mistake by a single programmer. Instead, one programmer makes reasonable assumptions about how a bit of code will work, then a later change invalidates those assumptions. Suddenly, the data isn’t valid as long as the original programmer expected, and an exploitable bug results. </p><p>These bugs have real consequences. For example, according to Google Threat Analysis Group, a <a href="https://crbug.com/1296150">use-after-free in the ChromeHTML engine</a> was <a href="https://blog.google/threat-analysis-group/countering-threats-north-korea/">exploited this year</a> by North Korea. </p><p>Half of the known exploitable bugs in Chrome are use-after-frees:  </p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjol0tDHrKfloO3-RsAhVwMGPRBFmg8FmM2nMbHfA4kPTHu4PVaoqFAkdKXkE63ePSIC4U4rH8pMSa8FfLYY-0CdahMPzcP_GqoILj0bBtquIwVuf-oLRpnZqe6cNBgTHv6LPnM_l1YrkqPHote0DMbIkYy7BZjDiZITG2u05T9YoxV6OqhnonD1TlY9g/s512/bug%20types.png"><img alt="" border="0" width="600" data-original-height="317" data-original-width="512" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjol0tDHrKfloO3-RsAhVwMGPRBFmg8FmM2nMbHfA4kPTHu4PVaoqFAkdKXkE63ePSIC4U4rH8pMSa8FfLYY-0CdahMPzcP_GqoILj0bBtquIwVuf-oLRpnZqe6cNBgTHv6LPnM_l1YrkqPHote0DMbIkYy7BZjDiZITG2u05T9YoxV6OqhnonD1TlY9g/s600/bug%20types.png"></a></div> <p><strong>Diving Deeper: Not All Use-After-Free Bugs Are Equal</strong>  </p><p>Chrome has a <a href="https://www.chromium.org/developers/design-documents/multi-process-architecture/">multi-process architecture</a>, partly to ensure that web content is isolated into a sandboxed “renderer” process where little harm can occur. An attacker therefore usually needs to find and exploit <em>two</em> vulnerabilities - one to achieve code execution in the renderer process, and another bug to break out of the sandbox. </p><p>The first stage is often the easier one. The attacker has lots of influence in the renderer process. It’s easy to arrange memory in a specific way, and the renderer process acts upon many different kinds of web content, giving a large “attack surface” that could potentially be exploited. </p><p>The second stage, escaping the renderer sandbox, is trickier. Attackers have two options how to do this: </p><ol><li>They can exploit a bug in the underlying operating system (OS) through the limited interfaces available inside Chrome’s sandbox.  </li><li>Or, they can exploit a bug in a more powerful, privileged part of Chrome - like the “browser” process. This process coordinates all the other bits of Chrome, so fundamentally <em>has</em> to be all-powerful. </li></ol><p>We imagine the attackers squeezing through the narrow part of a funnel:  </p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrD_PVCwSIrVn0tVWBs7b0PueDknbg8BrwznIfKHmYqgNFlGuVupFVZaPMSO9uoj4QawGujzyOS42-Nsemdl9AXD3gOaUFeqnBkhVd0Aem99UK5C9bt6trfnF_4UplnWFdXUrXfM-P4QvnZq81lrsz8o7M6QLZaKzSSLm7_ni10BPT2xaLSyhITCHE9A/s1600/Screenshot%202022-09-13%207.28.31%20AM.png"><img alt="" border="0" data-original-height="405" data-original-width="646" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrD_PVCwSIrVn0tVWBs7b0PueDknbg8BrwznIfKHmYqgNFlGuVupFVZaPMSO9uoj4QawGujzyOS42-Nsemdl9AXD3gOaUFeqnBkhVd0Aem99UK5C9bt6trfnF_4UplnWFdXUrXfM-P4QvnZq81lrsz8o7M6QLZaKzSSLm7_ni10BPT2xaLSyhITCHE9A/s1600/Screenshot%202022-09-13%207.28.31%20AM.png"></a></div> If we can reduce the size of the narrow part of the funnel, we will make it as hard as possible for attackers to assemble a full exploit chain. We can reduce the size of the orange slice by removing access to more OS interfaces within the renderer process sandbox, and we’re continuously working on that. The MiraclePtr project aims to reduce the size of the blue slice. <p>Here’s a sample of 100 recent high severity Chrome security bugs that made it to the stable channel, divided by root cause and by the process they affect. </p><p> </p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNa-V0mokSe10I_waRxQNuH_GNg6kqPyAszlWZ2EqMIgiySJcLWQ_FQQYSCl5dnF-u7acqGaqNE1bKXKJGG9b2GKKzIDMrKQWPhJWdp-0Te2HZYOecDVpLJXamMCzdO8ErcezDkFly1D19YlPrPHDHDf01O8GisMqoCOnfsAK8jWl9W8_JeUDJglHLNw/s512/bugs%20chart%202.png"><img alt="" border="0" width="600" data-original-height="317" data-original-width="512" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNa-V0mokSe10I_waRxQNuH_GNg6kqPyAszlWZ2EqMIgiySJcLWQ_FQQYSCl5dnF-u7acqGaqNE1bKXKJGG9b2GKKzIDMrKQWPhJWdp-0Te2HZYOecDVpLJXamMCzdO8ErcezDkFly1D19YlPrPHDHDf01O8GisMqoCOnfsAK8jWl9W8_JeUDJglHLNw/s600/bugs%20chart%202.png"></a></div><p>You might notice: </p><ul><li>This doesn’t quite add up to 100 - that’s because a few bugs were in other processes beyond the renderer or browser.  </li><li>We claimed that the browser process is the more difficult part to exploit, yet there are more potentially-exploitable bugs! That may be so, but we believe they are typically harder to exploit because the attacker has less control over memory layout. </li></ul><p>As you can see, the biggest category of bugs in each process is: V8 in the renderer process (JavaScript engine logic bugs - <a href="https://docs.google.com/document/d/1FM4fQmIhEqPG8uGp5o9A-mnPB5BOeScZYpkHjo0KKA8/edit">work in progress</a>) and use-after-free bugs in the browser process. If we can make that “thin” bit thinner still by removing some of those use-after-free bugs, we make the whole job of Chrome exploitation markedly harder. </p><p><strong>MiraclePtr: Preventing Exploitation of Use-After-Free Bugs</strong></p><p>This is where <a href="https://docs.google.com/document/d/1pnnOAIz_DMWDI4oIOFoMAqLnf_MZ2GsrJNb_dbQ3ZBg/edit">MiraclePtr</a> comes in. It is a technology to prevent exploitation of use-after-free bugs. Unlike aforementioned *Scan technologies that offer a non-invasive approach to this problem, MiraclePtr relies on rewriting the codebase to use a new smart pointer type, <a href="https://chromium.googlesource.com/chromium/src/+/main/base/memory/raw_ptr.md">raw_ptr&lt;T&gt;</a>. There are multiple ways to implement MiraclePtr. We came up with <a href="https://docs.google.com/document/d/1qsPh8Bcrma7S-5fobbCkBkXWaAijXOnorEqvIIGKzc0/edit">~10 algorithms</a> and compared the pros and cons. After analyzing their performance overhead, memory overhead, security protection guarantees, developer ergonomics, etc., we concluded that BackupRefPtr was the most promising solution. </p><p></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqjNDqH-vs-iOJi4MZ8xgPNPFQin31tNdn0Ixh2w9wEKgTWB0KDsRBFg47IRrLsZ1BMSFAY0a1rmCUf5ETwzhUicglI4S9Lq6ue9h0UiK9vXX5WF6ZPVdEFSvDMGQOsLJ6MI0ZlyRbMCkd58hLxNBOy5FobolQUuyj7o6gYA2lZFDLt9QO_VLTpLJ1cA/s512/raw1.png"><img alt="" border="0" width="200" data-original-height="484" data-original-width="512" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqjNDqH-vs-iOJi4MZ8xgPNPFQin31tNdn0Ixh2w9wEKgTWB0KDsRBFg47IRrLsZ1BMSFAY0a1rmCUf5ETwzhUicglI4S9Lq6ue9h0UiK9vXX5WF6ZPVdEFSvDMGQOsLJ6MI0ZlyRbMCkd58hLxNBOy5FobolQUuyj7o6gYA2lZFDLt9QO_VLTpLJ1cA/s200/raw1.png"></a></div>      The BackupRefPtr algorithm is based on reference counting. It uses support of Chrome's own heap allocator, <a href="https://chromium.googlesource.com/chromium/src/+/main/base/allocator/partition_allocator/PartitionAlloc.md">PartitionAlloc</a>, which carves out a little extra space for a hidden reference count for each allocation. raw_ptr&lt;T&gt; increments or decrements the reference count when it’s constructed, destroyed or modified. When the application calls free/delete and the reference count is greater than 0, PartitionAlloc quarantines that memory region instead of immediately releasing it. The memory region is then only made available for reuse once the reference count reaches 0. Quarantined memory is poisoned to further reduce the likelihood that use-after-free accesses will result in exploitable conditions, and in hope that future accesses lead to an easy-to-debug crash, turning these security issues into less-dangerous ones.    <pre class="prettyprint">class A { ... };<br>class B {<br>  B(A* a) : a_(a) {}<br>  void doSomething() { a_-&gt;doSomething(); }<br>  raw_ptr&lt;A&gt; a_;  // MiraclePtr<br>};<br><br>std::unique_ptr&lt;A&gt; a = std::make_unique&lt;A&gt;();<br>std::unique_ptr&lt;B&gt; b = std::make_unique&lt;B&gt;(a.get());<br>[…]<br>a = nullptr;  // The free is delayed because the MiraclePtr is still pointing to the object.<br>b-&gt;doSomething();  // Use-after-free is neutralized.</pre>  <p>We successfully <a href="https://chromium-review.googlesource.com/c/chromium/src/+/3305132">rewrote more than 15,000 raw pointers</a> in the Chrome codebase into raw_ptr&lt;T&gt;, then enabled BackupRefPtr for the browser process on Windows and Android (both 64 bit and 32 bit) in Chrome 102 Stable. We anticipate that MiraclePtr meaningfully reduces the browser process attack surface of Chrome by protecting ~50% of use-after-free issues against exploitation. We are now working on enabling BackupRefPtr in the network, utility and GPU processes, and for other platforms. In the end state, our goal is to enable BackupRefPtr on <em>all</em> platforms because that ensures that a given pointer is protected for <em>all</em> users of Chrome. </p><p><strong>Balancing Security and Performance</strong></p><p>There is no free lunch, however. This security protection comes at a cost, which we have carefully weighed in our decision making.  </p><p>Unsurprisingly, the main cost is memory. Luckily, related investments into PartitionAlloc over the past year led to 10-25% total memory savings, depending on usage patterns and platforms. So we were able to spend some of those savings on security: MiraclePtr increased the memory usage of the browser process 4.5-6.5% on Windows and 3.5-5% on Android<sup>1</sup>, still well below their previous levels. While we were worried about quarantined memory, in practice this is a tiny fraction (0.01%) of the browser process usage. By far the bigger culprit is the additional memory needed to store the reference count. One might think that adding 4 bytes to each allocation wouldn’t be a big deal. However, there are many small allocations in Chrome, so even the 4B overhead is not negligible. PartitionAlloc also uses pre-defined bucket sizes, so this extra 4B pushes certain allocations (particularly power-of-2 sized) into a larger bucket, e.g. 4096B-&gt;5120B. </p><p>We also considered the performance cost. Adding an atomic increment/decrement on common operations such as pointer assignment has unavoidable overhead. Having excluded a number of performance-critical pointers, we drove this overhead down until we could gain back the same margin through other performance optimizations. On Windows, no statistically significant performance regressions were observed on most of our top-level performance metrics like Largest Contentful Paint, First Input Delay, etc. The only adverse change there<sup>1</sup> is an increase of the main thread contention (~7%). On Android<sup>1</sup>, in addition to a similar increase in the main thread contention (~6%), there were small regressions in First Input Delay (~1%), Input Delay (~3%) and First Contentful Paint (~0.5%). We don't anticipate these regressions to have a noticeable impact on user experience, and are confident that they are strongly outweighed by the additional safety for our users.  </p><p>We should emphasize that MiraclePtr currently protects only class/struct pointer fields, to minimize the overhead. As future work, we are exploring options to expand the pointer coverage to on-stack pointers so that we can protect against more use-after-free bugs. </p><p>Note that the primary goal of MiraclePtr is to prevent exploitation of use-after-free bugs. Although it wasn’t designed for diagnosability, it already helped us find and fix a number of bugs that were previously undetected. We have ongoing efforts to make MiraclePtr crash reports even more informative and actionable. </p><p><strong>Continue to Provide Us Feedback</strong></p><p>Last but not least, we’d like to encourage security researchers to continue to report issues through the <a href="https://g.co/ChromeBugRewards">Chrome Vulnerability Reward Program</a>, even if those issues are mitigated by MiraclePtr. We still need to make MiraclePtr available to all users, collect more data on its impact through reported issues, and further refine our processes and tooling. Until that is done, we will not consider MiraclePtr when determining the severity of a bug or the reward amount. </p><p><sup>1</sup> Measured in Chrome 99. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Use-after-freedom: MiraclePtr]]></title>
<description><![CDATA[Posted by Adrian Taylor, Bartek Nowierski and Kentaro Hara on behalf of the MiraclePtr team Memory safety bugs are the most numerous category of Chrome security issues and we’re continuing to investigate many solutions – both in C++ and in new programming languages. The most common type of memory...]]></description>
<link>https://tsecurity.de/de/1629763/it-security-nachrichten/use-after-freedom-miracleptr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1629763/it-security-nachrichten/use-after-freedom-miracleptr/</guid>
<pubDate>Tue, 13 Sep 2022 21:16:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="byline-author"> Posted by Adrian Taylor, Bartek Nowierski and Kentaro Hara on behalf of the MiraclePtr team</span> <p>Memory safety bugs are the most numerous category of Chrome security issues and we’re continuing to <a href="https://security.googleblog.com/2021/09/an-update-on-memory-safety-in-chrome.html">investigate many solutions</a> – both in C++ and in new programming languages. The most common type of memory safety bug is the “use-after-free”. We <a href="https://security.googleblog.com/2022/05/retrofitting-temporal-memory-safety-on-c.html">recently posted about</a> an exciting series of technologies designed to prevent these. Those technologies (collectively, *Scan, pronounced “star scan”) are very powerful but likely require hardware support for sufficient performance. </p><p>Today we’re going to talk about a different approach to solving the same type of bugs. </p><p>It’s hard, if not impossible, to avoid use-after-frees in a non-trivial codebase. It’s rarely a mistake by a single programmer. Instead, one programmer makes reasonable assumptions about how a bit of code will work, then a later change invalidates those assumptions. Suddenly, the data isn’t valid as long as the original programmer expected, and an exploitable bug results. </p><p>These bugs have real consequences. For example, according to Google Threat Analysis Group, a <a href="https://crbug.com/1296150">use-after-free in the ChromeHTML engine</a> was <a href="https://blog.google/threat-analysis-group/countering-threats-north-korea/">exploited this year</a> by North Korea. </p><p>Half of the known exploitable bugs in Chrome are use-after-frees:  </p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjol0tDHrKfloO3-RsAhVwMGPRBFmg8FmM2nMbHfA4kPTHu4PVaoqFAkdKXkE63ePSIC4U4rH8pMSa8FfLYY-0CdahMPzcP_GqoILj0bBtquIwVuf-oLRpnZqe6cNBgTHv6LPnM_l1YrkqPHote0DMbIkYy7BZjDiZITG2u05T9YoxV6OqhnonD1TlY9g/s512/bug%20types.png"><img alt="" border="0" width="600" data-original-height="317" data-original-width="512" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjol0tDHrKfloO3-RsAhVwMGPRBFmg8FmM2nMbHfA4kPTHu4PVaoqFAkdKXkE63ePSIC4U4rH8pMSa8FfLYY-0CdahMPzcP_GqoILj0bBtquIwVuf-oLRpnZqe6cNBgTHv6LPnM_l1YrkqPHote0DMbIkYy7BZjDiZITG2u05T9YoxV6OqhnonD1TlY9g/s600/bug%20types.png"></a></div> <p><strong>Diving Deeper: Not All Use-After-Free Bugs Are Equal</strong>  </p><p>Chrome has a <a href="https://www.chromium.org/developers/design-documents/multi-process-architecture/">multi-process architecture</a>, partly to ensure that web content is isolated into a sandboxed “renderer” process where little harm can occur. An attacker therefore usually needs to find and exploit <em>two</em> vulnerabilities - one to achieve code execution in the renderer process, and another bug to break out of the sandbox. </p><p>The first stage is often the easier one. The attacker has lots of influence in the renderer process. It’s easy to arrange memory in a specific way, and the renderer process acts upon many different kinds of web content, giving a large “attack surface” that could potentially be exploited. </p><p>The second stage, escaping the renderer sandbox, is trickier. Attackers have two options how to do this: </p><ol><li>They can exploit a bug in the underlying operating system (OS) through the limited interfaces available inside Chrome’s sandbox.  </li><li>Or, they can exploit a bug in a more powerful, privileged part of Chrome - like the “browser” process. This process coordinates all the other bits of Chrome, so fundamentally <em>has</em> to be all-powerful. </li></ol><p>We imagine the attackers squeezing through the narrow part of a funnel:  </p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrD_PVCwSIrVn0tVWBs7b0PueDknbg8BrwznIfKHmYqgNFlGuVupFVZaPMSO9uoj4QawGujzyOS42-Nsemdl9AXD3gOaUFeqnBkhVd0Aem99UK5C9bt6trfnF_4UplnWFdXUrXfM-P4QvnZq81lrsz8o7M6QLZaKzSSLm7_ni10BPT2xaLSyhITCHE9A/s1600/Screenshot%202022-09-13%207.28.31%20AM.png"><img alt="" border="0" data-original-height="405" data-original-width="646" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrD_PVCwSIrVn0tVWBs7b0PueDknbg8BrwznIfKHmYqgNFlGuVupFVZaPMSO9uoj4QawGujzyOS42-Nsemdl9AXD3gOaUFeqnBkhVd0Aem99UK5C9bt6trfnF_4UplnWFdXUrXfM-P4QvnZq81lrsz8o7M6QLZaKzSSLm7_ni10BPT2xaLSyhITCHE9A/s1600/Screenshot%202022-09-13%207.28.31%20AM.png"></a></div> If we can reduce the size of the narrow part of the funnel, we will make it as hard as possible for attackers to assemble a full exploit chain. We can reduce the size of the orange slice by removing access to more OS interfaces within the renderer process sandbox, and we’re continuously working on that. The MiraclePtr project aims to reduce the size of the blue slice. <p>Here’s a sample of 100 recent high severity Chrome security bugs that made it to the stable channel, divided by root cause and by the process they affect. </p><p> </p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNa-V0mokSe10I_waRxQNuH_GNg6kqPyAszlWZ2EqMIgiySJcLWQ_FQQYSCl5dnF-u7acqGaqNE1bKXKJGG9b2GKKzIDMrKQWPhJWdp-0Te2HZYOecDVpLJXamMCzdO8ErcezDkFly1D19YlPrPHDHDf01O8GisMqoCOnfsAK8jWl9W8_JeUDJglHLNw/s512/bugs%20chart%202.png"><img alt="" border="0" width="600" data-original-height="317" data-original-width="512" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNa-V0mokSe10I_waRxQNuH_GNg6kqPyAszlWZ2EqMIgiySJcLWQ_FQQYSCl5dnF-u7acqGaqNE1bKXKJGG9b2GKKzIDMrKQWPhJWdp-0Te2HZYOecDVpLJXamMCzdO8ErcezDkFly1D19YlPrPHDHDf01O8GisMqoCOnfsAK8jWl9W8_JeUDJglHLNw/s600/bugs%20chart%202.png"></a></div><p>You might notice: </p><ul><li>This doesn’t quite add up to 100 - that’s because a few bugs were in other processes beyond the renderer or browser.  </li><li>We claimed that the browser process is the more difficult part to exploit, yet there are more potentially-exploitable bugs! That may be so, but we believe they are typically harder to exploit because the attacker has less control over memory layout. </li></ul><p>As you can see, the biggest category of bugs in each process is: V8 in the renderer process (JavaScript engine logic bugs - <a href="https://docs.google.com/document/d/1FM4fQmIhEqPG8uGp5o9A-mnPB5BOeScZYpkHjo0KKA8/edit">work in progress</a>) and use-after-free bugs in the browser process. If we can make that “thin” bit thinner still by removing some of those use-after-free bugs, we make the whole job of Chrome exploitation markedly harder. </p><p><strong>MiraclePtr: Preventing Exploitation of Use-After-Free Bugs</strong></p><p>This is where <a href="https://docs.google.com/document/d/1pnnOAIz_DMWDI4oIOFoMAqLnf_MZ2GsrJNb_dbQ3ZBg/edit">MiraclePtr</a> comes in. It is a technology to prevent exploitation of use-after-free bugs. Unlike aforementioned *Scan technologies that offer a non-invasive approach to this problem, MiraclePtr relies on rewriting the codebase to use a new smart pointer type, <a href="https://chromium.googlesource.com/chromium/src/+/main/base/memory/raw_ptr.md">raw_ptr&lt;T&gt;</a>. There are multiple ways to implement MiraclePtr. We came up with <a href="https://docs.google.com/document/d/1qsPh8Bcrma7S-5fobbCkBkXWaAijXOnorEqvIIGKzc0/edit">~10 algorithms</a> and compared the pros and cons. After analyzing their performance overhead, memory overhead, security protection guarantees, developer ergonomics, etc., we concluded that BackupRefPtr was the most promising solution. </p><p></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqjNDqH-vs-iOJi4MZ8xgPNPFQin31tNdn0Ixh2w9wEKgTWB0KDsRBFg47IRrLsZ1BMSFAY0a1rmCUf5ETwzhUicglI4S9Lq6ue9h0UiK9vXX5WF6ZPVdEFSvDMGQOsLJ6MI0ZlyRbMCkd58hLxNBOy5FobolQUuyj7o6gYA2lZFDLt9QO_VLTpLJ1cA/s512/raw1.png"><img alt="" border="0" width="200" data-original-height="484" data-original-width="512" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqjNDqH-vs-iOJi4MZ8xgPNPFQin31tNdn0Ixh2w9wEKgTWB0KDsRBFg47IRrLsZ1BMSFAY0a1rmCUf5ETwzhUicglI4S9Lq6ue9h0UiK9vXX5WF6ZPVdEFSvDMGQOsLJ6MI0ZlyRbMCkd58hLxNBOy5FobolQUuyj7o6gYA2lZFDLt9QO_VLTpLJ1cA/s200/raw1.png"></a></div>      The BackupRefPtr algorithm is based on reference counting. It uses support of Chrome's own heap allocator, <a href="https://chromium.googlesource.com/chromium/src/+/main/base/allocator/partition_allocator/PartitionAlloc.md">PartitionAlloc</a>, which carves out a little extra space for a hidden reference count for each allocation. raw_ptr&lt;T&gt; increments or decrements the reference count when it’s constructed, destroyed or modified. When the application calls free/delete and the reference count is greater than 0, PartitionAlloc quarantines that memory region instead of immediately releasing it. The memory region is then only made available for reuse once the reference count reaches 0. Quarantined memory is poisoned to further reduce the likelihood that use-after-free accesses will result in exploitable conditions, and in hope that future accesses lead to an easy-to-debug crash, turning these security issues into less-dangerous ones.    <pre class="prettyprint">class A { ... };<br>class B {<br>  B(A* a) : a_(a) {}<br>  void doSomething() { a_-&gt;doSomething(); }<br>  raw_ptr&lt;A&gt; a_;  // MiraclePtr<br>};<br><br>std::unique_ptr&lt;A&gt; a = std::make_unique&lt;A&gt;();<br>std::unique_ptr&lt;B&gt; b = std::make_unique&lt;B&gt;(a.get());<br>[…]<br>a = nullptr;  // The free is delayed because the MiraclePtr is still pointing to the object.<br>b-&gt;doSomething();  // Use-after-free is neutralized.</pre>  <p>We successfully <a href="https://chromium-review.googlesource.com/c/chromium/src/+/3305132">rewrote more than 15,000 raw pointers</a> in the Chrome codebase into raw_ptr&lt;T&gt;, then enabled BackupRefPtr for the browser process on Windows and Android (both 64 bit and 32 bit) in Chrome 102 Stable. We anticipate that MiraclePtr meaningfully reduces the browser process attack surface of Chrome by protecting ~50% of use-after-free issues against exploitation. We are now working on enabling BackupRefPtr in the network, utility and GPU processes, and for other platforms. In the end state, our goal is to enable BackupRefPtr on <em>all</em> platforms because that ensures that a given pointer is protected for <em>all</em> users of Chrome. </p><p><strong>Balancing Security and Performance</strong></p><p>There is no free lunch, however. This security protection comes at a cost, which we have carefully weighed in our decision making.  </p><p>Unsurprisingly, the main cost is memory. Luckily, related investments into PartitionAlloc over the past year led to 10-25% total memory savings, depending on usage patterns and platforms. So we were able to spend some of those savings on security: MiraclePtr increased the memory usage of the browser process 4.5-6.5% on Windows and 3.5-5% on Android<sup>1</sup>, still well below their previous levels. While we were worried about quarantined memory, in practice this is a tiny fraction (0.01%) of the browser process usage. By far the bigger culprit is the additional memory needed to store the reference count. One might think that adding 4 bytes to each allocation wouldn’t be a big deal. However, there are many small allocations in Chrome, so even the 4B overhead is not negligible. PartitionAlloc also uses pre-defined bucket sizes, so this extra 4B pushes certain allocations (particularly power-of-2 sized) into a larger bucket, e.g. 4096B-&gt;5120B. </p><p>We also considered the performance cost. Adding an atomic increment/decrement on common operations such as pointer assignment has unavoidable overhead. Having excluded a number of performance-critical pointers, we drove this overhead down until we could gain back the same margin through other performance optimizations. On Windows, no statistically significant performance regressions were observed on most of our top-level performance metrics like Largest Contentful Paint, First Input Delay, etc. The only adverse change there<sup>1</sup> is an increase of the main thread contention (~7%). On Android<sup>1</sup>, in addition to a similar increase in the main thread contention (~6%), there were small regressions in First Input Delay (~1%), Input Delay (~3%) and First Contentful Paint (~0.5%). We don't anticipate these regressions to have a noticeable impact on user experience, and are confident that they are strongly outweighed by the additional safety for our users.  </p><p>We should emphasize that MiraclePtr currently protects only class/struct pointer fields, to minimize the overhead. As future work, we are exploring options to expand the pointer coverage to on-stack pointers so that we can protect against more use-after-free bugs. </p><p>Note that the primary goal of MiraclePtr is to prevent exploitation of use-after-free bugs. Although it wasn’t designed for diagnosability, it already helped us find and fix a number of bugs that were previously undetected. We have ongoing efforts to make MiraclePtr crash reports even more informative and actionable. </p><p><strong>Continue to Provide Us Feedback</strong></p><p>Last but not least, we’d like to encourage security researchers to continue to report issues through the <a href="https://g.co/ChromeBugRewards">Chrome Vulnerability Reward Program</a>, even if those issues are mitigated by MiraclePtr. We still need to make MiraclePtr available to all users, collect more data on its impact through reported issues, and further refine our processes and tooling. Until that is done, we will not consider MiraclePtr when determining the severity of a bug or the reward amount. </p><p><sup>1</sup> Measured in Chrome 99. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-36046]]></title>
<description><![CDATA[Next.js is a React framework that can provide building blocks to create web applications. All of the following must be true to be affected by this CVE: Next.js version 12.2.3, Node.js version above v15.0.0 being used with strict `unhandledRejection` exiting AND using next start or a [custom serve...]]></description>
<link>https://tsecurity.de/de/1617545/sicherheitsluecken/cve-2022-36046/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1617545/sicherheitsluecken/cve-2022-36046/</guid>
<pubDate>Wed, 31 Aug 2022 23:04:16 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Next.js is a React framework that can provide building blocks to create web applications. All of the following must be true to be affected by this CVE: Next.js version 12.2.3, Node.js version above v15.0.0 being used with strict `unhandledRejection` exiting AND using next start or a [custom server](https://nextjs.org/docs/advanced-features/custom-server). Deployments on Vercel ([vercel.com](https://vercel.com/)) are not affected along with similar environments where `next-server` isn't being shared across requests.]]></content:encoded>
</item>
<item>
<title><![CDATA[Authentication with an NFC Reader, just PAM and rust magic for all the Cyborgs out there. :3]]></title>
<description><![CDATA[Linux Authentication with a NFC tag What is this post about? Hey Linux people. :3 You are interested on Linux, like to see a smarter/securer authentication, you are a cyborg? \ Then this post is exactly the right one for you, go ahead! :) \ This post will show an example how PAM (Pluggable Authen...]]></description>
<link>https://tsecurity.de/de/1539078/linux-tipps/authentication-with-an-nfc-reader-just-pam-and-rust-magic-for-all-the-cyborgs-out-there-3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1539078/linux-tipps/authentication-with-an-nfc-reader-just-pam-and-rust-magic-for-all-the-cyborgs-out-there-3/</guid>
<pubDate>Sun, 12 Jun 2022 18:30:37 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><h1>Linux Authentication with a NFC tag</h1> <h2>What is this post about?</h2> <p>Hey Linux people. :3</p> <p>You are interested on <code>Linux</code>, like to see a <code>smarter/securer authentication</code>, you are a <code>cyborg</code>? \ Then this post is exactly the right one for you, go ahead! :) \ This post will show an example how <code>PAM</code> (Pluggable Authentication Modules) can be used, a self written small tool to handle authentication with a NFC reader and some need to know things about NFC. :3</p> <h2>About me / what is a NFC tag</h2> <p>Foremost, I wanna explain who I am and what "my problem" was. \ I'm a <code>Cyborg</code> since ~10 years, in my hand there is an <code>NFC implant</code>. \ An NFC implant is just a small microchip with the size of a rice corn. \ The special thing about that chip is, it has a <code>unique ID</code>, which I will use later on. :3 \ The idea behind that chip is it to authenticate me as a person. \ For example, <code>opening the door</code> in my apartment. \ Do you know companies with that secure and fancy round key opener? \ That small plastic chip which holds against a terminal and opens the door? \ That's exactly a NFC tag, a NFC tag can be a key ring, a card, or in my case an implanted chip.</p> <h2>What have you done?!</h2> <p>Like I said, I can <code>open my front door</code> just with my hand (the NFC chip in it), I was <code>annoyed to type in my password</code> every time I lock my screen or authenticate against sudo. \ So I thought about the idea "hey why couldn't I not just use my NFC implant to authenticate myself?"... \ After looking how Linux works with authentication, I saw it's quite easy? \ Just editing a small python script and editing the <code>PAM</code> file? \ And voilà, my first tool was done, but I wasn't really happy with my shitty python script. <sup><sup>"</sup></sup> \ After years of procrastination, I rewrote my python snippet into Rust. \ And that's what I wanna share with all of you. :3 \ What the tool can is you can authenticate yourself just with a <code>NFC tag</code>. \ Hold the tag against the reader, press enter after typing your sudo command or username and that's it! \ <code>No more annoying password typing</code>. \ And yes, for all people who are paranoid, you can use that as a <code>two-factor authentication</code>. \ So you would need to type in your password AND authenticate with the NFC tag. :3 \ <code>Fun fact</code>: I had enough room in my laptop to built-in a NFC reader, just behind/under the keyboard. On my main working machine, I have a NFC reader sticked under my desk (which feels more natural to hold the hand against it). </p> <h2>How does the tool work?</h2> <p>The small tool (I call it pam_nfc) is quire simple. In the <code>add process</code> the scanned UID is hashed with bcrypt and stored with the username in <code>/etc/shadow_nfc</code>, the syntax is very similar to the <code>/etc/shadow</code> approach. \ After adding a user, the <code>verify process</code> (which will be used every time you authenticate) will work as intended. \ Just hold the tag against a NFC reader and run <code>pam_nfc</code>, the tool is checking if the scanned UID is in the <code>/etc/shadow_nfc</code> with the given <code>user</code>, if the UID is in there, the tool will return a success, otherwise it will return failed. \ So this small tool just needs to be added to the <code>PAM</code> (Authentication system in Linux). The <code>PAM</code> is doing exactly that, it runs the script and checks the return status. :)</p> <h2>Where code?!</h2> <p>The entire code is open source and can be found under: <a href="https://gitlab.com/kerkmann/pam_nfc/">https://gitlab.com/kerkmann/pam_nfc/</a> \ You can <code>build-it</code> yourself or just install the built <code>binary</code>. :) Also, the installation process and how to set up PAM to work with that tool is (hopefully well) <code>documented in the repository</code>.</p> <h2>Thanks for reading it</h2> <p>If you have read till there, <code>thank you very much for your time</code>! :) \ I hope you like the idea behind that tool, and <code>I would like to hear about your opinions</code>. \ I would also like it if you have <code>some good ideas to improve the tool</code>, all contributors and people are welcome! &lt;3 \ <code>Would you use such a tool?</code> \ <code>Do you need help to set it up or have some questions?</code></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/NotakuDotMe"> /u/NotakuDotMe </a> <br><span><a href="https://www.reddit.com/r/linux/comments/vah79w/authentication_with_an_nfc_reader_just_pam_and/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/vah79w/authentication_with_an_nfc_reader_just_pam_and/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anomali Cyber Watch: Conti’s Talent Goes to Other Ransom Groups, China-Based Espionage Targets Russia, XorDdos Stealthy Linux Trojan is on the Rise, and More]]></title>
<description><![CDATA[The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: APT, Botnets, Conti Ransomware, Disinformation, Internet of things, Phishing, VMware, and Vulnerabilities. The IOCs related to these stories are attached to Anomali Cyber Watch and c...]]></description>
<link>https://tsecurity.de/de/1528976/it-security-nachrichten/anomali-cyber-watch-contis-talent-goes-to-other-ransom-groups-china-based-espionage-targets-russia-xorddos-stealthy-linux-trojan-is-on-the-rise-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1528976/it-security-nachrichten/anomali-cyber-watch-contis-talent-goes-to-other-ransom-groups-china-based-espionage-targets-russia-xorddos-stealthy-linux-trojan-is-on-the-rise-and-more/</guid>
<pubDate>Sat, 04 Jun 2022 07:05:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: <b>APT, Botnets, Conti Ransomware, Disinformation, Internet of things, Phishing, VMware,</b> and <b>Vulnerabilities</b>. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity.</p>

<p><img src="https://www.anomali.com/images/uploads/blog/acw-052422.png"><br><b>Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.</b></p>

<h2>Trending Cyber News and Threat Intelligence</h2>

<div class="trending-threat-article">
<h3><a href="https://unit42.paloaltonetworks.com/cve-2022-22954-vmware-vulnerabilities/" target="_blank">VMware Vulnerabilities Exploited in the Wild (CVE-2022-22954 and Others)</a></h3>

<p>(published: May 20, 2022)</p>

<p>In April 2022, VMware publicly revealed several vulnerabilities affecting its products, and by May 2022 Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive to mitigate two of the VMware vulnerabilities (CVE-2022-22954 and CVE-2022-22960). CVE-2022-22954 is a remote code execution (RCE) vulnerability using server-side template injection to target VMware Workspace ONE Access and Identity Manager. It can be easily exploited with a single HTTP request to a vulnerable device and was seen delivering various payloads including coinminers, Perl Shellbots, Scanning/Callbacks, and Webshells. CVE-2022-22954 is also being exploited to drop variants of the Mirai/Gafgyt, and in the case of the observed Enemybot variant, final payloads themselves embed CVE-2022-22954 exploits for further exploitation and propagation.<br><b>Analyst Comment:</b> Update impacted VMware products to the latest version or remove impacted versions from organizational networks. If a compromise is detected, immediately isolate affected systems, collect relevant logs and artifacts, and consider incident response services.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947138" target="_blank">[MITRE ATT&amp;CK] Exploit Public-Facing Application - T1190</a> | <a href="https://ui.threatstream.com/ttp/3904527" target="_blank">[MITRE ATT&amp;CK] Ingress Tool Transfer - T1105</a> | <a href="https://ui.threatstream.com/ttp/3906161" target="_blank">[MITRE ATT&amp;CK] Command and Scripting Interpreter - T1059</a> | <a href="https://ui.threatstream.com/ttp/947222" target="_blank">[MITRE ATT&amp;CK] Account Manipulation - T1098</a> | <a href="https://ui.threatstream.com/ttp/947235" target="_blank">[MITRE ATT&amp;CK] Obfuscated Files or Information - T1027</a> | <a href="https://ui.threatstream.com/ttp/947136" target="_blank">[MITRE ATT&amp;CK] Deobfuscate/Decode Files or Information - T1140</a> | <a href="https://ui.threatstream.com/ttp/2402525" target="_blank">[MITRE ATT&amp;CK] Resource Hijacking - T1496</a> | <a href="https://ui.threatstream.com/ttp/2402530" target="_blank">[MITRE ATT&amp;CK] Network Denial of Service - T1498</a><br><b>Tags:</b> VMware, Perl Shellbot, Stealth Shellbot, Godzilla Webshell, Gafgyt, Mirai, XMRig, Coinminer, CVE-2022-22958, CVE-2022-22959, CVE-2022-22960, CVE-2017-17215, CVE-2022-22961, CVE-2022-22954, CVE-2022-22955, CVE-2022-22956, CVE-2022-22957, CVE-2022-22973, CVE-2022-22972, Linux, Server-side template injection, RCE</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.advintel.io/post/discontinued-the-end-of-conti-s-brand-marks-new-chapter-for-cybercrime-landscape" target="_blank">DisCONTInued: The End of Conti’s Brand Marks New Chapter For Cybercrime Landscape</a></h3>

<p>(published: May 20, 2022)</p>

<p>Advanced Intel researchers report that Conti ransomware group (Wizard Spider) is in the long-planned process of discontinuing its brand and has turned off its infrastructure including their negotiations service site and the admin panel of the Conti official website. The attack on Costa Rica was intentionally causing publicity for Conti, giving them an excuse for the planned exit. Conti is morphing into a horizontal network of loosely connected groups acting either independently or inside other ransomware groups. Some groups move completely into data-stealing operations without using crypters (lockers): BlackBasta, BlackByte, and Karakurt. Some groups become Conti-loyal collective affiliates within other ransomware groups (AlphV/BlackCat, AvosLocker, HelloKitty/FiveHands, and HIVE). And some groups completely assume existing small-brand ransomware operations.<br><b>Analyst Comment:</b> The threat to organizations remains high because after a period of inactivity these actors are expected to resurface again with renewed tools and infrastructure. It is a common tactic for ransomware groups to rebrand after coming into a law enforcement spotlight. If Lapsus$ and many ex-Conti ransom groups indeed rely solely on information theft, protecting sensitive information becomes even more crucial.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/2402531" target="_blank">[MITRE ATT&amp;CK] Data Encrypted for Impact - T1486</a> | <a href="https://ui.threatstream.com/ttp/3904494" target="_blank">[MITRE ATT&amp;CK] Exfiltration Over C2 Channel - T1041</a><br><b>Tags:</b> Conti, Conti ransomware, Ryuk, HelloKitty, Hive, BlackCat, AvosLocker, BlackBasta, BlackByte, Karakurt, Wizard Spider, Ransomware, Data exfiltration, Government, USA, target-country:US, Costa Rica, target-country:CR, Russia, source-country:RU</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://6068438.fs1.hubspotusercontent-na1.net/hubfs/6068438/fronton-report.pdf" target="_blank">Fronton: A Botnet for Creation, Command, and Control of Coordinated Inauthentic Behavior</a></h3>

<p>(published: May 19, 2022)</p>

<p>Nisos researchers discovered that the Fronton botnet developed for the Russian government can run social media influencing campaigns. In 2020, when the project documents started leaking, it was thought that Fronton was focused on DDoS capabilities. New data shows Fronton and its web-based dashboard SANA give capabilities to managed bots to promote certain informational campaigns on social media. The system allows for creation of fake users with set time-based and social activity and then make coordinated reaction to a certain news: varied by activity type (comment, like, repost), comments could be positive or negative, and based on a chosen style/template. The leaked materials showed that the Fronton/SANA system was initially tried targeting Kazakhstan, but the scope of its current use is not known.<br><b>Analyst Comment:</b> Change the default credentials on your Internet of things (IoT) devices. Apply security updates once they become available.<br><b>Tags:</b> Fronton, SANA, Disinformation, Social media, Bots, DDoS, IoT, VPN, TOR, Proxy, 0Dt, Zeroday Technologies, Pavel Sitnikov, FlatL1ne, Russia, Source-country:RU, FSB, Kazakhstan, target-country:KZ</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.microsoft.com/security/blog/2022/05/19/rise-in-xorddos-a-deeper-look-at-the-stealthy-ddos-malware-targeting-linux-devices/" target="_blank">Rise in XorDdos: A Deeper Look at the Stealthy DDoS Malware Targeting Linux Devices</a></h3>

<p>(published: May 19, 2022)</p>

<p>Microsoft telemetry shows increasing targeting of Linux-based operating systems (OS), which are commonly deployed on cloud infrastructures and Internet of Things (IoT) devices. First discovered in 2014, the XorDdos Linux trojan has been observed to have increased its activity 254% in the last six months. XorDdos is known for its XOR-based encryption and for primary use for distributed denial-of-service (DDoS) attacks, but it steals sensitive data and can potentially serve as a gateway for other malware. XorDdos spreads via SSH brute force attacks and employs a number of stealthiness and anti-analysis methods: daemon process, process hiding, process name spoofing, and other.<br><b>Analyst Comment:</b> Follow best password practices to make brute force attacks less dangerous, targeted devices can show an uptick in failed sign-ins. Organizations should implement endpoint detection and response (EDR) that will protect their Linux OS. Special focus can be on the use of a malicious shell script for initial access and drop-and-execution of binaries from a world-writable location.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947231" target="_blank">[MITRE ATT&amp;CK] Valid Accounts - T1078</a> | <a href="https://ui.threatstream.com/ttp/3906161" target="_blank">[MITRE ATT&amp;CK] Command and Scripting Interpreter - T1059</a> | <a href="https://ui.threatstream.com/ttp/947127" target="_blank">[MITRE ATT&amp;CK] Scheduled Task - T1053</a> | <a href="https://ui.threatstream.com/ttp/3904527" target="_blank">[MITRE ATT&amp;CK] Ingress Tool Transfer - T1105</a> | <a href="https://ui.threatstream.com/ttp/947092" target="_blank">[MITRE ATT&amp;CK] Rootkit - T1014</a> | <a href="https://ui.threatstream.com/ttp/947235" target="_blank">[MITRE ATT&amp;CK] Obfuscated Files or Information - T1027</a> | <a href="https://ui.threatstream.com/ttp/947136" target="_blank">[MITRE ATT&amp;CK] Deobfuscate/Decode Files or Information - T1140</a> | <a href="https://ui.threatstream.com/ttp/3905776" target="_blank">[MITRE ATT&amp;CK] Hide Artifacts - T1564</a> | <a href="https://ui.threatstream.com/ttp/3905040" target="_blank">[MITRE ATT&amp;CK] Create or Modify System Process - T1543</a> | <a href="https://ui.threatstream.com/ttp/3905768" target="_blank">[MITRE ATT&amp;CK] Boot or Logon Autostart Execution - T1547</a> | <a href="https://ui.threatstream.com/ttp/947194" target="_blank">[MITRE ATT&amp;CK] Indicator Removal on Host - T1070</a> | <a href="https://ui.threatstream.com/ttp/3904494" target="_blank">[MITRE ATT&amp;CK] Exfiltration Over C2 Channel - T1041</a> | <a href="https://ui.threatstream.com/ttp/2402529" target="_blank">[MITRE ATT&amp;CK] Endpoint Denial of Service - T1499</a><br><b>Tags:</b> XorDdos, XMRig, Tsunami, IoT, Cloud, DDoS, SSH, Brute force, Detection evasion, Daemon process, Process name spoofing, Process hiding, Persistence, Linux</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://research.checkpoint.com/2022/twisted-panda-chinese-apt-espionage-operation-against-russians-state-owned-defense-institutes/" target="_blank">Twisted Panda: Chinese APT Espionage Operation Against Russian’s State-Owned Defense Institutes</a></h3>

<p>(published: May 19, 2022)</p>

<p>Checkpoint researchers discovered a novel malware named Spinner that was used in two China-sponsored, cyberespionage campaigns targeting state-owned defense institutes in Russia, and to a lesser extent, in Belarus. Observed phishing lures and decoy documents were themed around Russian government documents with topics such as government awards, Ukraine-related sanction lists, and even bioweapon allegations. The actors significantly improved their tactics between their first campaign (June 2021) and their second (March-April 2022). These improvements include splitting some functions between several components, adding complex compiler-level obfuscations to existing shellcode, and dynamic API resolving with name hashing.<br><b>Analyst Comment:</b> Defense-in-depth (fail-safe defense processes, layering of security mechanisms, redundancy) is the best way to ensure safety from advanced persistent threats (APTs), including a focus on both network and host-based security. Prevention and detection capabilities should also be in place. Furthermore, all employees should be educated on the risks of spearphishing and how to identify such attempts.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/3905074" target="_blank">[MITRE ATT&amp;CK] Phishing - T1566</a> | <a href="https://ui.threatstream.com/ttp/947235" target="_blank">[MITRE ATT&amp;CK] Obfuscated Files or Information - T1027</a> | <a href="https://ui.threatstream.com/ttp/947136" target="_blank">[MITRE ATT&amp;CK] Deobfuscate/Decode Files or Information - T1140</a> | <a href="https://ui.threatstream.com/ttp/947127" target="_blank">[MITRE ATT&amp;CK] Scheduled Task - T1053</a> | <a href="https://ui.threatstream.com/ttp/3906161" target="_blank">[MITRE ATT&amp;CK] Command and Scripting Interpreter - T1059</a> | <a href="https://ui.threatstream.com/ttp/3905764" target="_blank">[MITRE ATT&amp;CK] Hijack Execution Flow - T1574</a> | <a href="https://ui.threatstream.com/ttp/947125" target="_blank">[MITRE ATT&amp;CK] System Information Discovery - T1082</a> | <a href="https://ui.threatstream.com/ttp/947259" target="_blank">[MITRE ATT&amp;CK] Data Encoding - T1132</a> | <a href="https://ui.threatstream.com/ttp/947141" target="_blank">[MITRE ATT&amp;CK] Masquerading - T1036</a> | <a href="https://ui.threatstream.com/ttp/947142" target="_blank">[MITRE ATT&amp;CK] Process Injection - T1055</a> | <a href="https://ui.threatstream.com/ttp/3904527" target="_blank">[MITRE ATT&amp;CK] Ingress Tool Transfer - T1105</a> | <a href="https://ui.threatstream.com/ttp/947195" target="_blank">[MITRE ATT&amp;CK] File and Directory Discovery - T1083</a><br><b>Tags:</b> Twisted Panda, Spinner, Windows, Government, Military, Defense, Russia, target-country:RU, Belarus, target-country:BY, China, source-country:CN, APT, Cyberespionage, Spearphishing, Anti-analysis, Ukraine</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/interactive-phishing-using-chatbot-like-web-applications-to-harvest-information/" target="_blank">Interactive Phishing: Using Chatbot-Like Web Applications to Harvest Information</a></h3>

<p>(published: May 19, 2022)</p>

<p>Trustwave researchers discovered a mail-delivery themed phishing campaign that utilizes an automated chatbot. Once a user gets on the phishing typosquatted website impersonating DHL (shipping company), the automated dialog box engages with questions, guidance, alleged photo of the parcel, and explanations why the victim needs to provide credit card data to pay a small delivery fee.<br><b>Analyst Comment:</b> Users should verify the domain before entering sensitive information. Be especially suspicious regarding unwarranted emails, delivery notifications, and unexpected payment requests.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/3905074" target="_blank">[MITRE ATT&amp;CK] Phishing - T1566</a><br><b>Tags:</b> Phishing, DHL, Chatbot, Typosquatting</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://blog.malwarebytes.com/threat-intelligence/2022/05/custom-powershell-rat-targets-germans-seeking-information-about-the-ukraine-crisis/" target="_blank">Custom PowerShell RAT Targets Germans Seeking Information About The Ukraine Crisis</a></h3>

<p>(published: May 16, 2022)</p>

<p>Threat actors, possibly connected to Russia, re-registered collaboration-bw[.]de, an expired German domain themed around Baden-Württemberg (a German state) and impersonated the state’s government website. The visitors of the spoofed website are prompted to download a ZIP archive allegedly to inform on the Ukraine crisis. Opening the containing HTM (Microsoft’s HTML help) file results in displaying a decoy error message while a malicious PowerShell script runs in the background. It results in an additional script being downloaded from the same domain, and dropping two files: a CMD file to run a TXT file containing a remote access trojan (RAT) written in PowerShell. Persistence is achieved by creating a scheduled task and Windows Antimalware Scan Interface (AMSI) bypassing is done by using an AES-encrypted function.<br><b>Analyst Comment:</b> Organizations should teach their employees to detect spoofed government and other high-value websites. Pay attention to the domain name, certificate information, and possible typos and content miss-match.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947205" target="_blank">[MITRE ATT&amp;CK] User Execution - T1204</a> | <a href="https://ui.threatstream.com/ttp/3906161" target="_blank">[MITRE ATT&amp;CK] Command and Scripting Interpreter - T1059</a> | <a href="https://ui.threatstream.com/ttp/3297570" target="_blank">[MITRE ATT&amp;CK] File and Directory Permissions Modification - T1222</a> | <a href="https://ui.threatstream.com/ttp/947127" target="_blank">[MITRE ATT&amp;CK] Scheduled Task - T1053</a> | <a href="https://ui.threatstream.com/ttp/947235" target="_blank">[MITRE ATT&amp;CK] Obfuscated Files or Information - T1027</a> | <a href="https://ui.threatstream.com/ttp/947136" target="_blank">[MITRE ATT&amp;CK] Deobfuscate/Decode Files or Information - T1140</a> | <a href="https://ui.threatstream.com/ttp/947082" target="_blank">[MITRE ATT&amp;CK] System Owner/User Discovery - T1033</a><br><b>Tags:</b> Germany, target-country:GE, EU, Russia, Ukraine, ZIP, HTM, CMD, PowerShell, RAT, AMSI, AES</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.prodaft.com/m/reports/WizardSpider_TLPWHITE_v.1.4.pdf" target="_blank">Wizard Spider In-Depth Analysis</a></h3>

<p>(published: May 16, 2022)</p>

<p>Prodaft researchers were able to uncover multiple details regarding Russia-based actor group Wizard Spider, and its work with affiliates regarding the Conti ransomware. Researchers were able to analyze Conti intrusion servers and to profile Conti’s hash-cracking station operation, cold-call center they use to additionally scare victims into paying the ransom. The details regarding their tools, virtual private network (VPN), and beacon configurations were also analyzed. While being flexible on intrusion techniques, first steps of the infection chain often contain QBot infection followed by System BC proxy malware and a Cobalt Strike beacon. Observed customizable Cobalt strike beacons were generated for each team on a daily basis, mostly sharing the same data center for command-and-control (C2) communication: ReliableSite (USA).<br><b>Analyst Comment:</b> Defenders should block the observed indicators of compromise (available in ThreatStream and Match). Monitor for known Conti/Wizard Spider tools, especially when your employees do not have a legitimate reason to use those. Keep your systems patched and have resilient backup systems.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/3904527" target="_blank">[MITRE ATT&amp;CK] Ingress Tool Transfer - T1105</a> | <a href="https://ui.threatstream.com/ttp/2402531" target="_blank">[MITRE ATT&amp;CK] Data Encrypted for Impact - T1486</a> | <a href="https://ui.threatstream.com/ttp/947227" target="_blank">[MITRE ATT&amp;CK] Brute Force - T1110</a> | <a href="https://ui.threatstream.com/ttp/947098" target="_blank">[MITRE ATT&amp;CK] Email Collection - T1114</a> | <a href="https://ui.threatstream.com/ttp/3905074" target="_blank">[MITRE ATT&amp;CK] Phishing - T1566</a> | <a href="https://ui.threatstream.com/ttp/947138" target="_blank">[MITRE ATT&amp;CK] Exploit Public-Facing Application - T1190</a> | <a href="https://ui.threatstream.com/ttp/3906161" target="_blank">[MITRE ATT&amp;CK] Command and Scripting Interpreter - T1059</a> | <a href="https://ui.threatstream.com/ttp/3905359" target="_blank">[MITRE ATT&amp;CK] Proxy - T1090</a> | <a href="https://ui.threatstream.com/ttp/3905036" target="_blank">[MITRE ATT&amp;CK] Credentials from Password Stores - T1555</a> | <a href="https://ui.threatstream.com/ttp/3905348" target="_blank">[MITRE ATT&amp;CK] OS Credential Dumping - T1003</a><br><b>Tags:</b> Wizard Spider, Conti, Russia, source-country:RU, USA, target-country:US, VPN, QBot, SystemBC, Cobalt Strike, Cobalt Strike beacon, Cryptocurrency, Ransomware, Call-center, Hash cracking, VMware vCenter, Log4j2, ReliableSite, Wireguard VPN, Linux, Windows</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.justice.gov/usao-edny/press-release/file/1505981/download" target="_blank">UNITED STATES OF AMERICA - against - MOISES LUIS ZAGALA GONZALEZ, Also Known as “Nosophoros,” “Aesculapius” and “Nebuchadnezzar,” Defendant.</a></h3>

<p>(published: May 16, 2022)</p>

<p>The US Department of Justice issued an arrest warrant for a citizen of France and Venezuela who resides in Venezuela and is responsible for two ransomware operations. In or around 1997, Moises Luis Zagala Gonzalez (Zagala), joined a criminal underground group called “High Cracking University” and started coding malware. More recently, in 2019-2022, he was creating ransomware and renting it to other actors. First, Zagala rewrote the Jigsaw ransomware and marketed it as “Jigsaw v .2”. Then he started the Thanos ransomware-as-a-service project.<br><b>Analyst Comment:</b> Zagala’s conversations with confidential sources revealed heavy reliance on remote desktop protocol (RDP) access and that companies lacking backup pay ransom more readily. It highlights the necessity for defenders to have an unerasable backup and to limit and monitor remote access to their system.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/2402531" target="_blank">[MITRE ATT&amp;CK] Data Encrypted for Impact - T1486</a> | <a href="https://ui.threatstream.com/ttp/947135" target="_blank">[MITRE ATT&amp;CK] Data from Local System - T1005</a> | <a href="https://ui.threatstream.com/ttp/3905778" target="_blank">[MITRE ATT&amp;CK] Impair Defenses - T1562</a> | <a href="https://ui.threatstream.com/ttp/947162" target="_blank">[MITRE ATT&amp;CK] Remote Services - T1021</a><br><b>Tags:</b> Thanos, Ransomware, Jigsaw v .2, Aesculapius, Nosophoros, Nebuchadnezzar, Haron, Jigsaw, Thanos ransomware, Hakbit, Moises Luis Zagala Gonzalez, RaaS, USA, target-country:US, Venezuela, source-country:VE</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://home.treasury.gov/system/files/126/20220516_dprk_it_worker_advisory.pdf" target="_blank">Guidance on the Democratic People’s Republic of Korea Information Technology Workers</a></h3>

<p>(published: May 16, 2022)</p>

<p>The U.S. authorities are warning that North Korea is dispatching its IT workers to get remote jobs at companies across the world. Not only can hiring a North Korean have legal consequences, the privileged access obtained by these IT workers is sometimes used to facilitate cyber intrusions. These actors go a long way to obfuscate their real identity. They are often located in China or Russia, less frequently in Africa or Southeast Asia. They often change their name, pretend to be from South Korea, the US, or another country. They use VPN services, dedicated machines, fake portfolio websites, forged documents, proxy identities, and try to avoid video communication.<br><b>Analyst Comment:</b> Organizations should implement background checks, monitor for red flags, segment their networks and restrict access on the need-to-have basis. Warning signs include your remote employer changing multiple IPs geolocated in different countries over a short period of time, using port 3389 or other remote desktop sharing configuration, and frequent transfers to China-linked banks and digital payment systems. Monitor for requests to change address, phone number and email provided during original interview.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947231" target="_blank">[MITRE ATT&amp;CK] Valid Accounts - T1078</a><br><b>Tags:</b> North Korea, source-country:KP, DPRK, China, Russia, IT workers, Insider threat</p>
</div>

<h2>Observed Threats</h2>

<p>Additional information regarding the threats discussed in this week's Anomali Cyber Watch can be found below:</p>

<div>
<p><a href="https://ui.threatstream.com/actor/27829" target="_blank">Wizard Spider</a><br>
Wizard Spider is a financially-motivated APT group operating out of Russia that has been active since 2016. Their primary activities involve the development and administration of Trickbot, Conti, Diavol, and Ryuk malware families. Wizard Spider targets large organizations for a high-ransom return. This is a technique known as big game hunting (or BGH). Their main tool, Trickbot, is a banking trojan that harvests financial credentials and Personal Identifiable Information (PII). While phishing is the main method of malware propagation, other methods such as exposed RDP services are seeing an increase in use. Known associated groups are: Grim Spider - A group that has been operating Ryuk ransomware since August 2018; reported to be a cell of Wizard Spider, and Lunar Spider - This threat group is the Eastern European-based operator and developer of the commodity banking malware called BokBot (aka IcedID). Main activities involve data theft and wire fraud.</p>
<!--

<p--><a href="https://ui.threatstream.com/tip/3271732" target="_blank">Apache Log4j 2 Vulnerability Affects Numerous Companies, Millions of Users</a><br>
A critical vulnerability, registered as CVE-2021-44228 (Log4Shell), has been identified in Apache Log4j 2, which is an open source Java package used to enable logging in. The vulnerability was discovered by Chen Zhaojun of Alibaba in late November 2021, reported to Apache, and subsequently released to the public on December 9, 2021.
<p> </p>

<p><a href="https://ui.threatstream.com/vulnerability/1992809" target="_blank">CVE-2022-22954</a><br>
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Clang Checkers and CodeQL Queries for Detecting Untrusted Pointer Derefs and Tainted Loop Conditions]]></title>
<description><![CDATA[In the first blog of the series, we saw how CodeQL and Clang checkers can be used to find bugs in MySQL Cluster involving untrusted size arguments leading to buffer overflow or out-of-bound array accesses. Though the majority of bugs were out-of-bounds array accesses, there were also bugs involvi...]]></description>
<link>https://tsecurity.de/de/1527752/hacking/clang-checkers-and-codeql-queries-for-detecting-untrusted-pointer-derefs-and-tainted-loop-conditions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1527752/hacking/clang-checkers-and-codeql-queries-for-detecting-untrusted-pointer-derefs-and-tainted-loop-conditions/</guid>
<pubDate>Fri, 03 Jun 2022 18:22:36 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">In the <a href="https://www.zerodayinitiative.com/blog/2022/2/10/mindshare-when-mysql-cluster-encounters-taint-analysis">first blog</a> of the series, we saw how CodeQL and Clang checkers can be used to find bugs in MySQL Cluster involving untrusted size arguments leading to buffer overflow or out-of-bound array accesses. Though the majority of bugs were out-of-bounds array accesses, there were also bugs involving untrusted data being used in loop conditions or casted to pointers. In this final blog of the series, we experiment with CodeQL’s IR and Clang checkers for detecting such bug classes.</p><p class=""><strong>Defining taint sources - CSA vs CodeQL</strong></p>


<p>The first part of the problem is defining the taint sources. <a href="https://clang-analyzer.llvm.org/">Clang Static Analyzer (CSA)</a> provides an experimental checker alpha.security.taint.TaintPropagation for performing static taint analysis. Implemented as <a href="https://github.com/llvm/llvm-project/blob/main/clang/lib/StaticAnalyzer/Checkers/GenericTaintChecker.cpp">GenericTaintChecker</a>, it has a set of built-in taint sources. Since the Signal data used by message handlers does not come directly from these built-in taint sources, it is necessary to find an alternative approach to define taint sources. Lucas Leong had a quick approach to work around the problem - rewrite all access to <code>signal-&gt;theData</code> with <code>getenv()</code>. Since the return value of <code>getenv()</code> is considered tainted by <code>GenericTaintChecker</code>, taint propagation works after rewrite. Refer to his blog post <a href="https://www.zerodayinitiative.com/blog/2022/2/10/mindshare-when-mysql-cluster-encounters-taint-analysis">“MindShaRE: When MySQL Cluster Encounters Taint Analysis”</a> for details on using existing taint checkers and CodeQL to find memory corruption bugs.</p>
<p>One has to be careful with this approach to avoid missing potential taint sources. Though MySQL Cluster has defined APIs like Signal::getDataPtr() to fetch the Signal data pointer, various handlers don’t follow  the standard. Instead, <code>signal-&gt;theData</code> is accessed in numerous other ways from offset 0 or from various other offsets. I rewrote some common patterns using find and sed. This may not be exhaustive but provides sufficient taint sources to experiment with the checkers.</p>

<p>The situation is much different when working with CodeQL, where defining taint sources is far more flexible. All we have to do is override the <code>isSource()</code> predicate to something like this:</p>

<p class=""><strong>CWE-822: Untrusted Pointer Dereference</strong></p><p class="">In an <a href="https://cwe.mitre.org/data/definitions/822.html">untrusted pointer deference</a> vulnerability, data from an untrusted source is casted to a pointer for further use. The impact of the bug depends on the usage of the casted pointer. This section provides details about detecting such pointer load operation using CSA and CodeQL.</p><p class=""><strong><em>Detecting untrusted pointer dereference using CSA</em></strong></p>


<p>To detect this vulnerability using CSA, I relied on path-sensitive checker callback <code>check::Location</code> which fires every time a program accesses memory for read or write. The information below is from the <a href="https://github.com/llvm/llvm-project/blob/main/clang/lib/StaticAnalyzer/Checkers/CheckerDocumentation.cpp">checker documentation</a>:</p>

<p>The <a href="https://clang.llvm.org/doxygen/classclang_1_1ento_1_1SVal.html">SVal symbolic value</a> <code>Loc</code> points to the memory region being accessed. <code>IsLoad</code> indicates whether the access is a read or a write. To check if a memory load is happening from a tainted memory region, we can check if <code>Loc</code> is tainted. If so, we can use the statement <code>S</code> to get the type of the expression:</p>

<p>Whenever the expression type is a pointer, it is logged as a bug. Scanning MySQL Cluster with this checker gave about 86 results, which is significantly high and also has false positives. Here is what the scan results look like:</p>

















  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            "><img class="thumb-image" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f0430f33-eed8-444b-9ca7-5f5cd0c4ed29/Fig1.png" data-image-dimensions="2106x2008" data-image-focal-point="0.5,0.5" alt="" data-load="false" data-image-id="621553997afba602bab6dd9e" data-type="image" src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f0430f33-eed8-444b-9ca7-5f5cd0c4ed29/Fig1.png?format=1000w"></figure><p>The large number of results is due to the fact that any pointer derived from a tainted value (via pointer arithmetic, array indexing, etc.) is also considered tainted, irrespective of whether the tainted value is constrained by validation. In some cases, OOB reads which load pointers are also reported. Understanding the nature of false-positive results significantly improves the triage experience.</p>
<p>Considering the high number of results, we can sort the results by “File” which is likely to organize the result by feature, or for a less familiar code base, sorting by “Path Length” can help identify code paths reachable with minimum complexity.</p>

















  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            "><img class="thumb-image" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/66fbd0d4-a3cb-46cb-8342-6c292f25f298/Fig2.png" data-image-dimensions="2130x1066" data-image-focal-point="0.5,0.5" alt="" data-load="false" data-image-id="621553bdbe56a9444a8fb3af" data-type="image" src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/66fbd0d4-a3cb-46cb-8342-6c292f25f298/Fig2.png?format=1000w"></figure><p class=""><em>scan-view results sorted by File</em></p>


















  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            "><img class="thumb-image" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/34afb056-d2f5-4699-a801-9efec4816474/Fig3.png" data-image-dimensions="2134x1350" data-image-focal-point="0.5,0.5" alt="" data-load="false" data-image-id="621553f35e4cd47ea828c7c7" data-type="image" src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/34afb056-d2f5-4699-a801-9efec4816474/Fig3.png?format=1000w"></figure><p class=""><em>scan-view results sorted by Path Length</em></p><p class="">CSA reported a number of bugs in the code handling <a href="https://dev.mysql.com/doc/ndb-internals/en/ndb-internals-kernel-blocks-dbdih.html">DBDIH block</a> with a path length of 1. Here is an example bug report:</p>


















  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            "><img class="thumb-image" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a67addad-3ed2-4e68-8421-9b886511c31e/Fig4.png" data-image-dimensions="1200x592" data-image-focal-point="0.5,0.5" alt="" data-load="false" data-image-id="621554370812d3738212c5e2" data-type="image" src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a67addad-3ed2-4e68-8421-9b886511c31e/Fig4.png?format=1000w"></figure><p>Using a known bug pattern, it is possible to apply filters to reduce the results in addition to the taint check. For example, we can check the AST statements for pointer loads which are only assignment statements like above. The checker can be tweaked as per the nature of bugs in the codebase.</p>
<b data-preserve-html-node="true"><i data-preserve-html-node="true">Analyzing memory loads using CodeQL IR</i></b>

<p>To perform a similar analysis in CodeQL, one can possibly rely on expression classes such as <code>PointerDereferenceExpr</code>, <code>VariableAccess</code>, <code>FieldAccess</code> and its subtypes. But in this case, I was curious to explore CodeQL’s <a href="https://codeql.github.com/codeql-standard-libraries/cpp/semmle/code/cpp/ir/implementation/raw/IR.qll/module.IR.html">Intermediate Representation (IR)</a> to track memory loads. Since the documentation around CodeQL’s IR is limited, I used the <code>Instruction</code> class to dump the IR for further analysis. Here is a partial dump of IR for the line <code>EmulatedJamBuffer * jambuf = (EmulatedJamBuffer*)req-&gt;jamBufferPtr</code> in function <code>execDIH_SCAN_TAB_REQ()</code>:</p>

<p>The CodeQL query used to dump the IR along with source code information:</p>

<p>Consider the below set of instructions in the IR:</p>

<p class="">Here the <a href="https://codeql.github.com/codeql-standard-libraries/cpp/semmle/code/cpp/ir/implementation/raw/Instruction.qll/type.Instruction%24LoadInstruction.html">LoadInstruction</a> relies on 2 operands - a source address operand (r17303_4) and a source value operand (m17300_12). The source value operand is a <a href="https://codeql.github.com/codeql-standard-libraries/cpp/semmle/code/cpp/ir/implementation/raw/Operand.qll/type.Operand%24MemoryOperand.html">MemoryOperand</a>. The MemoryOperand describes the memory address accessed by the instruction, whose value gets copied to the result register (r17303_5). Moreover, the result is also associated with type information. The idea was to filter all tainted memory load operations whose return type is a pointer. However, such a query resulted in an unusably large number of results.</p><p class=""><strong><em>Adding constraints using overlap relationship and virtual variables</em></strong></p><p class="">Consulting CodeQL’s <a href="https://github.com/github/codeql/blob/main/cpp/ql/lib/semmle/code/cpp/ir/implementation/SSA.md">IR SSA Construction</a> documentation, I found a couple of features that could be useful for refining the query: the overlap relationship and VirtualVariables.</p>


<p>Overlap defines the relationship between the definition of a memory location and its usage. The most interesting relationship for this analysis is <code>MustExactlyOverlap</code> - the set of bits written by the definition is identical to the set of bits read by the use, and the data type of both the definition and the use are the same. For more clarity on the overlap relationship, refer to the <a href="https://github.com/github/codeql/blob/da14647e5ae0d9e3dd14b3ee3affd2130936a178/cpp/ql/test/library-tests/ir/ssa/ssa.cpp">SSA test case</a> found in the repository. In the case of untrusted pointer load bugs, it is very likely that there will be a mismatch of data type between definition and usage (type casting) or that the number of bits read will be a subset of the definition. Therefore, we can skip Load operations where the source value operand has an exactly overlapping relationship with its definition. The <code>getOperandMemoryLocation()</code> predicate provides information regarding the <code>MemoryLocation</code> read by a memory operand. Consider the output of the following query:</p>

<p>The memory operands that are <a href="https://github.com/github/codeql/blob/3c59aa319ee79d8038eec863df7ab18372c7b30e/cpp/ql/lib/semmle/code/cpp/ir/implementation/aliased_ssa/Operand.qll#L150">marked with tilde “~”</a> are the ones that do not have an exactly overlapping relationship. This can also be checked using <a href="https://codeql.github.com/codeql-standard-libraries/cpp/semmle/code/cpp/ir/implementation/raw/Operand.qll/predicate.Operand%24Operand%24isDefinitionInexact.0.html">isDefinitionInexact()</a> predicate. Putting all this together, we can override the <code>isSink()</code> predicate to get a meaningful number of results to work with.</p>

<p>Many of the false-positive results were due to multiple load operations performed using some misidentified pointer. These results can be either skipped or removed by adding further constraints to the query, such as ignoring certain variable names in the sink or checking for AST patterns.</p>
<p>In the case of MySQL Cluster, one such constraint explored for filtering memory access to the <code>Signal</code> structure is <code>VirtualVariable</code>. As per the documentation, “Each MemoryLocation is associated with exactly one VirtualVariable. A VirtualVariable represents a set of MemoryLocations such that any two MemoryLocations that overlap have the same VirtualVariable.” VirtualVariable information can be fetched from a <code>MemoryLocation</code> using the <code>getVirtualVariable()</code> predicate.</p>

<p>When the variable names are consistent, we can add a constraint to consider only Load operations where the memory operand points to the <code>signal</code> variable. A more generic option is to fetch the type information of the virtual variable to check if it is a <code>Signal</code>structure. Such a query is still restrictive (not as much variable name) but significantly reduces false positives and returns results involving <code>jamBufferPtr</code>:</p>

<p class=""><strong>CWE-606: Unchecked Input for Loop Condition</strong></p><p class="">In CWE-606: <a href="https://cwe.mitre.org/data/definitions/606.html">Unchecked Input for Loop Condition</a>, values from an untrusted source are used for loop termination conditions. This may lead to a DoS or other issues depending on the operations done in the loop body. This section provides details about detecting such tainted loop conditions using CSA and CodeQL.</p><p class=""><strong><em>Detecting tainted loop condition using CSA</em></strong></p><p class="">Unlike tainted memory loads, I couldn’t find any path-sensitive callback to trigger on loop conditions. Moreover, AST-based matchers without path-sensitivity are not useful in this case. Therefore, I relied on the check::BranchCondition callback which fires every time a control flow branching occurs during analysis. The following information is from the checker documentation:</p>


<p class="">The idea here is, whenever the callback triggers due to a conditional statement, walk up the AST using <a href="https://clang.llvm.org/doxygen/classclang_1_1ParentMap.html">ParentMap</a> and check for a loop statement. Here is what an example AST looks like for while loop:</p>


<p>For loop operations we are only interested in 3 AST statement classes – WhileStmtClass, DoStmtClass and ForStmtClass. Below is the loop detection code used in the checker:</p>

<p class="">Once we know that the condition statement triggering the callback is part of a loop statement, we can check if it is tainted. Specifically, I wanted to look for some common code patterns involving <a href="https://en.wikipedia.org/wiki/Induction_variable">induction variables</a> compared against untrusted values, or untrusted values used as induction variables to decide on loop termination. Consider a couple of common code patterns below that involve explicit <a href="https://clang.llvm.org/doxygen/classclang_1_1BinaryOperator.html">binary comparison operations</a>:</p>


<p class="">•      The induction variable is compared against a potentially untrusted value. For example, RHS could be tainted and LHS is not.<br>•      The induction variable could be potentially untrusted. Here LHS value is compared against constant 0 on RHS.</p><p class=""> The checker specifically looks for these cases to make decisions on bugs. When RHS is constant 0, check if LHS is tainted. Otherwise, check if RHS is tainted:</p>


<p class="">Another common code pattern is <a href="https://clang.llvm.org/doxygen/classclang_1_1UnaryOperator.html#details">unary operations</a> in loop statements, especially while and do while loops:</p>


<p class="">No special breakdown is necessary in case of unary operations in the way we handled binary operations. However, in certain cases, <a href="https://en.cppreference.com/w/cpp/language/implicit_conversion">implicit Boolean conversions</a> result in implicit conditional statements received by the check::BranchCondition callback. Here is what the AST looks like:</p>


<p class="">To handle these, if any non-binary conditional operations have a Boolean outcome, it is possibly due to implicit casting and hence we get the sub-expression associated with the expression.</p>


<p class=""><strong><em>Evaluating constraints on tainted variables</em></strong></p><p class="">While it is possible to know if an input is tainted or not, there is no way to know if the tainted input value is constrained by some validation. Without this information, the checker is going to generate a lot of false-positive results. To solve this problem, I used the solution provided by Andrew Ruef in the blog post <a href="https://blog.trailofbits.com/2014/04/27/using-static-analysis-and-clang-to-find-heartbleed/">Trail of Bits - Using Static Analysis and Clang to Find Heartbleed</a>. Since Signal data is treated as an unsigned 32-bit integer in most cases, I queried if the variable can take a value greater than 0x10000. If yes, consider the variable as unconstrained and log the bug.</p><p class=""><strong><em>Configuring analyzer-max-loop in CSA</em></strong></p><p class="">Clang analyzer has a configuration parameter to choose the number of times a basic block in a loop gets executed. By default, this value is 4.</p>


<p>So how does it matter in our analysis? Consider the below code:</p>

<p>Here is <code>buffer-&gt;index</code> is validated and the loop operation is considered safe. But the checker still reports a false positive bug.</p>

<p>What seems to be happening here is, the symbolic expression gets evaluated analyzer-max-loop number of times i.e., for each visit to the basic block.</p>

<p>The analyzer seems to evaluate that the decrement operation can underflow resulting in a value greater than 0x10000, therefore reporting it as a bug. I’m not entirely sure of the right way to solve this issue, but a quick workaround is to set <code>analyzer-max-loop</code> to 1. This can also be done in <a href="http://manpages.ubuntu.com/manpages/trusty/man1/scan-build.1.html">scan-build</a> using the <code>maxloop</code> parameter. In this case, the expression is evaluated only once and it does not report the bug.</p>
<p>        <code>(reg_$3&lt;unsigned int Element{SymRegion{conj_$2{char *, LC2, S26616, #1}},0 S64b,struct index_buf}.index&gt;) &gt; 65536U</code></p>
<p>The scan reported around 46 bugs, with some valid ones including previously found issues like ZDI-CAN-14488, ZDI-CAN-15120, ZDI-CAN-15121.</p>

















  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            "><img class="thumb-image" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/0d36faf1-2988-4479-a0f7-ec792107b229/Fig5.png" data-image-dimensions="2142x1494" data-image-focal-point="0.5,0.5" alt="" data-load="false" data-image-id="621558af1077556c2c1d4b4d" data-type="image" src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/0d36faf1-2988-4479-a0f7-ec792107b229/Fig5.png?format=1000w"></figure><p>Here is the example bug report for vulnerability in <code>Dbdict::execLIST_TABLES_CONF()</code>:</p>

















  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            "><img class="thumb-image" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a3b90489-4e20-43ed-973e-c2412007e455/Fig6.png" data-image-dimensions="1300x1984" data-image-focal-point="0.5,0.5" alt="" data-load="false" data-image-id="621558d420d4727b3980a172" data-type="image" src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a3b90489-4e20-43ed-973e-c2412007e455/Fig6.png?format=1000w"></figure><b data-preserve-html-node="true"><i data-preserve-html-node="true">Detecting tainted loop condition using CodeQL</i></b>

<p>Using the analysis done earlier for CSA, an equivalent query in CodeQL can be implemented using the Loop class. The <code>isSink()</code> predicate essentially looks as follows:</p>

<p><b data-preserve-html-node="true">Building and Performing the Scan</b></p>
<p>In order to build clang with custom checkers, copy the source files to the <code>clang/lib/StaticAnalyzer/Checkers</code> directory in the LLVM toolchain. Then add the filenames to the CMakeLists:</p>

<p>Also update the <code>clang/include/clang/StaticAnalyzer/Checkers/Checkers.td</code> file to add the package information:</p>

<p>Once you <code>make clang</code>, the new checkers will be listed alongside other alpha checkers.</p>

<p>Now we can use scan-build to perform the analysis. Use the <code>maxloop</code> and <code>use-analyzer</code> configurations if necessary.</p>

<p>Building with checkers can be slow. To speed up the scan, limit the target path by either modifying the Makefile as necessary or use the custom <a href="https://gist.github.com/zdi-team/eecde9e971680d5599562c1615a0faf3#file-blog-mindshare-mysql-snippet-6-makefile">Makefile</a> by Lucas. All this analysis was performed on clang 12.0 and MySQL Cluster 8.0.25</p>
<p>Scanning with CodeQL requires creating a database, followed by running any queries we are interested in against the created database.</p>

<p class="">The source code for the Clang checkers and CodeQL queries can be found <a href="https://github.com/thezdi/PoC/tree/master/MySQL" target="_blank">here</a>.</p><p class=""><strong>Acknowledgments and References</strong></p><p class="">•      <a href="https://www.zerodayinitiative.com/blog/2022/2/10/mindshare-when-mysql-cluster-encounters-taint-analysis" target="_blank">MindShaRE: When MySQL Cluster Encounters Taint Analysis</a><br>•      <a href="https://github.com/haoNoQ/clang-analyzer-guide" target="_blank">Clang Static Analyzer - A Checker Developer's Guide</a><br>•      <a href="https://www.researchgate.net/publication/221430855_A_Memory_Model_for_Static_Analysis_of_C_Programs" target="_blank">A Memory Model for Static Analysis of C Programs</a><br>•      <a href="https://blog.trailofbits.com/2014/04/27/using-static-analysis-and-clang-to-find-heartbleed/" target="_blank">Using Static Analysis and Clang to Find Heartbleed</a><br>•      Source code of existing <a href="https://github.com/llvm/llvm-project/tree/main/clang/lib/StaticAnalyzer" target="_blank">clang checkers</a><br>•      <a href="https://msrc-blog.microsoft.com/2019/03/19/vulnerability-hunting-with-semmle-ql-part-2/" target="_blank">Vulnerability hunting with Semmle QL</a><br>•      <a href="https://github.com/github/codeql/blob/main/cpp/ql/lib/semmle/code/cpp/ir/implementation/SSA.md" target="_blank">CodeQL IR SSA Construction</a></p><p class=""><strong>Conclusion </strong></p><p class="">We hope you’ve enjoyed this look at finding bugs using Clang Static Analyzer, CodeQL, and Binary Ninja. As ZDI Vulnerability Analysts, these have proved helpful in finding new bugs. If you use these (or other) tools to find bugs of your own, consider submitting them to our program. Until then, you can find me on Twitter <a href="https://twitter.com/renorobertr" target="_blank">@RenoRobertr</a>, and follow the <a href="https://www.twitter.com/thezdi" target="_blank">team</a> for the latest in exploit techniques and security patches.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[After a long undesired break, I rewrote sysfetch (a tiny sys info fetch script). Looking for testers!]]></title>
<description><![CDATA[submitted by    /u/wick3dr0se  [link]   [comments]]]></description>
<link>https://tsecurity.de/de/1525441/linux-tipps/after-a-long-undesired-break-i-rewrote-sysfetch-a-tiny-sys-info-fetch-script-looking-for-testers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1525441/linux-tipps/after-a-long-undesired-break-i-rewrote-sysfetch-a-tiny-sys-info-fetch-script-looking-for-testers/</guid>
<pubDate>Sun, 22 May 2022 18:45:09 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/wick3dr0se"> /u/wick3dr0se </a> <br><span><a href="https://github.com/wick3dr0se/sysfetch">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/uvdkrb/after_a_long_undesired_break_i_rewrote_sysfetch_a/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rhythmbox 3.4.5 Released, Improves Support for Podcasts]]></title>
<description><![CDATA[A new version of open source music app Rhythmbox has been released. Rhythmbox 3.4.5 includes major improvements to its podcast downloading, playback, and management capabilities. For instance, devs rewrote the podcast downloader to offer better resume and retry; episode order is preserve if/when ...]]></description>
<link>https://tsecurity.de/de/1521196/linux-tipps/rhythmbox-345-released-improves-support-for-podcasts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1521196/linux-tipps/rhythmbox-345-released-improves-support-for-podcasts/</guid>
<pubDate>Mon, 02 May 2022 17:46:49 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="406" height="232" src="https://149366088.v2.pressablecdn.com/wp-content/uploads/2022/05/rhythmbox-icon-406x232.jpg" class="attachment-post-list size-post-list wp-post-image" alt="" srcset="https://149366088.v2.pressablecdn.com/wp-content/uploads/2022/05/rhythmbox-icon-406x232.jpg 406w , https://149366088.v2.pressablecdn.com/wp-content/uploads/2022/05/rhythmbox-icon-300x172.jpg 300w , https://149366088.v2.pressablecdn.com/wp-content/uploads/2022/05/rhythmbox-icon-840x480.jpg 840w , https://149366088.v2.pressablecdn.com/wp-content/uploads/2022/05/rhythmbox-icon-350x200.jpg 350w , https://149366088.v2.pressablecdn.com/wp-content/uploads/2022/05/rhythmbox-icon-768x440.jpg 768w , https://149366088.v2.pressablecdn.com/wp-content/uploads/2022/05/rhythmbox-icon-1536x880.jpg 1536w , https://149366088.v2.pressablecdn.com/wp-content/uploads/2022/05/rhythmbox-icon.jpg 1682w " sizes="(max-width: 406px) 100vw, 406px">A new version of open source music app Rhythmbox has been released. Rhythmbox 3.4.5 includes major improvements to its podcast downloading, playback, and management capabilities. For instance, devs rewrote the podcast downloader to offer better resume and retry; episode order is preserve if/when multiple podcasts episodes share the same publication date; and podcast episode GUIDs (globally unique identifier) are now used to handle episode URL changes. Adding a podcast feeds with no episode no longer throws an ‘unhelpful’ error message; cancelling a podcast download is more reliable; and various fixes ensure podcast album art and feed descriptions shows up as […]</p>
<p>This post, <a rel="nofollow" href="https://www.omgubuntu.co.uk/2022/05/rhythmbox-improves-podcast-plugin">Rhythmbox 3.4.5 Released, Improves Support for Podcasts</a> is from <a rel="nofollow" href="https://www.omgubuntu.co.uk/">OMG! Ubuntu!</a>. Do not reproduce elsewhere without permission.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/d0od?a=zE0lzNWAFdI:epUHq9GlrdA:wBxX2hOkimM"><img src="http://feeds.feedburner.com/~ff/d0od?i=zE0lzNWAFdI:epUHq9GlrdA:wBxX2hOkimM" border="0"></a> <a href="http://feeds.feedburner.com/~ff/d0od?a=zE0lzNWAFdI:epUHq9GlrdA:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/d0od?d=I9og5sOYxJI" border="0"></a> <a href="http://feeds.feedburner.com/~ff/d0od?a=zE0lzNWAFdI:epUHq9GlrdA:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/d0od?d=qj6IDK7rITs" border="0"></a> <a href="http://feeds.feedburner.com/~ff/d0od?a=zE0lzNWAFdI:epUHq9GlrdA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/d0od?i=zE0lzNWAFdI:epUHq9GlrdA:V_sGLiPBpWU" border="0"></a> <a href="http://feeds.feedburner.com/~ff/d0od?a=zE0lzNWAFdI:epUHq9GlrdA:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/d0od?i=zE0lzNWAFdI:epUHq9GlrdA:gIN9vFwOqvQ" border="0"></a> <a href="http://feeds.feedburner.com/~ff/d0od?a=zE0lzNWAFdI:epUHq9GlrdA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/d0od?d=yIl2AUoC8zA" border="0"></a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Play Time with Jetpack Compose]]></title>
<description><![CDATA[Learn about Google Play Store’s strategy for adopting Jetpack Compose, how they overcame specific performance challenges, and improved developer productivity and happiness.

Posted by Andrew Flynn & Jon Boekenoogen, Tech leads on Google Play





In 2020, Google Play Store engineering leadership ...]]></description>
<link>https://tsecurity.de/de/1519079/android-tipps/play-time-with-jetpack-compose/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1519079/android-tipps/play-time-with-jetpack-compose/</guid>
<pubDate>Sun, 24 Apr 2022 07:02:11 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://blogger.googleusercontent.com/img/a/AVvXsEi6y_NUo9gnpHYdRc7lwnbVnraBtUSIZTnIoAcHXkbq8Z0AFHBUHDI_s7HwwP2h2nTwo571RnRuXN-sUWdgJ7qkNb2MSslYiXWP3tteXooTdwAS_YzbZMTux25eLZk0kgdLtXmWTRLdolft-ZcsgGjCyJnH-CjzHsZXGy8vNVxB5oFZkBExOpBwvoDL"><h3><em>Learn about Google Play Store’s strategy for adopting Jetpack Compose, how they overcame specific performance challenges, and improved developer productivity and happiness.</em></h3>

<p><em>Posted by Andrew Flynn &amp; Jon Boekenoogen, Tech leads on Google Play</em></p><p>




</p><p>
In 2020, Google Play Store engineering leadership made the big decision to revamp its entire storefront tech stack. The existing code was 10+ years old and had incurred tremendous tech debt over countless Android platform releases and feature updates. We needed new frameworks that would scale to the <strong>hundreds of engineers</strong> working on the product while not negatively impacting <strong>developer productivity</strong>, <strong>user experience, or the performance</strong> of the store itself.
</p>
<p>
We laid out a multi-year roadmap to update everything in the store from the network layer all the way to the pixel rendering. As part of this we also wanted to adopt a modern, declarative UI framework that would satisfy our product goals around interactivity and user delight. After analyzing the landscape of options, we made the bold (at the time) decision to commit to <strong><a href="https://developer.android.com/jetpack/compose">Jetpack Compose</a></strong>, which was still in pre-Alpha.
</p>
<p>
Since that time, the Google Play Store and Jetpack Compose teams at Google have worked extremely closely together to release and polish a version of Jetpack Compose that meets our specific needs. In this article we'll cover our approach to migration as well as the challenges and benefits we found along the way, to share some insight into what adopting Compose can be like for an app with many contributors.
</p>


<center><div class="separator"><a href="https://blogger.googleusercontent.com/img/a/AVvXsEi6y_NUo9gnpHYdRc7lwnbVnraBtUSIZTnIoAcHXkbq8Z0AFHBUHDI_s7HwwP2h2nTwo571RnRuXN-sUWdgJ7qkNb2MSslYiXWP3tteXooTdwAS_YzbZMTux25eLZk0kgdLtXmWTRLdolft-ZcsgGjCyJnH-CjzHsZXGy8vNVxB5oFZkBExOpBwvoDL"><img alt="Play Store rewrote their UI with 50% less code with Compose" border="0" data-original-height="1080" data-original-width="1920" src="https://blogger.googleusercontent.com/img/a/AVvXsEi6y_NUo9gnpHYdRc7lwnbVnraBtUSIZTnIoAcHXkbq8Z0AFHBUHDI_s7HwwP2h2nTwo571RnRuXN-sUWdgJ7qkNb2MSslYiXWP3tteXooTdwAS_YzbZMTux25eLZk0kgdLtXmWTRLdolft-ZcsgGjCyJnH-CjzHsZXGy8vNVxB5oFZkBExOpBwvoDL"></a></div></center>

<br><h2>Considerations</h2>


<p>
When we were considering Jetpack Compose for our new UI rendering layer, our top two priorities were:
</p>
<ol><li><strong>Developer Productivity:</strong> Play Store team has hundreds of engineers contributing to this code, so it should be easy (and fun) to develop against.

</li><li><strong>Performance:</strong> Play Store renders lots of media-heavy content with many business metrics that are very sensitive to latency and jank, so we needed to make sure it performed well across <strong>all</strong> devices, especially low-memory hardware and Android (Go Edition) devices.
</li>
</ol><br><h3>Developer Productivity</h3>


<p>
We have been writing UI code using Jetpack Compose for <strong>over a year now</strong> and enjoy how Jetpack Compose makes UI development more simple.
</p>
<p>
We love that <strong>writing UI requires much less code, sometimes up to 50%</strong>. This is made possible by Compose being a declarative UI framework and harnessing Kotlin’s conciseness. Custom drawing and layouts are now simple function calls instead of View subclasses with N method overrides.
</p>
<p>
Using the Ratings Table as an example:
</p>


<div class="separator"><a href="https://blogger.googleusercontent.com/img/a/AVvXsEgcmmVZ5wincH-Pje9YIe0WHfb0ZBOWl4xNt5IbIPNteb7iFyvw9KtiXIjz6mQ3V9VKh9tm-K8lPQgNQmZNl8Po7WloN7Ks-mqYWp2Mr906Vm3Z13y9RBLhWdLqch6JCVmslK6ISSNEg_kqGYcmV-pclO_YtpnfHeAa6t7pM17uDgTQB3zgo1t0SzYV"><img alt="ratings table" border="0" data-original-height="189" data-original-width="618" src="https://blogger.googleusercontent.com/img/a/AVvXsEgcmmVZ5wincH-Pje9YIe0WHfb0ZBOWl4xNt5IbIPNteb7iFyvw9KtiXIjz6mQ3V9VKh9tm-K8lPQgNQmZNl8Po7WloN7Ks-mqYWp2Mr906Vm3Z13y9RBLhWdLqch6JCVmslK6ISSNEg_kqGYcmV-pclO_YtpnfHeAa6t7pM17uDgTQB3zgo1t0SzYV"></a></div>


<p>
With Views, this table consists of:
</p>
<ul><li>3 View classes total, with 2 requiring custom drawing for the rounded rects, and stars

</li><li>~350 lines of Java, 55 lines of XML
</li>
</ul><p>
With Compose, this table consists of:
</p>
<ul><li>All <code>@Composable</code> functions contained in the same file and language!

</li><li>~210 lines of Kotlin
</li>
</ul><p>
   </p><p><img alt="buffering GIF" height="220" src="https://blogger.googleusercontent.com/img/a/AVvXsEj9dVqrcKRGBY0Q4CfyQFq5vJRNIZPNV8PtGj3X3fd_qDx6eJS0JHR2iRRva4_uhIsFgzB3OkWL7YK5lQ3J5_wTPd1vfURkYC_3Y5TtQREgsXG7rQJ57NK1x7Di63lHGWofzA0pS0rZJfUPtFtZSiIsTBS7iabYRRL7LcKfigsyKQOseRd65VmzbCRm" width="220px"></p>

<strong>Animations</strong> are a <a href="https://www.youtube.com/watch?v=Z_T1bVjhMLk">hailed feature of Compose</a> for their simplicity and expressiveness. Our team is building motion features that delight our Play Store users more than ever with Compose. With Compose’s declarative nature and animations APIs, <strong>writing sequential or parallel animations has never been easier</strong>. Our team no longer fears all the corner cases of animations around cancellation and call back chaining. <a href="https://airbnb.io/projects/lottie-android/">Lottie</a>, a popular animation library, already provides Compose APIs that are simple to work with.

<p>
Now you might be thinking: this all sounds great, but what about library dependencies that provide Views? It's true, not all library owners have implemented Compose-based APIs, especially when we first migrated. However, Compose provides <strong>easy View interoperability</strong> with its <code>ComposeView</code> and <code>AndroidView</code> APIs. We successfully integrated with popular libraries like <a href="https://exoplayer.dev/">ExoPlayer</a> and <a href="https://developers.google.com/youtube/android/player">YouTube’s Player</a> in this fashion. 
</p>

<center><div class="separator"><a href="https://blogger.googleusercontent.com/img/a/AVvXsEjwtSLBwzAjtel5VQweS_uj3BvOk1Y2A7LeFV0dgpGJ8erCG8t0YKCloeUY9Y9NhcNRD0LGnWCfmBydncD1AYacw2uvL2-mwvO7z9ArRdhpDyPkg7Z7RmNw8T-0YfhzVqFobFKzCMaCpGvt0fN89GtC6xVhr3OGF1Q2s16NFrcwGnURK4mVgWg6S_0P"><img alt="Headshot of Andrew" border="0" data-original-height="1081" data-original-width="1921" src="https://blogger.googleusercontent.com/img/a/AVvXsEjwtSLBwzAjtel5VQweS_uj3BvOk1Y2A7LeFV0dgpGJ8erCG8t0YKCloeUY9Y9NhcNRD0LGnWCfmBydncD1AYacw2uvL2-mwvO7z9ArRdhpDyPkg7Z7RmNw8T-0YfhzVqFobFKzCMaCpGvt0fN89GtC6xVhr3OGF1Q2s16NFrcwGnURK4mVgWg6S_0P"></a></div></center>

<br><h3>Performance</h3>


<p>
The Play Store and Jetpack Compose teams worked closely together to make sure Compose could run as fast and be as jank-free as the View framework. Due to how Compose is bundled within the app (rather than being included as part of the Android framework), this was a tall order. Rendering individual UI components on the screen was fast, but end to end times of loading the entire Compose framework into memory for apps was expensive.
</p>

<p>
One of the largest Compose adoption performance improvements for the Play Store came from the development of <strong><a href="https://developer.android.com/studio/profile/baselineprofiles">Baseline Profiles</a></strong>. While <a href="https://android-developers.googleblog.com/2019/04/improving-app-performance-with-art.html">cloud profiles</a> help improve app startup time and have been available for some time now, they are only available for API 28+ and are not as effective for apps with frequent (weekly) release cadences. To combat this, the Play Store and Android teams worked together on Baseline Profiles: a developer-defined, bundled profile that app owners can specify. They ship with your app, are fully compatible with cloud profiles and can be defined both at the app-level of specificity and library-level (Compose adopters will get this for free!). By rolling out baseline profiles, Play Store saw a <strong>decrease in initial page rendering time</strong> on its search results page <strong>of 40%</strong>. That’s huge!
</p>
<p>
<strong>Re-using UI components</strong> is a <a href="https://developer.android.com/jetpack/compose/lifecycle">core mechanic</a> of what makes Compose performant for rendering, particularly in scrolling situations. Compose does its best to skip recomposition for composables that it knows can be skipped (e.g. they are immutable), but developers can also force composables to be treated as skippable if all parameters meet the <code><a href="https://developer.android.com/reference/kotlin/androidx/compose/runtime/Stable">@Stable</a></code> annotation requirements. The Compose compiler also provides a <a href="https://github.com/androidx/androidx/blob/androidx-main/compose/compiler/design/compiler-metrics.md">handy guide</a> on what is preventing specific functions from being skippable. While creating heavily re-used UI components in Play Store that were used frequently in scrolling situations, we found that unnecessary recompositions were adding up to missed frame times and thus jank. We built a <code><a href="https://github.com/android/snippets/blob/master/compose/recomposehighlighter/src/main/java/com/example/android/compose/recomposehighlighter/RecomposeHighlighter.kt">Modifier</a></code> to easily spot these recompositions in our debug settings as well. By applying these techniques to our UI components, <strong>we were able to reduce jank by 10-15%.</strong></p>



<center> <a href="https://blogger.googleusercontent.com/img/a/AVvXsEjrA4HErEi7ovyWGTl4iClAzJCT6JHEJkB7-x4bCCd9TFAr6C3BCS7fstZ2CX3Wcs3EBF9yLDDPPoIm_2DrIKKe5BgUpYjfGc-OxTif0KNa-nhspBgntOnNBqg9iHUF8IsP5bXLPOVw8ZarsGQ6xW3nZ35esbcdiIocKlQBWo1_eFv5VGGJGTzi6PXn" imageanchor="1"><img alt="Recomposition visualization Modifier in action" border="0" src="https://blogger.googleusercontent.com/img/a/AVvXsEjrA4HErEi7ovyWGTl4iClAzJCT6JHEJkB7-x4bCCd9TFAr6C3BCS7fstZ2CX3Wcs3EBF9yLDDPPoIm_2DrIKKe5BgUpYjfGc-OxTif0KNa-nhspBgntOnNBqg9iHUF8IsP5bXLPOVw8ZarsGQ6xW3nZ35esbcdiIocKlQBWo1_eFv5VGGJGTzi6PXn" data-original-width="1058" data-original-height="714"></a><p>Recomposition visualization Modifier in action. Blue (no recompositions), Green (1 recomposition).</p></center>

<p>
Another key component to optimizing Compose for the Play Store app was having a detailed, <strong>end-to-end migration strategy for the entire app</strong>. During initial integration experiments, we ran into the Two Stack Problem: running both Compose and View rendering within a single user session was very memory intensive, especially on lower-end devices. This cropped up both during rollouts of the code on the same page, but also when two different pages (for example, the Play Store home page and the search results page) were each on a different stack. In order to ameliorate this startup latency, it was important for us to have a concrete plan for the <strong>order and timeline of pages migrating to Compose</strong>. Additionally, we found it helpful to add short-term pre-warming of common classes as stop-gaps until the app is fully migrated over.
</p>
<p>
Compose unbundling from the Android framework has reduced the overhead in our team directly contributing to Jetpack Compose, resulting in fast turnaround times for improvements that benefit all developers. We were able to collaborate with the Jetpack Compose team and launch features like <a href="https://r.android.com/1789196">LazyList item type caching</a> as well as move quickly on lightweight fixes like <a href="https://r.android.com/1950996">extra object allocations</a>.
</p>

<center><div class="separator"><a href="https://blogger.googleusercontent.com/img/a/AVvXsEhSjbt-KVkwZrpwDu1KnM-CGfcTrhc4I-mdqONbOQ9V4Nmx6PzfoBIH_hN2qLeav9bedAYFaca3jRm40xD9yg_rLDANu5sCHypD-3vDplL8p001xqExCkAbyA7_dmm5DFZBJ9vCcmMAFCSaNDJcSdPx9x6-g2lsNExULF9JPNh6MJt1ye-29eD8XRO7"><img alt="Headshot of Jon" border="0" data-original-height="1081" data-original-width="1921" src="https://blogger.googleusercontent.com/img/a/AVvXsEhSjbt-KVkwZrpwDu1KnM-CGfcTrhc4I-mdqONbOQ9V4Nmx6PzfoBIH_hN2qLeav9bedAYFaca3jRm40xD9yg_rLDANu5sCHypD-3vDplL8p001xqExCkAbyA7_dmm5DFZBJ9vCcmMAFCSaNDJcSdPx9x6-g2lsNExULF9JPNh6MJt1ye-29eD8XRO7"></a></div></center>
<br><h2>Looking Ahead</h2>


<p>
The Play Store’s adoption of Compose has been a boon for our team’s developer happiness, and <strong>a big step-up for code quality and health</strong>. All new Play Store features are built on top of this framework, and Compose has been instrumental in unlocking <strong>better velocity and smoother landings for the app</strong>. Due to the nature of our Compose migration strategy, we haven’t been able to measure things like <a href="https://developer.android.com/jetpack/compose/ergonomics#apk-and-build">APK size</a> changes or build speed as closely, but all signs that we can see look very positive!
</p>
<p>
  <a href="https://developer.android.com/jetpack/compose">Compose</a> is the future of Android UI development, and from the Play Store’s point of view, we couldn’t be happier about that!
</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/blogspot/hsDu?a=Y_l7Je-JcCU:t4rI2LdNqWM:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/blogspot/hsDu?d=yIl2AUoC8zA" border="0"></a> <a href="http://feeds.feedburner.com/~ff/blogspot/hsDu?a=Y_l7Je-JcCU:t4rI2LdNqWM:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/blogspot/hsDu?i=Y_l7Je-JcCU:t4rI2LdNqWM:-BTjWOF_DHI" border="0"></a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[keym 1.0 - a small X11 tool to control the mouse smoothly with a keyboard in 127 lines of C]]></title>
<description><![CDATA[https://github.com/cwkx/keym This is a small tool I made for controlling the mouse smoothly one-handed with a keyboard in 127 lines of C, so you can drink your morning coffee more comfortably while scrolling through reddit. I've used it for 5 years, although up until today it only used to work wi...]]></description>
<link>https://tsecurity.de/de/1515621/linux-tipps/keym-10-a-small-x11-tool-to-control-the-mouse-smoothly-with-a-keyboard-in-127-lines-of-c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1515621/linux-tipps/keym-10-a-small-x11-tool-to-control-the-mouse-smoothly-with-a-keyboard-in-127-lines-of-c/</guid>
<pubDate>Fri, 30 Jul 2021 18:00:13 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><a href="https://github.com/cwkx/keym">https://github.com/cwkx/keym</a></p> <p>This is a small tool I made for controlling the mouse smoothly one-handed with a keyboard in 127 lines of C, so you can drink your morning coffee more comfortably while scrolling through reddit.</p> <p>I've used it for 5 years, although up until today it only used to work with awesomewm, so I rewrote it to only need X11 and Xtst. There's some similar code out there but I find this the most simple and usable. It's especially good for people with RSI or hand pain. It's easy to modify the hotkeys, e.g. if you want to change it from being left-handed to right-handed. Out-of-the-box it has 5 discrete speed settings, fast/smooth scrolling, and supports the 5 mouse buttons.</p> <p>Please let me know if you encounter any bugs or have any further usability suggestions.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/cwkx"> /u/cwkx </a> <br><span><a href="https://www.reddit.com/r/linux/comments/oumfbr/keym_10_a_small_x11_tool_to_control_the_mouse/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/oumfbr/keym_10_a_small_x11_tool_to_control_the_mouse/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-32702]]></title>
<description><![CDATA[The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before and including `1.4.1` are vulnerable to reflected XSS. An attacker can execute arbitrary code by providing an XSS payload in the `error` query parameter which is then processed by the ...]]></description>
<link>https://tsecurity.de/de/1510909/sicherheitsluecken/cve-2021-32702/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1510909/sicherheitsluecken/cve-2021-32702/</guid>
<pubDate>Sat, 26 Jun 2021 15:02:36 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before and including `1.4.1` are vulnerable to reflected XSS. An attacker can execute arbitrary code by providing an XSS payload in the `error` query parameter which is then processed by the callback handler as an error message. You are affected by this vulnerability if you are using `@auth0/nextjs-auth0` version `1.4.1` or lower **unless** you are using custom error handling that does not return the error message in an HTML response. Upgrade to version `1.4.1` to resolve. The fix adds basic HTML escaping to the error message and it should not impact your users.]]></content:encoded>
</item>
<item>
<title><![CDATA[I did a thing... why is it stupid?]]></title>
<description><![CDATA[I've been playing with Docker over the past two days, trying to get Firefox to run with GPU acceleration. The x11docker documentation prescribes three options, one of which was just starting with an nvidia/cudagl container. I did that and... Great Success! Here's the weird bit... I looked for a K...]]></description>
<link>https://tsecurity.de/de/1467704/linux-tipps/i-did-a-thing-why-is-it-stupid/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1467704/linux-tipps/i-did-a-thing-why-is-it-stupid/</guid>
<pubDate>Tue, 11 May 2021 06:45:12 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I've been playing with Docker over the past two days, trying to get Firefox to run with GPU acceleration.</p> <p>The x11docker documentation prescribes three options, one of which was just starting with an nvidia/cudagl container. I did that and... Great Success!</p> <p>Here's the weird bit...</p> <p>I looked for a Kali Container that was GPU accelerated but couldn't find one... so, I rewrote the /etc/apt/sources.list with Kali's Repos on the said container (originally Ubuntu 20.04), installed the package <code>kali-linux-core</code> &amp; ran a full system upgrade.</p> <p>I ended up with a nearly 1 GB container that looks, feels, &amp; functions like Kali - but started life as Ubuntu.</p> <p>Now I'm wondering why what I did was stupid &amp; why I shouldn't have done that... help me out with these questions, will ya?</p> <p>EDIT: Should have made it clearer, the Firefox container is completely separate. I didn't do anything radical there.</p> <p>Code for the curious.</p> <pre><code>┌──(root?35bafd737faa)-[~] └─# cat /etc/os-release PRETTY_NAME="Kali GNU/Linux Rolling" NAME="Kali GNU/Linux" ID=kali VERSION="2021.1" VERSION_ID="2021.1" VERSION_CODENAME="kali-rolling" ID_LIKE=debian ANSI_COLOR="1;31" HOME_URL="https://www.kali.org/" SUPPORT_URL="https://forums.kali.org/" BUG_REPORT_URL="https://bugs.kali.org/" ┌──(root?35bafd737faa)-[~] └─# cat /etc/lsb-release DISTRIB_ID=Ubuntu DISTRIB_RELEASE=20.04 DISTRIB_CODENAME=focal DISTRIB_DESCRIPTION="Ubuntu 20.04.2 LTS" ┌──(root?35bafd737faa)-[~] └─# nvidia-smi Tue May 11 09:49:15 2021 +-----------------------------------------------------------------------------+ | NVIDIA-SMI 460.73.01 Driver Version: 460.73.01 CUDA Version: 11.2 | |-------------------------------+----------------------+----------------------+ | GPU Name Persistence-M| Bus-Id Disp.A | Volatile Uncorr. ECC | | Fan Temp Perf Pwr:Usage/Cap| Memory-Usage | GPU-Util Compute M. | | | | MIG M. | |===============================+======================+======================| | 0 Quadro RTX 4000 Off | 00000000:09:00.0 On | N/A | | 30% 48C P8 12W / 125W | 314MiB / 7973MiB | 0% Default | | | | N/A | +-------------------------------+----------------------+----------------------+ +-----------------------------------------------------------------------------+ | Processes: | | GPU GI CI PID Type Process name GPU Memory | | ID ID Usage | |=============================================================================| +-----------------------------------------------------------------------------+ </code></pre> <p>​</p> <pre><code>FROM nvidia/cudagl:11.2.0-base-ubuntu20.04 ## Install Wget RUN apt update; \ env DEBIAN_FRONTEND=noninteractive apt install -y --no-install-recommends \ wget ## Clean apt cache &amp; replace sources.list RUN apt clean all; \ echo "deb [arch=amd64] http://kali.download/kali kali-last-snapshot main contrib non-free" &gt; /etc/apt/sources.list; \ wget -O - https://archive.kali.org/archive-key.asc | apt-key add - ## Disable Nvidia repos RUN sed -i '1s/^/# /' /etc/apt/sources.list.d/* ## Install Kali-Linux-Core RUN apt update; \ env DEBIAN_FRONTEND=noninteractive apt install -y --no-install-recommends \ kali-linux-core \ bash-builtins \ bash-completion ## Full System Update RUN apt update; \ env DEBIAN_FRONTEND=noninteractive apt full-upgrade -f -y --no-install-recommends ## Housekeeping RUN apt update; \ apt remove -y --purge wget; \ apt autoremove -y WORKDIR /root CMD ["/bin/bash"] </code></pre> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/garar71853"> /u/garar71853 </a> <br><span><a href="https://www.reddit.com/r/linux/comments/n9ooej/i_did_a_thing_why_is_it_stupid/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/n9ooej/i_did_a_thing_why_is_it_stupid/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Buer Malware Variant Rewritten in Rust Programming Language]]></title>
<description><![CDATA[Researchers suggest a few reasons why operators rewrote Buer in an entirely new language]]></description>
<link>https://tsecurity.de/de/1460221/it-security-nachrichten/buer-malware-variant-rewritten-in-rust-programming-language/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1460221/it-security-nachrichten/buer-malware-variant-rewritten-in-rust-programming-language/</guid>
<pubDate>Mon, 03 May 2021 22:00:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Researchers suggest a few reasons why operators rewrote Buer in an entirely new language]]></content:encoded>
</item>
<item>
<title><![CDATA[rkeep 0.2.0 - Clip passwords from keepass using rofi. Customizable keep-alive timeout and clipboard clear timer.]]></title>
<description><![CDATA[This is one of my first few rust projects I use on the daily. As the title says, it comes with customizable keep-alive timeout (how long your kdbx database should remain unlocked) and a clipboard clear timer, as well as multiple sessions- if you have multiple kdbx files. I recently rewrote the da...]]></description>
<link>https://tsecurity.de/de/1454461/linux-tipps/rkeep-020-clip-passwords-from-keepass-using-rofi-customizable-keep-alive-timeout-and-clipboard-clear-timer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1454461/linux-tipps/rkeep-020-clip-passwords-from-keepass-using-rofi-customizable-keep-alive-timeout-and-clipboard-clear-timer/</guid>
<pubDate>Wed, 28 Apr 2021 00:45:16 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>This is one of my first few rust projects I use on the daily. As the title says, it comes with customizable keep-alive timeout (how long your kdbx database should remain unlocked) and a clipboard clear timer, as well as multiple sessions- if you have multiple kdbx files.</p> <p>I recently rewrote the daemon (rkeepd), so it now uses the very awesome crate <a href="https://github.com/sseemayer/keepass-rs">keepass-rs</a> for keepass integration, but I wanted to wait for its next release before posting this as I had a merged PR there.</p> <p>The release binaries are built on the latest arch, so they may or may not work for you. Anyway I hope it's useful to someone!</p> <p><a href="https://github.com/leaty/rkeep">https://github.com/leaty/rkeep</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/leaty"> /u/leaty </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/n00a5y/rkeep_020_clip_passwords_from_keepass_using_rofi/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/n00a5y/rkeep_020_clip_passwords_from_keepass_using_rofi/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Macchina - System information fetcher, is back with ASCII art and a TUI.]]></title>
<description><![CDATA[Last time I posted about Macchina, a system information fetcher written in Rust, I got lots and lots of feedback, and the most upvoted comment was a request to include ASCII art in the program. Well we did just that, and a little bit more. We added a customizable TUI, a new local IP address entry...]]></description>
<link>https://tsecurity.de/de/1417465/linux-tipps/macchina-system-information-fetcher-is-back-with-ascii-art-and-a-tui/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1417465/linux-tipps/macchina-system-information-fetcher-is-back-with-ascii-art-and-a-tui/</guid>
<pubDate>Tue, 23 Mar 2021 09:30:15 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Last time I posted about Macchina, a system information fetcher written in Rust, I got lots and lots of feedback, and the most upvoted comment was a request to include ASCII art in the program.</p> <p>Well we did just that, and a little bit more.</p> <p>We added a customizable TUI, a new local IP address entry, a new theme, and rewrote the debugger to be more verbose and helpful!</p> <p><a href="https://preview.redd.it/y1lj4wj0xqo61.png?width=1212&amp;format=png&amp;auto=webp&amp;s=2fa24bdbd8d341fbdaffef9997c30e0d0e9c2cdf">https://preview.redd.it/y1lj4wj0xqo61.png?width=1212&amp;format=png&amp;auto=webp&amp;s=2fa24bdbd8d341fbdaffef9997c30e0d0e9c2cdf</a></p> <p>Visit the <a href="https://github.com/Macchina-CLI/macchina">GitHub repository</a>, or download from <a href="https://crates.io/">crates.io</a> or the <a href="https://aur.archlinux.org/packages/macchina/">AUR</a>.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/efrankee"> /u/efrankee </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/mbaryb/macchina_system_information_fetcher_is_back_with/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/mbaryb/macchina_system_information_fetcher_is_back_with/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR3274: My Custom dwm Setup]]></title>
<description><![CDATA[Intro - video on yt, audio on hpr https://youtu.be/EMFMyxYch14
Who am I? arfab, clearnitesky, trumpetplanet
my email has changed since my first hpr episode - thanks lavabit!
You can now use hello@richcolq.xyz
My previous episode was 0618


Story of ricing my own desktop:

Always been int...]]></description>
<link>https://tsecurity.de/de/1383467/podcasts/hpr3274-my-custom-dwm-setup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1383467/podcasts/hpr3274-my-custom-dwm-setup/</guid>
<pubDate>Thu, 18 Feb 2021 00:01:33 +0100</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<ul>
<li>Intro - video on yt, audio on hpr <a href="https://youtu.be/EMFMyxYch14">https://youtu.be/EMFMyxYch14</a></li>
<li>Who am I? arfab, clearnitesky, trumpetplanet</li>
<li>my email has changed since my first hpr episode - thanks lavabit!</li>
<li>You can now use hello@richcolq.xyz</li>
<li>My previous episode was <a href="http://hackerpublicradio.org/eps.php?id=0618">0618</a></li>
</ul>
<ol type="1">
<li>Story of ricing my own desktop:
<ul>
<li>Always been into customising look/feel, never satisfied</li>
<li>Found Luke Smith and liked i3, made own version.</li>
<li>Pandemic hits! Started learning Python, JavaScript but had no real use for them...</li>
<li>Made a website (inspired by disconnecting from social media)</li>
<li>check out <a href="https://richcolq.xyz/">richcolq.xyz</a> and <a href="https://github.com/clearnitesky">github.com/clearnitesky</a></li>
</ul></li>
<li>What programs am I using?
<ul>
<li>dwm (obviously)</li>
<li>dmenu</li>
<li>st</li>
<li>surf / brave</li>
<li>sxhkd - various short cuts sorted by purpose</li>
<li>dunst</li>
<li>sxiv/feh</li>
<li>zathura</li>
<li>my status stuff using dwmstat script</li>
<li>a look in <code>~/.local/bin</code></li>
<li>I recently learned about awk and rewrote all icon scripts which is what inspired me to record this episode.</li>
</ul></li>
<li>What next?
<ul>
<li>Is it necessary to patch dwm? Probably not.<br>
I've come to believe that the real value in these experiments has come from my custom status scripts and keyboard shortcuts - not from patching new features into dwm. It does what I need it to (manage windows!)</li>
</ul></li>
<li>Thanks for watching!</li>
</ol>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Few, the Tired, the Open Source Coders]]></title>
<description><![CDATA[Reader shanen shares a report (and offers this commentary): When the open source concept emerged in the '90s, it was conceived as a bold new form of communal labor: digital barn raisings. If you made your code open source, dozens or even hundreds of programmers would chip in to improve it. Many h...]]></description>
<link>https://tsecurity.de/de/1303702/it-security-nachrichten/the-few-the-tired-the-open-source-coders/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1303702/it-security-nachrichten/the-few-the-tired-the-open-source-coders/</guid>
<pubDate>Fri, 20 Nov 2020 21:31:14 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Reader shanen shares a report (and offers this commentary): When the open source concept emerged in the '90s, it was conceived as a bold new form of communal labor: digital barn raisings. If you made your code open source, dozens or even hundreds of programmers would chip in to improve it. Many hands would make light work. Everyone would feel ownership. Now, it's true that open source has, overall, been a wild success. Every startup, when creating its own software services or products, relies on open source software from folks like Jacob Thornton: open source web-server code, open source neural-net code. But, with the exception of some big projects -- like Linux -- the labor involved isn't particularly communal. Most are like Bootstrap, where the majority of the work landed on a tiny team of people. Recently, Nadia Eghbal -- the head of writer experience at the email newsletter platform Substack -- published Working in Public, a fascinating book for which she spoke to hundreds of open source coders. She pinpointed the change I'm describing here. No matter how hard the programmers worked, most "still felt underwater in some shape or form," Eghbal told me. 

Why didn't the barn-raising model pan out? As Eghbal notes, it's partly that the random folks who pitch in make only very small contributions, like fixing a bug. Making and remaking code requires a lot of high-level synthesis -- which, as it turns out, is hard to break into little pieces. It lives best in the heads of a small number of people. Yet those poor top-level coders still need to respond to the smaller contributions (to say nothing of requests for help or reams of abuse). Their burdens, Eghbal realized, felt like those of YouTubers or Instagram influencers who feel overwhelmed by their ardent fan bases -- but without the huge, ad-based remuneration. Sometimes open source coders simply walk away: Let someone else deal with this crap. Studies suggest that about 9.5 percent of all open source code is abandoned, and a quarter is probably close to being so. This can be dangerous: If code isn't regularly updated, it risks causing havoc if someone later relies on it. Worse, abandoned code can be hijacked for ill use. Two years ago, the pseudonymous coder right9ctrl took over a piece of open source code that was used by bitcoin firms -- and then rewrote it to try to steal cryptocurrency.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=The+Few%2C+the+Tired%2C+the+Open+Source+Coders%3A+https%3A%2F%2Fbit.ly%2F332cxKJ"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F20%2F11%2F20%2F1910214%2Fthe-few-the-tired-the-open-source-coders%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/20/11/20/1910214/the-few-the-tired-the-open-source-coders?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Starfield reportedly features a completely new animation system]]></title>
<description><![CDATA[New technology will power this new IP.

What you need to know


Starfield is the next big game from Bethesda Game Studios.
One of the senior programmers reportedly rewrote the animation system in Starfield from scratch.
Starfield does not currently have a release window. 


Starfield is the next ...]]></description>
<link>https://tsecurity.de/de/1271425/windows-tipps/starfield-reportedly-features-a-completely-new-animation-system/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1271425/windows-tipps/starfield-reportedly-features-a-completely-new-animation-system/</guid>
<pubDate>Wed, 21 Oct 2020 00:30:27 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[New technology will power this new IP.

What you need to know


Starfield is the next big game from Bethesda Game Studios.
One of the senior programmers reportedly rewrote the animation system in Starfield from scratch.
Starfield does not currently have a release window. 


Starfield is the next Bethesda Game Studios title and while it may still be a ways off, it looks like it'll feature completely new animation work. As spotted on ResetEra, senior programmer at Bethesda Game Studios Eric Braun wrote on his LinkedIn account that he rewrote the animation system for Starfield from scratch.

More specifically, Braun has replaced the Havok-based animation systems previously used for something custom that'll be in Starfield and "all future BGS console games," presumably referring to The Elder Scrolls 6. This lines up with statements Todd Howard recently made about how the partnership with Microsoft has helped bring the studio's "largest engine overhaul since Oblivion."

Microsoft is acqui...]]></content:encoded>
</item>
<item>
<title><![CDATA[The Supreme Court’s Attack on Habeas Corpus in DHS v. Thuraissigiam]]></title>
<description><![CDATA[Refugees are the primary target of the Court’s decision in DHS v. Thuraissigiam, but the the opinion endangers everyone – U.S. citizens included – by reopening settled questions about the Habeas Corpus Suspension Clause of the Constitution. Justice Alito not only rewrote and marginalized prior pr...]]></description>
<link>https://tsecurity.de/de/1218558/it-security-nachrichten/the-supreme-courts-attack-on-habeas-corpus-in-dhs-v-thuraissigiam/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1218558/it-security-nachrichten/the-supreme-courts-attack-on-habeas-corpus-in-dhs-v-thuraissigiam/</guid>
<pubDate>Tue, 25 Aug 2020 17:01:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Refugees are the primary target of the Court’s decision in DHS v. Thuraissigiam, but the the opinion endangers everyone – U.S. citizens included – by reopening settled questions about the Habeas Corpus Suspension Clause of the Constitution. Justice Alito not only rewrote and marginalized prior precedent on habeas corpus, but reached out to decide a procedural due process issue that his own analysis had rendered irrelevant.</p>
<p>The post <a rel="nofollow" href="https://www.justsecurity.org/72104/the-supreme-courts-attack-on-habeas-corpus-in-dhs-v-thuraissigiam/">The Supreme Court’s Attack on Habeas Corpus in DHS v. Thuraissigiam</a> appeared first on <a rel="nofollow" href="https://www.justsecurity.org/">Just Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 10's UWP Remote Desktop app just got a massive update]]></title>
<description><![CDATA[ARM64, light and dark modes, and much more!

What you need to know


The UWP Remote Desktop app for Windows 10 received a big update this week.
The upadte adds light and dark mode support, ARM64 support, and much more.
Insiders can check out this update now at the Microsoft Store.


The Insider v...]]></description>
<link>https://tsecurity.de/de/1216117/windows-tipps/windows-10s-uwp-remote-desktop-app-just-got-a-massive-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1216117/windows-tipps/windows-10s-uwp-remote-desktop-app-just-got-a-massive-update/</guid>
<pubDate>Fri, 21 Aug 2020 23:15:15 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ARM64, light and dark modes, and much more!

What you need to know


The UWP Remote Desktop app for Windows 10 received a big update this week.
The upadte adds light and dark mode support, ARM64 support, and much more.
Insiders can check out this update now at the Microsoft Store.


The Insider version of the official Microsoft Remote Desktop UWP app for Windows 10 received a pretty big update this week. The app now supports light and dark modes, adds ARM64 support, and much more. The app also now uses the same RDP core engine as its macOS and mobile counterparts.

Here's a look at the full release notes:


  
  Rewrote the client to use the same underlying RDP core engine as the iOS, macOS, and Android clients.
  Added support for the Azure Resource Manager-integrated version of Windows Virtual Desktop.
  Added support for x64 and ARM64.
  Updated the side panel design to full screen.
  Added support for light and dark modes.
  Added functionality to subscribe and connect to soverei...]]></content:encoded>
</item>
<item>
<title><![CDATA[To Keep Trump From Violating Its Rules...Facebook Rewrote the Rules]]></title>
<description><![CDATA["Starting in 2015 Mark Zuckerberg and Facebook rewrote their rules in order to not sanction then-candidate Donald Trump," writes Rick Zeman (Slashdot reader #15,628) — citing a new investigation by the Washington Post. (Also available here.) 

After Trump's infamous "the shooting starts" post, Fa...]]></description>
<link>https://tsecurity.de/de/1162785/it-security-nachrichten/to-keep-trump-from-violating-its-rulesfacebook-rewrote-the-rules/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1162785/it-security-nachrichten/to-keep-trump-from-violating-its-rulesfacebook-rewrote-the-rules/</guid>
<pubDate>Mon, 29 Jun 2020 04:01:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["Starting in 2015 Mark Zuckerberg and Facebook rewrote their rules in order to not sanction then-candidate Donald Trump," writes Rick Zeman (Slashdot reader #15,628) — citing a new investigation by the Washington Post. (Also available here.) 

After Trump's infamous "the shooting starts" post, Facebook deputies contacted the White House "with an urgent plea to tweak the language of the post or simply delete it," the article reveals, after which Trump himself called Mark Zuckerberg. (The article later notes that historically Facebook makes a "newsworthiness exception" for some posts which it refuses to remove, "determined on a case-by-case basis, with the most controversial calls made by Zuckerberg.") And in the end, Facebook also decided not to delete that post — and says now that even Friday's newly-announced policy changes still would not have disqualified the post:
The frenzied push-pull was just the latest incident in a five-year struggle by Facebook to accommodate the boundary-busting ways of Trump. The president has not changed his rhetoric since he was a candidate, but the company has continually altered its policies and its products in ways certain to outlast his presidency. Facebook has constrained its efforts against false and misleading news, adopted a policy explicitly allowing politicians to lie, and even altered its news feed algorithm to neutralize claims that it was biased against conservative publishers, according to more than a dozen former and current employees and previously unreported documents obtained by The Washington Post. One of the documents shows it began as far back as 2015... 

The concessions to Trump have led to a transformation of the world's information battlefield. They paved the way for a growing list of digitally savvy politicians to repeatedly push out misinformation and incendiary political language to billions of people. It has complicated the public understanding of major events such as the pandemic and the protest movement, as well as contributed to polarization. And as Trump grew in power, the fear of his wrath pushed Facebook into more deferential behavior toward its growing number of right-leaning users, tilting the balance of news people see on the network, according to the current and former employees... 

Facebook is also facing a slow-burning crisis of morale, with more than 5,000 employees denouncing the company's decision to leave Trump's post that said, "when the looting starts, the shooting starts," up... The political speech carveout ended up setting the stage for how the company would handle not only Trump, but populist leaders around the world who have posted content that test these boundaries, such as Rodrigo Duterte in the Philippines, Jair Bolsonaro in Brazil and Narendra Modi in India... 

 "The value of being in favor with people in power outweighs almost every other concern for Facebook," said David Thiel, a Facebook security engineer who resigned in March after his colleagues refused to remove a post he believed constituted "dehumanizing speech" by Brazil's president.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=To+Keep+Trump+From+Violating+Its+Rules...Facebook+Rewrote+the+Rules%3A+https%3A%2F%2Fbit.ly%2F2BNn9Cx"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F20%2F06%2F29%2F0050246%2Fto-keep-trump-from-violating-its-rulesfacebook-rewrote-the-rules%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/20/06/29/0050246/to-keep-trump-from-violating-its-rulesfacebook-rewrote-the-rules?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inspur InCloud OpenStack sets new SPEC records in results for four key technology indicators]]></title>
<description><![CDATA[Recently, SPEC (Standard Performance Evaluation Corporation) announced the test results for the latest SPEC Cloud IaaS 2018. Inspur InCloud OpenStack rewrote history by setting new records in results for four key technology indicators in performance, scalability, application instances, and provis...]]></description>
<link>https://tsecurity.de/de/1114818/it-security-nachrichten/inspur-incloud-openstack-sets-new-spec-records-in-results-for-four-key-technology-indicators/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1114818/it-security-nachrichten/inspur-incloud-openstack-sets-new-spec-records-in-results-for-four-key-technology-indicators/</guid>
<pubDate>Wed, 13 May 2020 02:31:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Recently, SPEC (Standard Performance Evaluation Corporation) announced the test results for the latest SPEC Cloud IaaS 2018. Inspur InCloud OpenStack rewrote history by setting new records in results for four key technology indicators in performance, scalability, application instances, and provisioning time, proving to be a leading platform for the future construction of data centers. Leading in all areas of technology in performance and scalability The main test indicators of SPEC Cloud IaaS 2018 include performance, … <a href="https://www.helpnetsecurity.com/2020/05/13/inspur-incloud-openstack/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a rel="nofollow" href="https://www.helpnetsecurity.com/2020/05/13/inspur-incloud-openstack/">Inspur InCloud OpenStack sets new SPEC records in results for four key technology indicators</a> appeared first on <a rel="nofollow" href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shellerator - Simple CLI Tool For The Generation Of Bind And Reverse Shells In Multiple Languages]]></title>
<description><![CDATA[Shellerator is a simple command-line tool aimed to help pentesters quickly generate one-liner reverse/bind shells in multiple languages (Bash, Powershell, Java, Python...).  This project is inspired by Print-My-Shell. I just rewrote it and added some options and glitter to it.  The lists of rever...]]></description>
<link>https://tsecurity.de/de/1111655/it-security-nachrichten/shellerator-simple-cli-tool-for-the-generation-of-bind-and-reverse-shells-in-multiple-languages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1111655/it-security-nachrichten/shellerator-simple-cli-tool-for-the-generation-of-bind-and-reverse-shells-in-multiple-languages/</guid>
<pubDate>Sat, 09 May 2020 14:31:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://1.bp.blogspot.com/-x4E6o2dNnpU/XqZNk1JQQtI/AAAAAAAASd0/Q2-SGhyCfEgK-O260E0qkID83_LwEhhmACNcBGAsYHQ/s1600/shellerator_1_example-menus.gif" imageanchor="1"><img border="0" data-original-height="713" data-original-width="1600" height="284" src="https://1.bp.blogspot.com/-x4E6o2dNnpU/XqZNk1JQQtI/AAAAAAAASd0/Q2-SGhyCfEgK-O260E0qkID83_LwEhhmACNcBGAsYHQ/s640/shellerator_1_example-menus.gif" width="640"></a></div><br>Shellerator is a simple command-line tool aimed to help <a href="https://www.kitploit.com/search/label/Pentesters" target="_blank" title="pentesters">pentesters</a> quickly generate one-liner reverse/bind <a href="https://www.kitploit.com/search/label/Shells" target="_blank" title="shells">shells</a> in multiple languages (Bash, Powershell, Java, Python...).  This project is inspired by <a href="https://github.com/sameera-madushan/Print-My-Shell/" rel="nofollow" target="_blank" title="Print-My-Shell">Print-My-Shell</a>. I just rewrote it and added some options and glitter to it.  <strong>The lists of <a href="https://www.kitploit.com/search/label/Reverse" target="_blank" title="reverse">reverse</a> and bind shells are not perfect yet. I'll work on this when I have the time to. I'll be happy to review pull requests too :)</strong><br><a name="more"></a><br><span><b>Install</b></span><br>The install is <a href="https://www.kitploit.com/search/label/PRETty" target="_blank" title="pretty">pretty</a> simple, just clone this git and install the requirements.<br><pre><code>git clone https://github.com/ShutdownRepo/shellerator<br>pip3 install --user -r requirements.txt</code></pre><br><span><b>Usage</b></span><br>Usage is dead simple too.<br><pre><code>usage: shellerator.py [-h] [-b | -r] [-t TYPE] [-p LPORT] [-i LHOST]<br><br>Generate a bind/reverse shell<br><br>optional arguments:<br>  -h, --help              show this help message and exit<br>  -l, --list            Print all the types of shells shellerator can generate<br>  -b, --bind-shell        Generate a bind shell (you connect to the target)<br>  -r, --reverse-shell     Generate a reverse shell (the target connects to you)(Default)<br><br>Bind shell options:<br>  -t TYPE, --type TYPE    Type of the shell to generate (Bash, Powershell, Java...)<br>  -p LPORT, --port LPORT  <a href="https://www.kitploit.com/search/label/Listener" target="_blank" title="Listener">Listener</a> Port<br><br>Reverse shell options:<br>  -t TYPE, --type TYPE    Type of the shell to generate (Bash, Powershell, Java...)<br>  -i LHOST, --ip LHOST    Listener IP address<br>  -p LPORT, --port LPORT  Listener Port</code></pre><br><span><b>Without CLI menus</b></span><br>If you already know what type of shell you want to generate and don't have time to select the language in the beautiful CLI menu, you can set it with the appropriate <code>-t</code> (or <code>--type</code>) option.<br><pre><code>python3 shellerator.py [-r | -b] -t/--type bash -i/--ip 192.168.56.1 -p/--port 1337</code></pre><br><div class="separator"><a href="https://1.bp.blogspot.com/-ndaeKM4KiCo/XqZNuMsLJ2I/AAAAAAAASd4/_dRrYNvr47giKwUNemIXAYEM2XtQYzPKACNcBGAsYHQ/s1600/shellerator_2_example-no-menus.gif" imageanchor="1"><img border="0" data-original-height="646" data-original-width="1600" height="258" src="https://1.bp.blogspot.com/-ndaeKM4KiCo/XqZNuMsLJ2I/AAAAAAAASd4/_dRrYNvr47giKwUNemIXAYEM2XtQYzPKACNcBGAsYHQ/s640/shellerator_2_example-no-menus.gif" width="640"></a></div><br><span><b>To-Do List</b></span><br><br><span><b>Things to add</b></span><br>Here are some things to add that I have in mind, I'll work on that asap<br><ul><li>Add bindshells</li><li>Add encrypted shells and separate them from bind/rev ?</li><li>Add some kind of option to help user get info on how to improve shell/tty (rlwrap, stty, ConPty (cf. PayloadsAllTheThings))</li></ul><br><span><b>Sources</b></span><br>Shells mostly come from the following links<br><ul><li><a href="https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md" rel="nofollow" target="_blank" title="https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md">https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md</a></li><li><a href="http://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet" rel="nofollow" target="_blank" title="http://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet">http://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet</a></li><li><a href="https://www.hackingtutorials.org/networking/hacking-netcat-part-2-bind-reverse-shells/" rel="nofollow" target="_blank" title="https://www.hackingtutorials.org/networking/hacking-netcat-part-2-bind-reverse-shells/">https://www.hackingtutorials.org/networking/hacking-netcat-part-2-bind-reverse-shells/</a></li><li><a href="https://ashr.net/bind/and/reverse/shell/cheatsheet/windows/and/linux.aspx" rel="nofollow" target="_blank" title="https://ashr.net/bind/and/reverse/shell/cheatsheet/windows/and/linux.aspx">https://ashr.net/bind/and/reverse/shell/cheatsheet/windows/and/linux.aspx</a></li></ul><br><br><div><b><span><a class="kiploit-download" href="https://github.com/ShutdownRepo/shellerator" rel="nofollow" target="_blank" title="Download Shellerator">Download Shellerator</a></span></b></div><img src="http://feeds.feedburner.com/~r/PentestTools/~4/Yxf6odBCrlI" height="1" width="1" alt="">]]></content:encoded>
</item>
<item>
<title><![CDATA[Facebook Shrinks Messenger App Size Down By 75%]]></title>
<description><![CDATA[To make its iPhone messaging app run better -- especially on older phones -- Facebook rewrote it from the ground up. The new version is going live now. From a report: In August 2011, Facebook introduced Messenger, an iPhone and Android app that spun off the social network's chat feature into a st...]]></description>
<link>https://tsecurity.de/de/1039951/it-security-nachrichten/facebook-shrinks-messenger-app-size-down-by-75/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1039951/it-security-nachrichten/facebook-shrinks-messenger-app-size-down-by-75/</guid>
<pubDate>Mon, 02 Mar 2020 21:01:24 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[To make its iPhone messaging app run better -- especially on older phones -- Facebook rewrote it from the ground up. The new version is going live now. From a report: In August 2011, Facebook introduced Messenger, an iPhone and Android app that spun off the social network's chat feature into a stand-alone experience. [...] Messenger hit one billion monthly active users in 2016 and was the world's most-downloaded app in 2019, according to App Annie. Along the way, it supplemented its original text-based conversations with everything from voice and video calls to games to payments to bots to Snapchat-style stories. As its user base and ambitions grew, so did its size. What had been a wafer-thin 8.5MB download in 2012 expanded to take up 130MB of space on users' iPhones. That's about twice the size of WhatsApp, another Facebook messaging app that offers many similar features. 

But now Facebook has put the iOS version of Messenger on an extreme weight-reduction plan. By rewriting it from scratch, it's shrunk Messenger's footprint on your iPhone down to an eminently manageable 30MB, less than a quarter of its peak size. According to the company, the new version loads twice as fast as the one it's replacing. The update is so compact that Facebook was able to quietly build it into the existing version and test it by exposing it to a subset of users. As a giant piece of programming, the downsizing is even more dramatic. Messenger is going from 1.7 million lines of code to 360,000, for an 84% reduction.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Facebook+Shrinks+Messenger+App+Size+Down+By+75%25%3A+http%3A%2F%2Fbit.ly%2F2Ie1FP6"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F20%2F03%2F02%2F1858220%2Ffacebook-shrinks-messenger-app-size-down-by-75%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/20/03/02/1858220/facebook-shrinks-messenger-app-size-down-by-75?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Netdata release v1.19]]></title>
<description><![CDATA[Hey all, Introducing a major rewrite of our web log collector, cmocka unit testing, improvements on our Unbound collector and even more! Check out our blog post for full details or read our release notes below. Release v1.19.0 contains 2 new collectors, 19 bug fixes, 17 improvements, and 19 docum...]]></description>
<link>https://tsecurity.de/de/935799/linux-tipps/netdata-release-v119/</link>
<guid isPermaLink="true">https://tsecurity.de/de/935799/linux-tipps/netdata-release-v119/</guid>
<pubDate>Mon, 02 Dec 2019 22:00:17 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey all,</p> <p>Introducing a major rewrite of our web log collector, <a href="https://www.facebook.com/hashtag/cmocka?source=feed_text&amp;epa=HASHTAG&amp;__xts__%5B0%5D=68.ARDKJpuwODv-hPc236C7fM2r9vCYx9vTJeH93a18odECvej08YhKL8yikqtkH5YC0qIPbakDgFmmf15tnogjIj3cf_Wya85PQYEzfw9Y2OUmmX9y_0GfH_ikrxDZS109LzcjMTWo8zoUXSy893FBfR0_AxyBw6IFCcIkBObQiTOtCIjrxws3vt14_Jg5s_H61VJwB_KoiG9hPRXpuA6vV5Vm9rUSZUwM0KpucD6_6XrlRI2xwd7Sz5M_3Arnkqr4DckHC5NXNGGTVMUYJgz2H3mq1KcdwguQvlsigL2Pz4k6QW1ZCCYCvG21xk1UzcDAEEr15Yqxx-AEGa1AlNoxRqzZc8MM&amp;__tn__=%2ANK-R">cmocka</a> unit testing, improvements on our <a href="https://www.facebook.com/hashtag/unbound?source=feed_text&amp;epa=HASHTAG&amp;__xts__%5B0%5D=68.ARDKJpuwODv-hPc236C7fM2r9vCYx9vTJeH93a18odECvej08YhKL8yikqtkH5YC0qIPbakDgFmmf15tnogjIj3cf_Wya85PQYEzfw9Y2OUmmX9y_0GfH_ikrxDZS109LzcjMTWo8zoUXSy893FBfR0_AxyBw6IFCcIkBObQiTOtCIjrxws3vt14_Jg5s_H61VJwB_KoiG9hPRXpuA6vV5Vm9rUSZUwM0KpucD6_6XrlRI2xwd7Sz5M_3Arnkqr4DckHC5NXNGGTVMUYJgz2H3mq1KcdwguQvlsigL2Pz4k6QW1ZCCYCvG21xk1UzcDAEEr15Yqxx-AEGa1AlNoxRqzZc8MM&amp;__tn__=%2ANK-R">Unbound</a> collector and even more! Check out our blog post for full details or read our release notes below.</p> <p>Release v1.19.0 contains 2 new collectors, 19 bug fixes, 17 improvements, and 19 documentation updates. Full release notes can be found <a href="https://github.com/netdata/netdata/releases/tag/v1.19.0">here</a>.</p> <p><strong>At a glance</strong></p> <p>We completed a major rewrite of our web log collector to dramatically improve its flexibility and performance. The <a href="https://github.com/netdata/go.d.plugin/pull/141">new collector</a>, written entirely in Go, can parse and chart logs from Nginx and Apache servers, and combines numerous improvements. Netdata now supports the LTSV log format, creates charts for TLS and cipher usage, and is amazingly fast. In a test using SSD storage, the collector parsed the logs for 200,000 requests in about 200ms, using 30% of a single core.</p> <p>This Go-based collector also has powerful custom log parsing capabilities, which means we're one step closer to a generic application log parser for Netdata. We're continuing to work on this parser to support more application log formatting in the future.</p> <p>We have a new tutorial on <a href="https://docs.netdata.cloud/docs/tutorials/collect-apache-nginx-web-logs/">enabling the Go web log collector</a> and using it with Nginx and/or Apache access logs with minimal configuration. Thanks to <a href="https://github.com/Wing924">Wing924</a> for starting the Go rewrite!</p> <p>We introduced more <strong>cmocka unit testing</strong> to Netdata. In this release, we're testing how Netdata's internal web server processes HTTP requests—the first step to improve the quality of code throughout, reduce bugs, and make refactoring easier. We wanted to validate the web server's behavior but needed to build a layer of parametric testing on top of the CMocka test runner. Read all about our process of testing and selecting cmocka on our blog post: <a href="https://blog.netdata.cloud/agile-team-cmocka-foss/">Building an agile team's 'safety harness' with cmocka and FOSS</a>.</p> <p>Netdata's <strong>Unbound collector</strong> was also <a href="https://github.com/netdata/go.d.plugin/pull/287">completely rewritten in Go</a> to improve how it collects and displays metrics. This new version can get dozens of metrics, including details on queries, cache, uptime, and even show per-thread metrics. See our <a href="https://docs.netdata.cloud/docs/tutorials/collect-unbound-metrics/">tutorial</a> on enabling the new collector via Netdata's amazing auto-detection feature.</p> <p>We <a href="https://github.com/netdata/netdata/pull/7220">fixed an error</a> where <strong>invalid spikes</strong> appeared on certain charts by improving the incremental counter reset/wraparound detection algorithm.</p> <p>Netdata can now send <a href="https://docs.netdata.cloud/health/notifications/irc/"><strong>health alarm notifications to IRC channels</strong></a> thanks to <a href="https://github.com/Strykar">Strykar</a>!</p> <p>And, Netdata can now monitor <a href="https://docs.netdata.cloud/collectors/python.d.plugin/am2320/"><strong>AM2320 sensors</strong></a>, thanks to hard work from <a href="https://github.com/tommybuck">Tom Buck</a>.</p> <p><strong>Improvements</strong></p> <ul><li><strong>New Collectors</strong> <ul><li>AM2320 sensor collector plugin</li> <li>Added parsing of /proc/pagetypeinfo to provide metrics on fragmentation of free memory pages</li> <li>The unbound collector module was completely rewritten, in Go <a href="https://github.com/netdata/go.d.plugin/pull/287">go.d.plugin/#287</a></li> </ul></li> </ul><p><strong>Collector improvements</strong></p> <ul><li><strong>We rewrote our web log parser in Go, drastically improving its flexibility and performance</strong> <ul><li>The <a href="https://docs.netdata.cloud/collectors/go.d.plugin/modules/k8s_kubelet/">Kubernetes kubelet collector</a> now reads the service account token and uses it for authorization. We also added a new default job to collect metrics from https://localhost:10250/metrics</li> <li>Added a new default job to the <a href="https://docs.netdata.cloud/collectors/go.d.plugin/modules/coredns/">Kubernetes coredns</a> collector to collect metrics from <a href="http://kube-dns.kube-system.svc.cluster.local:9153/metrics">http://kube-dns.kube-system.svc.cluster.local:9153/metrics</a></li> <li>apps.plugin: Synced FRRouting daemons configuration with the frr 7.2 release</li> <li>apps.plugin: Added process group for git-related processes-apps.plugin: Added balena to the container-engines application group</li> <li>web_log: Treat 401 Unauthorized requests as successful</li> <li>xenstat.plugin: Prepare for xen 4.13 by checking for check xenstat_vbd_errorpresence</li> <li>mysql: Added galera cluster_statusalarm</li> </ul></li> <li><strong>Metrics Database</strong> <ul><li>Netdata generates alarms if the disk cannot keep up with data collection</li> </ul></li> <li><strong>Health</strong> <ul><li>Fine tune various default alarm configurations</li> <li>Update SYN cookie alarm to be less aggressive</li> <li>Added support for IRC alarm notifications</li> </ul></li> <li><strong>Installation/Packages</strong> <ul><li>Corrected the Makefile.am files indentation, to prevent unexpected errors</li> <li>Rationalized ownership and permissions of /etc/netdata</li> <li>Made various improvements to the installer script netdata-installer.sh</li> <li>Include go.d.plugin version v0.11.0</li> </ul></li> <li><strong>Other</strong> <ul><li>Improve Travis build warnings</li> <li>cmocka testing for http requests</li> <li>CI/CD: Prevented nightly jobs from timing out</li> </ul></li> </ul></div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/ktsaou"> /u/ktsaou </a> <br><span><a href="https://www.reddit.com/r/linux/comments/e54cn3/netdata_release_v119/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/e54cn3/netdata_release_v119/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft's Rust experiments are going well, but some features are missing]]></title>
<description><![CDATA[Microsoft rewrote a low-level Windows component in Rust. Calls the experience "generally positive."]]></description>
<link>https://tsecurity.de/de/911261/hacking/microsofts-rust-experiments-are-going-well-but-some-features-are-missing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/911261/hacking/microsofts-rust-experiments-are-going-well-but-some-features-are-missing/</guid>
<pubDate>Thu, 07 Nov 2019 20:15:29 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft rewrote a low-level Windows component in Rust. Calls the experience "generally positive."]]></content:encoded>
</item>
<item>
<title><![CDATA[Americans Shouldn't Have To Drive, But the Law Insists on It]]></title>
<description><![CDATA[An anonymous reader shares a report: In America, the freedom of movement comes with an asterisk: the obligation to drive. This truism has been echoed by the U.S. Supreme Court, which has pronounced car ownership a "virtual necessity." The Court's pronouncement is telling. Yes, in a sense, America...]]></description>
<link>https://tsecurity.de/de/548793/it-security-nachrichten/americans-shouldnt-have-to-drive-but-the-law-insists-on-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/548793/it-security-nachrichten/americans-shouldnt-have-to-drive-but-the-law-insists-on-it/</guid>
<pubDate>Wed, 10 Jul 2019 17:31:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader shares a report: In America, the freedom of movement comes with an asterisk: the obligation to drive. This truism has been echoed by the U.S. Supreme Court, which has pronounced car ownership a "virtual necessity." The Court's pronouncement is telling. Yes, in a sense, America is car-dependent by choice -- but it is also car-dependent by law. As I detail in a forthcoming journal article, over the course of several generations lawmakers rewrote the rules of American life to conform to the interests of Big Oil, the auto barons, and the car-loving 1 percenters of the Roaring Twenties. They gave legal force to a mind-set -- let's call it automobile supremacy -- that kills 40,000 Americans a year and seriously injures more than 4 million more. Include all those harmed by emissions and climate change, and the damage is even greater. As a teenager growing up in the shadow of Detroit, I had no reason to feel this was unjust, much less encouraged by law. It is both. 

It's no secret that American public policy throughout the 20th century endorsed the car -- for instance, by building a massive network of urban and interstate highways at public expense. Less well understood is how the legal framework governing American life enforces dependency on the automobile. To begin with, mundane road regulations embed automobile supremacy into federal, state, and local law. But inequities in traffic regulation are only the beginning. Land-use law, criminal law, torts, insurance, vehicle safety regulations, even the tax code -- all these sources of law provide rewards to cooperate with what has become the dominant transport mode, and punishment for those who defy it.<p></p>
<div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Americans+Shouldn't+Have+To+Drive%2C+But+the+Law+Insists+on+It%3A+http%3A%2F%2Fbit.ly%2F2XXMovd"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F19%2F07%2F10%2F1524219%2Famericans-shouldnt-have-to-drive-but-the-law-insists-on-it%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>

<a class="nobg" href="http://plus.google.com/share?url=https://news.slashdot.org/story/19/07/10/1524219/americans-shouldnt-have-to-drive-but-the-law-insists-on-it?utm_source=slashdot&amp;utm_medium=googleplus"><img src="https://www.gstatic.com/images/icons/gplus-16.png" alt="Share on Google+"></a>



</div>
<p><a href="https://news.slashdot.org/story/19/07/10/1524219/americans-shouldnt-have-to-drive-but-the-law-insists-on-it?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[The Small Macedonian Town That Runs Hundreds of Fake US Politics Websites]]></title>
<description><![CDATA[dryriver writes: BBC Future has the story of "Tamara" (not her real name) who used to be paid 24 euros a day to rewrite U.S. news stories for a slew of "fake news" U.S. politics websites targeted at American news readers but run out of Velev, Macedonia. Basically, Tamara's handler "Marco" would s...]]></description>
<link>https://tsecurity.de/de/515856/it-security-nachrichten/the-small-macedonian-town-that-runs-hundreds-of-fake-us-politics-websites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/515856/it-security-nachrichten/the-small-macedonian-town-that-runs-hundreds-of-fake-us-politics-websites/</guid>
<pubDate>Fri, 31 May 2019 05:01:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[dryriver writes: BBC Future has the story of "Tamara" (not her real name) who used to be paid 24 euros a day to rewrite U.S. news stories for a slew of "fake news" U.S. politics websites targeted at American news readers but run out of Velev, Macedonia. Basically, Tamara's handler "Marco" would send her eight real U.S. politics news stories via email every morning, asking Tamara to rewrite them with very extreme political views and slants injected into them. Tamara was often tasked with writing horrible things about Muslims for example, making up heinous crimes they had committed in various places, and injecting those made-up falsehoods into otherwise legit-looking news articles. The rewritten articles, which were engineered to trigger strong reactions in readers, went on Facebook -- where Marco had over 2,000,000 likes -- and on a number of "American looking" fake news websites also run by Marco out of Macedonia. On a good day, Marco would earn up to 2,000 euros a day from Google ad revenues for his fake news U.S. politics websites. Tamara, who was only paid 3 euros per article she rewrote, muses in the BBC Future article about how stupid people must be to eat up the falsehoods that she, Marco and others put online everyday. She characterizes the content of the rewritten articles as "insultingly ridiculous" and "obviously fake," but many American news readers apparently ate them up and frequently believed what they read.<p></p>
<div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=The+Small+Macedonian+Town+That+Runs+Hundreds+of+Fake+US+Politics+Websites%3A+http%3A%2F%2Fbit.ly%2F2XfKBhF"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fpolitics.slashdot.org%2Fstory%2F19%2F05%2F30%2F222246%2Fthe-small-macedonian-town-that-runs-hundreds-of-fake-us-politics-websites%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>

<a class="nobg" href="http://plus.google.com/share?url=https://politics.slashdot.org/story/19/05/30/222246/the-small-macedonian-town-that-runs-hundreds-of-fake-us-politics-websites?utm_source=slashdot&amp;utm_medium=googleplus"><img src="https://www.gstatic.com/images/icons/gplus-16.png" alt="Share on Google+"></a>



</div>
<p><a href="https://politics.slashdot.org/story/19/05/30/222246/the-small-macedonian-town-that-runs-hundreds-of-fake-us-politics-websites?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Scientists Create World's First Living Organism With Fully Redesigned DNA]]></title>
<description><![CDATA[An anonymous reader quotes a report from The Guardian: Scientists have created the world's first living organism that has a fully synthetic and radically altered DNA code. In a two-year effort, researchers at the laboratory of molecular biology, at Cambridge University, read and redesigned the DN...]]></description>
<link>https://tsecurity.de/de/500471/it-security-nachrichten/scientists-create-worlds-first-living-organism-with-fully-redesigned-dna/</link>
<guid isPermaLink="true">https://tsecurity.de/de/500471/it-security-nachrichten/scientists-create-worlds-first-living-organism-with-fully-redesigned-dna/</guid>
<pubDate>Thu, 16 May 2019 06:16:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from The Guardian: Scientists have created the world's first living organism that has a fully synthetic and radically altered DNA code. In a two-year effort, researchers at the laboratory of molecular biology, at Cambridge University, read and redesigned the DNA of the bacterium Escherichia coli (E coli), before creating cells with a synthetic version of the altered genome. The artificial genome holds 4m base pairs, the units of the genetic code spelled out by the letters G, A, T and C. Printed in full on A4 sheets, it runs to 970 pages, making the genome the largest by far that scientists have ever built. The DNA coiled up inside a cell holds the instructions it needs to function. When the cell needs more protein to grow, for example, it reads the DNA that encodes the right protein. The DNA letters are read in trios called codons, such as TCG and TCA.
 
The Cambridge team set out to redesign the E coli genome by removing some of its superfluous codons. Working on a computer, the scientists went through the bug's DNA. Whenever they came across TCG, a codon that makes an amino acid called serine, they rewrote it as AGC, which does the same job. They replaced two more codons in a similar way. More than 18,000 edits later, the scientists had removed every occurrence of the three codons from the bug's genome. The redesigned genetic code was then chemically synthesized and, piece by piece, added to E coli where it replaced the organism's natural genome. The result, reported in Nature, is a microbe with a completely synthetic and radically altered DNA code. Known as Syn61, the bug is a little longer than normal, and grows more slowly, but survives nonetheless.<p></p>
<div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Scientists+Create+World's+First+Living+Organism+With+Fully+Redesigned+DNA%3A+http%3A%2F%2Fbit.ly%2F2JlFDwv"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F19%2F05%2F15%2F2158209%2Fscientists-create-worlds-first-living-organism-with-fully-redesigned-dna%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>

<a class="nobg" href="http://plus.google.com/share?url=https://science.slashdot.org/story/19/05/15/2158209/scientists-create-worlds-first-living-organism-with-fully-redesigned-dna?utm_source=slashdot&amp;utm_medium=googleplus"><img src="https://www.gstatic.com/images/icons/gplus-16.png" alt="Share on Google+"></a>



</div>
<p><a href="https://science.slashdot.org/story/19/05/15/2158209/scientists-create-worlds-first-living-organism-with-fully-redesigned-dna?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[How Microsoft Rewrote Its C# Compiler in C# and Made It Open Source]]></title>
<description><![CDATA[Mads Torgersen, the lead designer of C# at Microsoft, remembers "Project Roslyn," which built an open-source, cross-platform compiler for C# and Visual Basic.NET "in the deepest darkness of last decade's corporate Microsoft:
 We would build a language engine! A unified, public API to C# code: We ...]]></description>
<link>https://tsecurity.de/de/381636/it-security-nachrichten/how-microsoft-rewrote-its-c-compiler-in-c-and-made-it-open-source/</link>
<guid isPermaLink="true">https://tsecurity.de/de/381636/it-security-nachrichten/how-microsoft-rewrote-its-c-compiler-in-c-and-made-it-open-source/</guid>
<pubDate>Sun, 30 Sep 2018 10:30:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mads Torgersen, the lead designer of C# at Microsoft, remembers "Project Roslyn," which built an open-source, cross-platform compiler for C# and Visual Basic.NET "in the deepest darkness of last decade's corporate Microsoft:
 We would build a language engine! A unified, public API to C# code: We would redefine the meaning of "compiler". Of course, once you are building an API for the broad C# community, it is kind of a slam-dunk that it should be a .NET API, implemented in C#. So, the old dream of "bootstrapping" C# in C# was fulfilled almost as an accidental side benefit. Roslyn was thus born out of an openness mindset: sharing the inner workings of the C# language for the world to programmatically consume. 
This in and of itself was a bit of a bold proposition in what was still a pervasively closed culture at Microsoft: We would share this intellectual property for free? We would empower tool builders that weren't us to better compete with us? The arguments that won the day for us here were about strengthening the ecosystem and becoming the best tooled language on the planet. They were about long-term growth of C# and .NET, versus short term monetization and protection of assets for Microsoft. So even without having mentioned open source, signing up for the cost and risk of the Roslyn project was a big and bold step for Microsoft.... 
F# released already in 2010 with an open source license and its own foundation -- the F# Software Foundation. The vibrant community that grew up around it soon became the envy of us all. Our team pushed strongly to have an open source production license for Roslyn, and finally a company-wide infrastructure emerged to make it real. By 2012, Microsoft had created Microsoft Open Tech; an organization specifically focused on open source projects. Roslyn moved under Microsoft Open Tech and officially became open source... C# language design and compiler implementation are now completely open processes, with lots of non-Microsoft participation, including whole language features being built by external contributors. 

Torgersen's article says C# now enjoys "the scaling of effort via contribution of features and bug fixes, but also the insight and course correction we get through the instant, daily feedback loop that open source provides. 

"It's been a long and wild journey, and one that to me is symbolic of the massive changes that Microsoft has undergone over the last decade."<p></p>
<div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=How+Microsoft+Rewrote+Its+C%23+Compiler+in+C%23+and+Made+It+Open+Source%3A+http%3A%2F%2Fbit.ly%2F2QgqdsH"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F18%2F09%2F29%2F0933246%2Fhow-microsoft-rewrote-its-c-compiler-in-c-and-made-it-open-source%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>

<a class="nobg" href="http://plus.google.com/share?url=https://developers.slashdot.org/story/18/09/29/0933246/how-microsoft-rewrote-its-c-compiler-in-c-and-made-it-open-source?utm_source=slashdot&amp;utm_medium=googleplus"><img src="https://www.gstatic.com/images/icons/gplus-16.png" alt="Share on Google+"></a>



</div>
<p><a href="https://developers.slashdot.org/story/18/09/29/0933246/how-microsoft-rewrote-its-c-compiler-in-c-and-made-it-open-source?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[KisMac - Open Source Wireless Stumbling And Security Tool For Mac OS X]]></title>
<description><![CDATA[KisMAC is a free, open source wireless stumbling and security tool for Mac OS X.Whats new:
Mac OS 10.9 - 10.12 (64-bit only)
ARC (64-bit only)
New GUI
Modern Objective-c syntax
Rewrote most part of deprecated methods
Remove debug info from release

How Build:
git clone https://github.com/IGRSoft/...]]></description>
<link>https://tsecurity.de/de/367895/it-security-nachrichten/kismac-open-source-wireless-stumbling-and-security-tool-for-mac-os-x/</link>
<guid isPermaLink="true">https://tsecurity.de/de/367895/it-security-nachrichten/kismac-open-source-wireless-stumbling-and-security-tool-for-mac-os-x/</guid>
<pubDate>Wed, 05 Sep 2018 23:31:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<div class="separator"><a href="https://2.bp.blogspot.com/-pub8VvqrPCk/W4roCgdm8SI/AAAAAAAAMVY/bx4I5u0lVYg97htlvMcb2J_zhoQ7Hu3pACLcBGAs/s1600/KisMac2_5_screenshot.png" imageanchor="1"><img border="0" data-original-height="478" data-original-width="757" height="404" src="https://2.bp.blogspot.com/-pub8VvqrPCk/W4roCgdm8SI/AAAAAAAAMVY/bx4I5u0lVYg97htlvMcb2J_zhoQ7Hu3pACLcBGAs/s640/KisMac2_5_screenshot.png" width="640"></a></div>
<br>KisMAC is a free, open source <a href="http://www.kitploit.com/search/label/Wireless">wireless</a> stumbling and security tool for Mac OS X.<br><br><span><b>Whats new:</b></span><br><ul>
<li>Mac OS 10.9 - 10.12 (64-bit only)</li>
<li>ARC (64-bit only)</li>
<li>New GUI</li>
<li>Modern Objective-c syntax</li>
<li>Rewrote most part of deprecated methods</li>
<li>Remove debug info from release</li>
</ul>
<a name="more"></a><br><span><b>How Build:</b></span><br><ul>
<li>git clone <a href="https://github.com/IGRSoft/KisMac2.git" rel="nofollow" target="_blank">https://github.com/IGRSoft/KisMac2.git</a> ./KissMac2</li>
<li>cd KissMac2</li>
<li>git submodule update --init --recursive</li>
<li>open KisMac2.xcworkspace</li>
<li>Build</li>
</ul>
<br><span><b>Current Developer and Origin:</b></span><br>This project, KisMac2, is an active project to continue where original development of KisMac has stopped. The lead developer is Vitalii Parovishnyk (Korich) - <a href="http://igrsoft.com/" rel="nofollow" target="_blank">http://IGRSoft.com</a> and you are welcome to contact us and join in the project.<br>Michael Rossberg / Geoffrey Kruse / kismac-ng.org is the original KisMac and the project is not actively maintained since 2011, please see the <a href="https://en.wikipedia.org/wiki/KisMAC" rel="nofollow" target="_blank">KisMac Wikipedia page</a> for more <a href="http://www.kitploit.com/search/label/Information">information</a> on the earlier history of that project.<br><br><span><b>Nightly Builds:</b></span><br><a href="http://downloads.igrsoft.com/beta/KisMac2.zip" rel="nofollow" target="_blank">http://downloads.igrsoft.com/beta/KisMac2.zip</a><br><br><br><div><b><span><a href="https://github.com/IGRSoft/KisMac2" rel="nofollow" target="_blank">Download KisMac2</a></span></b></div>
<img src="http://feeds.feedburner.com/~r/PentestTools/~4/kV7MP4V-kAs" height="1" width="1" alt="">
]]></content:encoded>
</item>
<item>
<title><![CDATA[Google releases source for Google I/O 2018 for Android]]></title>
<description><![CDATA[Posted by Shailen Tuli, DPE


Today we're releasing the source code for the official Google I/O 2018 for Android app.


The 2018 version constitutes a comprehensive rewrite of the app. For many years, the app has used a ContentProvider + SyncAdapter architecture. This year, we rewrote the app usi...]]></description>
<link>https://tsecurity.de/de/355770/android-tipps/google-releases-source-for-google-io-2018-for-android/</link>
<guid isPermaLink="true">https://tsecurity.de/de/355770/android-tipps/google-releases-source-for-google-io-2018-for-android/</guid>
<pubDate>Mon, 13 Aug 2018 19:45:04 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://4.bp.blogspot.com/-DVr_wyy6nd4/W24hRDNIsOI/AAAAAAAAFsM/ImiGNOs6qpUJ2NgVC1BrMFsC_7-geSrzACLcBGAs/s1600/Screen%2BShot%2B2018-07-31%2Bat%2B8.53.13%2BAMiamge1.png"><p>
Posted by Shailen Tuli, DPE
</p>
<p>
Today we're releasing the <a href="https://github.com/google/iosched">source code</a> for the official <a href="https://play.google.com/store/apps/details?id=com.google.samples.apps.iosched&amp;hl=en">Google I/O 2018</a> for Android app.
</p>
<p>
The 2018 version constitutes a comprehensive rewrite of the app. For many years, the app has used a ContentProvider + SyncAdapter architecture. This year, we rewrote the app using <a href="https://developer.android.com/topic/libraries/architecture/">Architecture Components</a> and brought the code in sync with the Android team's current recommendations for building modern apps.
</p>
<p>
<a href="https://4.bp.blogspot.com/-DVr_wyy6nd4/W24hRDNIsOI/AAAAAAAAFsM/ImiGNOs6qpUJ2NgVC1BrMFsC_7-geSrzACLcBGAs/s1600/Screen%2BShot%2B2018-07-31%2Bat%2B8.53.13%2BAMiamge1.png" imageanchor="1"><img border="0" src="https://4.bp.blogspot.com/-DVr_wyy6nd4/W24hRDNIsOI/AAAAAAAAFsM/ImiGNOs6qpUJ2NgVC1BrMFsC_7-geSrzACLcBGAs/s1600/Screen%2BShot%2B2018-07-31%2Bat%2B8.53.13%2BAMiamge1.png" data-original-width="1426" data-original-height="874"></a></p>
<h2>Architecture</h2>


<p>
We followed the recommendations laid out in the <a href="https://developer.android.com/jetpack/docs/guide">Guide to App Architecture</a> for writing modular, testable and maintainable code when deciding on the architecture for the app. We kept logic away from Activities and Fragments and moved it to <a href="https://developer.android.com/topic/libraries/architecture/viewmodel">ViewModels</a>. We observed data using <a href="https://developer.android.com/topic/libraries/architecture/livedata">LiveData</a> and used the <a href="https://developer.android.com/topic/libraries/data-binding/">Data Binding Library</a> to bind UI components in layouts to the app's data sources.
</p>
<p>
The overall architecture of the app can be summarized in this diagram:
</p>
<p>
<a href="https://3.bp.blogspot.com/-0GvaRwRK8kU/W24hW44gmYI/AAAAAAAAFsQ/oYNObyN05ZcaIxnUx1oKdKUi-r1NWOuPQCLcBGAs/s1600/IOSched%2BArchitecture%2BDiagramimage2.png" imageanchor="1"><img border="0" src="https://3.bp.blogspot.com/-0GvaRwRK8kU/W24hW44gmYI/AAAAAAAAFsQ/oYNObyN05ZcaIxnUx1oKdKUi-r1NWOuPQCLcBGAs/s1600/IOSched%2BArchitecture%2BDiagramimage2.png" data-original-width="886" data-original-height="1148"></a></p>
<p>
We used a Repository layer for handling data operations. IOSched's data comes from a few different sources —  user data is stored in <a href="https://firebase.google.com/docs/firestore/">Cloud Firestore</a> (either remotely or in a local cache for offline use), user preferences and settings are stored in SharedPreferences, conference data is stored remotely and is fetched and stored in memory for the app to use  —  and the repository modules are responsible for handling all data operations and abstracting the data sources from the rest of the app. If we ever wanted to swap out the Firestore backend for a different data source in the future, our architecture allows us to do so in a clean way. </p>
<p>We implemented a lightweight domain layer, which sits between the data layer and the presentation layer, and handles discrete pieces of business logic off the UI thread. <a href="https://github.com/google/iosched/search?q=UseCase&amp;unscoped_q=UseCase">Examples</a>.
</p>
<p>
We used <a href="https://github.com/google/dagger">Dagger2</a> for dependency injection and we heavily relied on <a href="https://google.github.io/dagger/android.html">dagger-android</a> to abstract away boilerplate code.
</p>
<p>
We used <a href="https://developer.android.com/training/testing/espresso/">Espresso</a> for basic instrumentation tests and JUnit and <a href="https://github.com/mockito/mockito">Mockito</a> for unit testing.
</p>
<h2>Firebase</h2>


<p>
The use of Firebase technologies has grown in the app as the Firebase platform has matured. The 2018 version uses the following Firebase components:
</p>
<ul>
<li>
<a href="https://firebase.google.com/docs/firestore/">Cloud Firestore</a> is our source for all user data (events starred or reserved by a user). Firestore gave us automatic sync and also seamlessly managed offline functionality for us.
</li>
<li>
<a href="https://firebase.google.com/docs/functions/">Firebase Cloud Functions</a> allowed us to run backend code. The reservations feature heavily depended on Functions checking a user's status (only attendees were allowed to make reservations), checking space availability and persisting reservation status in Firestore.
</li>
<li>
<a href="https://firebase.google.com/docs/cloud-messaging/concept-options">Firebase Cloud Messaging</a> let us inform the app about changes to conference data on our server. Conference data is <em>mostly</em> static, but it does change from time to time, especially after the keynote. The app has traditionally used a ping-and-fetch model when working with conference data, and we retained that usage this year. 
</li>
<li>
<a href="https://firebase.google.com/docs/remote-config/">Remote Config</a> helped us manage in-app constants. In previous years, we had found ourselves unable to inform users when data not directly related to the conference schedule — WiFi information, conference shuttle schedule, etc. — changed unexpectedly. Remote Config helped us update such values in a lightweight manner. </li>
</ul>
<h2>Kotlin</h2>


<p>
We made an early decision to rewrite the app from scratch to bring it in line with modern Android architecture. Using Kotlin for the rewrite was an easy choice: we loved Kotlin's expressive, concise, and powerful syntax; we found that Kotlin's support for safety features including nullability and immutability made our code more resilient; and we leveraged the enhanced functionality provided by <a href="https://developer.android.com/kotlin/ktx">Android Ktx extensions</a>.
</p>
<h2>Material Design</h2>


<p>
At I/O 2018, the Material Design team announced <a href="https://material.io/design/material-theming/overview.html#material-theming">Material Theming</a>, giving apps much greater ability to customize Material Design to bring more of their product's brand. As we launched the app before Material Theming, we couldn't use all of the new components but we managed to sneak a couple in like the new <a href="https://material.io/design/components/app-bars-bottom.html">Bottom App Bar</a> with inset Floating Action Button and we were able to incorporate a lot of the conference's branding elements.
</p>
<h2>Future plans</h2>


<p>
The rewrite of the app brings the code in sync with Android's opinionated recommendations about building apps, and it resulted in a cleaner, more maintainable codebase. We'll continue working on the app, incorporating JetPack components as they become available and finding opportunities to showcase platform features that are good fits for the app. Developers can follow changes to the code on <a href="https://github.com/google/iosched">GitHub</a>. 
</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/blogspot/hsDu?a=ttntdANEkCg:jBnP2rg6qkA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/blogspot/hsDu?d=yIl2AUoC8zA" border="0"></a> <a href="http://feeds.feedburner.com/~ff/blogspot/hsDu?a=ttntdANEkCg:jBnP2rg6qkA:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/blogspot/hsDu?i=ttntdANEkCg:jBnP2rg6qkA:-BTjWOF_DHI" border="0"></a>
</div>
<img src="http://feeds.feedburner.com/~r/blogspot/hsDu/~4/ttntdANEkCg" height="1" width="1" alt="">
]]></content:encoded>
</item>
<item>
<title><![CDATA[Android Studio 3.0]]></title>
<description><![CDATA[Posted by Jamal Eason, Product
Manager, Android



Android Studio 3.0 is ready to download today. Announced at Google I/O 2017,
Android Studio 3.0 is a large update focused on accelerating your app
development on Android.


This release of Android Studio is packed with many new updates, but there...]]></description>
<link>https://tsecurity.de/de/221032/android-tipps/android-studio-30/</link>
<guid isPermaLink="true">https://tsecurity.de/de/221032/android-tipps/android-studio-30/</guid>
<pubDate>Wed, 25 Oct 2017 18:30:05 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<em>Posted by <a href="https://www.google.com/+JamalEason">Jamal Eason</a>, Product
Manager, Android</em>
<div class="floatimg"><a href="https://1.bp.blogspot.com/-DAAJWGccTCQ/We_MGiMuSFI/AAAAAAAAEtk/5_COppUTDusIIx725jENI3fd9rqlRl0gQCLcBGAs/s1600/image8.png" imageanchor="1"><img border="0" src="https://1.bp.blogspot.com/-DAAJWGccTCQ/We_MGiMuSFI/AAAAAAAAEtk/5_COppUTDusIIx725jENI3fd9rqlRl0gQCLcBGAs/s1600/image8.png" data-original-width="1024" data-original-height="1024"></a></div>

<p>
Android Studio 3.0 is ready to download today. Announced at Google I/O 2017,
Android Studio 3.0 is a large update focused on accelerating your app
development on Android.
</p>
<p>
This release of Android Studio is packed with many new updates, but there are
three major feature areas you do not want to miss, including: a new suite of app
profiling tools to quickly diagnose performance issues, support for the Kotlin
programming language, and a new set of tools and wizards to accelerate your
development on the latest Android Oreo APIs.
</p>
<p>
We also invested time in improving stability and performance across many areas
of Android Studio. Thanks to your feedback during the preview versions of
Android Studio 3.0! If you are looking for high stability, want to build high
quality apps for Android Oreo, develop with the Kotlin language, or use the
latest in Android app performance tools, then you should download Android Studio
3.0 today.
</p>
<p>
Check out the the list of new features in Android Studio 3.0 below, organized by
key developer flows.
</p>
<center></center>
<center><em>What’s new in Android Studio 3.0</em></center>
<h3>Develop </h3>
<ul><li><strong>Kotlin Programming Language</strong> -<strong> </strong>As <a href="https://android-developers.googleblog.com/2017/05/android-announces-support-for-kotlin.html">announced
at Google I/O 2017</a>, the <a href="https://kotlinlang.org/">Kotlin</a>
programming language is now officially supported for Android development. Kotlin
is an expressive and concise language that is interoperable with existing
Android languages and runtimes, which means you can use as little or as much of
the language in your app as you want.  Kotlin is a production-ready language
used by many popular Android apps on Google Play today. 
<p>
This release of Android Studio is the first milestone of bundles the Kotlin
language support inside the IDE. Many of your favorite features such as code
completion and syntax highlighting work well this release and we will continue
to improve the remaining editor features in upcoming release.  You can choose to
add Kotlin to your project using the built-in conversion tool found under
<strong>Code</strong> → <strong>Convert Java File to Kotlin File</strong>, or
create a Kotlin enabled project with the New Project Wizard. Lean more about
Kotlin language <a href="https://d.android.com/kotlin/get-started.html">support
in Android Studio</a>.</p></li></ul><div class="blogimg1"><a href="https://1.bp.blogspot.com/-ezg28xkLIKw/We_NGmvtLqI/AAAAAAAAEts/B5GMGAi639gLNAv9AHMh6yAjtd3ETDVBACLcBGAs/s1600/image1.png" imageanchor="1"><img border="0" src="https://1.bp.blogspot.com/-ezg28xkLIKw/We_NGmvtLqI/AAAAAAAAEts/B5GMGAi639gLNAv9AHMh6yAjtd3ETDVBACLcBGAs/s1600/image1.png" data-original-width="1545" data-original-height="652"></a></div>
<center><em>Kotlin Language Conversion in Android Studio</em></center>
<ul><li><strong>Java 8 Language features</strong> -<strong> </strong>In Android
Studio 3.0, we are continuing to improve the support for Java 8 language
features. With the <a href="https://android-developers.googleblog.com/2017/03/future-of-java-8-language-feature.html">migration
to a javac</a> based toolchain, using Java 8 language features in your project
is even easier. To update your project to support the new Java 8 Language
toolchain, simply update your <em>Source</em> and <em>Target</em> compatibility
levels to 1.8 in the Project Structure dialog. <a href="https://developer.android.com/studio/write/java8-support.html">Learn
more</a>. </li></ul><ul><li><strong>Layout Editor</strong> -<strong> </strong>The component tree in the
Layout Editor has with better drag-and-drop view insertions, and a new error
panel. <a href="https://developer.android.com/studio/write/layout-editor.html">Learn
more</a>.</li></ul><ul><li><strong>Adaptive Icon Wizard</strong> -<strong> </strong>The new wizard
creates  a set of launcher icon assets and provides previews of how your
adaptive icon will look with different launcher screen icon masks. Support for
VectorDrawable layers is new for this release. <a href="https://developer.android.com/studio/write/image-asset-studio.html">Learn
more</a>. </li></ul><ul><li><strong>XML Fonts &amp; Downloadable Fonts </strong>-<strong> </strong>If you
target Android Oreo (API Level 26 and higher) for your Android app, you can now
add custom fonts &amp; downloadable fonts using XML with Android Studio
3.0.</li></ul><ul><li><strong>Android Things Support </strong>-<strong> </strong>Android Studio
3.0 includes a new set of templates in the New Project wizard and the New Module
wizard to develop for the Android Things platform.  <a href="https://developer.android.com/things/index.html">Learn more</a>.
</li></ul><ul><li><strong>IntelliJ Platform Update</strong>: Android Studio 3.0 includes the
IntelliJ 2017.1 release, which has features such as Java 8 language refactoring,
parameter hints, semantic highlighting, draggable breakpoints, enhanced version
control search, and more. <a href="https://www.jetbrains.com/idea/whatsnew/#v2017-1">Learn
more</a>.</li></ul><h3>Build</h3>
<ul><li><strong>Instant App Support </strong>-<strong> </strong>With this release of
Android Studio, you can add <a href="https://developer.android.com/topic/instant-apps/index.html">Instant
Apps</a> features to your project. Available for<a href="https://android-developers.googleblog.com/2017/05/android-instant-apps-is-open-to-all.html">
full development earlier this year</a>, Instant Apps are lightweight Android
apps that your users can immediately run without installation.  <a href="https://developer.android.com/topic/instant-apps/index.html">Learn
more</a>. </li></ul><ul><li><strong>Build Speed Improvements </strong>-<strong> </strong>To further
improve the speed of Gradle for larger scale projects with many modules, we
introduced a rare <em>breaking API change in the Android Gradle Plugin</em> to
improve scalability and build times. This change is one of reasons we jumped
version numbers from Android Studio 2.4 to 3.0.  If you depend on APIs provided
by the previous Gradle plugin you should validate compatibility with the new
plugin and migrate to the new APIs. To test, update the plugin version in your
<code>build.gradle</code> file.  <a href="https://developer.android.com/studio/preview/features/new-android-plugin.html">Learn
more</a>.</li></ul><ul><li><strong>Google's Maven Repository </strong>-<strong> </strong>To facilitate
smaller and faster updates, Android Studio 3.0 utilizes Google's Maven
Repository by default instead of using the Android SDK Manager to find updates
to Android Support Library, Google Play Services, and Firebase Maven
dependencies. Used in combination with the latest command line <a href="https://developer.android.com/studio/intro/update.html#download-with-gradle">SDK
Manager tool</a> and <a href="https://developer.android.com/studio/intro/update.html#download-with-gradle">Gradle</a>,
Continuous Integration builds should migrate to Google's Maven Repository for
future Maven repository updates.  <a href="https://developer.android.com/studio/build/dependencies.html#google-maven">Learn
more</a>.</li></ul><h3>Test &amp; Debug</h3>
<ul><li><strong>Google Play System Images </strong>-<strong> </strong>We also
updated the emulator system images for Android Oreo to now include the Google
Play Store. Bundling in the Google Play store allows you to do end-to-end
testing of apps with Google Play, and provides a convenient way to keep Google
Play services up-to-date in your Android Virtual Device (AVD). Just as Google
Play services updates on physical devices, you can trigger the same updates on
your AVDs.  
<div class="blogimg2"><a href="https://3.bp.blogspot.com/-8UIAKpGRG-M/We_OiL3ry_I/AAAAAAAAEt4/_5rhIttX47QS0bptRPo9DU7X9Ak2ycG_QCLcBGAs/s1600/image4.png" imageanchor="1"><img border="0" src="https://3.bp.blogspot.com/-8UIAKpGRG-M/We_OiL3ry_I/AAAAAAAAEt4/_5rhIttX47QS0bptRPo9DU7X9Ak2ycG_QCLcBGAs/s1600/image4.png" data-original-width="1122" data-original-height="1076"></a></div>
<center><em>Google Play Store in Android Emulator</em></center>

<p>
To ensure app security and a consistent experience with physical devices, the
emulator system images with the Google Play store included are signed with a
release key. This means you will not be able to get elevated privileges. If you
require elevated privileges (root) to aid with your app troubleshooting, you can
use the Android Open Source Project (AOSP) emulator system images that do not
include Google apps or services. <a href="https://developer.android.com/studio/run/emulator.html">Learn more.</a>
</p></li></ul><ul><li><strong>OpenGL ES 3.0 Support in Android Emulator </strong>-<strong>
</strong>The latest version of the Android Emulator has OpenGL ES 3.0 support
for Android Oreo system images along with significant improvements in OpenGL ES
2.0 graphics performance for older emulator system images. <a href="https://developer.android.com/studio/run/emulator-acceleration.html">Learn
more</a>.</li></ul><ul><li><strong>App Bug Reporter in Android Emulator </strong>-<strong> </strong>To
help in documenting bugs in your app, we have added an easier way to generate a
bug report with the Android Emulator with all the necessary configuration
settings and space to capture your repro steps. <a href="https://developer.android.com/studio/report-bugs.html#emulator-bugs">Learn
more</a>.   </li></ul><ul><li><strong>Proxy Support in Android </strong>-<strong> </strong>If you use a
proxy to access the Internet, we have added a user interface to manage the HTTP
proxy settings used by the emulator. <a href="https://developer.android.com/studio/run/emulator-networking.html#proxy">Lean
more</a>. </li></ul><ul><li><strong>Android Emulator Quick Boot (Canary) </strong>-<strong> </strong>One
of the most common pain points we hear is that the emulator takes too long to
boot.  To address this concern, we are excited to preview a new feature to solve
this called Quick Boot, which significantly speeds up your emulator start time.
Once enabled, the first time you start an AVD a cold boot will occur (just like
powering on a device), but all subsequent starts are fast and the system is
restored to the state at which you closed the emulator (similar to waking a
device). If you want to try it out, ensure you are on the canary update release
channel and then you will find v26.2.0 of the Android Emulator in the SDK
Manager. <a href="https://developer.android.com/studio/preview/emulator.html">Learn
more</a>.  </li></ul><div class="blogimg3"><a href="https://1.bp.blogspot.com/-H5uYgwbhIRw/We_UsZFBx8I/AAAAAAAAEuI/lhVHeO4bU5QEzge2T9yaPQuc7UInPRnogCLcBGAs/s1600/image9.png" imageanchor="1"><img border="0" src="https://1.bp.blogspot.com/-H5uYgwbhIRw/We_UsZFBx8I/AAAAAAAAEuI/lhVHeO4bU5QEzge2T9yaPQuc7UInPRnogCLcBGAs/s1600/image9.png" data-original-width="1600" data-original-height="1043"></a></div>
<ul><li><strong>APK Debugging </strong>-<strong> </strong>Android Studio 3.0 allows
you to debug an arbitrary APK. This functionally is especially helpful for those
who develop your Android C++ code in another IDE, but want to debug and analyze
the APK in the context of Android Studio. As long as you have a debuggable
version of your APK, you can use the new APK Debugging features to analyze,
profile &amp; debug the APK. Moreover, if you have access to the sources of your
APK, you can link the source to the APK debugging flow for a higher fidelity
debugging process.  Get started by simply selecting <strong>Profile or debug
APK</strong> from the Android Studio Welcome Screen or <strong>File → Profile or
debug APK</strong>. <a href="https://developer.android.com/studio/preview/features/apk-debugger.html">Learn
More</a>.</li></ul><div class="blogimg4"><a href="https://3.bp.blogspot.com/-mORkxmNXgJc/We_VOWmeGYI/AAAAAAAAEuQ/LLWPUICDIKgHFLRVDIYDFV9r1mk9bYUlwCLcBGAs/s1600/image6.png" imageanchor="1"><img border="0" src="https://3.bp.blogspot.com/-mORkxmNXgJc/We_VOWmeGYI/AAAAAAAAEuQ/LLWPUICDIKgHFLRVDIYDFV9r1mk9bYUlwCLcBGAs/s1600/image6.png" data-original-width="1600" data-original-height="961"></a></div>
<center><em>APK Debugging</em></center>
<ul><li><strong>Layout Inspector </strong>-<strong> </strong>In this release we have
added a few additional enhancements for the Layout Inspector including better
grouping of properties into common categories, as well as search functionality
in both the View Tree and Properties Panels.  <a href="https://developer.android.com/studio/debug/layout-inspector.html">Learn
more</a>.</li></ul><ul><li><strong>Device File Explorer </strong>-<strong> </strong>The new Device File
Explorer in Android Studio 3.0 allows you to view the file and directory
structure of your Android device or emulator. As you are testing your app, you
can now quickly preview and modify app data files directly in Android Studio.
<a href="https://d.android.com/studio/debug/device-file-explorer.html">Learn
more</a>. </li></ul><ul><li><strong>Android Test Orchestrator Support</strong> - When used with
AndroidJUnitRunner 1.0 or higher, the Android Gradle plugin 3.0 supports the use
of the Android Test Orchestrator. The Android Test Orchestrator allows each of
your app's tests to run within its own <a href="https://developer.android.com/reference/android/app/Instrumentation.html">Instrumentation</a>.
<a href="https://developer.android.com/training/testing/junit-runner.html#using-android-test-orchestrator">Learn
more</a>.
<p></p></li></ul><strong><span>Optimize</span></strong>
<ul><li><strong>Android Profiler </strong>-<strong> </strong>Android Studio 3.0
includes a brand new suite of tools to help debug performance problems in your
app. We completely rewrote the previous set of Android Monitor tools, and
replaced them with the Android Profiler. Once you deploy your app to a running
device or emulator, click on the <strong>Android Profiler</strong> tab and you
will now have access to a real-time &amp; unified view of the CPU, Memory, &amp; Network
activity for your app. Each of the performance events are mapped to the UI event
timeline which highlights touch events, key presses, and activity changes so
that you have more context on when and why a certain event happened.  Click on
each timeline to dig into each performance aspect of your app. <a href="https://developer.android.com/studio/preview/features/android-profiler.html">Learn
more</a>. </li></ul><div class="blogimg5"><a href="https://2.bp.blogspot.com/-bK0QeifFdfs/We_V8zjOtDI/AAAAAAAAEuc/QGusE3IQcdQeQf7l0Qzq6WyXIGBRKeWigCLcBGAs/s1600/image2.png" imageanchor="1"><img border="0" src="https://2.bp.blogspot.com/-bK0QeifFdfs/We_V8zjOtDI/AAAAAAAAEuc/QGusE3IQcdQeQf7l0Qzq6WyXIGBRKeWigCLcBGAs/s1600/image2.png" data-original-width="1600" data-original-height="619"></a></div>
<center><em>Android Profiler - Combined timeline view.</em></center>

<div class="blogimg6"><a href="https://2.bp.blogspot.com/-btyJv3ipa5o/We_WRgdwxAI/AAAAAAAAEug/_-fbm6vmk_cEOL4IZYpgoXYlfNvuS0lvwCLcBGAs/s1600/image7.png" imageanchor="1"><img border="0" src="https://2.bp.blogspot.com/-btyJv3ipa5o/We_WRgdwxAI/AAAAAAAAEug/_-fbm6vmk_cEOL4IZYpgoXYlfNvuS0lvwCLcBGAs/s1600/image7.png" data-original-width="1600" data-original-height="1023"></a></div>
<center><em>CPU Profiler
</em></center>
<div class="blogimg7"><a href="https://3.bp.blogspot.com/-GiKRADK4aAQ/We_Wdc6GjTI/AAAAAAAAEuo/zLzrnL2WH70EMNzscaB95H3obVsUUJB8wCLcBGAs/s1600/image3.png" imageanchor="1"><img border="0" src="https://3.bp.blogspot.com/-GiKRADK4aAQ/We_Wdc6GjTI/AAAAAAAAEuo/zLzrnL2WH70EMNzscaB95H3obVsUUJB8wCLcBGAs/s1600/image3.png" data-original-width="1600" data-original-height="1023"></a></div>
<center>
<em>Memory Profiler</em>
</center>
<div class="blogimg8"><a href="https://3.bp.blogspot.com/-dOzg6FLRIP0/We_WsU_av9I/AAAAAAAAEus/sK0AMLwvAqk8sQ8Gqe5kfIhfnnvyAOUpgCLcBGAs/s1600/image5.png" imageanchor="1"><img border="0" src="https://3.bp.blogspot.com/-dOzg6FLRIP0/We_WsU_av9I/AAAAAAAAEus/sK0AMLwvAqk8sQ8Gqe5kfIhfnnvyAOUpgCLcBGAs/s1600/image5.png" data-original-width="1600" data-original-height="1023"></a></div>
<center>
<em>Network Profiler</em>
</center><ul><li><strong>APK Analyzer Improvements</strong> -<strong> </strong>We also
updated APK Analyzer with additional enhancements to help you further optimize
the size of your APK.  <a href="https://developer.android.com/studio/build/apk-analyzer.html">Learn
more</a>.</li></ul><p>
To recap, Android Studio 3.0 includes these new major features:
</p>
<div class="grid">
  <div class="box">
<p>
<strong>Develop</strong>
</p><ul><li><a href="http://d.android.com/kotlin/">Kotlin Language</a>
</li><li><a href="https://developer.android.com/studio/preview/features/java8-support.html">Java
8 Language</a>
</li><li><a href="https://developer.android.com/studio/write/layout-editor.html">Layout
Editor Improvements </a>
</li><li><a href="https://developer.android.com/preview/features/adaptive-icons.html">Adaptive
Icon Wizard</a>
</li><li><a href="https://developer.android.com/preview/features/working-with-fonts.html">XML
Fonts &amp; Downloadable Fonts</a>
</li><li><a href="https://developer.android.com/things/index.html">Android Things</a>
</li><li><a href="https://www.jetbrains.com/idea/whatsnew/#v2017-1">Intellij Platform
Update 2017.1</a> </li></ul><p>
<strong>Build</strong>
</p><ul><li><a href="https://developer.android.com/topic/instant-apps/index.html">Instant App
Support</a>
</li><li><a href="https://developer.android.com/studio/preview/features/new-android-plugin.html">Build
Speed Improvements</a>
</li><li><a href="http://developer.android.com/studio/build/dependencies.html#google-maven">Google's
Maven Repo Change</a></li></ul><p>
<strong>Optimize</strong>
</p><ul><li><a href="https://developer.android.com/studio/profile/cpu-profiler.html">CPU
Profiler</a>
</li><li><a href="https://developer.android.com/studio/profile/memory-profiler.html">Memory
Profiler</a>
</li><li><a href="https://developer.android.com/studio/profile/network-profiler.html">Network
Profiler</a>
</li><li><a href="https://developer.android.com/studio/build/apk-analyzer.html">APK
Analyzer Improvements</a></li></ul><p>
Check out the <a href="https://developer.android.com/studio/releases/index.html">release
notes</a> for more details.
</p>
<h3>Getting Started </h3>
<p>
<strong>Download </strong>
</p>
  </div>
  <div class="box">
<p>
<strong>Test &amp; Debug </strong>
</p><ul><li><a href="https://developer.android.com/studio/run/emulator.html">Emulator
Google Play System Images</a>
</li><li><a href="https://developer.android.com/studio/run/emulator-acceleration.html">Emulator
OpenGL ES 3.0 Support</a>
</li><li>Emulator Proxy Support
</li><li><a href="https://developer.android.com/studio/debug/bug-report.html">App Bug
Reporter</a>
</li><li><a href="https://developer.android.com/training/wearables/ui/rotary-input.html#emulator">Android
Wear Rotatory</a>
</li><li>Android Emulator Quick Boot (Canary)
</li><li><a href="https://developer.android.com/studio/preview/features/apk-debugger.html">APK
Debugging</a>
</li><li><a href="http://tools.android.com/tech-docs/layout-inspector">Layout
Inspector</a>
</li><li>Device File Explorer</li></ul></div>
</div>
<p>
If you are using a previous version of Android Studio, you can upgrade to
Android Studio 3.0 today or you can download the update from the official
Android Studio Preview <a href="https://developer.android.com/studio/preview/index.html">download
page</a>. As mentioned in this blog, there are some breaking Gradle Plugin API
changes to support new features in the IDE. Therefore, you should also update
your Android Gradle plugin version to 3.0.0 in your current project to test and
validate your app project setup.
</p>
<p>
We appreciate any feedback on things you like, issues or features you would like
to see. If you find a bug or issue, feel free to <a href="https://source.android.com/source/report-bugs#developer-tools">file an
issue</a>. Connect with us -- the Android Studio development team ‐ on our <a href="https://plus.google.com/103342515830390186255">Google+</a> page or on <a href="http://www.twitter.com/androidstudio">Twitter</a>
</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/blogspot/hsDu?a=zCRJ6H5cHwg:nZQlxIeT_0U:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/blogspot/hsDu?d=yIl2AUoC8zA" border="0"></a> <a href="http://feeds.feedburner.com/~ff/blogspot/hsDu?a=zCRJ6H5cHwg:nZQlxIeT_0U:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/blogspot/hsDu?i=zCRJ6H5cHwg:nZQlxIeT_0U:-BTjWOF_DHI" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/blogspot/hsDu/~4/zCRJ6H5cHwg" height="1" width="1" alt="">]]></content:encoded>
</item>
<item>
<title><![CDATA[Android Studio 3.0 Canary 1]]></title>
<description><![CDATA[By Jamal Eason, Product
Manager, Android

Just in time for Google I/O 2017, we're providing a sneak peak of Android Studio
3.0 - available to download today on our
canary release channel. Android Studio's our official IDE, purpose-built for
Android, and we keep increasing our investment. The feat...]]></description>
<link>https://tsecurity.de/de/160602/android-tipps/android-studio-30-canary-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/160602/android-tipps/android-studio-30-canary-1/</guid>
<pubDate>Wed, 17 May 2017 21:15:06 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<br><div class="separator">
<a href="https://4.bp.blogspot.com/-brgnjo5GUa0/WLhXuAwnQII/AAAAAAAAD88/oxL3WK0wiU8zRVDAKyt1sUo37VZLo3BrQCLcB/s1600/Android%2BLogo.png" imageanchor="1"><br></a><a href="https://4.bp.blogspot.com/-brgnjo5GUa0/WLhXuAwnQII/AAAAAAAAD88/oxL3WK0wiU8zRVDAKyt1sUo37VZLo3BrQCLcB/s1600/Android%2BLogo.png" imageanchor="1"><br></a><a href="https://4.bp.blogspot.com/-brgnjo5GUa0/WLhXuAwnQII/AAAAAAAAD88/oxL3WK0wiU8zRVDAKyt1sUo37VZLo3BrQCLcB/s1600/Android%2BLogo.png" imageanchor="1"><img border="0" height="160" src="https://4.bp.blogspot.com/-brgnjo5GUa0/WLhXuAwnQII/AAAAAAAAD88/oxL3WK0wiU8zRVDAKyt1sUo37VZLo3BrQCLcB/s200/Android%2BLogo.png" width="143"></a></div>
<em>By <a href="https://www.google.com/+JamalEason">Jamal Eason</a>, Product
Manager, Android</em>
<br><em><br></em>
Just in time for Google I/O 2017, we're providing a sneak peak of Android Studio
3.0 - available to <a href="https://developer.android.com/studio/preview/index.html">download</a> today on our
canary release channel. Android Studio's our official IDE, purpose-built for
Android, and we keep increasing our investment. The feature set in Android
Studio is focused on accelerating your app development flow and providing the
latest tools built for the Android platform.
<br><br>
To accelerate your development flow, Android Studio 3.0 includes three major
features: a new suite of app performance profiling tools to quickly diagnose
performance issues, support for the Kotlin programming language, and increased
Gradle build speeds for large sized app projects. Android Studio 3.0 also
tightly integrates with Android platform development with these additional key
features: support for Instant App development, inclusion of the Google Play
Store in the Android O emulator system images, and new wizards for Android O
development. Overall, this first canary release of Android Studio 3.0 has 20+
new features.
<br><br>
We have been quietly iterating on many of these features as part of the Android Studio 2.4
Canaries. Today we are renumbering the release to Android Studio 3.0 after
recognizing that we added many significant features, and that we had to
introduce a rare breaking change in the Android Gradle Plugin to improve
scalability and build times. If you want to target <a href="http://android-developers.googleblog.com/2017/05/whats-new-in-android-o-developer.html">Android O</a>, create an <a href="http://android-developers.googleblog.com/2017/05/android-instant-apps-is-open-to-all.html">Instant App</a>, start developing with the <a href="http://android-developers.googleblog.com/2017/05/android-announces-support-for-kotlin.html">Kotlin language </a>or use the latest in Android app
performance tools to improve your app quality then you should download Android
Studio 3.0 Canary 1 today.
<br><div>
</div>
<div>
<em>Android DevByte - What’s New in Android Studio 3.0 Canary 1</em><br><i><br></i>
<br><div>
Check out the the list below organized into key developer flow for the details of the new features in this first canary release of Android Studio 3.0.<br><br><h3>
Develop</h3>
<br><ul><li><strong>Kotlin Programming Language</strong> -<strong> </strong>By popular
request, Android Studio 3.0 now includes support for <a href="http://android-developers.googleblog.com/2017/05/android-announces-support-for-kotlin.html">Kotlin</a>. With this new language support, you
can seamlessly add Kotlin code next to your existing Android app code and have
access to all the great development tools found in Android Studio.  You can
choose to add Kotlin to your project using the built-in conversion tool found
under <strong>Code</strong> → <strong>Convert Java File to Kotlin File</strong>,
or you choose to create a Kotlin enabled project with the New Project Wizard.
Lean more about Kotlin language <a href="https://developer.android.com/kotlin">support in Android</a> and <a href="https://d.android.com/kotlin/get-started.html">Android Studio</a>.</li>
</ul><a href="https://4.bp.blogspot.com/-lHeuEY-SRDk/WRuYZwG9PII/AAAAAAAAEIc/Hoyf07WSM5UEPcines6EHPm-TqxsOy0SgCLcB/s1600/Screen%2BShot%2B2017-05-16%2Bat%2B5.24.36%2BPM.png" imageanchor="1"><img border="0" height="267" src="https://4.bp.blogspot.com/-lHeuEY-SRDk/WRuYZwG9PII/AAAAAAAAEIc/Hoyf07WSM5UEPcines6EHPm-TqxsOy0SgCLcB/s640/Screen%2BShot%2B2017-05-16%2Bat%2B5.24.36%2BPM.png" width="640"></a><br><center>
<em>Kotlin Language Conversion in Android Studio</em></center>
<div>
<br><br></div>
<ul><li><strong>Java 8 Language features</strong> -<strong> </strong>We are
continuing to evolve the support for Java 8 language features and APIs. With the
recent <a href="https://android-developers.googleblog.com/2017/03/future-of-java-8-language-feature.html">deprecation
of the Jack toolchain</a> and migration to the javac based toolchain, you have
access to features such as Instant Run for projects using the Java 8 language
features in Android Studio. To update your project to support the new Java 8
Language toolchain, simply update your <em>Source</em> and <em>Target</em>
compatibility levels to 1.8 in the Project Structure dialog. <a href="https://developer.android.com/studio/preview/features/java8-support.html">Learn
more</a>. </li>
</ul><div class="separator">
<a href="https://3.bp.blogspot.com/-zzGX2IibwyQ/WRuaSBSAoTI/AAAAAAAAEIo/vrTUOb7k65AOdiEpi9goTKuLnY7obuyowCLcB/s1600/Screen%2BShot%2B2017-05-16%2Bat%2B5.32.42%2BPM.png" imageanchor="1"><img border="0" height="438" src="https://3.bp.blogspot.com/-zzGX2IibwyQ/WRuaSBSAoTI/AAAAAAAAEIo/vrTUOb7k65AOdiEpi9goTKuLnY7obuyowCLcB/s640/Screen%2BShot%2B2017-05-16%2Bat%2B5.32.42%2BPM.png" width="640"></a><em>Update Project Structure Dialogue for Java 8 Language</em></div>
<div>
</div>
<br><br><br><br><ul><li><strong>Layout Editor</strong> -<strong> </strong>With this Android Studio
release, you will find additional enhancements to the Layout Editor. We have
updated the component tree with better drag-and-drop view insertions, and a new
error panel. In coordination with an update to <code>ConstraintLayout</code>,
the Layout Editor also supports creating view Barriers, creating Groups, and
enhances Chain Creation. <a href="https://developer.android.com/studio/write/layout-editor.html">Learn
more</a>.</li>
</ul><div class="separator">
<a href="https://4.bp.blogspot.com/-HZyj3VD96jA/WRucMgZZuNI/AAAAAAAAEI0/0qaSvv_50ZQmul67yIznTBLU4i_Q53_FACLcB/s1600/Screen%2BShot%2B2017-05-16%2Bat%2B5.40.30%2BPM.png" imageanchor="1"><img border="0" height="368" src="https://4.bp.blogspot.com/-HZyj3VD96jA/WRucMgZZuNI/AAAAAAAAEI0/0qaSvv_50ZQmul67yIznTBLU4i_Q53_FACLcB/s640/Screen%2BShot%2B2017-05-16%2Bat%2B5.40.30%2BPM.png" width="640"></a><em>Layout Editor Component Tree &amp; Warning Panel</em></div>
<div>
<br><br><br></div>
<ul><li><strong>Adaptive Icon Wizard</strong> -<strong> </strong>Android O
introduces adaptive launcher icons, which can display in different shapes across
different Android devices. The new Adaptive Launcher Icon wizard creates the new
and legacy launcher icon assets and provides previews of how your adaptive icon
will look on different launcher screen icon masks. Create a new asset by
right-clicking on the<strong> /res</strong> folder in your project then navigate
to → <strong>New</strong> → <strong>Image Asset</strong> → <strong>Launcher
Icons (Adaptive and Legacy) </strong> <a href="https://developer.android.com/preview/features/adaptive-icons.html">Learn
more</a>. </li>
</ul><div class="separator">
<a href="https://4.bp.blogspot.com/-YdVUEQRs6jg/WRueU5lQNoI/AAAAAAAAEJA/7aoBWnq2nwkUWMnXXr22LHmMjksin-j3ACLcB/s1600/Screen%2BShot%2B2017-05-16%2Bat%2B5.49.59%2BPM.png" imageanchor="1"><img border="0" height="428" src="https://4.bp.blogspot.com/-YdVUEQRs6jg/WRueU5lQNoI/AAAAAAAAEJA/7aoBWnq2nwkUWMnXXr22LHmMjksin-j3ACLcB/s640/Screen%2BShot%2B2017-05-16%2Bat%2B5.49.59%2BPM.png" width="640"></a><em>Adaptive Icon Wizard</em></div>
<div>
<div>
<br><br><br></div>
<ul><li><strong>XML Fonts &amp; Downloadable Fonts </strong>-<strong> </strong>Adding
custom fonts to your app (available when targeting Android O) is now even easier
with the XML fonts preview and font selection tools in Android Studio. You can
can also create a downloadable font resource for your app. Using downloadable
fonts allows you to use a custom font in your app while avoiding the need to
bundle in a font resource into your APK. To use downloadable fonts, ensure that
you device or emulator is running Google Play Services v11.2.63 or higher. <a href="https://developer.android.com/preview/features/working-with-fonts.html">Learn
more</a>.  </li>
</ul><div class="separator">
<a href="https://2.bp.blogspot.com/-YyJfefOOuYg/WRufh8oG_HI/AAAAAAAAEJM/uTgQ1p_GhtQsf9RUrISWfMSlJ48nB4gkQCLcB/s1600/Screen%2BShot%2B2017-05-16%2Bat%2B5.54.53%2BPM.png" imageanchor="1"><img border="0" height="416" src="https://2.bp.blogspot.com/-YyJfefOOuYg/WRufh8oG_HI/AAAAAAAAEJM/uTgQ1p_GhtQsf9RUrISWfMSlJ48nB4gkQCLcB/s640/Screen%2BShot%2B2017-05-16%2Bat%2B5.54.53%2BPM.png" width="640"></a><em>Downloadable Fonts Resource Picker <span class="Apple-tab-span"> </span></em></div>
<div class="separator">
<em><span class="Apple-tab-span"><br></span></em></div>
<div class="separator">
<a href="https://3.bp.blogspot.com/-9-R6bmQU9rE/WRugwGXaQhI/AAAAAAAAEJY/1eFsIT3RBi4DzQJknO5mrcClxWGjE3c9gCLcB/s1600/Screen%2BShot%2B2017-05-16%2Bat%2B6.00.17%2BPM.png" imageanchor="1"><img border="0" height="218" src="https://3.bp.blogspot.com/-9-R6bmQU9rE/WRugwGXaQhI/AAAAAAAAEJY/1eFsIT3RBi4DzQJknO5mrcClxWGjE3c9gCLcB/s640/Screen%2BShot%2B2017-05-16%2Bat%2B6.00.17%2BPM.png" width="640"></a><em>XML Fonts Preview<span class="Apple-tab-span"> </span></em></div>
<div>
</div>
<div class="separator">
<em><span class="Apple-tab-span"><br></span></em></div>
<div class="separator">
<em><span class="Apple-tab-span"><br></span></em></div>
<div>
<br></div>
<div>
<br></div>
<ul><li><strong>Android Things Support </strong>-<strong> </strong>With Android
Studio 3.0, you can start developing on Android Things with a new set of
templates in the New Project wizard and the New Module wizard. Android Things
allows you to extend your Android development knowledge into the Internet of
Things (IoT) device category.  <a href="https://developer.android.com/things/index.html">Learn more</a>.</li>
</ul><div>
<br></div>
<div class="separator">
<a href="https://1.bp.blogspot.com/-hddvLe6HWk4/WRui4egjJyI/AAAAAAAAEJk/JRLxBR_VhGY8IEsy9N6vQCS1TBNRvCu1gCLcB/s1600/Screen%2BShot%2B2017-05-16%2Bat%2B6.09.13%2BPM.png" imageanchor="1"><img border="0" height="398" src="https://1.bp.blogspot.com/-hddvLe6HWk4/WRui4egjJyI/AAAAAAAAEJk/JRLxBR_VhGY8IEsy9N6vQCS1TBNRvCu1gCLcB/s640/Screen%2BShot%2B2017-05-16%2Bat%2B6.09.13%2BPM.png" width="640"></a></div>
<div class="separator">
<em>Android Things New Module Wizard </em></div>
<div class="separator">
<em><br></em></div>
<div class="separator">
<em><br></em></div>
<div class="separator">
<em><br></em></div>
<div>
<br></div>
<ul><li><strong>IntelliJ Platform Update</strong>: Android Studio 3.0 Canary 1
includes the IntelliJ 2017.1 release, which has features such as Java 8 language
refactoring, parameter hints, semantic highlighting, draggable breakpoints,
enhanced version control search, and more. <a href="https://www.jetbrains.com/idea/whatsnew/#v2017-1">Learn
more</a>.</li>
</ul><div>
<br><h3>
Build</h3>
</div>
</div>
<ul><li><strong>Instant App Support </strong>-<strong> </strong>With Android Studio
3.0, you can create <a href="https://developer.android.com/topic/instant-apps/index.html">Instant
Apps</a> in your project. Instant Apps are lightweight Android apps that your
users can immediately run without installation. To support this, Android Studio
introduces two new module types: instant app and feature. Combined with a new
"Modularize" refactoring action and the <a href="https://developer.android.com/studio/write/app-link-indexing.html">App
Links Assistant</a>, Android Studio can help you extend your app into an Instant
App. To use you can use the New Module Wizard or right-click on a class and
navigate to: <strong>Refactor</strong> → <strong>Modularize</strong> <a href="http://android-developers.googleblog.com/2017/05/android-instant-apps-is-open-to-all.html">Learn more</a>. </li>
</ul><div>
<br></div>
<div class="separator">
<a href="https://2.bp.blogspot.com/-7s_5i1prU8k/WRumXwzk_KI/AAAAAAAAEJw/wlq8uV0D17oLd70hYNVJjNgpwfc_dkL8wCLcB/s1600/Untitled_document8.png" imageanchor="1"><img border="0" height="396" src="https://2.bp.blogspot.com/-7s_5i1prU8k/WRumXwzk_KI/AAAAAAAAEJw/wlq8uV0D17oLd70hYNVJjNgpwfc_dkL8wCLcB/s640/Untitled_document8.png" width="640"></a></div>
<div class="separator">
<em>Instant App Module Wizard</em></div>
<div>
<br></div>
<div>
<br><br></div>
<ul><li><strong>Build Speed Improvements </strong>-<strong> </strong>We are
continuing to invest in making build speeds faster. For this release, we focused
on improving speed for projects that have many modules. To achieve these speed
improvements and to support future enhancements, <em>we have made breaking API
changes</em> to the Android Gradle plugin used by Android Studio.  If you
depended on APIs provided by the previous plugin you should validate
compatibility with the new plugin and migrate applicable APIs. To test, update
the plugin version in your <code>
build.gradle</code> file.  <a href="https://developer.android.com/studio/preview/features/new-android-plugin.html">Learn more</a>.</li>
</ul><div>
<br></div>
<code></code><br><div class="code">
<code></code><br><div class="code">
<code>build.gradle</code></div>
<code>
</code></div>
<br><pre class="prettyprintcustom">dependencies {
   classpath 'com.android.tools.build:gradle:3.0.0-alpha1'
}</pre>
</div>
<ul><li><strong>Google's Maven Repository </strong>-<strong> </strong>Also, by
popular request, we are now distributing the Android Support Library maven
dependencies outside of the Android SDK Manager in a brand new Maven repository.
For those developing with a Continuous Integration (CI) system, this should make
Maven dependency management easier. Used in combination with the latest command
line <a href="https://developer.android.com/studio/intro/update.html#download-with-gradle">SDK
Manager tool</a> and <a href="https://developer.android.com/studio/intro/update.html#download-with-gradle">Gradle</a>,
CI builds should be easier to manage with Google's Maven Repository. To use the
the new Maven location, add the following url to your app module's
<code>build.gradle</code> file.  <a href="http://developer.android.com/studio/build/dependencies.html#google-maven">Learn more</a>.</li>
</ul><div class="code">
<div>
<code>build.gradle</code></div>
</div>
<pre class="prettyprintcustom">repositories {
   maven {
       url "https://maven.google.com"
   }
}
</pre>
<ul></ul><div>
<span></span><br></div>
<div>
<span><span><br></span></span></div>
<span>
</span>
<br><h3>
<span>Test &amp; Debug</span></h3>
<ul><li><strong>Google Play System Images </strong>-<strong> </strong>Along with the
update to the Android O Beta release, we updated the Android Emulator O system
images to include the Google Play Store. Bundling in the Google Play store
allows you to do end-to-end testing of apps with Google Play, and provides a
convenient way to keep Google Play services up-to-date in your Android Virtual
Device (AVD). Just as Google Play services updates on physical devices, you can
trigger the same updates on your AVDs.  </li>
</ul><div class="separator">
<a href="https://4.bp.blogspot.com/-44GDMUflbQM/WRurVK0GPaI/AAAAAAAAEKA/KG6cPrxcfaQEp_EO2b8DXOw2As7BQEvyACLcB/s1600/Untitled_document9.png" imageanchor="1"><img border="0" height="593" src="https://4.bp.blogspot.com/-44GDMUflbQM/WRurVK0GPaI/AAAAAAAAEKA/KG6cPrxcfaQEp_EO2b8DXOw2As7BQEvyACLcB/s640/Untitled_document9.png" width="640"></a></div>
<div class="separator">
<em>Google Play Store in Android Emulator</em></div>
<div>
<br><br><br></div>
<div class="separator">
<a href="https://4.bp.blogspot.com/-okSZTHiws6w/WRurwSZiYsI/AAAAAAAAEKE/NkLl-4rWFAgbErc8WSZUGBNCSBivbgC6QCLcB/s1600/Untitled_document10.png" imageanchor="1"><img border="0" height="538" src="https://4.bp.blogspot.com/-okSZTHiws6w/WRurwSZiYsI/AAAAAAAAEKE/NkLl-4rWFAgbErc8WSZUGBNCSBivbgC6QCLcB/s640/Untitled_document10.png" width="640"></a></div>
<div class="separator">
<em>Update Google Play Services in Android Emulator</em></div>
<div class="separator">
<em><br></em></div>
<div class="separator">
<em><br></em></div>
<div class="separator">
<em><br></em></div>
<div>
<br></div>
<div>
To ensure app security and a consistent experience with physical devices, the
emulator system images with the Google Play store included are signed with a
release key. This means you will not be able to get elevated privileges. If you
require elevated privileges (root) to aid with your app troubleshooting, you can
use the Android Open Source Project (AOSP) emulator system images that do not
include Google apps or services. To get started, make sure you are using Android
Emulator v26.1+, the latest system images API 24+ and then create a new AVD with
a Google Play icon next to the device definition. <a href="https://developer.android.com/studio/run/emulator.html">Learn more.</a>
</div>
<div>
<br></div>
<br><div class="separator">
<a href="https://4.bp.blogspot.com/-MsgkoqS9SPU/WRusSzxv-hI/AAAAAAAAEKM/gtYXdiPMMAMLitY38EGQFWfLYmtffZeCQCLcB/s1600/Untitled_document11.png" imageanchor="1"><img border="0" height="414" src="https://4.bp.blogspot.com/-MsgkoqS9SPU/WRusSzxv-hI/AAAAAAAAEKM/gtYXdiPMMAMLitY38EGQFWfLYmtffZeCQCLcB/s640/Untitled_document11.png" width="640"></a></div>
<div class="separator">
<em>Android Virtual Device Manager with Google Play Store Support </em></div>
<div>
<br><br><br><br><br></div>
<div>
</div>
<ul><li><b>OpenGL ES 3.0 Support in Android Emulator</b> - As a part of our ongoing investment in making your development experience fast, the latest version of the Android Emulator has OpenGL ES 3.0 support for Android O system images along with significant improvements in OpenGL ES 2.0 graphics performance for older emulator system images. Most modern graphics cards on all operating systems support OpenGL ES 2.0 acceleration. To use OpenGL ES 3.0 with the Android Emulator, your development machine needs a host GPU graphics card that supports OpenGL 3.2 or higher on Microsoft® Windows® or Linux (with Apple MacOS® support coming in the future). <a href="https://developer.android.com/studio/run/emulator-acceleration.html">Learn more</a>.</li>
</ul><br><div>
<br></div>
<div class="separator">
<a href="https://1.bp.blogspot.com/-9zTEvPDWlTs/WRusu2KQA7I/AAAAAAAAEKQ/TWBacAIL8Ok97nT-cTBg3BRdE1BXw6jQwCLcB/s1600/Untitled_document12.png" imageanchor="1"><img border="0" height="344" src="https://1.bp.blogspot.com/-9zTEvPDWlTs/WRusu2KQA7I/AAAAAAAAEKQ/TWBacAIL8Ok97nT-cTBg3BRdE1BXw6jQwCLcB/s640/Untitled_document12.png" width="640"></a></div>
<div class="separator">
<em>OpenGL ES 3.0 in Android Emulator</em></div>
<div>
<br><br><br><br></div>
<ul><li><strong>App Bug Reporter in Android Emulator </strong>-<strong> </strong>To
help in documenting bugs in your app, we have added an easier way to generate a
bug report with all the necessary configuration settings and space to capture
your repro steps. Additionally, if you want to share a specific emulator bug
with the Android team, we have also added a link to quickly generate a bug on
the Android Issue Tracker. To use this feature, navigate to the <strong>Emulator
Tool Bar</strong> → <strong>Extended Controls</strong> → <strong>Help</strong> →
<strong>Emulator Help</strong> → <strong>File a Bug</strong>. <a href="https://developer.android.com/studio/debug/bug-report.html">Learn
more</a>.   </li>
</ul><div>
<div class="separator">
<br></div>
<div class="separator">
<a href="https://1.bp.blogspot.com/-Cya9JApeEFA/WRutDad4wJI/AAAAAAAAEKU/cnfmghJv5Vkg6wgt-cOXUa8WNrss8DcMgCLcB/s1600/Untitled_document13.png" imageanchor="1"><img border="0" height="600" src="https://1.bp.blogspot.com/-Cya9JApeEFA/WRutDad4wJI/AAAAAAAAEKU/cnfmghJv5Vkg6wgt-cOXUa8WNrss8DcMgCLcB/s640/Untitled_document13.png" width="640"></a></div>
<div class="separator">
<em>App Bug Reporting in Android Emulator</em></div>
<div class="separator">
<em><br></em></div>
<div class="separator">
<em><br></em></div>
</div>
<div>
<ul><li><strong>Proxy Support in Android </strong>-<strong> </strong>For those who
need to use a HTTP proxy to access the Internet, we have added a user interface
to manage the proxy settings used by the emulator. By default, the Android
Emulator will now use the settings from Android Studio, but you can override
these settings for your network setup. To configure navigation to the
<strong>Extended Controls</strong> → <strong>Settings</strong> →
<strong>Proxy</strong>. </li>
</ul><div>
<div class="separator">
<a href="https://2.bp.blogspot.com/-5n5rvZxEmRA/WRuteQWd_BI/AAAAAAAAEKY/EieOKW2wZ4kugY87j8LBHrCI0FCEykpGwCLcB/s1600/Untitled_document14.png" imageanchor="1"><img border="0" height="486" src="https://2.bp.blogspot.com/-5n5rvZxEmRA/WRuteQWd_BI/AAAAAAAAEKY/EieOKW2wZ4kugY87j8LBHrCI0FCEykpGwCLcB/s640/Untitled_document14.png" width="640"></a></div>
<div class="separator">
<em>Android Emulator Proxy Settings</em></div>
<div>
<br><br></div>
</div>
<ul><li><strong>Android Wear Rotary Controls in Android Emulator </strong>-<strong>
</strong>The Android Emulator now supports rotary controls for the Android Wear
2.0 emulator system image. It is now easier to test your apps that target
Android Wear devices that include rotary input scrolling. To enable, create an
Emulator AVD that targets Android Wear, and the Rotary Input panel should appear
under Extended controls. <a href="https://developer.android.com/training/wearables/ui/rotary-input.html#emulator">Learn
more</a>.  </li>
</ul><div>
<br></div>
<div class="separator">
<a href="https://3.bp.blogspot.com/-n_TJ72D7ixw/WRuuAVCV48I/AAAAAAAAEKg/RyCdU-Xw8gk3ph1rDYtDP52HExF7xKnvQCLcB/s1600/Untitled_document15.png" imageanchor="1"><img border="0" height="486" src="https://3.bp.blogspot.com/-n_TJ72D7ixw/WRuuAVCV48I/AAAAAAAAEKg/RyCdU-Xw8gk3ph1rDYtDP52HExF7xKnvQCLcB/s640/Untitled_document15.png" width="640"></a></div>
<div class="separator">
<em>Rotary input in Android Emulator</em></div>
<div>
<br><br><br></div>
<ul><li><strong>APK Debugging </strong>-<strong> </strong>For those of you who just
want to debug an APK without building your project in Android Studio, the
Android Studio 3.0 release now has the ability to debug an arbitrary APK. This
functionally is especially helpful for those who develop your Android C++ code
in another development environment, but want to debug and analyze the APK in the
context of Android Studio. As long as you have a debuggable version of your APK,
you can use the new APK Debugging features to analyze, profile &amp; debug the APK.
Moreover, if you have access to the sources of your APK, you can link the source
to the APK debugging flow for a higher fidelity debugging process.  Get started
by simply selecting <strong>Profile or debug APK</strong> from the Android
Studio Welcome Screen or <strong>File → Profile or debug APK</strong>. <a href="https://developer.android.com/studio/preview/features/apk-debugger.html">Learn More</a>.</li>
</ul><div>
<br></div>
<div class="separator">
<a href="https://2.bp.blogspot.com/-9gMp5nOo5rM/WRuueexuPkI/AAAAAAAAEKk/w0TjKI9kM24RIib_2Rrw-S0cNjVe7cdgACLcB/s1600/Untitled_document16.png" imageanchor="1"><img border="0" height="463" src="https://2.bp.blogspot.com/-9gMp5nOo5rM/WRuueexuPkI/AAAAAAAAEKk/w0TjKI9kM24RIib_2Rrw-S0cNjVe7cdgACLcB/s640/Untitled_document16.png" width="640"></a></div>
<div class="separator">
<em>Profile or Debug an APK</em></div>
<div>
<br><br></div>
<div class="separator">
<a href="https://4.bp.blogspot.com/-Wc0TE7Aw21U/WRuuu5hcF9I/AAAAAAAAEKs/bg8N8ZtW43Ezf_licLqTjPRQD1HaK8sUACLcB/s1600/Untitled_document17.png" imageanchor="1"><img border="0" height="377" src="https://4.bp.blogspot.com/-Wc0TE7Aw21U/WRuuu5hcF9I/AAAAAAAAEKs/bg8N8ZtW43Ezf_licLqTjPRQD1HaK8sUACLcB/s640/Untitled_document17.png" width="640"></a></div>
<div class="separator">
<em>APK Debugging</em></div>
<div class="separator">
<em><br></em></div>
<div class="separator">
<em><br></em></div>
<div>
<ul><li><strong>Layout Inspector </strong>-<strong> </strong>You will find that the
Layout Inspector has a few additional enhancements in Android Studio 3.0 that
make it easier to debug issues in your app layouts. A couple of the enhancements
include better grouping of properties into common categories, as well as search
functionality in both the View Tree and Properties Panels. While an application
is running, access the Layout Inspector via <strong>Tools</strong> →
<strong>Android</strong> → <strong>Layout Inspector</strong>. <a href="http://tools.android.com/tech-docs/layout-inspector">Learn more</a>.</li>
</ul><div class="separator">
<a href="https://4.bp.blogspot.com/-AnXGQN3rPAY/WRuvMQFkSSI/AAAAAAAAEKw/QJax6eLPM1s4jom6XYY7u1rIAZF2DRvrQCLcB/s1600/Untitled_document18.png" imageanchor="1"><img border="0" height="379" src="https://4.bp.blogspot.com/-AnXGQN3rPAY/WRuvMQFkSSI/AAAAAAAAEKw/QJax6eLPM1s4jom6XYY7u1rIAZF2DRvrQCLcB/s640/Untitled_document18.png" width="640"></a></div>
<div class="separator">
<em>Layout Inspector</em></div>
<div class="separator">
<em><br></em></div>
<div class="separator">
<em><br></em></div>
</div>
<ul><li><strong>Device File Explorer </strong>-<strong> </strong>Ported from DDMS
into Android Studio by popular demand, the new Device File Explorer allows you
to view the file and directory structure of your Android device or emulator. As
you are testing your app, you can now quickly preview and modify app data files
directly in Android Studio.</li>
</ul><div>
<br></div>
<div class="separator">
<a href="https://1.bp.blogspot.com/-AXNjf7DcsPc/WRuvmxc-F8I/AAAAAAAAEK0/ConW_Yck8R80WbTtrYT1sHfXnVh9SflRACLcB/s1600/Untitled_document19.png" imageanchor="1"><img border="0" height="475" src="https://1.bp.blogspot.com/-AXNjf7DcsPc/WRuvmxc-F8I/AAAAAAAAEK0/ConW_Yck8R80WbTtrYT1sHfXnVh9SflRACLcB/s640/Untitled_document19.png" width="640"></a></div>
<div class="separator">
<em>Device File Explorer</em></div>
<div class="separator">
<em><br></em></div>
<div class="separator">
<em><br></em></div>
<div class="separator">
<br></div>
<h3>
Optimize</h3>
<div>
<ul><li><b>Android Profiler</b> - Android Studio 3.0 includes a brand new suite of tools to help debug performance problems in your app. We completely rewrote the previous set of Android Monitor tools, and replaced them with the Android Profiler. Once you deploy your app to a running device or emulator, click on the <b>Android Profiler</b> tab and you will now have access to a real-time &amp; unified view of the CPU, Memory, &amp; Network activity for your app. Each of the performance events are mapped to the UI event timeline which highlights touch events, key presses, and activity changes so that you have more context on when and why a certain event happened.  Click on each timeline to dig into each performance aspect of your app. <a href="https://developer.android.com/studio/preview/features/android-profiler.html">Learn more</a>. </li>
</ul><div>
<br></div>
<div class="separator">
<a href="https://3.bp.blogspot.com/-ldsm-bneWBA/WRuwE497u5I/AAAAAAAAEK4/3gd7l7XjC7wuhHYdVFNuwQGrw8uYnYpRQCLcB/s1600/Untitled_document20.png" imageanchor="1"><img border="0" height="286" src="https://3.bp.blogspot.com/-ldsm-bneWBA/WRuwE497u5I/AAAAAAAAEK4/3gd7l7XjC7wuhHYdVFNuwQGrw8uYnYpRQCLcB/s640/Untitled_document20.png" width="640"></a></div>
<div class="separator">
<em>Android Profiler - Combined timeline view.</em></div>
<div class="separator">
<em><br></em></div>
</div>
<ul><li><strong>CPU Profiler </strong>-<strong> </strong>Unnecessary CPU processing
and load spikes are symptoms of poor app performance.  With the CPU Profiler,
you can analyze the CPU thread usage of your app by triggering a sample or
instrumented CPU trace. At this point, you can troubleshoot CPU performance
issues using a variety of data views and filters built into the CPU Profiler. <a href="https://developer.android.com/studio/profile/cpu-profiler.html">Learn more</a>.</li>
</ul><div class="separator">
<br></div>
<div class="separator">
<a href="https://3.bp.blogspot.com/-ZDxNakmTddo/WRuwWl4Hc5I/AAAAAAAAELA/nAAjBOzpC_QCJU11Aa-Vs0e8U5FGaGCiwCLcB/s1600/Untitled_document21.png" imageanchor="1"><img border="0" height="376" src="https://3.bp.blogspot.com/-ZDxNakmTddo/WRuwWl4Hc5I/AAAAAAAAELA/nAAjBOzpC_QCJU11Aa-Vs0e8U5FGaGCiwCLcB/s640/Untitled_document21.png" width="640"></a></div>
<em>CPU Profiler</em><br><em><br></em>
<em><br></em></div>
<ul><li><strong>Memory Profiler</strong> -<strong> </strong> Using memory
inefficiently can lead to many device problems ranging from a janky UI to low
memory events. The Memory Profiler combines the functionality of the previous
Heap Viewer and Allocation Tracker in one rich interface to help debug memory
usage problems in your app. You can diagnose a range of memory issues by
analyzing memory allocations, heap dumps and more. <a href="https://developer.android.com/studio/profile/memory-profiler.html">Learn more</a>.</li>
</ul><div>
<div>
<br></div>
</div>
<div>
<div class="separator">
<a href="https://1.bp.blogspot.com/-80loiOrn5Z8/WRuw99AssFI/AAAAAAAAELI/tDPfHoISCnsIiHbMR-deITizLHgubOlVgCLcB/s1600/Untitled_document22.png" imageanchor="1"><img border="0" height="376" src="https://1.bp.blogspot.com/-80loiOrn5Z8/WRuw99AssFI/AAAAAAAAELI/tDPfHoISCnsIiHbMR-deITizLHgubOlVgCLcB/s640/Untitled_document22.png" width="640"></a></div>
<div class="separator">
<em>Memory Profiler</em></div>
<div class="separator">
<em><br></em></div>
<div class="separator">
<em><br></em></div>
<div class="separator">
<em><br></em></div>
</div>
<ul><li><strong>Network Profiler</strong> -<strong> </strong>Optimizing foreground
and background network usage in your app can lead to a more performant app and
lower app data usage. The network profiler allows you to monitor the network
activity of your app, inspect the payload of each of your network requests, and
link back to the line of source code that generated the network request.
Currently, the network profiler works with <a href="https://developer.android.com/reference/java/net/HttpURLConnection.html">HttpURLConnection</a>,
<a href="http://square.github.io/okhttp/">OkHttp</a>, and <a href="https://developer.android.com/training/volley/index.html">Volley</a>
network libraries. The network profiler is an advanced analysis feature that can
be enabled on Pre-Android O devices &amp; emulators by selecting <em>Enable Advanced
Profiling</em> in the Profiling Tab in the Run Configuration box. In addition to
enabling network request and payload analysis, this checkbox enables event
collection at the top level, memory object count, and memory garbage collection.
 For Android O-based devices and emulator, just deploy your app. <a href="https://developer.android.com/studio/profile/network-profiler.html">Learn more</a>.</li>
</ul><div>
<div class="separator">
<a href="https://4.bp.blogspot.com/-J3S4UdSMzRA/WRuxdBRfmrI/AAAAAAAAELQ/qjlVRSND1Goh3zEVmo599kBPeBh4ZBEYACLcB/s1600/Untitled_document23.png" imageanchor="1"><img border="0" height="376" src="https://4.bp.blogspot.com/-J3S4UdSMzRA/WRuxdBRfmrI/AAAAAAAAELQ/qjlVRSND1Goh3zEVmo599kBPeBh4ZBEYACLcB/s640/Untitled_document23.png" width="640"></a></div>
<div class="separator">
<em>Network Profiler</em></div>
<div class="separator">
<em><br></em></div>
<div class="separator">
<em><br></em></div>
<div class="separator">
<em><br></em></div>
<div class="separator">
<em><br></em></div>
<div>
<div class="separator">
<a href="https://4.bp.blogspot.com/-TuWuC_XpCA0/WRuxqTmfYSI/AAAAAAAAELU/iLiINZ0mLwUxWcbTpH5lBTRK3LgpHsE1ACLcB/s1600/Untitled_document24.png" imageanchor="1"><img border="0" height="448" src="https://4.bp.blogspot.com/-TuWuC_XpCA0/WRuxqTmfYSI/AAAAAAAAELU/iLiINZ0mLwUxWcbTpH5lBTRK3LgpHsE1ACLcB/s640/Untitled_document24.png" width="640"></a></div>
<div class="separator">
<em>Network Profiler Setup for Pre- Android O Devices</em></div>
<div class="separator">
<em><br></em></div>
<div class="separator">
<em><br></em></div>
<div>
<ul><li><strong>APK Analyzer Improvements</strong> -<strong> </strong>In Android
Studio 3.0, we have added some additional enhancements to the APK Analyzer to
help you further optimize the size of your APK. With this feature update, you
can now analyze Instant App zip files &amp; AARs, and view dex bytecode of classes &amp;
methods. You can also generate Proguard configuration rules and load Proguard
mapping files in the dex viewer.  <a href="https://developer.android.com/studio/build/apk-analyzer.html">Learn
more</a>.</li>
</ul><div>
<br></div>
</div>
<div class="separator">
<a href="https://3.bp.blogspot.com/-nLI51BtTL0Y/WRux-GmCeCI/AAAAAAAAELY/JhV81jDLfUkxYHiFdqbV7T1jX3sK_2ZfwCLcB/s1600/Untitled_document25.png" imageanchor="1"><img border="0" height="480" src="https://3.bp.blogspot.com/-nLI51BtTL0Y/WRux-GmCeCI/AAAAAAAAELY/JhV81jDLfUkxYHiFdqbV7T1jX3sK_2ZfwCLcB/s640/Untitled_document25.png" width="640"></a></div>
<div class="separator">
<em>APK Analyzer</em></div>
<div>
<br><br><br><br><br><br><div>
To recap, Android Studio 3.0 Canary 1 includes these new major features: </div>
<table><tbody><tr><td><strong><br></strong>
<strong><br></strong>
<strong>Develop</strong><br><ul><li><a href="http://android-developers.googleblog.com/2017/05/android-announces-support-for-kotlin.html">Kotlin Language</a>
</li>
<li><a href="https://developer.android.com/studio/preview/features/java8-support.html">Java
8 Language</a>
</li>
<li><a href="https://developer.android.com/studio/write/layout-editor.html">Layout
Editor Improvements </a>
</li>
<li><a href="https://developer.android.com/preview/features/adaptive-icons.html">Adaptive
Icon Wizard</a>
</li>
<li><a href="https://developer.android.com/preview/features/working-with-fonts.html">XML
Fonts &amp; Downloadable Fonts</a>
</li>
<li><a href="https://developer.android.com/things/index.html">Android Things</a>
</li>
<li><a href="https://www.jetbrains.com/idea/whatsnew/#v2017-1">Intellij Platform
Update 2017.1</a> </li>
</ul><strong><br></strong>
<strong><br></strong>
<strong>Build</strong><br><ul><li><a href="http://android-developers.googleblog.com/2017/05/android-instant-apps-is-open-to-all.html">Instant App Support</a>
</li>
<li><a href="https://developer.android.com/studio/preview/features/new-android-plugin.html">Build Speed Improvements</a>
</li>
<li><a href="http://developer.android.com/studio/build/dependencies.html#google-maven">Google's Maven Repo Change</a></li>
</ul></td>
   <td><strong><br></strong>
<strong><br></strong><strong>Test &amp; Debug</strong><br><ul><li><a href="https://developer.android.com/studio/run/emulator.html">Emulator
Google Play System Images</a>
</li>
<li><a href="https://developer.android.com/studio/run/emulator-acceleration.html">Emulator
OpenGL ES 3.0 Support</a>
</li>
<li>Emulator Proxy Support
</li>
<li><a href="https://developer.android.com/studio/debug/bug-report.html">App Bug
Reporter</a>
</li>
<li><a href="https://developer.android.com/training/wearables/ui/rotary-input.html#emulator">Android
Wear Rotatory</a>
</li>
<li><a href="https://developer.android.com/studio/preview/features/apk-debugger.html">APK Debugging</a></li>
<li><a href="http://tools.android.com/tech-docs/layout-inspector">Layout
Inspector</a>
</li>
<li>Device File Explorer</li>
</ul><strong><br></strong>
<strong>Optimize</strong><br><ul><li><a href="https://developer.android.com/studio/preview/features/android-profiler.html">CPU
Profiler</a>
</li>
<li><a href="https://developer.android.com/studio/profile/memory-profiler.html">Memory Profiler</a>
</li>
<li><a href="https://developer.android.com/studio/profile/network-profiler.html">Network Profiler</a>
</li>
<li><a href="https://developer.android.com/studio/build/apk-analyzer.html">APK
Analyzer Improvements</a></li>
</ul></td>
  </tr></tbody></table></div>
<div>
Check out the <a href="http://developer.android.com/studio/preview/features/index.html">release notes</a> for more details.<br><h3>
</h3>
<h3>
Getting Started  </h3>
<h4>
Download</h4>
If you are using a previous version of Android Studio, you can install Android
Studio 3.0 Canary 1 <a href="https://developer.android.com/studio/preview/install-preview.html">alongside
your stable version</a>. You can download this update from the official Android
Studio Preview <a href="https://developer.android.com/studio/preview/index.html">download
page</a>. As mention in this blog, there are some breaking Gradle Plugin API
changes to support new features in the IDE. Therefore, you should also update
your Android Gradle plugin version to 3.0.0-alpha1 in your current project to
test and validate your app project setup.
<br><br><br>
We appreciate any feedback on things you like, issues or features you would like
to see. If you find a bug or issue, feel free to <a href="https://source.android.com/source/report-bugs#developer-tools">file an
issue</a>. Connect with us -- the Android Studio development team ‐ on our <a href="https://plus.google.com/103342515830390186255">Google+</a> page or on <a href="http://www.twitter.com/androidstudio">Twitter</a>.
<br><br><br><br><br></div>
</div>
</div>
</div>
</div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/blogspot/hsDu?a=ohJ9yEqwnLM:IHLFfIEEJIk:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/blogspot/hsDu?d=yIl2AUoC8zA" border="0"></a> <a href="http://feeds.feedburner.com/~ff/blogspot/hsDu?a=ohJ9yEqwnLM:IHLFfIEEJIk:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/blogspot/hsDu?i=ohJ9yEqwnLM:IHLFfIEEJIk:-BTjWOF_DHI" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/blogspot/hsDu/~4/ohJ9yEqwnLM" height="1" width="1" alt="">]]></content:encoded>
</item>
<item>
<title><![CDATA[Qt 5.8 Massive Release Lets You Create Devices with Multiple UI Processes, More]]></title>
<description><![CDATA[It took the Qt developers more than two and a half months to finish the feature set of Qt 5.8, the next major release of the multiplatform and open-source software development framework for creating modern graphical user interfaces for mobile and desktop platforms.

Qt 5.8 is everything you love ...]]></description>
<link>https://tsecurity.de/de/116034/it-security-nachrichten/qt-58-massive-release-lets-you-create-devices-with-multiple-ui-processes-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/116034/it-security-nachrichten/qt-58-massive-release-lets-you-create-devices-with-multiple-ui-processes-more/</guid>
<pubDate>Tue, 24 Jan 2017 02:46:14 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It took the Qt developers more than two and a half months to finish the feature set of Qt 5.8, the next major release of the multiplatform and open-source software development framework for creating modern graphical user interfaces for mobile and desktop platforms.

Qt 5.8 is everything you love about Qt, but faster, more powerful, and lighter. It improves the cross-platform compatibility for Linux, Android, macOS, and Microsoft Windows accelerating your development of beautiful products for any device, including Internet of Things (IoT). Qt 5.8 introduces a new way to configure Qt for your needs thanks to a new project codenamed Qt Lite.

"Implementing support for this put us on a longer journey, where we rewrote most parts of the system that was being used to configure Qt. The new system cleans up a system that had grown over the last 15 years, and that also lead to many inconsistencies on how Qt was ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Qt 5.8 Massive Release Lets You Create Devices with Multiple UI Processes, More]]></title>
<description><![CDATA[It took the Qt developers more than two and a half months to finish the feature set of Qt 5.8, the next major release of the multiplatform and open-source software development framework for creating modern graphical user interfaces for mobile and desktop platforms.

Qt 5.8 is everything you love ...]]></description>
<link>https://tsecurity.de/de/116034/it-security-nachrichten/qt-58-massive-release-lets-you-create-devices-with-multiple-ui-processes-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/116034/it-security-nachrichten/qt-58-massive-release-lets-you-create-devices-with-multiple-ui-processes-more/</guid>
<pubDate>Tue, 24 Jan 2017 02:46:14 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It took the Qt developers more than two and a half months to finish the feature set of Qt 5.8, the next major release of the multiplatform and open-source software development framework for creating modern graphical user interfaces for mobile and desktop platforms.

Qt 5.8 is everything you love about Qt, but faster, more powerful, and lighter. It improves the cross-platform compatibility for Linux, Android, macOS, and Microsoft Windows accelerating your development of beautiful products for any device, including Internet of Things (IoT). Qt 5.8 introduces a new way to configure Qt for your needs thanks to a new project codenamed Qt Lite.

"Implementing support for this put us on a longer journey, where we rewrote most parts of the system that was being used to configure Qt. The new system cleans up a system that had grown over the last 15 years, and that also lead to many inconsistencies on how Qt was ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Lawyer Rewrites Instagram's Privacy Policy So Kids and Parents Can Have a Meaningful Talk About Privacy]]></title>
<description><![CDATA[Kids, of age between 12 and 15, are increasingly joining Facebook's Instagram service, but according to a research, they likely don't even understand what they are signing up for. Jenny Afia, a privacy law expert at Schillings, a UK-based law firm, rewrote Instagram's terms of service in child-fr...]]></description>
<link>https://tsecurity.de/de/110345/it-security-nachrichten/lawyer-rewrites-instagrams-privacy-policy-so-kids-and-parents-can-have-a-meaningful-talk-about-privacy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/110345/it-security-nachrichten/lawyer-rewrites-instagrams-privacy-policy-so-kids-and-parents-can-have-a-meaningful-talk-about-privacy/</guid>
<pubDate>Mon, 09 Jan 2017 17:46:08 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kids, of age between 12 and 15, are increasingly joining Facebook's Instagram service, but according to a research, they likely don't even understand what they are signing up for. Jenny Afia, a privacy law expert at Schillings, a UK-based law firm, rewrote Instagram's terms of service in child-friendly language, so that not only the kids but their parents are able to understand what things are at stake. Highlighted are the changes the lawyer has made: Officially you own any original pictures and videos you post, but we are allowed to use them, and we can let others use them as well, anywhere around the world. Other people might pay us to use them and we will not pay you for that. [...] We may keep, use and share your personal information with companies connected with Instagram. This information includes your name, email address, school, where you live, pictures, phone number, your likes and dislikes, where you go, who your friends are, how often you use Instagram, and any other personal information we find such as your birthday or who you are chatting with, including in private messages (DMs). [...] We might send you adverts connected to your interests which we are monitoring. You cannot stop us doing this and it will not always be obvious that it is an advert.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Lawyer+Rewrites+Instagram's+Privacy+Policy+So+Kids+and+Parents+Can+Have+a+Meaningful+Talk+About+Privacy%3A+http%3A%2F%2Fbit.ly%2F2iaFDk8"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F17%2F01%2F09%2F1413215%2Flawyer-rewrites-instagrams-privacy-policy-so-kids-and-parents-can-have-a-meaningful-talk-about-privacy%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>

<a class="nobg" href="http://plus.google.com/share?url=https://yro.slashdot.org/story/17/01/09/1413215/lawyer-rewrites-instagrams-privacy-policy-so-kids-and-parents-can-have-a-meaningful-talk-about-privacy?utm_source=slashdot&amp;utm_medium=googleplus"><img src="http://www.gstatic.com/images/icons/gplus-16.png" alt="Share on Google+"></a>                                                                                                                                                                              



</div><p><a href="https://yro.slashdot.org/story/17/01/09/1413215/lawyer-rewrites-instagrams-privacy-policy-so-kids-and-parents-can-have-a-meaningful-talk-about-privacy?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lawyer Rewrites Instagram's Privacy Policy So Kids and Parents Can Have a Meaningful Talk About Privacy]]></title>
<description><![CDATA[Kids, of age between 12 and 15, are increasingly joining Facebook's Instagram service, but according to a research, they likely don't even understand what they are signing up for. Jenny Afia, a privacy law expert at Schillings, a UK-based law firm, rewrote Instagram's terms of service in child-fr...]]></description>
<link>https://tsecurity.de/de/110345/it-security-nachrichten/lawyer-rewrites-instagrams-privacy-policy-so-kids-and-parents-can-have-a-meaningful-talk-about-privacy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/110345/it-security-nachrichten/lawyer-rewrites-instagrams-privacy-policy-so-kids-and-parents-can-have-a-meaningful-talk-about-privacy/</guid>
<pubDate>Mon, 09 Jan 2017 17:46:08 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kids, of age between 12 and 15, are increasingly joining Facebook's Instagram service, but according to a research, they likely don't even understand what they are signing up for. Jenny Afia, a privacy law expert at Schillings, a UK-based law firm, rewrote Instagram's terms of service in child-friendly language, so that not only the kids but their parents are able to understand what things are at stake. Highlighted are the changes the lawyer has made: Officially you own any original pictures and videos you post, but we are allowed to use them, and we can let others use them as well, anywhere around the world. Other people might pay us to use them and we will not pay you for that. [...] We may keep, use and share your personal information with companies connected with Instagram. This information includes your name, email address, school, where you live, pictures, phone number, your likes and dislikes, where you go, who your friends are, how often you use Instagram, and any other personal information we find such as your birthday or who you are chatting with, including in private messages (DMs). [...] We might send you adverts connected to your interests which we are monitoring. You cannot stop us doing this and it will not always be obvious that it is an advert.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Lawyer+Rewrites+Instagram's+Privacy+Policy+So+Kids+and+Parents+Can+Have+a+Meaningful+Talk+About+Privacy%3A+http%3A%2F%2Fbit.ly%2F2iaFDk8"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F17%2F01%2F09%2F1413215%2Flawyer-rewrites-instagrams-privacy-policy-so-kids-and-parents-can-have-a-meaningful-talk-about-privacy%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>

<a class="nobg" href="http://plus.google.com/share?url=https://yro.slashdot.org/story/17/01/09/1413215/lawyer-rewrites-instagrams-privacy-policy-so-kids-and-parents-can-have-a-meaningful-talk-about-privacy?utm_source=slashdot&amp;utm_medium=googleplus"><img src="http://www.gstatic.com/images/icons/gplus-16.png" alt="Share on Google+"></a>                                                                                                                                                                              



</div><p><a href="https://yro.slashdot.org/story/17/01/09/1413215/lawyer-rewrites-instagrams-privacy-policy-so-kids-and-parents-can-have-a-meaningful-talk-about-privacy?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA['Fake News' And How The Washington Post Rewrote Its Story On Russian Hacking Of The Power Grid]]></title>
<description><![CDATA[What the Washington Post’s rush to be the first to report on Russian hackers breaching the US power grid teaches us about how “breaking news” can all too often become “fake news” when we over-trust government sources and fail to verify facts]]></description>
<link>https://tsecurity.de/de/109613/it-security-nachrichten/fake-news-and-how-the-washington-post-rewrote-its-story-on-russian-hacking-of-the-power-grid/</link>
<guid isPermaLink="true">https://tsecurity.de/de/109613/it-security-nachrichten/fake-news-and-how-the-washington-post-rewrote-its-story-on-russian-hacking-of-the-power-grid/</guid>
<pubDate>Sat, 07 Jan 2017 21:02:07 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[What the Washington Post’s rush to be the first to report on Russian hackers breaching the US power grid teaches us about how “breaking news” can all too often become “fake news” when we over-trust government sources and fail to verify facts]]></content:encoded>
</item>
<item>
<title><![CDATA['Fake News' And How The Washington Post Rewrote Its Story On Russian Hacking Of The Power Grid]]></title>
<description><![CDATA[What the Washington Post’s rush to be the first to report on Russian hackers breaching the US power grid teaches us about how “breaking news” can all too often become “fake news” when we over-trust government sources and fail to verify facts]]></description>
<link>https://tsecurity.de/de/109613/it-security-nachrichten/fake-news-and-how-the-washington-post-rewrote-its-story-on-russian-hacking-of-the-power-grid/</link>
<guid isPermaLink="true">https://tsecurity.de/de/109613/it-security-nachrichten/fake-news-and-how-the-washington-post-rewrote-its-story-on-russian-hacking-of-the-power-grid/</guid>
<pubDate>Sat, 07 Jan 2017 21:02:07 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[What the Washington Post’s rush to be the first to report on Russian hackers breaching the US power grid teaches us about how “breaking news” can all too often become “fake news” when we over-trust government sources and fail to verify facts]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker Compromises Fosshub to Distribute MBR-Hijacking Malware]]></title>
<description><![CDATA[A hacker who goes by the Cult of Peggle handle on Twitter has compromised Fosshub and embedded malware inside some of the files hosted on the website that were offered for download.

According to Cult of Peggle, he breached the website and embedded a malware payload inside some of the files hoste...]]></description>
<link>https://tsecurity.de/de/58136/it-security/hacker-compromises-fosshub-to-distribute-mbr-hijacking-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/58136/it-security/hacker-compromises-fosshub-to-distribute-mbr-hijacking-malware/</guid>
<pubDate>Wed, 03 Aug 2016 13:20:11 +0200</pubDate>
<category>📰 IT Security</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A hacker who goes by the Cult of Peggle handle on Twitter has compromised Fosshub and embedded malware inside some of the files hosted on the website that were offered for download.

According to Cult of Peggle, he breached the website and embedded a malware payload inside some of the files hosted on Fosshub, a downloads portal, in the same category as Softpedia.

Infected applications include Audacity, an audio editor and recorder, and Classic Shell, an app for enhancing the Windows desktop experience.

Based on tweets, the hacker seems to have compromised the Fosshub accounts for the developers of those two projects.

Malware rewrote MBR with harmless message

According to multiple reports from users complaining on 4chan and the]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker Compromises Fosshub to Distribute MBR-Hijacking Malware]]></title>
<description><![CDATA[A hacker who goes by the Cult of Peggle handle on Twitter has compromised Fosshub and embedded malware inside some of the files hosted on the website that were offered for download.

According to Cult of Peggle, he breached the website and embedded a malware payload inside some of the files hoste...]]></description>
<link>https://tsecurity.de/de/58136/it-security/hacker-compromises-fosshub-to-distribute-mbr-hijacking-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/58136/it-security/hacker-compromises-fosshub-to-distribute-mbr-hijacking-malware/</guid>
<pubDate>Wed, 03 Aug 2016 13:20:11 +0200</pubDate>
<category>📰 IT Security</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A hacker who goes by the Cult of Peggle handle on Twitter has compromised Fosshub and embedded malware inside some of the files hosted on the website that were offered for download.

According to Cult of Peggle, he breached the website and embedded a malware payload inside some of the files hosted on Fosshub, a downloads portal, in the same category as Softpedia.

Infected applications include Audacity, an audio editor and recorder, and Classic Shell, an app for enhancing the Windows desktop experience.

Based on tweets, the hacker seems to have compromised the Fosshub accounts for the developers of those two projects.

Malware rewrote MBR with harmless message

According to multiple reports from users complaining on 4chan and the]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,17ms -->